What This Update Actually Is
App Install Governance is a new admin control layer inside HubSpot. It lives at Settings > Integrations > Connected Apps under a new "Approved Apps" tab.
Before this shipped, any user with the right permissions could install an app. Admins had limited visibility into what was connected, who connected it, and what data it could touch. That gap was already uncomfortable for most RevOps and IT leads. Then AI connectors arrived, and the stakes got higher.
Now, Super Admins control the full lifecycle. They can approve an app before anyone installs it, decide which users or teams can install it, set data permissions at the connector level, and revoke access at any time for a single user or the whole account.
One important note: some HubSpot-built integrations aren't supported yet because their access is managed through existing HubSpot permissions. That list will grow over time, but it's worth knowing the coverage isn't 100% on day one.
Why HubSpot Shipped This
The external problem is real: app sprawl. The average HubSpot portal we audit has a surprising number of connected apps the current admin didn't set up and can't fully explain. Some are dormant. Some still have write access to live CRM data.
The internal frustration is just as real. Admins feel like they're chasing ghosts. A new AI connector pops up, a well-meaning rep enabled it, and now your CRM data is flowing somewhere you didn't sanction. That's not a security posture. That's hope.
AI connectors made this urgent. When the HubSpot connectors for ChatGPT, Claude, and Gemini launched, they came with powerful data access options. Humans needed a way to adopt those tools intentionally, not accidentally. This update gives them that path.
How to Use It Step by Step
- Go to Settings > Integrations > Connected Apps and click the "Approved Apps" tab. This is where governance lives now.
- Browse available connectors and click Approve on the ones your organization wants to use. Don't approve everything by default. Be deliberate.
- Set installation permissions. Choose between Super Admins only, specific users and teams, or everyone in the account. Match this to the app's risk level and your team's readiness.
- Review data permissions during setup. For AI connectors, this step is required. Required permissions can't be disabled, but optional ones like read vs. write access are yours to configure.
- Monitor the Approved Apps table. Once an app is live, you can adjust installation permissions, update data permissions, uninstall it for specific users, or revoke it entirely. Full revocation uninstalls the app for everyone and takes up to 30 minutes to take effect.
- Handle incoming requests. If a user wants an app that isn't approved yet, they can submit a request from inside HubSpot. You'll receive it as a notification and can approve or deny it from the same admin panel.
What It Touches in Your HubSpot Strategy
This update ripples into more than just your integrations tab. Here's where it matters most.
AI connector strategy: If your team is using or planning to use the HubSpot connectors for ChatGPT, Claude, or Gemini, this governance layer changes how you roll them out. Instead of installing at the admin level and opening access to everyone, you now set the rules at approval time. That's a better workflow for any organization with compliance requirements.
Data governance and RevOps: Every connected app is a potential data surface. Governance here connects directly to your data hygiene and CRM health posture. If you're building out your data strategy, this control layer belongs in that conversation.
Key Takeaway
Revoking approval for an app automatically uninstalls it for every user in the account. That's a meaningful admin power, especially for AI connectors that have write access to CRM data. Use it deliberately.
User-level app permissions: This update pairs naturally with HubSpot's broader push toward per-user permission models. If you're building or managing apps in your ecosystem, understanding how governance and user-level permissions interact is now essential. Our breakdown of HubSpot User-Level Apps and per-user permissions covers how third-party apps can act on behalf of a specific user, which is the other side of this governance coin.
MCP server and AI workflows: If you're connecting HubSpot to external AI tools through the MCP server, you'll want to audit which connectors are currently installed and apply governance rules before adding more. Our look at the HubSpot MCP server update covers what AI tools can access from your CRM, which informs how tightly you should configure permissions here.
Key Takeaway
Optional data permissions, like read-only vs. write access, are configurable at the app level. For AI connectors, this is where you decide how much your CRM data feeds external models. Start restrictive and open up as trust is established.
The broader question of when AI tools stay tools and when they start making decisions without you is one every team needs to think through. Our article on when a tool stops being a tool is worth a read alongside this governance setup.
Who Should Care Most
This update is highest priority for these roles and scenarios:
- RevOps leads and HubSpot Super Admins who manage portals with 10 or more connected apps and have had little visibility into what's actually installed.
- Companies in regulated industries where data access controls are a compliance requirement, not just a preference. Finance, healthcare, and legal teams especially.
- Mid-market and enterprise teams actively deploying AI connectors for ChatGPT, Claude, or Gemini who need to govern access across departments without slowing adoption entirely.
- Smaller teams where one or two humans wear the admin hat and need a clear, fast way to say yes or no to app requests without digging through the connected apps list manually.
- Agency partners managing multiple client portals who need a consistent governance process they can document and repeat across accounts.
George's Take
Every portal audit we run reveals the same thing: connected apps that nobody remembers approving, some with permissions that would make your security team wince. This update is one of those quiet, unglamorous features that actually changes how safely your organization can grow. The AI connector piece is what makes it urgent right now. Humans are connecting their CRM to external AI models faster than most admin processes can keep up with, and the default before this was either lock everything down or hope for the best. App Install Governance gives you the middle path: intentional adoption with real controls. Set it up before you need it, not after something goes sideways.
“The goal isn't to block your team from using powerful tools. It's to make sure you know exactly what's connected, what it can touch, and who said yes.”
If your portal has grown faster than your governance process, or if you're about to roll out AI connectors to your team and want to do it right, let's talk. Book a strategy call with the Sidekick team and we'll walk through your connected apps, your permission structure, and build a governance plan that lets your team move fast without giving up control.
Frequently Asked Questions
What is HubSpot App Install Governance?
App Install Governance is a HubSpot feature that lets Super Admins approve which apps can be installed in their account, control who can install them, set data permissions for each app, and revoke access at any time. It applies to all apps including AI connectors like ChatGPT, Claude, and Gemini, and is available across all hubs and tiers.
Who can approve apps using App Install Governance in HubSpot?
Only Super Admins can approve apps, manage permissions, and revoke access. Regular users who want access to an unapproved app can submit a request from inside HubSpot, and Super Admins receive these as notifications they can act on directly from the Approved Apps settings panel.
How do I set up App Install Governance in HubSpot?
Go to Settings > Integrations > Connected Apps and open the Approved Apps tab. From there, review available connectors, approve the ones you want, set installation permissions by user or team, and configure optional data permissions like read vs. write access. The Approved Apps table lets you monitor and adjust everything after initial setup.
What happens when App Install Governance approval is revoked?
When a Super Admin revokes approval for an app, it's automatically uninstalled for all users in the account. The uninstall can take up to 30 minutes to fully take effect. Admins can also uninstall the app for individual users without revoking it for the entire account, giving more granular control over access.
Does App Install Governance cover HubSpot's AI connectors?
Yes. App Install Governance explicitly covers AI connectors including the HubSpot connectors for ChatGPT, Claude, and Gemini. It replaces the previous workflow where admins had to install AI connectors themselves and then grant blanket access. Now admins can set data permissions and user access rules before any AI connector goes live.
Are all HubSpot integrations covered by App Install Governance?
Not yet. Some HubSpot-built integrations aren't supported because their access is managed through existing HubSpot permissions. Coverage is expected to expand over time. Super Admins should check the Approved Apps tab to see which connectors are currently available for governance and plan accordingly for any gaps.






