Granular Tool Permissions for Breeze Assistant & Agent Connectors

Monday, September 14, 2026

HubSpot AIDeveloper PlatformFreeStarterProfessionalEnterpriseLive

What it is

Admins can now control which tools an individual agent or connector is allowed to use. Turn off write access if you want a connector to stay read-only, or remove tools an agent never calls to cut down on what it has to consider. The show's read is that this control lives at the connector level rather than per agent, though the announcement itself does not say so directly.

Why it matters

This is the unglamorous half of agentic AI, and it is the half that decides whether a security team signs off on turning any of it on. A tool a connector cannot touch is a tool that cannot cause a problem. The rollout landed the same day as Connectors for Breeze adds several new integrations, so the timing reads as HubSpot shipping the guardrail alongside the reason you would need one.

The Take

Casey Hawkins + Chris Carolan

Keeping up with what a connector can and cannot touch has been a real headache, not because permissions are a bad idea but because the underlying tools keep changing their own scopes out from under you. The frustration on the show was specific: the setup flow walks you into a screen that looks like a checklist, then sends you somewhere else to actually turn the thing on. If HubSpot gets this right, the next step is obvious, and the hosts said it out loud: tell Breeze what you want locked down and let it configure the connector for you instead of hunting through settings.

Watch Us Discuss This

The full segment from the show, us working through this update start to finish.

Granular tool permissions: the boring half of agents that security cares about2:00

FAQ

Does this control live on the connector or on the individual agent?

The announcement does not say directly. The reading on the show was that it lives on the connector, but that was not confirmed against the actual settings screen.

What can I actually restrict?

You can remove write access so an agent or connector stays read-only, and you can remove tools it does not use to cut down on what it has to consider when it runs.

Why does this matter if I am not running agents yet?

It is the control a security team will ask for before agents get turned on at all. Setting it up now means the guardrail is already in place when you start using more of Agent Hub.

Produced by Value-First Media