HubSpot Read-Only
Makes the HubSpot connection read-only by blocking the write tool.
- Direction
- ingress
- Rego package
hubspot.ingress.readonly- App
- hubspot
- Bundles
- crmsoc2gdpr-ccpa
- Published
- Minimum gateway
- 1.0.0b24
- Schema version
- 1.0.0
- Checksum
sha256:c4ef50764a959af252cfbd5474bfea02a57b207fa3d352636dc70b8f11b45de0
hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa
What this policy does
Direction: ingress (tool_pre_invoke)
Default: deny on match, allow otherwise
Package: hubspot.ingress.readonly
What it does
Makes the HubSpot connection read-only by blocking the write tool. Any call to
hubspot-manage-crm-objects — the create/update tool exposed by the HubSpot MCP
server — is denied. Every other HubSpot tool (search, list, read) passes
through unchanged.
Compliance alignment
- SOC 2 CC6.1; CC6.3 — logical access restriction and least privilege: agents get a read-only HubSpot posture; no write reaches the CRM through the gateway.
- HIPAA §164.312(a)(1); §164.308(a)(4) — access control and information access management on the MCP path, for portals whose contact records carry health-related data.
- PCI DSS 7.2.1; 7.2.2 — least-privilege access model: the agent channel is restricted to the minimum (read) access needed.
- GDPR Art. 25; Art. 29 — data protection by default on the agent channel, and processing only on documented instructions — no unsanctioned agent writes to personal data.
- ISO 27001 A.5.15 — access control: enforces the read-only access decision at a technical control point.
Why ingress
Writes have permanent side effects on the CRM. The connection's read/write posture is fully determined by the tool being called, so denying the write tool at ingress guarantees no mutation reaches HubSpot regardless of the payload.
How it matches
The policy is default allow := false and re-allows every tool except the
one whose (lowercased) name ends with -manage-crm-objects. Suffix matching
keeps the policy portable regardless of the MCP server name prefix the gateway
adds (hubspot-, hubspot-mcp-, etc.). Confirm the exact tool name with the
dump-input debug technique before deploying.
Examples
Allowed (read tool)
{
"input": {
"action": "tool_pre_invoke",
"resource": { "name": "hubspot-list-objects", "type": "tool" },
"payload": { "name": "hubspot-list-objects", "args": { "objectType": "deals" } }
}
}
allow = true, no reason.
Denied (write tool)
{
"input": {
"action": "tool_pre_invoke",
"resource": { "name": "hubspot-manage-crm-objects", "type": "tool" },
"payload": {
"name": "hubspot-manage-crm-objects",
"args": { "updateRequest": { "objects": [ { "objectType": "deals", "id": "12345" } ] } }
}
}
}
allow = false, reason = "HubSpot write operations are disabled on this gateway. This connection is read-only.".
Known limitations
- Single write tool. This assumes
hubspot-manage-crm-objectsis the only write tool exposed by the HubSpot MCP server on the gateway. If your server exposes other mutating tools (e.g. dedicated association or engagement endpoints), add their suffixes to the deny condition. - Suffix tool-name match. The policy allows any tool that does not end in
-manage-crm-objects. If a non-HubSpot MCP server exposed a tool with that same suffix, it would also be blocked — narrow the match if that is a concern. - No identity-based exemptions. All callers are read-only. To allow a
break-glass writer, add an
allow ifbranch gated oninput.subject.claims.
Compliance note. This policy supports alignment with the cited framework controls on the MCP path only. No policy or bundle makes an organization compliant with any framework; web-UI, native-API, and in-app access are outside the gateway's reach by design. Validate against your own compliance program before relying on it.
Policy source (Rego)
package hubspot.ingress.readonly
default allow := false
allow if {
not endswith(lower(input.resource.name), "-manage-crm-objects")
}
reason := "HubSpot write operations are disabled on this gateway. This connection is read-only." if not allow Canonical source: policy.md on GitHub · raw · raw on this site (.md)
Used in these guides
Related policies
Airtable: Redact PII in Record Reads
Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…
Asana: Redact PII in Task & Comment Reads
On the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…
BigQuery: Redact PII in Query Results
Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Block Agent Email to External Recipients
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Block BigQuery Exfiltration and Cross-Project Writes
Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…
bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa
Block Bulk Export & External Staging (Snowflake)
Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…
snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa