A messy portal just became a safety problem.
HubSpot is putting AI agents inside workflows. Before your client connects one, HubScan checks whether the portal is safe to act on: who can act, the data the agent will trust, the automation it will collide with, and what it all costs. Read-only, every number traced back to an API call, delivered under your name.
Keep a human in the loop. Start before you connect.
Until now, a messy HubSpot was a tidiness problem. A few hundred unused properties, some stale deals, a couple of admins who left two years ago. Annoying, not dangerous.
HubSpot's "Run agent" workflow action drops an AI agent into a workflow as a step. It fires on whatever enrolls the workflow, and its output feeds the actions after it: update a record, branch, follow up. That is in beta on Professional and Enterprise today, and a more capable Agentic Automation Builder is in early access. The agent runs on a trigger, not on anyone's judgment. Garbage in, garbage out becomes garbage acted on, at machine speed.
The answer is not to keep agents out. Your clients are going to switch them on, and they should. The answer is to keep a human in the loop, and the first place that human belongs is before the agent is connected. That is the job HubScan does: a read-only audit a consultant reads, judges and signs off. Nothing is written back to the portal. Nothing touches an LLM. You stay the adult in the room.
Four things that decide whether an agent helps or harms.
Each is a section of the same read-only HubScan report, with the same evidence and caveats. Licensing, data quality and access drift run today; automation covers the slice HubSpot's API makes readable. No client data is stored, and nothing touches an LLM.
Blast radius
AvailableAccess & permission drift. Who, and now what, can act unsupervised. Super-Admin proliferation and stale grants (deactivated users still flagged admin) are doors someone forgot they left open, and workflows, connected apps and integrations already write to the portal before an agent joins them.
In the report: Every admin and stale grant RAG-banded, plus the automated actors already writing to the portal, counted per source.
Ground truth
AvailableData quality. An agent believes the CRM. Unowned records, records owned by deactivated users, stale data and missing fields become wrong autonomous decisions, fired on a trigger set once and forgotten.
In the report: Per-object hygiene across contacts, companies, deals, tickets and custom objects.
Collision surface
PartialAutomation health. What is already running before an agent lands in the middle of it: sequence senders, contact-owner workflows, orphaned sequences, and the fields those workflows already write on a trigger.
In the report: Sequence senders, orphaned sequences, and the collision surface: which properties enabled workflows already write, busiest first. Plus the workflows already broken before an agent arrives: sends that will fail, notifications that reach nobody, and rotations that can never assign.
Cost exposure
AvailableLicensing & seat efficiency. Seats nobody needs and marketing-contact bloat that quietly inflate the bill. Agent runs are free while the action is in beta and will consume credits once it ships, on top of whatever the portal already wastes.
In the report: Per-seat recommendations with savings math and a confidence level on each one.
"My client is not running agents yet."
Then you are early, which is the whole point. These four checks are the portal hygiene you would audit anyway. The agent timeline does not add work, it adds a date: the thing that was a nice-to-have last year is a gate now.
Run the audit before anything is connected and you have a clean baseline, a defensible reason to fix what it finds, and the conversation that gets you invited when the agent project starts. Better you raise it than the client's next vendor.
See a portal's agent-readiness before you connect.
Run a free first audit and get the exact report your client would: evidence, caveats and all. It is a reason to look, not a reason to wait.