What developers use instead of HubSpot
2026-09-30 · edited by Aetha Editorial
Whether developers should use anything instead of HubSpot depends on whether anyone on the team writes code. If not, stop here and take the platform — this article argues you into it, not out of it. If yes, there is a third path besides paying per seat forever or building from nothing: have a coding agent generate the CRM as code you own.
Vendor facts below come from docs/strategy/COMPETITOR_MAP.md (HubSpot row researched August 18, 2026 from search-index excerpts of the vendor's own pages) plus one fact re-verified today: HubSpot's remote MCP server is in public beta since May 2026 (developer changelog, read 2026-09-30), letting AI clients such as Cursor and Claude interact with HubSpot data. No pricing figures appear here — nothing quoted, nothing to go stale. Licence descriptions are factual summaries, not legal advice. We refresh comparison content on a 90-day clock.
Take HubSpot if nobody writes code
HubSpot is a vendor-hosted SaaS CRM ("Smart CRM" in their docs) with a free tools tier (map, August 18, 2026). If your team will never open a repository, that sentence ends the evaluation: configured software with support beats a framework your team cannot operate, every time. The MCP beta above also means "our AI assistant updates the CRM" is a supported path without building anything.
Take the builder path if a dev is on the team
The builder path exists for one situation: a commercial process unusual enough that configuration keeps bending it out of shape, plus someone to own the result. That is what this framework is: a coding agent generates a bespoke CRM as reviewable, owned code — a module manifest becomes a migration, a service, a REST resource, an SDK method and Admin screens (C-01) — with deterministic commercial policy (C-03), an approval refusal a non-human actor cannot cross, asserted by a test (C-04), the same refusal where the money is, with a 403 and code HUMAN_APPROVAL_REQUIRED (C-21), and an audit event plus step-level trace on every mutation (C-16). SQLite is built in; PostgreSQL needs one pinned driver (C-17).
Read what day 30 of that build looks like before deciding — it is about the four things that go wrong, not the demo that goes right — and whether an agent may approve on your behalf for the boundary in Q/A form.
What the builder path still lacks, exactly
This is where evaluations usually die, so here it is up front. No hosted CRM and no account exist — the output is an application in your repository, not a product you sign up for (L-07). No authentication ships; the deployment supplies the verifier (L-01). No email, calendar or marketing integrations ship (L-05) — a HubSpot team lives in those, so count the cost honestly. Nothing bills: no invoices, payments, tax or revenue recognition (L-10). If any line on that list is load-bearing for you this quarter, take the platform and revisit later.
Every claim and every limitation is on one page, and so are the questions this project refuses to answer.
What this post does not mean
These pages describe this repository at this commit. None of them implies the framework is deployable, and none of them is a roadmap: nothing that is not merged appears on this site, in any tense.
- No authentication ships: the framework authenticates nobody. Production Spine v1 (ADR-038) gives the framework verified identity, organizations and memberships, server-authoritative authorization and one tenant per application instance — so tenancy and authorization now exist and are enforced. What does not exist is authentication: no login, password, session or OIDC implementation ships, and a deployment must supply the adapter that verifies the request. Production mode refuses to start without one. In local-development mode an actor header is accepted as an assertion and is not an identity, which is the default developer posture. This is not shared-database multi-tenancy and it is not a readiness claim.
- Not shared-database tenancy. createAccordoAppAsync can boot one tenant onto dedicated PostgreSQL databases. Shared-database row-level tenancy is not implemented, and this is not a production-readiness claim.
- Timers exist; a service that runs them for you does not. Durable jobs, a transactional outbox and scheduled asks exist for self-hosted applications that explicitly start a worker. Nothing autostarts; a timer opens an ask, never makes a decision, and no managed worker service or recurrence is included.
- No email, calendar or marketing integrations. An in-memory notification provider contract exists. MK1 marketing records supplied funnel observations and human-reviewed proposals only; it has no sending, publishing or spending path.
- The build benchmark has not been run. The protocol is designed and published; no Successful Agent Build Rate exists yet. Any number you see quoted for this project is not ours.
- Ownership means vendored source: there is no framework dependency to bump. The published create-accordo@0.1.0 scaffolds vendored source; it is the August 19 snapshot, not the current repository feature set. Use a current source checkout for the capabilities described here; upgrades require merging source (L-08). The framework is copied into the project, not installed as a framework library dependency. The accordo npm name is an empty reservation; the @accordo scope is claimed and deliberately empty.
Every claim and every limitation is on one page, and the questions this project refuses to answer are published beside them.
The evidence this post rests on
Claims
- C-01 Write a module manifest; the agent turns it into a migration, a service, a REST resource, an SDK method and Admin screens — with no page code.
LimitGenerated CRUD only. The factory does not generate workflows or approvals for a custom object — that is still handwritten (JTBD-06, partially supported).
- C-03 Commercial policy is deterministic code, not a model's judgement: a renewal at or above the threshold stops and waits for a named human.
LimitProven for the built-in renewal object and its single value threshold. A general policy engine over arbitrary custom objects does not exist.
- C-04 The agent cannot approve on the human's behalf. A test asserts the refusal, so the boundary is a property of the system rather than a promise in a README.
LimitIn local-development mode the actor is asserted, not authenticated: no authentication ships, so an actor header there is not an identity. This holds a boundary against an honest agent, not against an attacker with network access.
- C-16 Every mutation goes through a module service or a named workflow, and leaves an audit event and a step-level trace behind it.
LimitAudit records what the process did under an asserted actor. It is not a tamper-evident or externally attestable log, and it is not a compliance control.
- C-17 SQLite is Node's built-in node:sqlite. PostgreSQL requires one pinned runtime driver, pg@8.23.0. There is no ORM, no query builder, no build step and no framework underneath your framework.
LimitApplications that select PostgreSQL carry pg@8.23.0. The SQLite path still needs no third-party driver. This is not a production-readiness claim and not shared-database tenancy; composition is dedicated-database, not row tenancy.
- C-21 The same refusal holds where the money is: an agent actor asking to approve a discounted quote is refused with a 403, and only a human user actor can decide.
LimitThe assertion lives inside a composite end-to-end test rather than a test named for it, so the citation is a file and a line rather than a test name. Extracting it into a named test is tracked in docs/strategy/GO_TO_MARKET.md; until then, cite the line.
Grounded in
docs/strategy/COMPETITOR_MAP.md
Editor of record
- Aetha Editorial