Best AI Agent Security Software for Claude Managed Agents and Anthropic Managed Agents
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
For most teams on Claude Managed Agents, the best AI agent security software starts with Anthropic's own controls: limited networking with an explicit host list, vaults for every credential, always_ask on anything that writes, and a budget on every session. Add a dedicated runtime gate only when agents run on a schedule or face customers and can move money, change records or send messages through MCP servers, because that is where Anthropic's approval model runs out.
We sell that gate, so leading with "Anthropic's controls may be enough" is deliberate. For an engineer-supervised research or coding agent, it is the right answer.
Why teams are reviewing Managed Agents security now
Claude Managed Agents has been in beta since April 2026 and is enabled by default for every Claude API account. Two recent changes put security on the agenda. On September 10, 2026 Anthropic added the auto permission policy, where its server evaluates each tool call and runs it, denies it or pauses for approval. On October 7 it changed web_fetch to fetch only URLs that already appeared in the session, a change Anthropic says "reduces the risk of data exfiltration," and applied limited networking host lists to the web tools.
Four facts from Anthropic's documentation shape every option below:
- Defaults. The built-in agent toolset, including
bash, defaults toalways_allow. MCP toolsets default toalways_ask. An environment created through the API without a networking setting gets unrestricted egress. - Auto. "
autois not a human checkpoint." Text relayed in user messages counts as your intent and can get a call allowed. - Custom tools. Permission policies do not apply to them. Your application decides.
- Data. Managed Agents "is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage."
Six options compared
| Option | What it covers | Where it stops | Best for |
|---|---|---|---|
| Anthropic native controls | Permission policies, vaults, limited networking, web domain lists, budgets, the evaluation field on tool events | No approval routing, timeouts or approver identity; auto lets safe-looking calls run unseen | Every team, as the baseline |
| Checks in your custom tool handlers | Any rule you write, on calls your app executes | Only custom tools; MCP and built-in calls bypass it | Agents whose write actions are all custom tools |
| Messages API or Agent SDK on an eligible setup instead | Full control of the loop and its data handling | You build sessions, sandboxes and scheduling yourself | PHI, ZDR contracts, strict retention rules |
| SaaS and agent discovery tools | Inventory of agents, owners, integrations and risky configurations | Tells you what exists, does not decide a single call | Large estates with agents nobody owns |
| Build your own MCP gateway | Exactly the rules you want | Approval routing, audit storage and upkeep are yours | Platform teams with spare capacity |
| AgentShield MCP gateway | Per-tool, per-argument policy on every MCP call, holds for a named approver, injection checks, audit trail | Does not make Managed Agents BAA or ZDR eligible, does not govern bash inside the sandbox | Scheduled or customer-facing agents with MCP write tools |
Option 1, Anthropic's native controls
Start here whatever else you buy. Create environments with limited networking and list only the hosts the agent needs, remembering that any allowed host accepts any request, uploads included. Override bash to always_ask, or disable it for agents that do not need a shell. Put MCP tokens and API keys in vaults, where MCP credentials are injected at connection time and environment variable credentials stay placeholders until egress. Set a budget on every deployment; it applies to each run separately.
The gap is the decision itself. always_ask pauses the session and "waits indefinitely for a response," so on a 6 a.m. scheduled run someone has to be there, and the record of who answered is whatever your client keeps. auto removes the wait by letting Anthropic's server judge each call, which is useful and is, by Anthropic's own description, not a human checkpoint.
Option 2, checks in your custom tool handlers
Custom tools are the part of Managed Agents that passes through your code. The session emits agent.custom_tool_use, your handler runs, and you send back a result. If every write action is a custom tool, validating arguments and holding risky calls in that handler is a sound design and costs nothing extra.
The trap is the hybrid build, where reads go through custom tools you validate and writes go through an MCP server set to auto to keep scheduled runs moving. The validated half is the half that could not hurt you.
Option 3, keep regulated workloads somewhere else
This is the honest answer for many US healthcare, insurance and financial services teams, and it means buying nothing. If a workload carries PHI or a Zero Data Retention commitment, Managed Agents is not eligible today, and Anthropic says the exclusion covers self-hosted sandboxes too. Run that loop on the Messages API or with the Claude Agent SDK under an eligible arrangement. You give up hosted sessions and scheduling. You keep an answer your auditor accepts.
Option 4, SaaS and agent discovery tools
Several SaaS security vendors now inventory Claude Managed Agents across a company: who built each agent, what it connects to, whether MCP connections are unauthenticated, which agents outlived their owners. That is real value once dozens of teams have API keys. It answers what exists. It does not stop a specific fee waiver or refund at the moment the agent proposes it, so treat discovery as the map and pair it with something on the call path.
It is also worth asking whether a given scheduled job needs an autonomous agent at all. A run whose only work is reading vendor invoices into the books is a job for invoice OCR software, not for a harness with a shell and a gate in front of it.
Option 5, build the gateway yourself
A gateway in front of your MCP servers that evaluates each call is ordinary engineering. The rules engine is the easy part. The work is approval routing to the right person, timeouts and escalation for unattended runs, an audit store the agent cannot write, and keeping rules current as tools change. If your platform team has the capacity and wants to own it, build it, and budget for running it after launch.
Option 6, AgentShield as the MCP gateway
You point each MCP server that can write at an AgentShield gateway endpoint instead of the raw server, and the gateway holds the real credential. Every call is evaluated against per-tool, per-argument permissions, risky calls wait for a named approver through a human approval gate with routing and timeouts, inputs are checked for injected instructions, and each decision lands in an AI agent audit trail outside the session. It enforces the same way on a scheduled run as on an interactive one, and a tenant's claim that a manager already approved changes nothing.
What it does not do: change Anthropic's retention, make Managed Agents BAA or ZDR eligible, or govern bash inside the sandbox. For the shell, use Anthropic's own policy and network controls.
Which option fits your situation
| Situation | Pick | Buy anything new |
|---|---|---|
| Research, coding or report agents an engineer supervises | Option 1 | No |
| PHI, ZDR contracts or strict retention rules | Option 3 | No |
| All write actions are custom tools you own | Options 1 and 2 | No |
| Hundreds of agents across teams, nobody sure who owns what | Add Option 4 | Maybe |
| MCP write tools, platform team has capacity | Option 5 | Engineering time |
| Scheduled or customer-facing agents with MCP write tools, auditor asks who approved | Option 6 | Yes |
Three of six situations buy nothing new. That ratio will shift as more teams move back-office work onto scheduled deployments.
Questions buyers ask
Is the auto permission policy enough for production agents?
For low-risk calls, often yes. For calls that move money or change records, no. Anthropic states auto is not a human checkpoint: a call the server judges safe runs before anyone sees it, and text relayed in user messages counts as your intent. Keep always_ask or an external gate on consequential tools.
Is Claude Managed Agents covered by a HIPAA BAA?
Not as of October 8, 2026. Anthropic states Managed Agents is not currently eligible for Zero Data Retention or HIPAA BAA coverage, including self-hosted sandboxes, because sessions are stateful and transcripts persist until deleted. Keep PHI out of Managed Agents sessions.
Can I require human approval for every Claude Managed Agents tool call?
Yes, with always_ask on each toolset, and the session then waits indefinitely for a confirmation from your client. What Anthropic does not provide is routing to a specific approver, timeouts or a record of who approved. That is the job of a gate in front of your MCP servers.
What does Claude Managed Agents cost?
Anthropic prices sessions at public list rates: model tokens at list price, web searches at 10 dollars per 1,000 and session running time at 8 cents per hour, per its session budget docs on October 8, 2026.
Next step
If your agents only read and an engineer watches them, configure Anthropic's controls and stop there. If they write through MCP on a schedule or for customers, read our Claude Managed Agents security page for the full control map and checklist, and the MCP server security page for the server side. Then create your workspace and put the gateway in front of one write tool first.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.
Keep reading