AgentShield
How it works Pricing Blog FAQ Contact Sign in

Best AI Agent Security Software for Claude Managed Agents and Anthropic Managed Agents

AgentShield Security Team·Oct 8, 2026·8 min read

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

Security lead and engineer reviewing a vendor shortlist on a laptop in a conference room

For most teams on Claude Managed Agents, the best AI agent security software starts with Anthropic's own controls: limited networking with an explicit host list, vaults for every credential, always_ask on anything that writes, and a budget on every session. Add a dedicated runtime gate only when agents run on a schedule or face customers and can move money, change records or send messages through MCP servers, because that is where Anthropic's approval model runs out.

We sell that gate, so leading with "Anthropic's controls may be enough" is deliberate. For an engineer-supervised research or coding agent, it is the right answer.

Why teams are reviewing Managed Agents security now

Claude Managed Agents has been in beta since April 2026 and is enabled by default for every Claude API account. Two recent changes put security on the agenda. On September 10, 2026 Anthropic added the auto permission policy, where its server evaluates each tool call and runs it, denies it or pauses for approval. On October 7 it changed web_fetch to fetch only URLs that already appeared in the session, a change Anthropic says "reduces the risk of data exfiltration," and applied limited networking host lists to the web tools.

Four facts from Anthropic's documentation shape every option below:

  • Defaults. The built-in agent toolset, including bash, defaults to always_allow. MCP toolsets default to always_ask. An environment created through the API without a networking setting gets unrestricted egress.
  • Auto. "auto is not a human checkpoint." Text relayed in user messages counts as your intent and can get a call allowed.
  • Custom tools. Permission policies do not apply to them. Your application decides.
  • Data. Managed Agents "is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage."

Six options compared

OptionWhat it coversWhere it stopsBest for
Anthropic native controlsPermission policies, vaults, limited networking, web domain lists, budgets, the evaluation field on tool eventsNo approval routing, timeouts or approver identity; auto lets safe-looking calls run unseenEvery team, as the baseline
Checks in your custom tool handlersAny rule you write, on calls your app executesOnly custom tools; MCP and built-in calls bypass itAgents whose write actions are all custom tools
Messages API or Agent SDK on an eligible setup insteadFull control of the loop and its data handlingYou build sessions, sandboxes and scheduling yourselfPHI, ZDR contracts, strict retention rules
SaaS and agent discovery toolsInventory of agents, owners, integrations and risky configurationsTells you what exists, does not decide a single callLarge estates with agents nobody owns
Build your own MCP gatewayExactly the rules you wantApproval routing, audit storage and upkeep are yoursPlatform teams with spare capacity
AgentShield MCP gatewayPer-tool, per-argument policy on every MCP call, holds for a named approver, injection checks, audit trailDoes not make Managed Agents BAA or ZDR eligible, does not govern bash inside the sandboxScheduled or customer-facing agents with MCP write tools

Option 1, Anthropic's native controls

Start here whatever else you buy. Create environments with limited networking and list only the hosts the agent needs, remembering that any allowed host accepts any request, uploads included. Override bash to always_ask, or disable it for agents that do not need a shell. Put MCP tokens and API keys in vaults, where MCP credentials are injected at connection time and environment variable credentials stay placeholders until egress. Set a budget on every deployment; it applies to each run separately.

The gap is the decision itself. always_ask pauses the session and "waits indefinitely for a response," so on a 6 a.m. scheduled run someone has to be there, and the record of who answered is whatever your client keeps. auto removes the wait by letting Anthropic's server judge each call, which is useful and is, by Anthropic's own description, not a human checkpoint.

Option 2, checks in your custom tool handlers

Custom tools are the part of Managed Agents that passes through your code. The session emits agent.custom_tool_use, your handler runs, and you send back a result. If every write action is a custom tool, validating arguments and holding risky calls in that handler is a sound design and costs nothing extra.

The trap is the hybrid build, where reads go through custom tools you validate and writes go through an MCP server set to auto to keep scheduled runs moving. The validated half is the half that could not hurt you.

Option 3, keep regulated workloads somewhere else

This is the honest answer for many US healthcare, insurance and financial services teams, and it means buying nothing. If a workload carries PHI or a Zero Data Retention commitment, Managed Agents is not eligible today, and Anthropic says the exclusion covers self-hosted sandboxes too. Run that loop on the Messages API or with the Claude Agent SDK under an eligible arrangement. You give up hosted sessions and scheduling. You keep an answer your auditor accepts.

Option 4, SaaS and agent discovery tools

Several SaaS security vendors now inventory Claude Managed Agents across a company: who built each agent, what it connects to, whether MCP connections are unauthenticated, which agents outlived their owners. That is real value once dozens of teams have API keys. It answers what exists. It does not stop a specific fee waiver or refund at the moment the agent proposes it, so treat discovery as the map and pair it with something on the call path.

It is also worth asking whether a given scheduled job needs an autonomous agent at all. A run whose only work is reading vendor invoices into the books is a job for invoice OCR software, not for a harness with a shell and a gate in front of it.

Option 5, build the gateway yourself

A gateway in front of your MCP servers that evaluates each call is ordinary engineering. The rules engine is the easy part. The work is approval routing to the right person, timeouts and escalation for unattended runs, an audit store the agent cannot write, and keeping rules current as tools change. If your platform team has the capacity and wants to own it, build it, and budget for running it after launch.

Option 6, AgentShield as the MCP gateway

You point each MCP server that can write at an AgentShield gateway endpoint instead of the raw server, and the gateway holds the real credential. Every call is evaluated against per-tool, per-argument permissions, risky calls wait for a named approver through a human approval gate with routing and timeouts, inputs are checked for injected instructions, and each decision lands in an AI agent audit trail outside the session. It enforces the same way on a scheduled run as on an interactive one, and a tenant's claim that a manager already approved changes nothing.

What it does not do: change Anthropic's retention, make Managed Agents BAA or ZDR eligible, or govern bash inside the sandbox. For the shell, use Anthropic's own policy and network controls.

Which option fits your situation

SituationPickBuy anything new
Research, coding or report agents an engineer supervisesOption 1No
PHI, ZDR contracts or strict retention rulesOption 3No
All write actions are custom tools you ownOptions 1 and 2No
Hundreds of agents across teams, nobody sure who owns whatAdd Option 4Maybe
MCP write tools, platform team has capacityOption 5Engineering time
Scheduled or customer-facing agents with MCP write tools, auditor asks who approvedOption 6Yes

Three of six situations buy nothing new. That ratio will shift as more teams move back-office work onto scheduled deployments.

Questions buyers ask

Is the auto permission policy enough for production agents?

For low-risk calls, often yes. For calls that move money or change records, no. Anthropic states auto is not a human checkpoint: a call the server judges safe runs before anyone sees it, and text relayed in user messages counts as your intent. Keep always_ask or an external gate on consequential tools.

Is Claude Managed Agents covered by a HIPAA BAA?

Not as of October 8, 2026. Anthropic states Managed Agents is not currently eligible for Zero Data Retention or HIPAA BAA coverage, including self-hosted sandboxes, because sessions are stateful and transcripts persist until deleted. Keep PHI out of Managed Agents sessions.

Can I require human approval for every Claude Managed Agents tool call?

Yes, with always_ask on each toolset, and the session then waits indefinitely for a confirmation from your client. What Anthropic does not provide is routing to a specific approver, timeouts or a record of who approved. That is the job of a gate in front of your MCP servers.

What does Claude Managed Agents cost?

Anthropic prices sessions at public list rates: model tokens at list price, web searches at 10 dollars per 1,000 and session running time at 8 cents per hour, per its session budget docs on October 8, 2026.

Next step

If your agents only read and an engineer watches them, configure Anthropic's controls and stop there. If they write through MCP on a schedule or for customers, read our Claude Managed Agents security page for the full control map and checklist, and the MCP server security page for the server side. Then create your workspace and put the gateway in front of one write tool first.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.

Open the console