Best AI Agent Security Software for Notion Custom Agents and MCP Connections in 2026
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
For Notion Custom Agents that only read and edit Notion pages, the best security software is Notion itself, configured well: write tools left on Always ask, custom MCP servers limited to an approved list, web access off where it is not needed, and agent use restricted to the people who need it. You need a separate runtime layer once a Custom Agent can change something outside Notion, through a custom MCP connection, Slack writes or a sub-agent that holds those tools, without a person approving each call.
We sell that runtime layer, so leading with "you may not need us" is a choice. It is the accurate answer, and it saves you a demo if your agents are still summarizing meeting notes.
Why Notion teams are asking about agent security this quarter
Custom Agents went generally available on May 4, 2026 on the Business and Enterprise plans, billed in Notion credits that Notion lists at 10 US dollars per 1,000 per month (checked October 2, 2026). For most of the summer they were workspace helpers. Two September releases changed that.
On September 9, Notion added a trigger that starts a Custom Agent as soon as an AI Meeting Note is finished, so agents now run unattended on text that every meeting participant can shape. On September 15, Notion 3.7 added custom MCP connections in beta: "You can now connect GitHub, Amplitude, and other tools with the Custom MCP connection so you can grab context, check performance, or take action in the tools your team already uses." The same release let a Custom Agent "call other Custom Agents as sub-agents, each with its own instructions, context, access, and model."
Put those together and a Notion agent can be started by a meeting, read what a contractor pasted into the notes, and open, close or relabel GitHub issues through a token a builder pasted into a header field. Notion's security team is candid that this is hard. Its engineering post on Custom Agents says prompt injection is unsolved and that "we don't design our system assuming that all prompt injections will get caught."
What Notion gives you before you buy anything
| Built-in control | What it does | Where it stops |
|---|---|---|
| Build-from-nothing access | Agents start without access and get pages and apps one by one | Users can reach data through an agent that they cannot open directly |
| Always ask on write tools | Pauses for approval before a create, update, delete or send | Editors can switch tools to Run automatically or a server to Always allow |
| Admin connection approval | Approved only mode lets admins pick which MCP connections members install | Says which servers, not which calls or values |
| URL confirmation | Pauses when the agent generates a URL that was not in the prompt | Does not cover text the agent already reads |
| Agent Directory and spend caps | Lists agents, controls who creates them, pauses unusual spend | Visibility and cost, not action authorization |
Notion's own guidance for agent owners is short and good: "Enable human confirmation for non-read-only tools" and "Only add external MCP servers you trust." If your team follows both and never relaxes them, you have a reasonable baseline.
The six options compared
| Option | What it covers | Best for | Where it falls short |
|---|---|---|---|
| Notion configured well | Always ask on writes, approved-only connections, web off, narrow agent sharing | Agents that read and edit Notion only | Per-tool on or off, no per-value rules, gates erode as teams automate |
| Scoped credentials on each MCP server | Fine-grained tokens and integration users with only the permissions the agent needs | Every team, as a first step that costs nothing | Limits reach, cannot hold a single risky call for approval |
| Notion Enterprise plan | Audit log, zero data retention, SCIM, DLP and SIEM connections | Teams that need records and retention controls inside Notion | Logs configuration and access changes, not each tool argument |
| SaaS DLP such as Nightfall for Notion | Detects PII, secrets and keys in Notion content | Regulated teams worried about what lands in pages | Inspects data at rest, does not authorize an agent's outbound action |
| Self-built MCP proxy with an open-source policy engine | Your own gateway using OPA, Cedar or Microsoft's Agent Governance Toolkit | Platform teams with time to build and run it | You write, host, patch and staff it |
| AgentShield MCP gateway | Per-tool, per-argument policy, named approvals, injection checks, audit trail | Agents writing to GitHub, CRM, ticketing or finance tools | A paid product; unnecessary for Notion-only agents |
Two of the six cost nothing, and the second one should happen whatever else you choose. A GitHub fine-grained token limited to one repository and to issues does more for a release agent than any product we could sell you on top of a token with admin rights.
When each option is the right buy
Stay with Notion's settings if your agents draft pages, update databases, post summaries to Slack channels you control and never connect a custom MCP server. Keep Always ask on anything that writes, and check the Agent Directory once a month for agents whose tools were switched to Run automatically.
Upgrade to Enterprise if your compliance team needs a record of who changed an agent's access or tool settings, or if zero data retention with model providers is a requirement. Notion lists the audit log and the DLP and SIEM security connections under Enterprise, so a Business workspace cannot get them by configuration.
Add a SaaS DLP tool if the risk you are managing is sensitive data sitting in pages that agents summarize and share, such as patient details or credentials pasted into a runbook. That is a data problem, and DLP is built for it.
Build your own proxy if you already run an internal MCP platform and have engineers who want to own policy code. The open-source engines are capable. The cost is people, not licenses.
Add a runtime gateway when an agent can change something outside Notion and you want the decision made per call: close issues only in one repository, hold anything that deletes or merges for a named approver, refuse bulk changes, and log every call with the trigger that started it. If the agent's whole job is routing incoming requests to the right owner, check first whether dedicated task assignment software does it without an agent holding write access at all. When the agent does need write tools, our Notion Custom Agents security page walks through the setup in detail.
How a gateway fits a Notion custom MCP connection
Notion's custom MCP connections accept OAuth or header-based authentication. That makes the integration simple. Instead of pointing the connection at GitHub's or your CRM's MCP server, you point it at an AgentShield MCP gateway endpoint. The token Notion stores unlocks only the gateway. The real credential lives with the gateway, which forwards each call only after it passes policy.
Policy is written per tool and per argument in AI agent permissions management, so the same rule applies whether the call comes from a parent agent, a sub-agent or an agent in another framework entirely. Calls that need a person go to a named approver group, as described on our human approval for AI agents page, and every allowed, held or denied call is written to the AI agent audit trail with its arguments. On the Business plan that is the only per-call record you will have.
Questions to ask any vendor before you buy
- Does it see each MCP tool call with its arguments, or only prompts and responses?
- Can it hold one call for approval while letting the rest of the agent run continue?
- Does the rule still apply if a builder switches the Notion tool to Always allow?
- Does it cover sub-agents, which carry their own access, without separate setup for each?
- Where does the real tool credential live, in Notion or outside it?
- Is the price published, or does every answer start with a sales call?
If your team is weighing builder platforms side by side, our guide to AI agent security software for Dify applies the same test to a self-hosted builder. To see what the gateway costs, the AgentShield pricing page lists every plan.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.
Keep reading