Best AI Agent Security Software for Zapier Agents and Zapier MCP in 2026
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
For most Zapier customers, the best AI agent security software is the set of controls Zapier already ships, switched on: Zapier MCP disabled in workspaces that do not use it, admin app restrictions, "Require approval before running" on every AI by Zapier tool that writes, and AI Guardrails on inbound text. You need a separate runtime layer once Claude, ChatGPT, Cursor or your own agents call Zapier MCP with actions that send, invoice, refund or change records, because that path has no per-call approval.
We sell that runtime layer, so opening with "you may not need us" is deliberate. It is the accurate answer for a large share of Zapier accounts, and it saves a sales call if your AI steps only draft and summarize.
Why Zapier teams are reviewing agent security this quarter
Three changes landed close together. First, Zapier MCP turned every Zapier account into an action layer for outside AI tools. Zapier's own security page states that "Zapier MCP is enabled by default for all accounts, including Enterprise" and that "All users within the account can access Zapier MCP." Many IT teams learned this from the History tab, not from a request.
Second, Zapier is migrating its standalone Zapier Agents into AI by Zapier steps inside the Zap editor. No shutdown date has been set, but the help center already walks users through a "Migrate your Zap" button. Old agents asked for approval through a sentence in their instructions. The new step has a real platform switch, "Require approval before running", and Zapier documents that "This toggle is off by default."
Third, at ZapConnect on September 23, 2026, Zapier announced Next Gen Zaps: workflows you can describe in Claude, ChatGPT or Cursor and deploy through MCP, watched by a monitoring agent that "can apply or suggest a fix." That feature, Agentic Management, is on by default where it is available. So an AI tool can now create automations, and another agent can edit them.
None of this makes Zapier unsafe. It moves the decision about which write happens from a fixed Zap to a model, and that is the moment security owners should look again.
Six options compared
| Option | What it covers | Where it stops | Best for |
|---|---|---|---|
| Zapier built-in settings | MCP on or off per workspace, app access controls, approval switch per AI tool, Human in the Loop step | Scope is per app and action, not per value; no approval on calls from outside MCP clients | Every Zapier account, as the baseline |
| AI Guardrails by Zapier | Detect Prompt Attack, PII, toxicity and sentiment checks inside Zaps | Returns a result; your Zap must branch on it | AI steps that read email, tickets or form text |
| Zapier Enterprise plan | Admin-managed apps, publishing restrictions, SIEM streaming, configurable retention | Better governance of who builds what; still no judgment on each call | Large teams with many builders |
| DLP tools that scan MCP traffic | Finding and masking sensitive data in what tools return to the model | Focused on data leaving, not on actions being taken | Teams whose main risk is PII reaching a model |
| Self-hosted policy engine | Open source policy checks you deploy and run yourself | You own hosting, upgrades, approver flow and on-call | Platform teams with spare engineering time |
| AgentShield runtime gateway | Per-action, per-argument policy on Zapier MCP calls, named approvers, injection checks, decision log | Does not sit inside AI by Zapier steps that run within Zapier | Outside agents calling Zapier MCP with write actions |
The first two rows are already in your subscription. Start there.
Start with Zapier's own settings switched on
Most of the exposure we see in Zapier accounts comes from defaults nobody revisited. Disable Zapier MCP in workspaces where nobody uses it and restrict it by membership elsewhere. Use app access controls to keep finance and payroll apps away from teams that do not need them. In every AI by Zapier step that has a tool which creates, updates, sends or deletes, turn on "Require approval before running". Zapier's own guidance lists the right candidates: customer-facing messages, "Creating invoices, modifying contracts, updating payment information", and data changes that are hard to undo.
When the switch is on, the step "pauses before that tool runs and waits for your approval, regardless of how specific your prompt is," and sends an email with a review link. That last clause is the important improvement over legacy Zapier Agents, where approval was a sentence the model was asked to follow.
AI Guardrails by Zapier inside your Zaps
Zapier launched AI Guardrails in March 2026. It adds actions such as Detect Prompt Attack, Detect PII and Detect Toxicity that you place in a Zap before or after an AI step. The design choice to understand is that it reports rather than blocks. You add a filter, a path or a human review step that acts on the result. Zapier is candid that "No AI-powered detection system is 100% accurate" and that the feature is "designed to supplement, not replace, your existing security, privacy, and compliance measures." Used that way, it is a sensible, low-cost layer for any Zap that feeds outside text into a model.
The Zapier Enterprise plan for large builder teams
Enterprise adds the governance large teams ask for: admin-managed app connections, publishing restrictions, log streaming to Datadog, Splunk or another SIEM, and configurable retention for history. If your problem is fifty builders creating Zaps with personal connections, this solves more of it than any third-party tool. What it does not add is a decision about whether a particular call with particular values should run.
DLP scanning and self-hosted policy engines
DLP vendors now scan MCP traffic for sensitive data, which is the right tool if your worry is customer PII or secrets flowing from Zapier lookups into a model's context. A self-hosted policy engine, such as Microsoft's open source Agent Governance Toolkit, can intercept agent actions before they execute if you are willing to run it. Both are honest choices. The first is aimed at data, not actions. The second is a project your platform team owns, including the approver experience and the pager.
A runtime gateway in front of Zapier MCP
The gap the built-in options leave is narrow and specific: an AI client outside Zapier chooses an action, Zapier MCP executes it with stored connections, and nothing between them asks whether this invoice, this email to this customer or this deal stage change should happen. That is where we fit. Claude, ChatGPT, Cursor or your in-house agents connect to an AgentShield MCP gateway endpoint, the Zapier token stays with the gateway, and policy decides per action and per argument what runs, what waits for a named approver and what is refused. Inputs are checked for injected instructions with prompt injection protection, and each decision lands in the AI agent audit trail with the approver and the rule. The full control map is on our Zapier MCP security page.
We are not the right answer inside Zapier itself. An AI by Zapier step that runs within a Zap calls Zapier actions directly, so use the approval switch and AI Guardrails there.
Which option fits which Zapier account
| Your situation | What to buy |
|---|---|
| Classic Zaps only, no AI steps, nobody using MCP | Nothing. Turn Zapier MCP off. |
| AI steps that read, summarize or create drafts | Nothing. Add AI Guardrails on inbound text. |
| Migrated Zapier Agents with write tools | Nothing new. Switch on approval for each write tool after migrating. |
| Many builders, personal connections everywhere | The Enterprise plan |
| Outside agents calling Zapier MCP to send, invoice or update records | A runtime gateway with per-argument policy and named approvers |
| Agents allowed to create or publish Zaps through MCP | A gateway rule that holds deploy actions for a named approver |
Before buying anything for a finance Zap, ask whether it needs an agent at all. A Zap that only matches incoming payments to open invoices is a reconciliation job, and dedicated bank reconciliation software does that with fixed rules and no model to manipulate. Agents earn their place where judgment is needed, and that is also where approval belongs.
Questions buyers ask
Is Zapier MCP safe for business use?
Yes, at the connection level. It is covered by Zapier's SOC 2 Type II program, uses OAuth or token authentication, keeps credentials out of chat windows and logs tool calls in the History tab. Zapier itself calls MCP "an integration layer, not a security scanner", so judging each action remains your job.
Do Zapier agents need approval before sending emails or invoices?
They should. In AI by Zapier, switch on "Require approval before running" for each tool that sends, invoices or updates records, since the switch is off by default. For calls that arrive through Zapier MCP from Claude, ChatGPT or Cursor, add approval at a gateway in front of MCP, because Zapier has no per-call approval on that path.
What happens to approvals when I migrate Zapier Agents?
The migration copies your prompt, instructions and tools into one AI by Zapier step. An approval written as a sentence in the instructions stays a sentence the model is asked to follow. To get a platform-enforced pause, turn on "Require approval before running" on each write tool in the converted Zap, then test and publish it.
If you are weighing approval designs more broadly, our page on approval gates for AI agents shows how holds, approvers and expiry work, and teams running a self-hosted workflow tool beside Zapier should read n8n security.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.
Keep reading