AgentShield
How it works Pricing Blog FAQ Contact Sign in

Best AI Agent Security Software for Zapier Agents and Zapier MCP in 2026

AgentShield Security Team·Oct 5, 2026·8 min read

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

Server room aisle with a locked access gate

For most Zapier customers, the best AI agent security software is the set of controls Zapier already ships, switched on: Zapier MCP disabled in workspaces that do not use it, admin app restrictions, "Require approval before running" on every AI by Zapier tool that writes, and AI Guardrails on inbound text. You need a separate runtime layer once Claude, ChatGPT, Cursor or your own agents call Zapier MCP with actions that send, invoice, refund or change records, because that path has no per-call approval.

We sell that runtime layer, so opening with "you may not need us" is deliberate. It is the accurate answer for a large share of Zapier accounts, and it saves a sales call if your AI steps only draft and summarize.

Why Zapier teams are reviewing agent security this quarter

Three changes landed close together. First, Zapier MCP turned every Zapier account into an action layer for outside AI tools. Zapier's own security page states that "Zapier MCP is enabled by default for all accounts, including Enterprise" and that "All users within the account can access Zapier MCP." Many IT teams learned this from the History tab, not from a request.

Second, Zapier is migrating its standalone Zapier Agents into AI by Zapier steps inside the Zap editor. No shutdown date has been set, but the help center already walks users through a "Migrate your Zap" button. Old agents asked for approval through a sentence in their instructions. The new step has a real platform switch, "Require approval before running", and Zapier documents that "This toggle is off by default."

Third, at ZapConnect on September 23, 2026, Zapier announced Next Gen Zaps: workflows you can describe in Claude, ChatGPT or Cursor and deploy through MCP, watched by a monitoring agent that "can apply or suggest a fix." That feature, Agentic Management, is on by default where it is available. So an AI tool can now create automations, and another agent can edit them.

None of this makes Zapier unsafe. It moves the decision about which write happens from a fixed Zap to a model, and that is the moment security owners should look again.

Six options compared

OptionWhat it coversWhere it stopsBest for
Zapier built-in settingsMCP on or off per workspace, app access controls, approval switch per AI tool, Human in the Loop stepScope is per app and action, not per value; no approval on calls from outside MCP clientsEvery Zapier account, as the baseline
AI Guardrails by ZapierDetect Prompt Attack, PII, toxicity and sentiment checks inside ZapsReturns a result; your Zap must branch on itAI steps that read email, tickets or form text
Zapier Enterprise planAdmin-managed apps, publishing restrictions, SIEM streaming, configurable retentionBetter governance of who builds what; still no judgment on each callLarge teams with many builders
DLP tools that scan MCP trafficFinding and masking sensitive data in what tools return to the modelFocused on data leaving, not on actions being takenTeams whose main risk is PII reaching a model
Self-hosted policy engineOpen source policy checks you deploy and run yourselfYou own hosting, upgrades, approver flow and on-callPlatform teams with spare engineering time
AgentShield runtime gatewayPer-action, per-argument policy on Zapier MCP calls, named approvers, injection checks, decision logDoes not sit inside AI by Zapier steps that run within ZapierOutside agents calling Zapier MCP with write actions

The first two rows are already in your subscription. Start there.

Start with Zapier's own settings switched on

Most of the exposure we see in Zapier accounts comes from defaults nobody revisited. Disable Zapier MCP in workspaces where nobody uses it and restrict it by membership elsewhere. Use app access controls to keep finance and payroll apps away from teams that do not need them. In every AI by Zapier step that has a tool which creates, updates, sends or deletes, turn on "Require approval before running". Zapier's own guidance lists the right candidates: customer-facing messages, "Creating invoices, modifying contracts, updating payment information", and data changes that are hard to undo.

When the switch is on, the step "pauses before that tool runs and waits for your approval, regardless of how specific your prompt is," and sends an email with a review link. That last clause is the important improvement over legacy Zapier Agents, where approval was a sentence the model was asked to follow.

AI Guardrails by Zapier inside your Zaps

Zapier launched AI Guardrails in March 2026. It adds actions such as Detect Prompt Attack, Detect PII and Detect Toxicity that you place in a Zap before or after an AI step. The design choice to understand is that it reports rather than blocks. You add a filter, a path or a human review step that acts on the result. Zapier is candid that "No AI-powered detection system is 100% accurate" and that the feature is "designed to supplement, not replace, your existing security, privacy, and compliance measures." Used that way, it is a sensible, low-cost layer for any Zap that feeds outside text into a model.

The Zapier Enterprise plan for large builder teams

Enterprise adds the governance large teams ask for: admin-managed app connections, publishing restrictions, log streaming to Datadog, Splunk or another SIEM, and configurable retention for history. If your problem is fifty builders creating Zaps with personal connections, this solves more of it than any third-party tool. What it does not add is a decision about whether a particular call with particular values should run.

DLP scanning and self-hosted policy engines

DLP vendors now scan MCP traffic for sensitive data, which is the right tool if your worry is customer PII or secrets flowing from Zapier lookups into a model's context. A self-hosted policy engine, such as Microsoft's open source Agent Governance Toolkit, can intercept agent actions before they execute if you are willing to run it. Both are honest choices. The first is aimed at data, not actions. The second is a project your platform team owns, including the approver experience and the pager.

A runtime gateway in front of Zapier MCP

The gap the built-in options leave is narrow and specific: an AI client outside Zapier chooses an action, Zapier MCP executes it with stored connections, and nothing between them asks whether this invoice, this email to this customer or this deal stage change should happen. That is where we fit. Claude, ChatGPT, Cursor or your in-house agents connect to an AgentShield MCP gateway endpoint, the Zapier token stays with the gateway, and policy decides per action and per argument what runs, what waits for a named approver and what is refused. Inputs are checked for injected instructions with prompt injection protection, and each decision lands in the AI agent audit trail with the approver and the rule. The full control map is on our Zapier MCP security page.

We are not the right answer inside Zapier itself. An AI by Zapier step that runs within a Zap calls Zapier actions directly, so use the approval switch and AI Guardrails there.

Which option fits which Zapier account

Your situationWhat to buy
Classic Zaps only, no AI steps, nobody using MCPNothing. Turn Zapier MCP off.
AI steps that read, summarize or create draftsNothing. Add AI Guardrails on inbound text.
Migrated Zapier Agents with write toolsNothing new. Switch on approval for each write tool after migrating.
Many builders, personal connections everywhereThe Enterprise plan
Outside agents calling Zapier MCP to send, invoice or update recordsA runtime gateway with per-argument policy and named approvers
Agents allowed to create or publish Zaps through MCPA gateway rule that holds deploy actions for a named approver

Before buying anything for a finance Zap, ask whether it needs an agent at all. A Zap that only matches incoming payments to open invoices is a reconciliation job, and dedicated bank reconciliation software does that with fixed rules and no model to manipulate. Agents earn their place where judgment is needed, and that is also where approval belongs.

Questions buyers ask

Is Zapier MCP safe for business use?

Yes, at the connection level. It is covered by Zapier's SOC 2 Type II program, uses OAuth or token authentication, keeps credentials out of chat windows and logs tool calls in the History tab. Zapier itself calls MCP "an integration layer, not a security scanner", so judging each action remains your job.

Do Zapier agents need approval before sending emails or invoices?

They should. In AI by Zapier, switch on "Require approval before running" for each tool that sends, invoices or updates records, since the switch is off by default. For calls that arrive through Zapier MCP from Claude, ChatGPT or Cursor, add approval at a gateway in front of MCP, because Zapier has no per-call approval on that path.

What happens to approvals when I migrate Zapier Agents?

The migration copies your prompt, instructions and tools into one AI by Zapier step. An approval written as a sentence in the instructions stays a sentence the model is asked to follow. To get a platform-enforced pause, turn on "Require approval before running" on each write tool in the converted Zap, then test and publish it.

If you are weighing approval designs more broadly, our page on approval gates for AI agents shows how holds, approvers and expiry work, and teams running a self-hosted workflow tool beside Zapier should read n8n security.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.

Open the console