Updated October 6, 2026. Part 2 of APERION's Agent Platforms series.
To govern CrewAI in production, treat every crew as code your team runs and controls the edges of. Run a patched release. Send every model call and every MCP tool call through an endpoint you control. Give each crew its own credential and tie each run to the person who started it. Keep code execution in a sandbox, and record every call somewhere the crew cannot edit. CrewAI's task guardrails and execution hooks check an agent's work inside the run. Controls that must survive a code change belong outside the crew's process.
CrewAI is an open-source Python framework for multi-agent systems, released under the MIT license, with a commercial platform, CrewAI AMP, for deployment, tracing and access control (CrewAI on GitHub). Version 1.15.23 shipped on September 28, 2026 (PyPI). In March 2026, CERT/CC published four vulnerabilities in CrewAI tools in an attack chain that begins with prompt injection (CERT/CC VU#221883); two carry a CVSS score of 9.8 in the National Vulnerability Database. CrewAI's statement in the CERT/CC note, updated May 20, 2026, says all four are fixed in current releases.
What CrewAI Ships for Governance
| Control | What it does | Where it runs | What to check |
|---|---|---|---|
| Task guardrails | Validate a task's output with a function or an LLM check, and retry on failure (guardrail_max_retries, default 3) | Inside the crew | An LLM guardrail uses the agent's own model |
| Execution hooks | Intercept before and after model calls, tool calls and steps; abort with HookAborted | Inside the crew, synchronous | Hook context carries the agent, task, crew and tool, with no field for the end user |
| Human input | human_input=True on a task; @human_feedback steps in Flows | Inside the crew | Who reviews, and where the review is recorded |
| Run limits | max_iter (default 20), max_rpm, max_execution_time | Inside the crew | Set per agent; defaults allow long runs |
| MCP tool filter | Restrict which tools an MCP server exposes to an agent | Inside the crew | The filter lives in code that can change |
| AMP access control | Owner, Member and custom roles; permissions on automations, environment variables, LLM connections and repositories | CrewAI AMP | Who can deploy and who can read secrets |
| Agent Control Plane (beta) | PII redaction and cost limit policies, scoped by tools and tags | CrewAI AMP | Cost limits notify and never stop a run |
| Tracing and export | Traces in AMP; OpenTelemetry export to your own collector | CrewAI AMP | Retention, and who can read prompt content in traces |
Sources: CrewAI documentation for tasks, execution hooks, human feedback in Flows and agents. AMP access control and OpenTelemetry export. Agent Control Plane details as documented in July 2026; confirm against your plan.
Where a Crew's Model Calls and Tool Calls Go
Because a crew is code your team runs, you choose where its traffic goes. That is the main governance advantage CrewAI has over a hosted agent platform.
Model calls. CrewAI uses native SDKs for OpenAI, Anthropic, Google, Azure, AWS Bedrock and Snowflake Cortex, and LiteLLM for other providers when the optional extra is installed (CrewAI LLMs). The LLM() class takes a base_url, and CrewAI's documentation shows it pointed at a gateway:
import os
from crewai import LLM
llm = LLM(
model="anthropic/claude-sonnet-4-6",
custom_openai=True,
base_url="https://gateway.example.internal/v1",
api_key=os.environ["CREW_RESEARCH_KEY"],
)
Tool calls. Since version 1.4.0, an agent's mcps list accepts MCP server configurations over streamable HTTP, server-sent events or stdio (CrewAI MCP). In the open-source framework, authentication to an MCP server is a static header or a key in the URL. CrewAI's own guidance is to "only connect your CrewAI agents to MCP servers that you fully trust" (CrewAI MCP security).
Telemetry. CrewAI collects anonymous telemetry by default, including agent roles and tool names. Setting share_crew=True adds goals, backstories and task outputs. Set CREWAI_DISABLE_TELEMETRY=true where policy requires it (CrewAI telemetry).
How to Govern CrewAI Agents in 7 Steps
1. Run a patched release and track advisories
Inventory every crew and the CrewAI version it runs. Move all of them to a current release, then watch the CrewAI changelog and CERT/CC for new advisories. CrewAI removed its Code Interpreter tool in version 1.14.0, released April 7, 2026, and added SSRF and path-traversal protections in the same release (CrewAI changelog).
2. Send model calls through an endpoint you control
Set base_url on every LLM() to your gateway, and give each crew its own key. Keep provider keys out of code, environment files and container images. Per-crew keys let you see spend and behavior by crew, and revoke one crew without touching the rest.
3. Govern the tool path
Keep an allowlist of MCP servers each crew may call. Put remote servers behind a gateway that applies tool rules and records each call, and use tool_filter to expose only the tools a task needs. Run stdio servers only from packages your security team has reviewed, since a stdio server runs on the same host as the crew.
4. Keep code execution in a sandbox
CrewAI deprecated allow_code_execution and now points users to sandboxes such as E2B or Modal. If a crew must run code, run it in an isolated sandbox with no credentials and no network path to internal systems.
5. Tie every run to a person
On CrewAI AMP, start runs with a user bearer token so connected integrations act as that user, and keep the organization-level token for automation you can name (CrewAI AMP documentation). Pass the same identity to your gateway with each call. CrewAI's hook context has no field for the person behind a run, so identity has to travel with the request.
6. Require approval for consequential actions
Mark tasks that send, pay, delete or change access with human_input=True, or add @human_feedback steps in Flows. For actions taken through MCP tools, pause the call at the gateway and send it to a person who can approve it, so the approval survives a change to the crew's code.
7. Record every call outside the crew's process
Turn on tracing, export traces to your own OpenTelemetry collector, and keep the authoritative record at the gateway, where the crew cannot alter it. Set retention to your longest obligation.
What the 2026 CrewAI Vulnerabilities Show
The four issues CERT/CC published in March 2026 were in tools: a code interpreter fallback that allowed arbitrary C function calls (CVE-2026-2275), a JSON loader that read local files (CVE-2026-2285), server-side request forgery through retrieval tools (CVE-2026-2286), and remote code execution when Docker stopped running during a run and CrewAI fell back to a weaker sandbox (CVE-2026-2287). Each one started with text the agent read. The lesson applies to every framework: the tools an agent can reach set the size of what a prompt injection can do. Fewer tools, scoped credentials and a sandbox shrink it.
Operating Limits
- Hooks run in the crew's process. A code change can remove them.
- Cost limits in the Agent Control Plane notify. CrewAI's July 2026 documentation states that they never pause, throttle or stop a run.
- When memory is on, every agent in a crew shares it by default. Scope it per agent where agents handle different data.
- Default telemetry includes agent roles and tool names. Decide whether that is acceptable before production.
- Open-source MCP authentication is a static secret. Put remote servers behind a gateway that carries identity.
How APERION Fits
APERION's Smartflow serves OpenAI-compatible and Anthropic-compatible endpoints, so a crew's base_url can point at it, and its MCP gateway can front the servers a crew calls. Each crew gets its own key with model and route allowlists. Tool rules apply to every MCP call, an out-of-authority call goes to a person with approval rights, and every call lands in a hash-chained audit record your SIEM can ingest. Talk to APERION.
More in This Series
- How to govern AI agents across platforms
- Glean agents governance
- Agentforce governance
- Amazon Bedrock AgentCore governance
- Microsoft Copilot agent governance
- Google, ServiceNow, OpenAI, Anthropic and LangChain
Frequently Asked Questions
Is CrewAI secure enough for enterprise use?
CrewAI can run in regulated environments when the controls around it are in place: a patched release, model and tool calls routed through an endpoint you control, per-crew credentials, sandboxed code execution, and an audit record outside the crew. The framework's own guardrails check agent output inside the run.
Does CrewAI support guardrails?
Yes. Tasks accept function-based or LLM-based guardrails that validate output and retry on failure, three times by default. Execution hooks can inspect or block model calls and tool calls before and after they run.
How do I route CrewAI model calls through a gateway?
Set base_url and api_key on the LLM() object to your gateway's endpoint and a key issued for that crew. CrewAI's documentation shows this pattern with custom_openai=True for an OpenAI-compatible gateway.
Does CrewAI support MCP?
Yes. Since version 1.4.0, an agent's mcps list accepts MCP server configurations over streamable HTTP, server-sent events or stdio, with tool filtering per server.
How do I add human approval to a CrewAI crew?
Set human_input=True on tasks that need review, or add @human_feedback steps in a Flow. For actions taken through tools, pausing the call at a gateway keeps the approval in force even if the crew's code changes.
Does CrewAI collect telemetry?
By default, CrewAI collects anonymous usage telemetry, including agent roles and tool names. Set CREWAI_DISABLE_TELEMETRY=true to turn it off, and leave share_crew unset unless you intend to share goals and task outputs.
What CrewAI vulnerabilities were disclosed in 2026?
CERT/CC note VU#221883, published March 30, 2026, covers CVE-2026-2275, CVE-2026-2285, CVE-2026-2286 and CVE-2026-2287 in CrewAI tools. CrewAI's statement in the note, updated May 20, 2026, says all four are fixed in current releases.
Craig Alberino is the CEO and Founder of APERION, which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. Learn more about Smartflow →
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs