Guide

CrewAI Security and Governance: How to Run Crews in Production

CrewAI Security and Governance: How to Run Crews in Production

Updated October 6, 2026. Part 2 of APERION's Agent Platforms series.

To govern CrewAI in production, treat every crew as code your team runs and controls the edges of. Run a patched release. Send every model call and every MCP tool call through an endpoint you control. Give each crew its own credential and tie each run to the person who started it. Keep code execution in a sandbox, and record every call somewhere the crew cannot edit. CrewAI's task guardrails and execution hooks check an agent's work inside the run. Controls that must survive a code change belong outside the crew's process.

CrewAI is an open-source Python framework for multi-agent systems, released under the MIT license, with a commercial platform, CrewAI AMP, for deployment, tracing and access control (CrewAI on GitHub). Version 1.15.23 shipped on September 28, 2026 (PyPI). In March 2026, CERT/CC published four vulnerabilities in CrewAI tools in an attack chain that begins with prompt injection (CERT/CC VU#221883); two carry a CVSS score of 9.8 in the National Vulnerability Database. CrewAI's statement in the CERT/CC note, updated May 20, 2026, says all four are fixed in current releases.

What CrewAI Ships for Governance

ControlWhat it doesWhere it runsWhat to check
Task guardrailsValidate a task's output with a function or an LLM check, and retry on failure (guardrail_max_retries, default 3)Inside the crewAn LLM guardrail uses the agent's own model
Execution hooksIntercept before and after model calls, tool calls and steps; abort with HookAbortedInside the crew, synchronousHook context carries the agent, task, crew and tool, with no field for the end user
Human inputhuman_input=True on a task; @human_feedback steps in FlowsInside the crewWho reviews, and where the review is recorded
Run limitsmax_iter (default 20), max_rpm, max_execution_timeInside the crewSet per agent; defaults allow long runs
MCP tool filterRestrict which tools an MCP server exposes to an agentInside the crewThe filter lives in code that can change
AMP access controlOwner, Member and custom roles; permissions on automations, environment variables, LLM connections and repositoriesCrewAI AMPWho can deploy and who can read secrets
Agent Control Plane (beta)PII redaction and cost limit policies, scoped by tools and tagsCrewAI AMPCost limits notify and never stop a run
Tracing and exportTraces in AMP; OpenTelemetry export to your own collectorCrewAI AMPRetention, and who can read prompt content in traces

Sources: CrewAI documentation for tasks, execution hooks, human feedback in Flows and agents. AMP access control and OpenTelemetry export. Agent Control Plane details as documented in July 2026; confirm against your plan.

Where a Crew's Model Calls and Tool Calls Go

Because a crew is code your team runs, you choose where its traffic goes. That is the main governance advantage CrewAI has over a hosted agent platform.

Model calls. CrewAI uses native SDKs for OpenAI, Anthropic, Google, Azure, AWS Bedrock and Snowflake Cortex, and LiteLLM for other providers when the optional extra is installed (CrewAI LLMs). The LLM() class takes a base_url, and CrewAI's documentation shows it pointed at a gateway:

import os
from crewai import LLM

llm = LLM(
    model="anthropic/claude-sonnet-4-6",
    custom_openai=True,
    base_url="https://gateway.example.internal/v1",
    api_key=os.environ["CREW_RESEARCH_KEY"],
)

Tool calls. Since version 1.4.0, an agent's mcps list accepts MCP server configurations over streamable HTTP, server-sent events or stdio (CrewAI MCP). In the open-source framework, authentication to an MCP server is a static header or a key in the URL. CrewAI's own guidance is to "only connect your CrewAI agents to MCP servers that you fully trust" (CrewAI MCP security).

Telemetry. CrewAI collects anonymous telemetry by default, including agent roles and tool names. Setting share_crew=True adds goals, backstories and task outputs. Set CREWAI_DISABLE_TELEMETRY=true where policy requires it (CrewAI telemetry).

How to Govern CrewAI Agents in 7 Steps

1. Run a patched release and track advisories

Inventory every crew and the CrewAI version it runs. Move all of them to a current release, then watch the CrewAI changelog and CERT/CC for new advisories. CrewAI removed its Code Interpreter tool in version 1.14.0, released April 7, 2026, and added SSRF and path-traversal protections in the same release (CrewAI changelog).

2. Send model calls through an endpoint you control

Set base_url on every LLM() to your gateway, and give each crew its own key. Keep provider keys out of code, environment files and container images. Per-crew keys let you see spend and behavior by crew, and revoke one crew without touching the rest.

3. Govern the tool path

Keep an allowlist of MCP servers each crew may call. Put remote servers behind a gateway that applies tool rules and records each call, and use tool_filter to expose only the tools a task needs. Run stdio servers only from packages your security team has reviewed, since a stdio server runs on the same host as the crew.

4. Keep code execution in a sandbox

CrewAI deprecated allow_code_execution and now points users to sandboxes such as E2B or Modal. If a crew must run code, run it in an isolated sandbox with no credentials and no network path to internal systems.

5. Tie every run to a person

On CrewAI AMP, start runs with a user bearer token so connected integrations act as that user, and keep the organization-level token for automation you can name (CrewAI AMP documentation). Pass the same identity to your gateway with each call. CrewAI's hook context has no field for the person behind a run, so identity has to travel with the request.

6. Require approval for consequential actions

Mark tasks that send, pay, delete or change access with human_input=True, or add @human_feedback steps in Flows. For actions taken through MCP tools, pause the call at the gateway and send it to a person who can approve it, so the approval survives a change to the crew's code.

7. Record every call outside the crew's process

Turn on tracing, export traces to your own OpenTelemetry collector, and keep the authoritative record at the gateway, where the crew cannot alter it. Set retention to your longest obligation.

What the 2026 CrewAI Vulnerabilities Show

The four issues CERT/CC published in March 2026 were in tools: a code interpreter fallback that allowed arbitrary C function calls (CVE-2026-2275), a JSON loader that read local files (CVE-2026-2285), server-side request forgery through retrieval tools (CVE-2026-2286), and remote code execution when Docker stopped running during a run and CrewAI fell back to a weaker sandbox (CVE-2026-2287). Each one started with text the agent read. The lesson applies to every framework: the tools an agent can reach set the size of what a prompt injection can do. Fewer tools, scoped credentials and a sandbox shrink it.

Operating Limits

  • Hooks run in the crew's process. A code change can remove them.
  • Cost limits in the Agent Control Plane notify. CrewAI's July 2026 documentation states that they never pause, throttle or stop a run.
  • When memory is on, every agent in a crew shares it by default. Scope it per agent where agents handle different data.
  • Default telemetry includes agent roles and tool names. Decide whether that is acceptable before production.
  • Open-source MCP authentication is a static secret. Put remote servers behind a gateway that carries identity.

How APERION Fits

APERION's Smartflow serves OpenAI-compatible and Anthropic-compatible endpoints, so a crew's base_url can point at it, and its MCP gateway can front the servers a crew calls. Each crew gets its own key with model and route allowlists. Tool rules apply to every MCP call, an out-of-authority call goes to a person with approval rights, and every call lands in a hash-chained audit record your SIEM can ingest. Talk to APERION.

More in This Series

Frequently Asked Questions

Is CrewAI secure enough for enterprise use?

CrewAI can run in regulated environments when the controls around it are in place: a patched release, model and tool calls routed through an endpoint you control, per-crew credentials, sandboxed code execution, and an audit record outside the crew. The framework's own guardrails check agent output inside the run.

Does CrewAI support guardrails?

Yes. Tasks accept function-based or LLM-based guardrails that validate output and retry on failure, three times by default. Execution hooks can inspect or block model calls and tool calls before and after they run.

How do I route CrewAI model calls through a gateway?

Set base_url and api_key on the LLM() object to your gateway's endpoint and a key issued for that crew. CrewAI's documentation shows this pattern with custom_openai=True for an OpenAI-compatible gateway.

Does CrewAI support MCP?

Yes. Since version 1.4.0, an agent's mcps list accepts MCP server configurations over streamable HTTP, server-sent events or stdio, with tool filtering per server.

How do I add human approval to a CrewAI crew?

Set human_input=True on tasks that need review, or add @human_feedback steps in a Flow. For actions taken through tools, pausing the call at a gateway keeps the approval in force even if the crew's code changes.

Does CrewAI collect telemetry?

By default, CrewAI collects anonymous usage telemetry, including agent roles and tool names. Set CREWAI_DISABLE_TELEMETRY=true to turn it off, and leave share_crew unset unless you intend to share goals and task outputs.

What CrewAI vulnerabilities were disclosed in 2026?

CERT/CC note VU#221883, published March 30, 2026, covers CVE-2026-2275, CVE-2026-2285, CVE-2026-2286 and CVE-2026-2287 in CrewAI tools. CrewAI's statement in the note, updated May 20, 2026, says all four are fixed in current releases.


Craig Alberino is the CEO and Founder of APERION, which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. Learn more about Smartflow →

Craig Alberino
Craig Alberino
Craig Alberino is the Founder and CEO of APERION, which builds the runtime governance layer for AI agents in regulated enterprises. Inline policy enforcement and identity-bound audit, deployable on premises.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs