All posts
2 min readby Romiel Inolino

Zapier Agents is now a step inside your Zaps. Per-tool approvals and a 75-task cap make agents safer to ship

ZapierAI agentsautomationworkflow designguardrails

Zapier just moved its agents out of their own app and into the Zap editor, and that changes how you should design them.

What happened

On October 6, Zapier announced that Zapier Agents is now AI by Zapier. An agent's prompt, tools, trigger and permission to act now live inside a single AI step you can drop into any Zap. Zapier says the old standalone product sat outside the platform, so agents could not use Zap triggers, filters, paths or run history.

The changes that matter:

  • Approval is set per tool with "Require approval before running". Agents used to be all or nothing.
  • You pick a model tier (Standard, Advanced, Premium) or name a specific model per step.
  • You define the fields you want back, such as a category or a sentiment score, and they arrive as mappable outputs.
  • Every run lands in Zap History with tools called, inputs, outputs, model tier and tasks consumed.
  • AI steps bill as tasks. Default models are free, and other tiers carry multipliers, so a step can cost 1, 3 or 5 tasks.
  • If a single run crosses 75 tasks, it pauses for a human. Zapier's help center says the limit is adjustable up to 500.

Migration converts each agent into a Zap with a trigger and one AI step. Zapier has not set a shutdown date for the old Agents product and says it will email users first.

My take

This is the pattern I have been pushing clients toward for a while: let the model reason only where judgment is needed, and keep everything else deterministic. Zapier's own example says it well. Let the AI decide which record to update, then send the confirmation email with a normal action so it reads the same every time.

Three things I would do this week if you run Zapier Agents:

  1. Migrate, then split. Migration keeps your agent as one big AI step. The value comes after, when you pull fixed actions like sends and updates out into native steps.
  2. Turn on approval for every write that touches a customer or money. Leave reads open.
  3. Replace prose outputs with structured fields. Parsing paragraphs downstream is where most of my client bugs start.

The 75-task pause is the quiet hero here. Runaway loops were the main reason I kept agents off client accounts. A hard stop that waits for a human makes them much easier to approve.

More posts