Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

MuleSoft Agent Fabric vs Zenity

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms; Zenity is an AI agent security and governance platform.⁠Source 1, Source 2 Agent Fabric enforces policy at a gateway and orchestrates A2A-compliant agents; Zenity says it finds agents and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Agent Fabric inventories agents from other platforms, can stop an agent from acting, and keeps audit trails; Zenity says it does too.⁠Source 3, Source 5, Source 7, Source 8, Source 9
Where they differ
With Agent Fabric, teams define and deploy agent networks, whose brokers orchestrate A2A-compliant agents.⁠Source 3, Source 4, Source 10 Building agents with Zenity isn’t in Zenity’s public docs.
Running both
MuleSoft says its scanner can register agents from Salesforce’s separate Agentforce; Zenity says it keeps an inventory and activity record of them.⁠Source 3, Source 5, Source 11 Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 3
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 3
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 3
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 3
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 3
  • Agents across organizations: Not publicly documented

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 5
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 12
  • Agents across organizations: Not publicly documented

At a glance

TopicMuleSoft Agent FabricZenity
Who it’s forMuleSoft says it is for enterprises that want agents to have managed access to systems and data, with IT and security teams in control.⁠Source 13Security teams that discover and inventory agents, enforce policies, and reduce unmanaged risk, per Zenity.⁠Source 14
How agents are foundScanners register agents, APIs, and MCP servers on supported platforms, which MuleSoft says include Amazon, Google, Microsoft, and Databricks.⁠Source 3, Source 15 Other agents can be registered by uploading an agent card.⁠Source 13, Source 16Zenity says AI Observability scans an organization’s environment and catalogs agents in SaaS platforms, custom-built agents, and agents on laptops.⁠Source 5
Where rules are appliedAt Omni Gateway, placed in the request path of each managed agent, API, or MCP server.⁠Source 3Zenity says Runtime Boundaries can check agent actions against rules in real time.⁠Source 8 It says agent hooks can block a coding agent’s dangerous tool call, and custom agents can use an Evaluate API for inline enforcement.⁠Source 9, Source 12
HostingAgent Fabric runs on MuleSoft-hosted Anypoint control planes in supported geographies; Omni Gateway can be managed or self-managed.⁠Source 1, Source 17Software as a service; Zenity’s AWS Marketplace listing shows it deployed on AWS.⁠Source 2
Pricing modelMuleSoft packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 18 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 18Custom pricing on its main AWS Marketplace listing.⁠Source 2 A separate Security Hub Extended listing shows usage prices per resource and per million tokens.⁠Source 19

What each one is

MuleSoft Agent Fabric

MuleSoft documents Agent Fabric as a control plane for agents, MCP servers, and APIs across platforms.⁠Source 1 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request paths, and agent brokers orchestrate A2A-compliant agents.⁠Source 3, Source 4, Source 13

Zenity AI Agent Security & Governance Platform

Zenity is a SaaS security and governance platform for AI agents.⁠Source 2 Zenity describes three layers: Surface maps what an agent can reach and how it’s configured, Enforce lets safe actions through and stops unsafe ones, and Protect catches what slips through.⁠Source 14

The differences that matter

  1. Where rules are enforced

    MuleSoft Agent Fabric

    Omni Gateway sits in the request path of managed agents, APIs, and MCP servers; MuleSoft says third-party agents can be governed there unmodified.⁠Source 3, Source 13

    Zenity

    Runtime Boundaries can check agent actions in real time; Zenity says it can block actions only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 8

    For Amazon Bedrock AgentCore agents, Zenity says security teams can instrument the agent’s code to enforce inline controls.⁠Source 20 Omni Gateway is required for managed instances and rogue-agent containment.⁠Source 1

  2. What the inventory is for

    MuleSoft Agent Fabric

    Teams can publish agents, MCP servers, and APIs to the registry for other teams to reuse; it can also be searched through an MCP endpoint.⁠Source 3, Source 21

    Zenity

    Zenity says AI Observability gives security teams each agent’s configuration, permissions, and tool access, and flags agents outside sanctioned deployment channels.⁠Source 5, Source 14

    Whether employees or agents can search Zenity’s inventory isn’t in Zenity’s public docs.

  3. Building and orchestrating agents

    MuleSoft Agent Fabric

    Teams define agent networks in YAML and brokers in Agent Script; brokers orchestrate A2A-compliant agents and run on CloudHub 2.0 or Runtime Fabric.⁠Source 3, Source 4, Source 10

    Zenity

    Zenity says it inventories and tracks agents built elsewhere, from Copilot Studio and Agentforce to homegrown agents on Bedrock or Vertex AI.⁠Source 5

    MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 13

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicMuleSoft Agent FabricZenity
Network exposureOmni Gateway sits in managed agents’ request path; agent-network ingress gateways get a public endpoint, egress gateways none.⁠Source 3, Source 22Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 23
IdentityFor rogue-agent detection, agents are set up as service identities in your identity provider; Anypoint sign-in supports OIDC and SAML.⁠Source 7, Source 24Zenity says rules can reference Okta attributes such as role.⁠Source 8 Issuing agent identities isn’t in Zenity’s public docs.
Access changes and revocationAfter review, quarantine stops a flagged agent from acting and blocks it at model proxies with the Kill Switch policy.⁠Source 7Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 8 It says rules can shut agents down.⁠Source 8
Audit trailOmni Gateway can keep a traffic audit trail; Anypoint Platform audit logs are kept one year by default.⁠Source 3, Source 25Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 5, Source 9
ComplianceMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 26 Agent Fabric’s own scope: not publicly documented.Zenity says it has SOC 2 Type II, is ISO 27001 compliant, and announced FedRAMP “In Process” in March 2026.⁠Source 27, Source 28

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

MuleSoft Agent Fabric and Zenity compared on 18 criteria
MuleSoft Agent FabricZenity
What it is
What it is and who it’s forControl plane for agents, MCP servers, and APIs across platforms.⁠Source 1 MuleSoft says it discovers, governs, orchestrates, and observes agents.⁠Source 15A security and governance platform for AI agents across SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.⁠Source 2, Source 14
MaturityMuleSoft says it is generally available, with new capabilities each month.⁠Source 13 Its first release note is dated 3 October 2025.⁠Source 4Zenity announced Azure Marketplace (now Microsoft Marketplace) availability in March 2025 and AWS in January 2026.⁠Source 29, Source 30, Source 31
Control
Agent registry and discoveryOne inventory of agents, MCP servers, and APIs, whatever platform built them.⁠Source 3 Scanners fill it from supported platforms; agents can also be added by agent card.⁠Source 3, Source 16Zenity says AI Observability scans for agents in SaaS platforms, custom builds, and on laptops, listing each with its permissions and tool access.⁠Source 5
Identity and access controlOmni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 3 User roles come from Anypoint access management.⁠Source 1Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.⁠Source 8 Issuing agent identities isn’t in Zenity’s public docs.
Ownership, policy, and revocationGovernance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 3 Flagged agents can be quarantined after review.⁠Source 7Zenity says rules can allow an action, block it, or shut the agent down, but it blocks inline only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 8
Audit log and observabilityOmni Gateway can keep a traffic audit trail.⁠Source 3 Anypoint audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.⁠Source 25Zenity says it logs agent messages, tool calls, retrievals, and handoffs.⁠Source 5 It says its audit log events can stream to Splunk or Microsoft Sentinel.⁠Source 9
Connection
How agents connectOmni Gateway sits in the request path of each managed agent, API, or MCP server.⁠Source 3 Agent-network ingress gateways get a public endpoint; egress gateways don’t.⁠Source 22Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for inline enforcement.⁠Source 9 Network needs: not in Zenity’s public docs.
Agents across organizationsAn egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 22 Partner-held access controls: not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 23
Protocol supportOmni Gateway supports MCP and A2A.⁠Source 32 A2A powers orchestration in agent networks; MCP Bridge turns an API into an MCP server without custom code.⁠Source 3, Source 33Zenity says OpenTelemetry agents can connect; agent hooks can block dangerous coding-agent tool calls.⁠Source 9, Source 12 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedMuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.⁠Source 13, Source 15 Brokers orchestrate only A2A-compliant agents.⁠Source 3Zenity says it covers agents in Copilot Studio and Agentforce; homegrown agents on Bedrock or Vertex AI; coding agents; agents emitting OpenTelemetry.⁠Source 5, Source 9, Source 12
Operations
Deployment options and data residencyAgent Fabric runs on MuleSoft-hosted regional control planes.⁠Source 17 Omni Gateway can be self-managed.⁠Source 1, Source 34 Self-hosting its control plane isn’t publicly documented.Software as a service, shown on AWS Marketplace as deployed on AWS.⁠Source 2 Regions, data residency, and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR.⁠Source 26 An attestation naming Agent Fabric is not publicly documented.Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.⁠Source 27 It announced FedRAMP “In Process” status in March 2026.⁠Source 28
Support and SLAMuleSoft’s Cloud Offerings SLA commits to 99.95% monthly for covered services, on subscriptions started by 1 May 2025.⁠Source 35 Anypoint plans include Premier Success.⁠Source 36Zenity’s terms commit to at least 99.9% monthly uptime, with commercially reasonable efforts.⁠Source 37 Support requests go through Zendesk in business hours.⁠Source 37
Time and effort to get runningWith product access, an admin turns Agent Fabric on.⁠Source 1 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.⁠Source 1Zenity says its Cursor plugin installs in Cursor desktop and its Security Hub integration starts from that console.⁠Source 38, Source 39 Prerequisites: not in Zenity’s public docs.
Pricing model and public pricesMuleSoft packages start at $2,000 a month, billed annually, with usage in Mule Credits.⁠Source 18 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 18Main AWS listing: custom pricing.⁠Source 2 Security Hub Extended listing: prices per resource or per million tokens, such as $130 per resource a month for Observability.⁠Source 19
Building
Agent building toolsAgent networks are defined in YAML, brokers in Agent Script.⁠Source 3, Source 10 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 13Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 23
Model accessBrokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 10 Model Proxy is one access layer for several providers, with spend caps.⁠Source 3, Source 40Zenity says its detection and response (AIDR) combines deterministic rules with LLM-based detections.⁠Source 41 Which models it uses isn’t in Zenity’s public docs.
Integrations and ecosystemMuleSoft says it has hundreds of enterprise connectors.⁠Source 13 The catalog has curated public MCP servers from the Official MCP Registry and Informatica.⁠Source 3Zenity says its signals can show in Microsoft Agent 365 and findings in AWS Security Hub Extended; it is on the Cursor Marketplace.⁠Source 38, Source 39, Source 42

Which to choose

Choose MuleSoft Agent Fabric if

  • You already run MuleSoft’s Anypoint Platform: Agent Fabric uses Anypoint Platform access management and is turned on there.⁠Source 1
  • You want a gateway in managed agents’ request path that can require authentication and limit tool calls.⁠Source 3
  • You want brokers to orchestrate A2A-compliant agents across ecosystems, with LLM reasoning kept apart from deterministic control flow.⁠Source 3, Source 4
  • You want Model Proxy to cap a caller’s token or dollar spend against a model provider.⁠Source 3

Choose Zenity if

  • You want what Zenity says it offers: finding agents on laptops and in ChatGPT Enterprise, with flags for those outside sanctioned channels.⁠Source 5
  • Developers use coding agents such as Claude Code, Cursor, or GitHub Copilot, and Zenity says it can block their dangerous tool calls.⁠Source 9, Source 12
  • Your security team wants threat detection that, Zenity says, combines rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.⁠Source 41
  • You want what Zenity says it offers: posture policies that can alert, block, or automatically remediate, with each discovered agent’s ownership surfaced.⁠Source 43

Questions buyers ask

Do they work with Salesforce Agentforce agents?

MuleSoft says its Agentforce scanner became generally available in January 2026.⁠Source 11 Agentforce agents aren’t A2A-compliant on their own, so an A2A bridge presents them as A2A-compliant for orchestration.⁠Source 1, Source 3, Source 44 Zenity says it builds an inventory and activity record for agents inside Agentforce.⁠Source 5

How is each one priced?

MuleSoft packages start at $2,000 a month, billed annually.⁠Source 18 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 18 Zenity’s main AWS Marketplace listing has custom pricing; its Security Hub Extended listing shows prices such as $130 per resource monthly for Observability.⁠Source 2, Source 19

Do they support MCP and A2A?

Agent Fabric’s Omni Gateway supports both, and A2A powers orchestration in its agent networks.⁠Source 32, Source 33 For coding agents, Zenity says its agent hooks can block or modify a dangerous tool call before it executes.⁠Source 12 Whether Zenity supports A2A isn’t publicly documented.

Can either one stop an agent?

After admin review, Agent Fabric can quarantine a flagged agent, stopping it and blocking it at model proxies using the Agent Kill Switch policy.⁠Source 7 Zenity says its kill switch immediately disables an agent’s tool and data access, and its rules can shut an agent down.⁠Source 8

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

49 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Get Started with Agent Fabric Salesforce · checked Back:abcdefghijk

  2. Source 2: AWS Marketplace: Zenity Zenity · checked Back:abcdefgh

  3. Source 3: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz272829303132

  4. Source 4: Agent Fabric Release Notes Salesforce · checked Back:abcdef

  5. Source 5: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijklm

  6. Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abc

  7. Source 7: Detect and Contain Rogue Agents Salesforce · checked Back:abcde

  8. Source 8: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefghi

  9. Source 9: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefgh

  10. Source 10: Building Agent Networks for Agent Fabric Salesforce · checked Back:abcd

  11. Source 11: Salesforce Expands MuleSoft Agent Fabric with Automated Discovery for Any AI Agent or Tool Salesforce · checked Back:ab

  12. Source 12: Coding and Personal Agents | Zenity Zenity · checked Back:abcdef

  13. Source 13: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdefghi

  14. Source 14: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abcd

  15. Source 15: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abc

  16. Source 16: Register Services Manually Salesforce · checked Back:ab

  17. Source 17: Salesforce Hyperforce Overview Salesforce · checked Back:ab

  18. Source 18: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdef

  19. Source 19: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  20. Source 20: Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore Zenity · checked Back to text

  21. Source 21: Retrieving Asset Metadata Using an MCP Server Endpoint Salesforce · checked Back to text

  22. Source 22: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abc

  23. Source 23: Zenity Documentation (login) Zenity · checked Back:abc

  24. Source 24: Configuring Identity Management in Anypoint Platform Salesforce · checked Back to text

  25. Source 25: Audit Logging in Anypoint Platform Salesforce · checked Back:ab

  26. Source 26: Anypoint Platform Trust Center Salesforce · checked Back:ab

  27. Source 27: Zenity Trust Center Zenity · checked Back:ab

  28. Source 28: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  29. Source 29: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  30. Source 30: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  31. Source 31: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back to text

  32. Source 32: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:ab

  33. Source 33: Using A2A Protocol in Agent Networks Salesforce · checked Back:ab

  34. Source 34: Requirements and Limits for Omni Gateway Salesforce · checked Back to text

  35. Source 35: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  36. Source 36: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  37. Source 37: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  38. Source 38: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back:ab

  39. Source 39: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back:ab

  40. Source 40: Creating and Managing Model Proxies Salesforce · checked Back to text

  41. Source 41: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back:ab

  42. Source 42: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  43. Source 43: AI Security Posture Management (AISPM) | Stop Agent Risk Before Deployment | Zenity Zenity · checked Back to text

  44. Source 44: Enhanced MuleSoft Experience Release Notes Salesforce · checked Back to text

  45. Source 45: Your company's private network Blocks.ai · checked Back to text

  46. Source 46: Network requirements Blocks.ai · checked Back to text

  47. Source 47: Solutions: Agent sprawl Blocks.ai · checked Back to text

  48. Source 48: Solutions: Partner networks Blocks.ai · checked Back to text

  49. Source 49: Pricing Blocks.ai · checked Back to text