Skip to main content

Web search security

Apply your Zscaler Internet Access (ZIA) URL policy to the QuilrAI Web Search MCP, so agents can only open web pages your users are allowed to visit.

Setup has two parts: connect ZIA once for your tenant, then set the policy on the QuilrAI Web Search server.

note

This policy applies only to the built-in QuilrAI Web Search server. Other MCP servers are not affected.

Connect ZIA​

Go toQuilrAI consoleSettingsAI GatewayMCP Gateway...ZIA integration

  1. Enter the ZIA base URL, for example https://zsapi.zscaler.net.
  2. Enter the API key, Admin username and Admin password of a ZIA admin account.
  3. Click Connect ZIA.

The status changes to Connected and shows how many ZIA groups and departments are available. Credentials are not displayed again. To change them, enter new values and connect again.

Set the policy​

Go toQuilrAI consoleSettingsAI GatewayMCP GatewayQuilrAI Web Search cardConfigureGeneral

Scroll to Web Search policy ("Apply ZIA-backed group policy and explicit URL overrides to web-search results").

SettingWhat it does
ZIA check timeoutMaximum seconds to wait for a ZIA decision before assuming the URL is allowed.
ZIA URL overridesOne URL or domain per line. These values override the ZIA lookup.
Groups with domain exclusionsA switch per smart group. Turn it on for the groups that receive domain exclusions in their search results.

Click Save settings in the footer to apply your changes.

How it works​

  1. An agent asks QuilrAI Web Search to open one or more web pages.
  2. The gateway looks up the person's ZIA groups and department and checks each URL with ZIA, applying your ZIA URL overrides first.
  3. URLs ZIA blocks for that person are removed. The rest are fetched and returned.

Because the check uses the person's own ZIA identity, web search results follow the same ZIA URL policy that applies to that person.

Going further with the Policy Engine​

The Web Search Security card (stage 4, Response) in Govern > Policy Engine > MCP Gateway carries the same controls as policy effects: ZIA timeout, URL overrides, excluded domains and a result domain action. Edits join a shared draft and apply once you publish a revision.

Scenarios the card supports beyond the server setting:

  • Exclude domains outright. List domains such as paste sites or raw file hosts as excluded domains and set result domain action to block, independent of the ZIA lookup.
  • Different rules per group or agent. Match smart groups, user email or agent name, for example a stricter exclusion list for contractors.
  • Pair with token saving. One response rule can also turn on smart JSON compression and HTML to text for search results.
compress_and_fence_searchresponse

runs on responsepriority 400

WhenMCP nameisWeb Search
Then
smart JSON compressiontrue
HTML to texttrue
excluded domainspastebin.comraw.githubusercontent.com
result domain actionblock