Arcade: The Actions Runtime for Enterprise AI Agents

Govern every action for every AI agent

Arcade is the actions runtime between your agents and every system they reach. One control point to enforce, execute, and govern every action, every time. Teams keep shipping. Security stays in control.

Arcade is trusted for production agents at

Failed approaches to agent security

ROI results from agents taking on real work in production: updating records, closing tickets, moving money. But every action comes with a blast radius. And common approaches to securing these agents fail.

Agents get service accounts

Requires reducing permissions to the lowest common denominator, which limits the value of the actions it can take. Shared creds mean no accountability or auditability that can tie back to real users. And every new agent is one more account to manage.

Agents inherit user identity

Inherits all user permissions, which over-provisions the agent. Agents can now delete folders or take destructive actions, with no way to shrink the security boundary. And nothing in the audit trail separates the agent's actions from the user's.

Build custom security infra yourself

Building for one tool or agent quickly grows to hundreds. Your team now owns the consequence of every action, and it requires real security and application expertise to run at scale. You don't try to build your own SSO anymore, nor should you build internal agent governance systems.

Safely get agents into everyone's hands with a single runtime

Arcade enforces your security and governance policies on every action, executes reliably across every business system, and governs agents from a single control plane.

Everything agents need to ship

Enforce Execute Govern Integrate

Enforce

Authentication runs against your IdP. Authorization is delegated, so the agent acts as its user and never past its own scope. Your existing policies are enforced in the path of every action, outside the model where a prompt can't undo it.

Execute

8,000+ permission-aware tools, plus support for custom MCP you build or bring. Built-in evals catch hallucinated and destructive calls before they run, so agents hold up in production, at a lower cost per action.

Govern

One control plane grants, revokes, and versions every tool. Each action leaves one record, naming the agent, the user, and the system, streamed to your SIEM. Review the runtime once, and the golden path is the governed path.

Integrate everywhere

Any client, any model, whatever framework your team picked. Arcade runs alongside the IdPs, policy engines, and observability and eval tools you already use, so you ship faster and never get locked in.

Built to clear the security review

Compliance-ready

SOC 2 compliant. SSO, RBAC, and full audit logs out of the box.

Deploy on your terms

Cloud, on-prem, air-gapped, or hybrid. You control where your data lives and how it's secured.

The team that solved security for MCP

The Arcade team comes from Okta, Snowflake, Redis, Airbyte, and MongoDB. We authored the MCP tool authorization specification and sit on the steering committees for MCP security and governance.

What customers are saying

The runtime layer from Arcade makes MCP enterprise-ready. Connects to identity providers, enforces agent authorization, and enables real actions in Google, Slack, and Salesforce.

Harrison Chase

Co-Founder and CEO

Your questions, answered

How does Arcade govern AI agent actions?

Arcade enforces permissions through your existing OAuth and identity provider flows. Agents act on behalf of the authenticated user, never through broad service accounts. Every action runs at the intersection of what the user can do and what the agent is scoped to do. Cross either line and the action stops. You see and control every tool your agent touches.

What is an MCP runtime for AI agents?

An MCP runtime is the infrastructure layer that enables AI agents to securely connect to external tools and business systems. Arcade is the MCP runtime that handles user authentication, authorization, policy enforcement, and tool execution. Developers deploy production-ready AI agents without building custom integration infrastructure.

How does Arcade secure AI agent actions?

Arcade enforces user-specific permissions through your existing OAuth and identity provider flows. Agents act only on behalf of the authenticated user, not through broad service accounts. The runtime gives you visibility and control over every tool your AI agent accesses.

Can I deploy Arcade on my own infrastructure?

Yes. You can deploy the Arcade MCP runtime in your own cloud environment, a virtual private cloud, on-premises, or in a fully air-gapped environment. This deployment flexibility gives enterprise teams control over where data lives and how it is secured.

Can I add custom policies to Arcade for AI agents?

Yes. Arcade supports pre- and post-tool-call hooks that let your team add custom policies without forking the runtime. Inspect every request before it runs and every response before it returns. Block sensitive actions, redact PII, and stop data from leaving systems it shouldn't. The runtime enforces your policies on every call.