Runtime authorization & controls
Arcade
Actions runtime that brokers agent tool calls to SaaS systems, handling OAuth and user token storage and applying per-action authorization so an agent acts within both the user's and its own scope. Pre- and post-tool-call hooks allow blocking or redaction, though the hosted tool catalogue is vendor-maintained.
hybrid · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Runtime authorization & controls · Agent identity & access · Agent building & orchestration
Useful conversation with: Application security lead, Platform engineer, IAM manager.
Ask for a demonstration
Show me an agent calling a Gmail tool through Arcade where the user consents via OAuth, a pre-tool-call hook blocks a send action, and the audit log records the decision.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
Arcade handles OAuth and user token management and enforces security policies on every action, adding per-action authorization at runtime on top of existing IdP, DLP and compliance policies.
Limit: Documentation home page does not specify policy syntax or how conflicts with IdP policy are resolved.
Source s1
Vendor claim
The product page states pre- and post-tool-call hooks can inspect requests and responses to block sensitive actions, redact PII and prevent data leaving systems.
Limit: Hook behaviour and failure modes are asserted on the product page rather than documented in reference material fetched here.
Source s2
Documented by provider
Arcade provides a large catalogue of agent-optimised tools across MCP servers and supports connection from MCP clients such as Cursor, VS Code and Claude Desktop, with a central governance control plane.
Limit: Tool counts are vendor-reported; individual tool integrations were not verified.
Source s1
Limitations to discuss
- Some enforcement detail only on marketing pages
- Open-source component is the tool framework, not the runtime
Sources
- Arcade Docs · Arcade · official docs
Access date reported by researcher: 2026-09-06 - Arcade: The Actions Runtime for Enterprise AI Agents · Arcade · official product
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction