AI Dispatch
The wirewireAug 13, 2026

Agent tool-runtime Arcade enforces permissions through customers' own OAuth flows; its pricing is usage-based, not outcome-linked, and it discloses no insurance terms

Arcade, a Model Context Protocol runtime for connecting AI agents to enterprise systems, ties agent permissions to a company's existing identity provider and logs actions for audit. Its published pricing is billed by usage rather than a verified outcome, and the vendor names no insurance, indemnity or liability terms.

Arcade, a runtime that sits between AI agents and the enterprise systems they act on, says it enforces access at the moment an agent tries to act. "Arcade enforces permissions through your existing OAuth and identity provider flows. Agents act on behalf of the authenticated user, never through broad service accounts. Every action runs at the intersection of what the user can do and what the agent is scoped to do. Cross either line and the action stops," the company's site states.

The vendor describes a centralized audit function: "You can answer that for every action, every time, without slowing down the teams shipping agents. One place to set policy, one place to audit." Arcade offers a range of deployment models, including for customers who cannot use a shared cloud: "You can deploy the Arcade MCP runtime in your own cloud environment, a virtual private cloud, on-premises, or in a fully air-gapped environment." It ships a catalog of pre-built connectors: "AI agents using Arcade access a catalog of pre-built Model Context Protocol tools for major systems like Google Workspace, Slack, Microsoft, and Salesforce."

On compliance, the company states: "Compliance-ready SOC 2 compliant. SSO, RBAC, and full audit logs out of the box." The page does not name a SOC 2 report type, auditor or certificate.

Arcade's published pricing is metered by usage rather than tied to a verified result: "Free to start. Priced by usage." Under AI Dispatch's trust-gap rubric, payment released regardless of outcome -- as opposed to payment withheld until a result is verified -- is scored as an absence on the outcome-settlement dimension, not a partial credit toward it. The vendor's site names no insurance carrier, no coverage limit, no customer indemnity and no liability cap, according to AI Dispatch's review of its published material.

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 6

  1. Arcade enforces permissions through your existing OAuth and identity provider flows. Agents act on behalf of the authenticated user, never through broad service accounts. Every action runs at the intersection of what the user can do and what the agent is scoped to do. Cross either line and the action stops.
    arcade-ai.com · checked Aug 1, 2026
  2. You can answer that for every action, every time, without slowing down the teams shipping agents. One place to set policy, one place to audit.
    arcade-ai.com · checked Aug 1, 2026
  3. You can deploy the Arcade MCP runtime in your own cloud environment, a virtual private cloud, on-premises, or in a fully air-gapped environment.
    arcade-ai.com · checked Aug 1, 2026
  4. AI agents using Arcade access a catalog of pre-built Model Context Protocol tools for major systems like Google Workspace, Slack, Microsoft, and Salesforce.
    arcade-ai.com · checked Aug 1, 2026
  5. Compliance-ready SOC 2 compliant. SSO, RBAC, and full audit logs out of the box.
    arcade-ai.com · checked Aug 1, 2026
  6. Free to start. Priced by usage.
    arcade-ai.com · checked Aug 1, 2026