Skip to main content

Arcade.dev vs WitnessAI

Arcade.dev's category is Agent identity & tool-calling runtime; WitnessAI's is AI security & governance (AI firewall). On the 12 governance and compliance criteria below, the two are closer to each other than either is to a governance control plane: neither enforces Segregation of Duties. Pick between them on runtime fit. If the requirement is deterministic authorization and audit-grade compliance evidence, neither is the answer on its own.

Agent identity & tool auth vs. The AI firewall — compared on 12 governance & compliance criteria for enterprises putting AI agents into production.

First-party research · Comparison data last verified

Strong / documented Partial / indirect Absent / not publicly documented

Arcade.dev

Agent identity & tool-calling runtime

Arcade.dev is an agent authorization and tool-calling runtime — "SSO for AI agents." Built by ex-Okta/Auth0 engineers, it lets agents act as the real user via OAuth, brokering tokens and secrets so tool calls run with the right identity and scopes, and enforcing per-action authorization at runtime.

Founded 2024 · San Francisco · ~$72M (Series A, SYN Ventures) · Sells to Developers / platform engineering

Source: arcade.dev

WitnessAI

AI security & governance (AI firewall)

WitnessAI is an inline "AI firewall" — agentless network-level discovery (Observe), an intent-based policy engine (Control), and inline protection with PII tokenization and prompt-injection blocking (Protect), enforcing at the tool-call and MCP-server level.

Founded 2023 · Mountain View, CA · ~$85M · Sells to Security / IT-Security (CISO org)

Source: witness.ai

How do Arcade.dev and WitnessAI compare?

12 criteria that decide whether an enterprise can prove — not just hope — that its AI agents stay inside policy.

Criterion Arcade WitnessAI
Deterministic, rule-based authorization Provable allow/deny decisions, not ML/probabilistic detection
Pre-execution enforcement Evaluates and blocks an action before it executes
Segregation of Duties enforcement Conflict-of-duty rules across agent actions
Excessive-agency prevention / least privilege Scopes each agent to the narrowest action surface
Design-time action-surface mapping Maps what an agent can do before it ships
Compliance-classified tools catalog Tools/MCP servers pre-scored against SoD & regulations at design time
Full lifecycle coverage (design-time + runtime) Governs the agent before and during production
Named-approver human-in-the-loop routing Routes risky actions to specific accountable approvers
SOX / GDPR / financial-GRC control mapping & evidence Maps agent actions to financial & privacy control obligations
AI-specific standards (ISO 42001, EU AI Act, NIST AI RMF, OWASP LLM) Alignment to emerging AI governance standards
Immutable / tamper-evident audit ledger Cryptographically defensible evidence of every decision
GRC / internal-audit / IT-governance buyer fit Built for the compliance owner, not only the security engineer

What is Arcade.dev best at?

  • OAuth token brokering and agent identity — its crown jewel, built by ex-Okta/Auth0 engineers
  • Deterministic, scope-based authorization checks on each tool call
  • Broad MCP runtime — 7,500+ tools across 81 servers, with an open-source SDK
  • Pre/post-execution hooks that can inspect and block requests inline

What is WitnessAI best at?

  • Best-in-class agentless AI observability — network-level shadow-AI discovery, no endpoint agents
  • Identity-based policy that attributes every agent action back to a human identity
  • Strong inline data protection — PII/PCI/PHI tokenization before data reaches a model
  • Real inline pre-execution blocking, with heavyweight backing and fast enterprise traction

What do Arcade.dev and WitnessAI both leave to you?

Arcade.dev and WitnessAI secure how agents operate — but neither enforces Segregation of Duties, maps an agent's action surface at design time, or produces SOX/GDPR-grade compliance evidence. That is the layer LangGuard adds.

  • Deterministic, rule-based authorization on every action — reproducible and auditable, not probabilistic
  • Segregation-of-Duties enforcement built in — the only vendor in this set to ship it
  • Design-time action-surface mapping plus a compliance-classified tools catalog (SoD, SOX, GDPR, ISO 42001)
  • Named-approver human-in-the-loop routing and an immutable, tamper-evident audit ledger
  • Built for GRC, internal audit and IT governance — with SOX/GDPR control evidence

Which should you choose?

Arcade.dev and WitnessAI are both strong runtime security tools. If your requirement is deterministic authorization, Segregation of Duties, design-time action-surface mapping, and audit-grade compliance evidence, LangGuard governs what agents are allowed to do — before they do it — and works alongside either.

Request Free Trial

Common questions

What is the difference between Arcade.dev and WitnessAI?

Arcade.dev is categorised as Agent identity & tool-calling runtime. WitnessAI is categorised as AI security & governance (AI firewall). The practical difference is where each one sits relative to the agent's action: one governs the request path, the other governs the decision to allow the action at all.

Does Arcade.dev enforce Segregation of Duties?

Arcade.dev does not enforce Segregation of Duties. Segregation of Duties is a conflict-of-duty rule across an agent's actions — the control that stops one agent both raising and approving the same transaction. It is the criterion most agent-security tools leave to the customer.

Does WitnessAI enforce Segregation of Duties?

WitnessAI does not enforce Segregation of Duties. Check this against your own control matrix before assuming runtime monitoring covers it — detecting a violation after the fact is not the same control as preventing it.

Which one gives you SOX and GDPR compliance evidence?

Arcade.dev does not map to SOX or GDPR control obligations. WitnessAI produces logs that need work before an auditor will accept them. Logging that an action happened is not the same as evidence that it was authorized against a named control, which is what an internal auditor asks for.

Can Arcade.dev and WitnessAI be used together?

Yes. They operate at different layers, so running both is common — one handles the runtime path, the other the authorization decision. The question is not which to buy but which layer you have not covered yet.

How were these 12 criteria scored?

Each vendor was scored against 12 governance and compliance criteria using public documentation, product pages and published compliance material as of August 14, 2026. Full means the capability is documented and shipping; partial means it is indirect or requires customer-authored policy; absent means it is not publicly documented. No vendor was contacted for a private briefing.

How did we score this?

This comparison is first-party research by LangGuard. Every vendor in the set is scored against the same 12 governance and compliance criteria, drawn from public product documentation, pricing and compliance pages, and published technical material, last verified .

  • Strong — the capability is documented and shipping.
  • Partial — present but indirect, or dependent on policy the customer writes.
  • Absent — not publicly documented at the time of review.

We publish comparisons that include our own product, so treat the LangGuard column as a vendor claim and check it the same way you would check anyone else's. Scoring is against public material only; no vendor was given a private briefing or a right of reply. Found something out of date? Tell us and we will correct it.

Sources: Arcade.dev — official site · WitnessAI — official site

More comparisons

Find out what your agents can do —
before your auditor does.

LangGuard maps your complete agent action surface in minutes. Free for the first five managed agents. All Scopes (Finance, IT, Procurement, HR) included from day one. No policy writing required.

Test Your Agent Action Surface Free See a Live SoD Detection Demo

No credit card required  ·  First 5 agents free  ·  All LOB Scopes included  ·  Enterprise ready