Arcade.dev is now an ecosystem partner in the Cisco Duo marketplace. For teams that run Duo, Arcade now sits on top of the identity and access management (IAM) stack you already trust and enforces your access controls on every action an AI agent takes.

Organizations have spent years defining secure access policy in Cisco Duo; who belongs to which group, what each role can reach, and the conditions access depends on. That investment shouldn’t be thrown out the moment you adopt agents. Rather than recreating a parallel policy layer, the goal is to put your existing Duo policy to work. Duo stays the source of truth for who can do what, and then Arcade steps in to enforce what comes next.

Identity grants access, then Arcade enforces

An agent is only useful when it can act, and it acts by calling a tool. Arcade, the actions runtime for enterprise AI agents, hosts those tools so the agent invokes an action rather than reaching into your systems on its own. A tool that hits the system directly is fast and ungoverned. Arcade sends every call through Cisco Duo first, where your access policies already live, and runs the action only on the authorization Duo returns.

The agent acts as the real person behind the request, signed in through your IdP. That handshake happens between the person and Duo, outside the model and the agent, so the credential never reaches the prompt or the agent itself. Every action lands in an audit trail your security team can read. The identities, groups, and scopes your team already manages in Duo become the same controls that govern what an agent does on your behalf. Enforcement does not stop at static rules. For a sensitive or out-of-the-ordinary action, Arcade applies contextual guardrails at runtime, triggering step-up verification such as an out-of-band Duo MFA check before the action goes through.

We’re proud to share a core belief with the Duo team; routing an agent to a tool isn’t enough. You have to also answer for the human behind the agent: can this user’s agent invoke this specific tool, on this specific server, within this user’s permissions, right now?

What this means for Duo customers

If you run Cisco Duo for Agentic IAM, you can now adopt Arcade as your actions runtime and keep the identity and audit controls you already trust. Your security team approves the enforcement layer once, and every agent you ship after that runs against the same foundation.

Find Arcade in the Cisco Duo marketplace, or reach out to get started.

Connect with confidence. Act with control.