Skip to main content

Give every agent exactly the access it should have.

PolicyArc decides — in real time — what every person, service, and autonomous agent is allowed to do with your data, by evaluating organizational policy and live user consent together.

Live decisionsSandbox stream
AllowScheduling agentappointment historyConsent on file, purpose matches booking scope11 ms
AllowCare teamlab resultsClinician in circle of care, active encounter8 ms
DenyAnalytics servicemental health notesDirective excludes sensitive category6 ms
AllowDelegateparent portal recordsGuardianship verified, expires in 14 days13 ms
PartialBenefits APIincome attributesFields redacted to purpose-bound subset15 ms
DenyResearch agentcohort extractGrant window elapsed, token not renewed5 ms
AllowCitizen serviceaddress of recordSelf-service request, identity assurance IAL29 ms
DenyThird-party appprescription listConsent withdrawn 2 minutes ago7 ms
Certified & recognized
ISO 27001 certifiedSOC 2 Type IIDeloitte Technology Fast 500

One engine for every access decision.

PolicyArc is a policy-based access control engine that sits behind standard protocols like OAuth 2.0. Instead of scattering rules across applications, you express policy once — PolicyArc evaluates it against real-time context and the user’s own consent directives on every request.

The result is our User-Based Access Control (UBAC) model: organizational policy and individual consent, harmonized into a single, auditable decision.

Policy as code
RBAC, ABAC, ReBAC, and TBAC expressed once, centrally.
Live consent
User directives evaluated on every single request.
Agent-aware
Scoped, revocable permissions for autonomous AI.
Full audit trail
Every decision logged and explainable.

Twelve years in the hardest access problems in the country. Now packaged for you.

PolicyArc wasn’t designed in a vacuum. It’s the engine we built, rebuilt, and hardened inside Canadian health and government programs — where consent is law, delegation is real, and a wrong access decision has consequences. We’ve broken it out of those deployments and packaged it as a product you can put behind your own APIs and agents.

Since 2014
Built inside live programs
Provincial health and government deployments where consent directives, delegates, and audit obligations were requirements from day one.
Proven at scale
Hardened, not theorized
Twelve years of edge cases — proxy access, revocation, purpose limitation — resolved in production rather than on a whiteboard.
Today
Packaged as a product
The same engine, extracted and productized: deploy it behind your own APIs, services, and AI agents in weeks, not years.

Open your services safely — to citizens and to AI.

As agents and integrations multiply, the risk isn’t access — it’s access without accountability. PolicyArc lets you say yes with confidence.

By team
Security & IT leaders
One place to govern, audit, and prove compliance. Combine static attributes like role and MFA with live signals like resource sensitivity and workflow state to be zero-trust ready.
AI & platform teams
Give agents exactly the access they need — scoped, time-bound, and revocable. Safe AI delegation, automatic data handling rules, and ecosystem outcomes without vendor lock in.
Privacy & compliance
One place to govern, audit, and prove compliance. Every access decision logged and reportable, so you can show a regulator how any single access decision was made, with consent state and policy version attached.
By industry

Four steps, one auditable decision.

1
Request arrives
A person, service, or AI agent asks for a resource through OAuth 2.0.
2
Policy evaluated
PolicyArc resolves your organizational rules against real-time context.
3
Consent checked
The user’s current directives are applied — scope, purpose, and duration.
4
Decision issued
One allow-or-deny with a complete, exportable audit record.

Implementation-ready.

Pre-configured for the standards and platforms your team already runs — no bespoke integration work to get the first decision flowing.

OAuth 2.0OpenID ConnectSAML 2.0HL7 FHIRSMART on FHIRREST and GraphQL APIsKubernetesAzure and AWS

Proven in the systems people can’t afford to get wrong.

PolicyArc comes out of a decade of work inside Canadian health and government programs — certified, audited, and run by a team that has stayed.

12 years
Delivering identity and access programs for Canadian government and healthcare organizations.
ISO 27001 · SOC 2 Type II
Independently certified information security, with controls audited over time — not at a single point in time.
7 years
Average tenure of our engineering and delivery leads, so the people who built it are still the people you talk to.
We have spent twelve years inside health and government systems where a wrong access decision has real consequences. PolicyArc is what we learned, made reusable.
Alec LawsChief Technology Officer, IDENTOS

Most access control stops at the org chart. Ours starts with the person.

Generic IAM and homegrown rules can tell you a role is allowed. Only PolicyArc also enforces what the individual agreed to — on every request, with a trail you can hand to a regulator.

CapabilityPolicyArcTypical IAM
Enforces user consent per requestcheck_circleremove
Harmonizes RBAC, ABAC, ReBAC & TBACcheck_circleremove
Scoped, revocable access for AI agentscheck_circleremove
Exportable, regulator-ready audit trailcheck_circleremove
Enforces user consent per request
PolicyArcTypical IAM
Harmonizes RBAC, ABAC, ReBAC & TBAC
PolicyArcTypical IAM
Scoped, revocable access for AI agents
PolicyArcTypical IAM
Exportable, regulator-ready audit trail
PolicyArcTypical IAM

Start with a demo. Leave with a plan.

Book a session with our architects. We’ll map PolicyArc to your protocols, policies, and consent requirements — and scope a pilot you can run.

Contact Sales