Why we didn't fight for the word "control plane"

TL;DR

Every AI gateway company right now sounds literally the same. Arcade, Barndoor, and Runlayer have collectively raised well over a hundred million dollars, and all three lead with some version of the same sentence: one governed point that decides which AI agent can reach which tool. We could have tried to say it better than they do. We didn't. The half of this problem nobody else is describing is what happens after that question gets answered: whether the other 90 percent of a company, the people who aren't engineers, ever gets to use any of this.

Logos for Arcade, a green leaf-mark competitor, and Runlayer grouped together, with the Metorial logo set apart in blue

Every homepage in this category reads like the same one

Read Arcade's, Barndoor's, and Runlayer's homepages back to back and the words blur together before you notice anything else. Arcade calls itself the secure action layer. Barndoor calls itself the first control plane for agentic AI workforces. Runlayer skips the slogan and leads with a security audit instead. Strip the logos off and you'd struggle to say which page belongs to which company.

Control plane, action layer, trust layer: three costumes on the same idea, one governed point deciding which agent can reach which tool, and logging that it did. It's a real idea. It's also not a differentiated one anymore, once three well-funded companies have all said a version of it.

Why not just say it better than they do

The honest case for staying in that fight is that the underlying risk is real. Agents with production access and no audit trail is a genuine problem, not a marketing invention. Nobody gets to skip that conversation just because it's crowded.

But being right about the risk doesn't make it smart to out-message three companies that have collectively raised well over a hundred million dollars to say the same thing. That's not a content strategy, it's a spending contest. If four shops on one street sell the identical product at the identical price, the only lever left is who can afford the bigger sign. We're not interested in a bigger sign. So we looked for a different street. Personally, that really reminded me of what Jon Sexton did back in the day when he brought NYU Abu Dhabi to life, the place where I met Wen.

The street nobody else is standing on

The other half of the problem, the one none of them lead with, is what happens after the security question gets answered: whether the rest of the company ever uses any of it.

Most companies don't have one shared, versioned place where a workflow an agent follows gets written down, so the same skill gets rebuilt five times by five different people, five slightly wrong ways, and nobody notices until two of them disagree. The person who catches a broken refund workflow is almost never the person who can open a pull request against it, so companies end up paying for a GitHub seat just so someone in ops can edit a config file twice a year. And an engineer happy in Cursor and a support lead happy in Claude shouldn't end up with two different access setups just because they picked two different tools.

Nobody in this category leads with any of that. Read their homepages closely and it's all about locking access down, almost nothing about getting the other 90 percent of a company using any of it in the first place.

Table stakes, not the headline

Not leading with something is different from not having it. We ship role-based access, single sign-on, audit logs, and per-call isolation today. It's just not the headline, because a headline is supposed to be the thing nobody else offers, and on security specifically, three companies got there first. Security is the floor here, not the pitch.

The honest part

I don't think anyone gets to call this bet correct yet, and I'd rather say that directly than pretend otherwise. It commits a real share of what we write and say for a while. The signal that tells us it's working isn't a vanity metric, it's a change in how a sales conversation opens. Some still open with "is this secure." So far the bet seems to be right, more of them start opening with "how do we get everyone using this" instead. If that shift didn't happen, the wedge would need revisiting, not defending.

The category has plenty of companies telling a buyer their agents are dangerous. It's short on companies telling them how to get two hundred people, not twenty, using agents well. That's the harder problem. It's also the one nobody's competing with us for yet.

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.