Integrations entry points
OAuth-bound · scoped · written back

Integrations

Meet your tools where work already lives

Native connectors and MCP, with a signed record on every action.

The category

Integrations should do more than post notifications. Each action stays scoped, OAuth-bound, and logged in the workspace with the same provenance as a generate run.

  • Least-privilege OAuth per action class. No `repo:all` for a single PR.

  • Two-way sync with Jira, Linear, GitHub, Slack, Figma, and Google Workspace.

  • MCP servers treated as native tools with the same approval gates.

  • Every external action carries a provenance ID in the workspace.

Drop into the stack you already run on

One “new” affordance and a project pipeline that mirror Slack, Jira, GitHub, Figma, Linear, and Notion — with OAuth-bound actions and provenance on every writeback.

Top bar new menu
One “new” menu, every kind of work, in the tool that owns it.
Product projects pipeline
Pipeline, the same projects, synced into your existing trackers.

The gap

Most “integrations” are shallow bots

Most AI tools ignore your stack or ship a shallow Slack bot. Both make your workflow worse.

Shallow

A Slack bot is not enough

Real integration reads context, takes action, and stays accountable in the tool.

Glue

You end up writing the glue

Zapier, cron, and webhooks become maintenance your team did not plan for.

Risk

OAuth scopes that scare security

Broad `repo:all` asks kill the integration in review.

Silos

Context does not cross tools

Brief, ticket, code, and deploy live in different places; AI sees one.

What Arvad plugs into on day one

Pick the integration. Authorize once. Same context and provenance everywhere.

Slack

Thread to ticket. Channel standup digest. @-mention for PR review with context blocks loaded.

Stays in the workspace with plan and checks

Jira · Linear · GitHub Issues

Two-way sync. Tickets created either side keep context and provenance.

Stays in the workspace with plan and checks

GitHub · GitLab · Bitbucket

Read-only first, write on approval. PRs, reviews, branches, status checks signed by the approver.

Stays in the workspace with plan and checks

Figma · Figma Make

Official API. Frame URLs become typed components; design tokens detected.

Stays in the workspace with plan and checks

Vercel · Netlify · AWS · Fly

Deploy, monitor, roll back. Every deploy carries a provenance bundle.

Stays in the workspace with plan and checks

Google Workspace

Docs round-trip for PRDs, Sheets for experiment results, Calendar for meeting linkage.

Stays in the workspace with plan and checks

Notion · Confluence

Ingest and writeback so your wiki stays a context source as code changes.

Stays in the workspace with plan and checks

MCP, first-class

Bring any MCP server with the same approval, provenance, and context guardrails.

Stays in the workspace with plan and checks

Real integration vs a notification bot

CapabilityMost AI toolsArvad integrations
DepthNotificationsRead, reason, and write
Context across toolsPer toolOne workspace context
OAuth scopesBroadLeast-privilege per action
Token rotationYou manage itAutomatic
Provenance on actionsNoEvery action signed
Approval gatesNoPer integration, per action class
MCPNot supportedFirst-class
Audit logMaybeTamper-evident, queryable

From OAuth to outcomes

Pick an integration, authorize with least-privilege scopes, set approval gates. Every action signed and logged.

Why security and platform teams sign off

Least-priv

Least-privilege scopes per action

No `repo:all` when one repo would do.

Auto

Automatic token rotation

Expired tokens fail closed.

SSO

SSO-bound identity

Off-boarding revokes that user’s Arvad access.

BYOC

Bring your own cloud

Available when your deployment model supports VPC hosting.

Straight answers

Limits stated plainly. No demo theater.

One question

When the build finishes, can you show a teammate the plan, preview, tests, and deploy status without digging through chat?

If you cannot, you still have a chat log. Arvad keeps that work in one workspace.

Keep your tools. Keep the trail.

Scoped OAuth, MCP, and provenance on every surface.