Harvey MCP and Dome
Harvey reaches your firm's systems. Each lawyer signs in.
Harvey connects to a firm's own MCP server over OAuth, and each user signs in for their own account. Point it at a Dome Gateway, and every lawyer signs in with their Dome account. Rules decide each call by person, and audit records every one under their name.
How Dome helps
Dome provides a governed gateway for Harvey
Each lawyer signs in
Harvey sends every user through sign-in on their first connection. With Dome, that sign-in is the lawyer's own Dome account.
Rules per lawyer
Rules read the signed-in lawyer's email. Associates search the know-how base, and partners can add to it.
Audit by name
Every call Harvey makes is recorded under the lawyer who made it. Revoke one person's grant and leave the rest.
Get started
Harvey on a Gateway in three steps
Turn on interactive access, permit what it may call, and add the Gateway to Harvey as your own MCP server. Each lawyer authorizes once in a browser.
01
Turn on interactive access
Name who may sign in, by exact email or identity provider subject. Dome creates one managed agent for the Gateway.
$ dome gateways interactive enable firm-gateway \--email partner@example.com \--email associate@example.com02
Permit what it may call
Apply the rule below to the managed agent. Its name is in dome gateways get.
$ dome rules apply harvey-notion.cedar \--agent gateway-interactive-<gateway-id> \--name harvey-notion03
Add the Gateway to Harvey
A Harvey workspace admin adds the Gateway's MCP URL as the firm's own server and enables it. Each lawyer then signs in once from Harvey.
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Harvey itself, see Harvey's documentation.
Rules
Search for everyone, write for partners
Everyone signed in may discover tools, search and fetch pages. Only the partner may have Harvey create a page.
permit ( principal is Dome::Agent, action == Dome::Action::"mcp:discover", resource); permit (principal is Dome::Agent, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "notion" && ["notion-search", "notion-fetch", "notion-create-pages"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "notion" && resource.tool_name == "notion-create-pages"}unless { principal has act_as && principal.act_as.email == "partner@example.com"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Signed in as
- Sign-inpartner@example.com is on the allow-list
- TokenInteractive token for firm-gateway, still valid
- RuleNew pages are open to the partner
Agent workflow
Bringing it together
Connecting Harvey to registered tools, identity, and models in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Harvey
This page
MCP server
Notion
See how
Models
FAQ
Common questions
Can Harvey connect to our own MCP server?
Yes. Harvey's Bring Your Own MCP connects a firm's server over HTTPS with OAuth, and a Dome Gateway with interactive access is that server.
Does each lawyer need a Dome account?
Yes. Each person signs in with their own Dome account, which needs access to the workspace as well as a place on the allow-list.
Can different lawyers get different access through Harvey?
Yes. Rules read the signed-in person's email, so one Gateway can give partners and associates different tools.
How do I remove one person's access?
Revoke their interactive grant in Dome, or take them off the allow-list. Everyone else keeps working.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Codex
Codex on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all