Dome Systems

Lindy and Dome

Lindy acts in your tools. Rules decide which actions.

Lindy switches on every tool an MCP integration lists. Behind a Dome Gateway, that stops mattering: Lindy calls in as a registered agent with its own key, and rules decide which of those tools it may use.

TeammatesAgentsDomeYour toolsCallersTeammatesAgentslindyAgentssupport-triagerAgentsrelease-notesGatewaysops-gatewayLinear issuesRead and commentIssue changesKept to your agentsModel poolYour own agentsRulesGuardsAuditsaudit-trail
lindy→linear/list_issues· scheduledAllowed

How Dome helps

Dome provides a governed gateway for Lindy

A key that's only Lindy's

Lindy authenticates with an agent key minted for it. Revoke that key and Lindy is cut off. Your own agents run on.

Comment, don't change

Lindy may read Linear issues and comment on them. Creating, editing and closing stay with your team.

Lindy's calls, labeled

Audit files each call under the lindy agent. Filter by it and you see Lindy's work alone.

Get started

Lindy on a Gateway in four steps

Register Lindy, mint its key, deploy the rules, then add the Gateway in Lindy as an MCP integration. The rules do the scoping.

  1. 01

    Register Lindy

    Register it with the Linear tools it may reach and the Gateway they sit behind.

    $ dome agents register --name lindy \
    --tool linear/list_issues \
    --tool linear/get_issue \
    --tool linear/save_comment \
    --gateway ops-gateway
  2. 02

    Create its key

    You get back the key and the Gateway's MCP URL. Both go into Lindy, and only there.

    $ dome agents create-key lindy --name lindy-mcp --gateway ops-gateway
  3. 03

    Apply the rules

    Scope them to the lindy agent. Simulate a create_issue to see it refused, then deploy.

    $ dome rules apply lindy-linear.cedar \
    --agent lindy --name lindy-linear
  4. 04

    Add the Gateway to Lindy

    In Lindy, open Integrations, choose Add, then MCP, and paste the MCP URL. Under Advanced, send the key as an Authorization bearer token.

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Lindy itself, see Lindy's documentation.

Rules

Read issues and comment

The permit opens three Linear tools to Lindy. The forbid refuses every other Linear tool, so Lindy can't create, edit or close an issue.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linear" &&
["list_issues", "get_issue", "save_comment"].contains(resource.tool_name)
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linear" &&
!["list_issues", "get_issue", "save_comment"].contains(resource.tool_name)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Action

agent lindy · scheduled
linear/save_comment(issueId: "OPS-412", body: "Customer confirmed the fix on their side.")
  1. Agentlindy is registered and its key is active
  2. Gatewaylindy may reach ops-gateway
  3. RuleComments are open to lindy
DecisionAllowed

Agent workflow

Bringing it together

Connecting Lindy to registered tools, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Can Lindy connect to a custom MCP server?

Yes. Lindy adds hosted MCP servers over HTTPS with a bearer token, so a Dome Gateway is one more integration.

How do I limit which tools Lindy can use?

Write rules for the lindy agent in Dome. Whatever Lindy switches on, a tool the rules refuse is refused at the Gateway.

What if Lindy's key leaks?

Revoke it in Dome and mint another. Within seconds the Gateway refuses the old key.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.