Dome Systems

By industry

AI agents transforming every industry

Dome helps enterprise teams deliver on their AI program supporting any agent in any environment through the definition of golden templates and pathways to get agents into production, and under governance.

Finance

KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.

Every financial agent touches nonpublic personal information, and examiners expect to see who did what. Set the patterns once: account numbers out of prompts, approved models only, and drafts that never approve, file or move money on their own.

Answers to GLBA Safeguards Rule · BSA/AML and the FinCEN CDD Rule · NYDFS Part 500 · Regulation E (EFTA) · CFPB UDAAP · Interagency third-party risk guidance · and 12 more

See the finance overview
Retail

Order lookups, replenishment and product copy. Refunds, orders and publishing stay with your people.

Retail agents work from the storefront to the warehouse, on Shopify, UKG, Manhattan and SAP. Set the patterns once for each team: what an agent may order, discount or publish, and what waits for a person.

Answers to PCI DSS v4.0.1 · State privacy laws (CCPA/CPRA) · SOX internal controls · FTC Act, Section 5 · Antitrust and algorithmic pricing · Predictive scheduling laws · and 1 more

See the retail overview
Gaming & sports betting

Player support, responsible gaming review and bonus setup. Self-exclusions and limits stay out of an agent's reach.

Gaming operators run agents next to player wallets, self-exclusion lists and identity checks, under regulators who inspect the record. Set the patterns once: limits an agent can read but never lift, bonuses capped by rule, and ID documents kept out of prompts.

On your systems

  • GAN
  • Zendesk
  • Jumio
  • Anthropic

Answers to State gaming regulations · Bank Secrecy Act (FinCEN casino rules) · Age, identity and location checks

See the agents

Self-exclusion can't be undone by an agent

player-support as w.dockery

gan/remove_self_exclusion(player: "P-208817")

  • Agent player-support is registered and active
  • Caller w.dockery verified through Okta
  • Tool remove_self_exclusion is on the gateway
  • Rule No agent may remove a self-exclusion

Refused by a rule

Healthcare

Prior authorizations, visit notes and eligibility checks. Agents read only the charts their clinician can read.

Every chart an agent opens is PHI, and every model it calls needs a BAA. Set the patterns once: care-team access, identifiers stripped before the model, and sign-off that stays with the clinician.

On your systems

  • Epic
  • Availity
  • Microsoft Teams
  • Anthropic

Answers to HIPAA minimum necessary · Business associate agreements · HIPAA Security Rule audit controls · CMS prior authorization rule (CMS-0057-F)

See the agents

Access follows the care team

note-drafter as dr.ferris

epic/read_chart(patient: "MRN 4471-203")

  • Agent note-drafter is registered and active
  • Caller dr.ferris verified through Entra ID
  • Tool read_chart is granted on clinical-tools
  • Rule dr.ferris is not on this patient's care team

Refused by a rule

Insurance

Claim intake, file summaries and fraud screening. Agents read only the claims assigned to their adjuster.

Claims agents handle policyholder PII, fraud signals and decisions that examiners review. Set the patterns once: assigned claims only, PII redacted, and fraud flags that go to your SIU and nowhere else.

On your systems

  • ClaimCenter
  • OnBase
  • ClaimSearch
  • Anthropic

Answers to NAIC Model Bulletin on AI Systems · Unfair claims settlement practices laws · Insurance data security laws

See the agents

Access follows the claim

claim-summarizer as k.ramsey

onbase/get_document(claim: "CLM-20814")

  • Agent claim-summarizer is registered and active
  • Caller k.ramsey verified through Entra ID
  • Tool get_document is granted on claims-tools
  • Rule CLM-20814 is not assigned to k.ramsey

Refused by a rule

Legal

Conflicts checks, clause extraction and redlines. Every agent acts as the lawyer who asked.

Law firm agents work inside ethical walls, on privileged documents, for clients who expect both to hold. Set the patterns once: walls that travel with the lawyer, client data redacted, and drafts that never send themselves.

On your systems

  • iManage Work
  • Intapp Open
  • DocuSign
  • Anthropic

Answers to ABA Formal Opinion 512 · Privilege after United States v. Heppner · Ethical walls (Model Rules 1.7, 1.9, 1.10)

See the agents

Walls travel with the lawyer

clause-extractor as s.gallagher

imanage/get_document(matter: "39107-001")

  • Agent clause-extractor is registered and active
  • Caller s.gallagher verified through Entra ID
  • Tool get_document is granted on matter-tools
  • Rule s.gallagher is walled from 39107-001

Refused by a rule

Professional services & systems integrators

Proposals, staffing and engagement status. Each agent sees only the engagements its consultant works on.

Professional services firms work for many clients at once, and every engagement carries its own confidentiality terms. Set the patterns once: agents scoped to their consultant's engagements, client names stripped from reused work, and staffing that stays a proposal.

On your systems

  • Salesforce
  • Kantata
  • SharePoint
  • Anthropic

Answers to Client confidentiality terms · AICPA Confidential Client Information Rule · SOC 2 · GDPR and state privacy laws

See the agents

Engagement walls travel with the consultant

status-reporter as a.pennington

sharepoint/list_files(site: "ENG-1987")

  • Agent status-reporter is registered and active
  • Caller a.pennington verified through Entra ID
  • Tool list_files is granted on delivery-tools
  • Rule a.pennington is not staffed on ENG-1987

Refused by a rule

Technology & software

Escalation triage, incident summaries and release notes. Agents read code and incidents. Shipping stays with engineers.

Software companies point agents at their own code, incidents and customers, in GitHub, PagerDuty and Jira. Set the patterns once: secrets stripped before any model, incidents read but never resolved, and releases that stay drafts.

On your systems

  • Jira
  • PagerDuty
  • GitHub
  • Anthropic

Answers to SOC 2 · ISO/IEC 42001 · EU AI Act · State privacy laws (CCPA/CPRA)

See the agents

Secrets never reach a model

incident-scribe as j.harlow

github/get_file(repo: "billing-api", path: ".env.production")

  • Caller j.harlow verified through Okta
  • Tool get_file is granted on eng-tools
  • Rule No agent may read .env files

Refused by a rule

Every industry

The same controls, whatever the work

The systems change from one industry to the next. What Dome enforces on each agent call doesn't.

Acts as the person who asked

Every call carries the identity of the lawyer, clinician or associate behind it. The agent's access follows theirs.

Limits on what it can do

Rules check the tool and its arguments: a refund amount, a discount's depth, which matter or chart.

Sensitive data stays out of prompts

Guards strip card numbers, PHI and client identifiers before a model sees them. Agents reach only approved models.

One record for every call

The agent, who it acted for, the system and the decision, refused calls included. Evidence for auditors and examiners.

FAQ

Common questions

What is AI agent governance?

Deciding which agents exist, what each may call, for whom and within what limits, and keeping a record of every call. Dome does it in the path of the call, through gateways.

What is an enterprise AI agent platform?

Software that registers your agents, connects them to tools and models, enforces what each may do, and records every call. Dome does that across every runtime and every cloud.

How do you secure an AI agent?

Give it an identity, route its tool and model calls through a gateway, check each call against rules, strip sensitive data, and record everything.

Is it safe to use AI agents in regulated industries?

It can be, when access follows the person the agent acts for, sensitive data is redacted before model calls, and every call is recorded for auditors and examiners.

Which industries does Dome work with?

Any. These pages show example agents for finance, gaming, healthcare, insurance, legal, professional services, retail and technology. The controls are the same everywhere, and our engineers tune the agents to your systems.

How do you implement AI governance for agents?

Start with one agent: register it, put its tools behind a gateway, write rules for what it may do, and read the audit record. Then add agents on the same rules.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.