Dome Systems

AI agents for retail

Give your associates agents that stay inside every limit you set

Three agents for order lookups, replenishment and product copy. The ones associates call act as that associate, and none of them can refund, submit or publish on their own. Every call lands in one audit record.

associatesAgentsDomeRetail systemsCallersassociatesAgentsorder-assistantAgentsrestock-plannerAgentscatalog-writerGatewaysretail-toolsShopifyStorefront & ordersZendeskCustomer serviceNetSuiteInventory & POsAnthropicApproved modelsRulesGuardsAuditsaudit-trail
restock-planner→netsuite/get_inventory· scheduledAllowed

Governing Retail Agents

Any tool, any model, any use case

Our example demonstrates three agents for your store and e-commerce work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.

Examples for Retail

More from the library · Retail

Also in the library

FinanceSecurityITHRSalesSupportEngineeringResearch

Answer order questions

Looks up orders, shipments and returns so an associate can answer a customer fast. It reads. Refunds stay with the associate.

Tools

ShopifyZendesk

Model

Claude Sonnet 5or any approved provider

Runs

Chat, in Zendesk

Limits

Acts as the associateRead-onlyCard data redacted

Tuned for your team

  • Your return and exchange policy
  • Order statuses as your fulfillment flow names them

Applying Controls to Agents

Enforce refunds, card data and spend limits in one place

Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches Shopify, NetSuite or a model.

Call

agent order-assistant · acting as d.mercer
shopify/get_order(order: "#48213")
  1. Agentorder-assistant is registered and active
  2. Callerd.mercer verified through Okta
  3. Toolget_order is granted on retail-tools
  4. RuleOrder reads are allowed
DecisionAllowed

Comprehensive Audit

Show finance exactly what an agent changed and spent

One record for every call: the agent, the associate it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.

Audit · retail-tools
Events 0Denied 0
  • restock-planner05:40:12
1 audit events

Regulation

Answer PCI DSS and your auditors from one record

Retail agents touch card data, customer records and spend. These are the rules that reach them, and what the controls above give you for each.

PCI DSS v4.0.1

What it asks

Systems that store, process or transmit cardholder data are in scope. The PCI Security Standards Council's AI guidance treats AI systems the same way.

What Dome gives you

A guard strips card numbers from tickets and orders before any model sees them. Every tool call is logged with the agent and the associate it acted for.

State privacy laws (CCPA/CPRA)

What it asks

Customers can ask what you hold about them. Personal data should be used only for the purpose it was collected for.

What Dome gives you

Addresses and contact details are redacted before a model call, and the audit record shows which agent read which system, for whom.

SOX internal controls

What it asks

For public retailers, changes that reach financial records need authorization and a trail. Purchase orders and refunds count.

What Dome gives you

Agents draft purchase orders under a cap and can't submit them or issue refunds. Every refused attempt is in the audit record.

FAQ

Common questions

Are AI agents in scope for PCI DSS?

If an agent can see cardholder data, the systems it runs through are in scope. The simpler path is to keep card data away from the agent: redact it at the gateway before any model call, and log every call. Dome does both in the path of the call.

How do you keep card data out of LLM prompts?

A guard on the gateway inspects each tool response and strips card numbers before the agent or model sees them. The agent still gets the order, the status and the history it needs.

Can an AI agent issue refunds or discounts?

Only if a rule allows it. Dome checks every call against rules on the agent, the person it acts for and the arguments, so a refund can be refused outright or capped at an amount.

How do you audit what an AI agent changed in Shopify or NetSuite?

Route its tool calls through a Dome gateway. Every call lands in one audit record: the agent, who it acted for, the tool, the system and the decision. Refused calls are recorded too.

How are AI agents used in retail?

Common first agents answer order questions, draft replenishment and write product copy. Each one reads or drafts, and people keep refunds, orders and publishing.

Forward deployed engineering

Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.

Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.

Key topics to discuss:

  • Review your AI plans, progress to date, and timeline for agentic projects in production.
  • Planning a specific agent, or agentic app, to bring under governance.
  • Learning more about our platform capabilities, from gateways to routing.
  • Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.

Explore

Other industries

Industries

AI agents for financial services

KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.

Agentic use cases

  • Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
  • Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
  • Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.

Answers to

  • GLBA Safeguards Rule
  • BSA/AML and the FinCEN CDD Rule
  • NYDFS Part 500
  • Regulation E (EFTA)
  • CFPB UDAAP
  • Interagency third-party risk guidance
  • ECOA and Regulation B
  • FCRA
  • SR 11-7 model risk management
  • PCI DSS v4.0.1
  • Regulation E (EFTA) error resolution
  • BSA/AML and OFAC sanctions screening
  • SEC Regulation S-P (2024 amendments)
  • SEC Marketing Rule and FINRA Rule 2210
  • Books and records (Rule 204-2 and Rule 17a-4)
  • FINRA Rule 3110 and Regulatory Notice 24-09
  • SEC Rule 17a-4 recordkeeping
  • Exchange Act Section 15(g) information barriers
See the finance agents