AI agents for e-commerce
Give your service reps agents that never give away the store
Three agents for customer tickets, promotions and fraud screening. The ones reps call act as that rep, and every credit, discount and hold stays inside the limit you set. Every call lands in one audit record.
Governing Retail Agents
Any tool, any model, any use case
Our example demonstrates three agents for your storefront and customer service work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.
Examples for E-commerce
More from the library · E-commerce
Also in the library
Resolve customer tickets
Reads the ticket and the order, drafts the reply, and issues store credit up to the rep's limit. Anything bigger stays with the rep.
Tools
Model
Runs
Limits
Tuned for your team
- Your return window and goodwill policy
- Credit limits set per team by service leads
Applying Controls to Agents
Cap credits, discounts and customer data in one place
Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches Shopify, Stripe or a model.
Credit
- Agentsupport-copilot is registered and active
- Callerr.whitaker verified through Okta
- Toolissue_store_credit is granted on commerce-tools
- Rule$25 is under the $50 limit for tier-1 reps
Comprehensive Audit
Show finance every credit and discount an agent gave
One record for every call: the agent, the service rep it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.
- fraud-screener02:14:07
| Timestamp | Type | Agent | Acting as | Resource | Outcome | Latency |
|---|---|---|---|---|---|---|
| 02:14:07.612 | ||||||
Regulation
Keep payment and customer data where the rules want it
Support, promotions and fraud agents touch payments, customer records and prices. These are the rules that reach them.
PCI DSS v4.0.1
What it asks
Systems that store, process or transmit cardholder data are in scope. The PCI Security Standards Council's AI guidance treats AI systems the same way.
What Dome gives you
A guard strips card numbers and addresses from tickets before a model sees them. Payment actions stay behind rules: the fraud agent can hold an order but never cancel or refund it.
State privacy laws (CCPA/CPRA)
What it asks
Customer data can't be shared or sold without notice, and bulk exports are where it leaks.
What Dome gives you
Exporting a customer list through an agent is refused, and every read is recorded with the rep the agent acted for.
FTC Act, Section 5
What it asks
Promotions and pricing claims can't mislead customers. The FTC has said AI is no exception.
What Dome gives you
Discount depth is capped per category by rule, so an agent can't create a code merchandising never set.
FAQ
Common questions
What can AI agents do in e-commerce?
Resolving tickets, building promotions and screening orders for fraud are common first agents. On Dome each runs inside limits: credit and discount caps, read-only where it should be, and no cancellations.
Can an AI agent issue store credit?
Up to a limit you set. A rule checks the amount against the rep's team limit on every call, and anything over it is refused and recorded.
How do you stop an AI agent from giving away too big a discount?
Cap it per category. The promotions agent can create codes up to that depth, and deeper ones are refused before they reach Shopify.
Are AI agents in scope for PCI DSS?
If an agent can see cardholder data, the systems it runs through are in scope. The simpler path is to keep card data away from the agent: redact it at the gateway before any model call, and log every call. On Dome, a guard does the redaction and every call lands in the audit record.
What is agentic commerce?
It usually means AI agents shopping on a customer's behalf, through protocols like OpenAI and Stripe's Agentic Commerce Protocol. This page covers the other side: governing the agents your own team runs.
Forward deployed engineering
Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.
Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.
Key topics to discuss:
- Review your AI plans, progress to date, and timeline for agentic projects in production.
- Planning a specific agent, or agentic app, to bring under governance.
- Learning more about our platform capabilities, from gateways to routing.
- Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.
Explore
Other retail solutions
Industry
Retail
Order lookups, replenishment and product copy. Refunds, orders and publishing stay with your people.
See the agentsRetail
Merchandising & planning
Assortment plans, competitive pricing and vendor briefs. Buyers see only their own categories.
See the agentsRetail
Store operations
Schedules, store walks and shrink review. Each manager's agent sees only that manager's store.
See the agentsRetail
Supply chain & fulfillment
Fulfillment exceptions, load tendering and inbound audits. Carriers, sites and chargebacks stay inside your rules.
See the agentsOther industries
AI agents for financial services
KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.
Agentic use cases
- Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
- Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
- Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.
Answers to
- GLBA Safeguards Rule
- BSA/AML and the FinCEN CDD Rule
- NYDFS Part 500
- Regulation E (EFTA)
- CFPB UDAAP
- Interagency third-party risk guidance
- ECOA and Regulation B
- FCRA
- SR 11-7 model risk management
- PCI DSS v4.0.1
- Regulation E (EFTA) error resolution
- BSA/AML and OFAC sanctions screening
- SEC Regulation S-P (2024 amendments)
- SEC Marketing Rule and FINRA Rule 2210
- Books and records (Rule 204-2 and Rule 17a-4)
- FINRA Rule 3110 and Regulatory Notice 24-09
- SEC Rule 17a-4 recordkeeping
- Exchange Act Section 15(g) information barriers
AI agents for gaming and sports betting
Player support, responsible gaming review and bonus setup. Self-exclusions and limits stay out of an agent's reach.
Agentic use cases
- Answer player questionsLooks up a player's account, bets and withdrawal status so a specialist can answer fast. It reads. Balances and limits stay with people.
- Review responsible gaming signalsReviews players flagged for risky play and drafts case notes for the responsible gaming team. It never changes a limit.
- Configure bonusesSets up deposit matches and free bets from a campaign brief, up to the cap you set. Self-excluded players are never targeted.
Answers to
- State gaming regulations
- Bank Secrecy Act (FinCEN casino rules)
- Age, identity and location checks
AI agents in healthcare
Prior authorizations, visit notes and eligibility checks. Agents read only the charts their clinician can read.
Agentic use cases
- Assemble prior authorizationsPulls the notes, orders and imaging a payer asks for into one authorization packet. A clinician reviews it and submits.
- Draft visit notesDrafts a visit note from the encounter and the chart, in the department's template. The clinician edits it and signs it.
- Verify eligibility before the visitChecks coverage for the next day's appointments overnight. Anything that needs a call before the visit goes to the patient access channel.
Answers to
- HIPAA minimum necessary
- Business associate agreements
- HIPAA Security Rule audit controls
- CMS prior authorization rule (CMS-0057-F)
AI agents for insurance claims
Claim intake, file summaries and fraud screening. Agents read only the claims assigned to their adjuster.
Agentic use cases
- Triage new claimsReads each first notice of loss, sets severity and line of business, and routes it to the right adjuster queue. It flags. It never settles.
- Summarize claim filesSummarizes medical records, police reports and correspondence in a claim file for the assigned adjuster. Only claims that adjuster handles.
- Screen claims for fraud signalsChecks each open claim against prior claims history and flags patterns for the special investigations unit. It never denies a claim.
Answers to
- NAIC Model Bulletin on AI Systems
- Unfair claims settlement practices laws
- Insurance data security laws
AI agents for law firms
Conflicts checks, clause extraction and redlines. Every agent acts as the lawyer who asked.
Agentic use cases
- Check new matters for conflictsSearches Intapp and past matters in iManage for parties that conflict with a proposed engagement. It reports. It never clears a conflict.
- Extract clauses from contractsPulls parties, dates, renewal and change-of-control terms from the contracts in a matter workspace. Only in matters the requester is staffed on.
- Draft redlines against the playbookMarks up a counterparty draft against your playbook and saves it as a new version. Counsel reviews it and sends it.
Answers to
- ABA Formal Opinion 512
- Privilege after United States v. Heppner
- Ethical walls (Model Rules 1.7, 1.9, 1.10)
AI agents for professional services firms
Proposals, staffing and engagement status. Each agent sees only the engagements its consultant works on.
Agentic use cases
- Draft proposalsReads an RFP and drafts a response from the firm's reuse library. Client names in past work are stripped before the model sees them.
- Match staff to engagementsMatches skills and availability to a new engagement's roles and proposes a team. Resource managers make the assignments.
- Report engagement statusReads the project plan and engagement files and drafts the weekly status report. It sees only engagements its consultant is on.
Answers to
- Client confidentiality terms
- AICPA Confidential Client Information Rule
- SOC 2
- GDPR and state privacy laws
AI agents for software companies
Escalation triage, incident summaries and release notes. Agents read code and incidents. Shipping stays with engineers.
Agentic use cases
- Triage engineering escalationsReads an escalated ticket and the code it points to, drafts a diagnosis and sets priority. Fixes stay with the engineer.
- Summarize incidentsFollows an incident's timeline and recent deploys, drafts status updates and a first postmortem. It never acknowledges, pages or resolves.
- Draft release notesReads the pull requests merged since the last release and drafts customer-facing notes. The release stays a draft until an engineer publishes it.
Answers to
- SOC 2
- ISO/IEC 42001
- EU AI Act
- State privacy laws (CCPA/CPRA)
Enabling agent operations
Governance at the agent‑action boundary.
However an agent was built and wherever it runs, the same three boundaries are available to control it: the code it ships as, the tools it calls, and the model it reasons through.
Code
Agent Registry
Make every agent known and manageable. Credentials issued, capabilities declared, lifecycle owned.
See moreTool
MCP Gateway
Evaluate every call against policy with full context. Allow, deny, or escalate. Filter what comes back.
See moreModel
Model Broker
Constrain how the agent reasons. Selection by policy, routing across providers, evals against real traffic.
See more