AI agents for software companies
Give your engineers agents that read everything and ship nothing
Three agents for escalation triage, incident summaries and release notes. The ones engineers call act as that engineer, secrets never reach a model, and nothing merges, pages or publishes on its own. Every call lands in one audit record.
Governing Technology Agents
Any tool, any model, any use case
Our example demonstrates three agents for your engineering and support work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.
Examples for Technology & software
More from the library · Software
Also in the library
Triage engineering escalations
Reads an escalated ticket and the code it points to, drafts a diagnosis and sets priority. Fixes stay with the engineer.
Tools
Model
Runs
Limits
Tuned for your team
- Your severity definitions and component owners
- Repositories mapped to the products they serve
Applying Controls to Agents
Keep secrets, incidents and releases under your rules
Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches GitHub, PagerDuty or a model.
File
- Callerj.harlow verified through Okta
- RuleDeploy config reads are allowed
- Guard1 access key redacted from the response
Comprehensive Audit
Show your auditor every repository an agent read
One record for every call: the agent, the engineer it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.
- incident-scribe03:12:44
| Timestamp | Type | Agent | Acting as | Resource | Outcome | Latency |
|---|---|---|---|---|---|---|
| 03:12:44.208 | ||||||
Regulation
Give your SOC 2 auditor the agents, not just the people
Engineering and support agents reach code, customer data and production systems. These are the frameworks that reach them, and what the controls above give you for each.
SOC 2
What it asks
Access to systems and data is authorized, changes are controlled, and there's evidence of both for the audit period.
What Dome gives you
Each agent is registered with its own credential and acts for a named engineer. Every call, allowed or refused, lands in one record you can hand the auditor.
ISO/IEC 42001
What it asks
An AI management system: know which AI systems you run, assess their risks, and operate controls on them.
What Dome gives you
The registry is the inventory of agents. Rules and guards are the controls, and the audit record shows them working.
EU AI Act
What it asks
For software sold in the EU: staff who use AI need AI literacy, and people must be told when they're talking to an AI system.
What Dome gives you
Every agent, its models and its tools are on record, which makes the disclosure and training scope concrete. Agents reach only approved models.
State privacy laws (CCPA/CPRA)
What it asks
Customer personal data is used only for the purpose it was collected for, and customers can ask what you hold.
What Dome gives you
Customer emails and payment details are redacted from tickets before a model call, and every read is recorded with the engineer it served.
FAQ
Common questions
How do you stop an AI agent from leaking secrets to an LLM?
Put a guard between the agent and its tools. On Dome, a guard strips API keys and tokens from logs, files and tickets before any model sees them, and a rule refuses reads of files like .env outright.
Can an AI agent resolve incidents in PagerDuty?
Only if a rule allows it. Most teams let the agent read the incident and draft updates, and keep acknowledging and resolving with the on-call engineer.
Are AI agents in scope for SOC 2?
If an agent can reach in-scope systems, its access is part of the audit. Give each agent its own identity, scope what it can call, and keep a record of every call.
How do you audit what an AI coding agent did in GitHub?
Route its tool calls through a Dome gateway. Every call lands in one record with the agent, the engineer it acted for, the repository and the decision.
How are software companies using AI agents?
Escalation triage, incident summaries and release notes are common first agents. Each reads or drafts, and engineers keep merging, paging and publishing.
Forward deployed engineering
Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.
Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.
Key topics to discuss:
- Review your AI plans, progress to date, and timeline for agentic projects in production.
- Planning a specific agent, or agentic app, to bring under governance.
- Learning more about our platform capabilities, from gateways to routing.
- Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.
Explore
Other industries
AI agents for financial services
KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.
Agentic use cases
- Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
- Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
- Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.
Answers to
- GLBA Safeguards Rule
- BSA/AML and the FinCEN CDD Rule
- NYDFS Part 500
- Regulation E (EFTA)
- CFPB UDAAP
- Interagency third-party risk guidance
- ECOA and Regulation B
- FCRA
- SR 11-7 model risk management
- PCI DSS v4.0.1
- Regulation E (EFTA) error resolution
- BSA/AML and OFAC sanctions screening
- SEC Regulation S-P (2024 amendments)
- SEC Marketing Rule and FINRA Rule 2210
- Books and records (Rule 204-2 and Rule 17a-4)
- FINRA Rule 3110 and Regulatory Notice 24-09
- SEC Rule 17a-4 recordkeeping
- Exchange Act Section 15(g) information barriers
AI agents for gaming and sports betting
Player support, responsible gaming review and bonus setup. Self-exclusions and limits stay out of an agent's reach.
Agentic use cases
- Answer player questionsLooks up a player's account, bets and withdrawal status so a specialist can answer fast. It reads. Balances and limits stay with people.
- Review responsible gaming signalsReviews players flagged for risky play and drafts case notes for the responsible gaming team. It never changes a limit.
- Configure bonusesSets up deposit matches and free bets from a campaign brief, up to the cap you set. Self-excluded players are never targeted.
Answers to
- State gaming regulations
- Bank Secrecy Act (FinCEN casino rules)
- Age, identity and location checks
AI agents in healthcare
Prior authorizations, visit notes and eligibility checks. Agents read only the charts their clinician can read.
Agentic use cases
- Assemble prior authorizationsPulls the notes, orders and imaging a payer asks for into one authorization packet. A clinician reviews it and submits.
- Draft visit notesDrafts a visit note from the encounter and the chart, in the department's template. The clinician edits it and signs it.
- Verify eligibility before the visitChecks coverage for the next day's appointments overnight. Anything that needs a call before the visit goes to the patient access channel.
Answers to
- HIPAA minimum necessary
- Business associate agreements
- HIPAA Security Rule audit controls
- CMS prior authorization rule (CMS-0057-F)
AI agents for insurance claims
Claim intake, file summaries and fraud screening. Agents read only the claims assigned to their adjuster.
Agentic use cases
- Triage new claimsReads each first notice of loss, sets severity and line of business, and routes it to the right adjuster queue. It flags. It never settles.
- Summarize claim filesSummarizes medical records, police reports and correspondence in a claim file for the assigned adjuster. Only claims that adjuster handles.
- Screen claims for fraud signalsChecks each open claim against prior claims history and flags patterns for the special investigations unit. It never denies a claim.
Answers to
- NAIC Model Bulletin on AI Systems
- Unfair claims settlement practices laws
- Insurance data security laws
AI agents for law firms
Conflicts checks, clause extraction and redlines. Every agent acts as the lawyer who asked.
Agentic use cases
- Check new matters for conflictsSearches Intapp and past matters in iManage for parties that conflict with a proposed engagement. It reports. It never clears a conflict.
- Extract clauses from contractsPulls parties, dates, renewal and change-of-control terms from the contracts in a matter workspace. Only in matters the requester is staffed on.
- Draft redlines against the playbookMarks up a counterparty draft against your playbook and saves it as a new version. Counsel reviews it and sends it.
Answers to
- ABA Formal Opinion 512
- Privilege after United States v. Heppner
- Ethical walls (Model Rules 1.7, 1.9, 1.10)
AI agents for professional services firms
Proposals, staffing and engagement status. Each agent sees only the engagements its consultant works on.
Agentic use cases
- Draft proposalsReads an RFP and drafts a response from the firm's reuse library. Client names in past work are stripped before the model sees them.
- Match staff to engagementsMatches skills and availability to a new engagement's roles and proposes a team. Resource managers make the assignments.
- Report engagement statusReads the project plan and engagement files and drafts the weekly status report. It sees only engagements its consultant is on.
Answers to
- Client confidentiality terms
- AICPA Confidential Client Information Rule
- SOC 2
- GDPR and state privacy laws
AI agents for retail
Order lookups, replenishment and product copy. Refunds, orders and publishing stay with your people.
Agentic use cases
- Answer order questionsLooks up orders, shipments and returns so an associate can answer a customer fast. It reads. Refunds stay with the associate.
- Plan replenishmentForecasts demand by store and drafts purchase orders against par levels. Buyers review them and send them.
- Write product copyWrites product titles and descriptions from supplier data, in your voice, and saves them as drafts. Merchandisers publish.
Answers to
- PCI DSS v4.0.1
- State privacy laws (CCPA/CPRA)
- SOX internal controls
- FTC Act, Section 5
- Antitrust and algorithmic pricing
- Predictive scheduling laws
- Routing guides and carrier contracts
Enabling agent operations
Governance at the agent‑action boundary.
However an agent was built and wherever it runs, the same three boundaries are available to control it: the code it ships as, the tools it calls, and the model it reasons through.
Code
Agent Registry
Make every agent known and manageable. Credentials issued, capabilities declared, lifecycle owned.
See moreTool
MCP Gateway
Evaluate every call against policy with full context. Allow, deny, or escalate. Filter what comes back.
See moreModel
Model Broker
Constrain how the agent reasons. Selection by policy, routing across providers, evals against real traffic.
See more