Dome Systems

AI agents for software companies

Give your engineers agents that read everything and ship nothing

Three agents for escalation triage, incident summaries and release notes. The ones engineers call act as that engineer, secrets never reach a model, and nothing merges, pages or publishes on its own. Every call lands in one audit record.

engineersAgentsDomeEngineering systemsCallersengineersAgentsescalation-botAgentsincident-scribeAgentsrelease-drafterGatewayseng-toolsJiraEscalations & sprintsPagerDutyIncidents & on-callGitHubCode & releasesAnthropicApproved modelsRulesGuardsAuditsaudit-trail
incident-scribe→pagerduty/get_incident· as b.strattonAllowed

Governing Technology Agents

Any tool, any model, any use case

Our example demonstrates three agents for your engineering and support work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.

Examples for Technology & software

More from the library · Software

Also in the library

FinanceSecurityITHRSalesSupportEngineeringResearch

Triage engineering escalations

Reads an escalated ticket and the code it points to, drafts a diagnosis and sets priority. Fixes stay with the engineer.

Tools

JiraGitHub

Model

Claude Sonnet 5or any approved provider

Runs

When a ticket is escalated in Jira

Limits

Acts as the engineerWrites triage fields onlySecrets redacted

Tuned for your team

  • Your severity definitions and component owners
  • Repositories mapped to the products they serve

Applying Controls to Agents

Keep secrets, incidents and releases under your rules

Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches GitHub, PagerDuty or a model.

File

agent incident-scribe · acting as j.harlow
github/get_file(repo: "billing-api", path: "deploy/worker.yaml")
  1. Callerj.harlow verified through Okta
  2. RuleDeploy config reads are allowed
  3. Guard1 access key redacted from the response
env: STRIPE_KEY: sk_live_51Hx9qLmT2vN8bRc
env: STRIPE_KEY: [REDACTED]
DecisionAllowed · Redacted

Comprehensive Audit

Show your auditor every repository an agent read

One record for every call: the agent, the engineer it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.

Audit · eng-tools
Events 0Denied 0
  • incident-scribe03:12:44
1 audit events

Regulation

Give your SOC 2 auditor the agents, not just the people

Engineering and support agents reach code, customer data and production systems. These are the frameworks that reach them, and what the controls above give you for each.

SOC 2

What it asks

Access to systems and data is authorized, changes are controlled, and there's evidence of both for the audit period.

What Dome gives you

Each agent is registered with its own credential and acts for a named engineer. Every call, allowed or refused, lands in one record you can hand the auditor.

ISO/IEC 42001

What it asks

An AI management system: know which AI systems you run, assess their risks, and operate controls on them.

What Dome gives you

The registry is the inventory of agents. Rules and guards are the controls, and the audit record shows them working.

EU AI Act

What it asks

For software sold in the EU: staff who use AI need AI literacy, and people must be told when they're talking to an AI system.

What Dome gives you

Every agent, its models and its tools are on record, which makes the disclosure and training scope concrete. Agents reach only approved models.

State privacy laws (CCPA/CPRA)

What it asks

Customer personal data is used only for the purpose it was collected for, and customers can ask what you hold.

What Dome gives you

Customer emails and payment details are redacted from tickets before a model call, and every read is recorded with the engineer it served.

FAQ

Common questions

How do you stop an AI agent from leaking secrets to an LLM?

Put a guard between the agent and its tools. On Dome, a guard strips API keys and tokens from logs, files and tickets before any model sees them, and a rule refuses reads of files like .env outright.

Can an AI agent resolve incidents in PagerDuty?

Only if a rule allows it. Most teams let the agent read the incident and draft updates, and keep acknowledging and resolving with the on-call engineer.

Are AI agents in scope for SOC 2?

If an agent can reach in-scope systems, its access is part of the audit. Give each agent its own identity, scope what it can call, and keep a record of every call.

How do you audit what an AI coding agent did in GitHub?

Route its tool calls through a Dome gateway. Every call lands in one record with the agent, the engineer it acted for, the repository and the decision.

How are software companies using AI agents?

Escalation triage, incident summaries and release notes are common first agents. Each reads or drafts, and engineers keep merging, paging and publishing.

Forward deployed engineering

Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.

Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.

Key topics to discuss:

  • Review your AI plans, progress to date, and timeline for agentic projects in production.
  • Planning a specific agent, or agentic app, to bring under governance.
  • Learning more about our platform capabilities, from gateways to routing.
  • Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.

Explore

Other industries

Industries

AI agents for financial services

KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.

Agentic use cases

  • Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
  • Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
  • Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.

Answers to

  • GLBA Safeguards Rule
  • BSA/AML and the FinCEN CDD Rule
  • NYDFS Part 500
  • Regulation E (EFTA)
  • CFPB UDAAP
  • Interagency third-party risk guidance
  • ECOA and Regulation B
  • FCRA
  • SR 11-7 model risk management
  • PCI DSS v4.0.1
  • Regulation E (EFTA) error resolution
  • BSA/AML and OFAC sanctions screening
  • SEC Regulation S-P (2024 amendments)
  • SEC Marketing Rule and FINRA Rule 2210
  • Books and records (Rule 204-2 and Rule 17a-4)
  • FINRA Rule 3110 and Regulatory Notice 24-09
  • SEC Rule 17a-4 recordkeeping
  • Exchange Act Section 15(g) information barriers
See the finance agents