# Dome Systems > The governance layer for agentic software. Connect, govern, and operate AI agents across every runtime, every cloud. Dome Systems builds the Agent Operations Platform. Enterprises are adopting AI agents faster than their existing governance can keep up — RBAC, API gateways, and audit logs were built for software that follows fixed paths, not for reasoning systems that decide what to do at runtime. Dome closes that gap with one platform that registers every agent, governs every tool and model call against policy, and produces an immutable audit trail across the entire estate, regardless of where the agent runs (cloud, SaaS, data platform, developer laptop) or who built it (your team, a vendor, an end user). The product is the **Dome Platform**: three control points — **Registry** (code), **Gateway** (tools), **Broker** (models) — on a control plane of **Access**, **Authorization** and **Audit**, administered through the Python SDK, an API, a CLI, and an MCP surface that exposes Dome itself to AI assistants. ## What Dome Does Every agent passes through the same path, whatever surface it runs on. Connect, Govern, Operate: - **Register**: Every agent gets a registry record — name, owner, workspace — and a managed lifecycle (provisioned, active, suspended, revoked). The credential issued at registration is the root of trust for everything that follows. - **Attach Tools**: Backends (MCP servers, REST APIs, internal services) are attached to the Tool Gateway. Tools surface into a per-agent catalog, filtered by policy, with credentials injected at egress and Guards applied to responses before they reach the agent. - **Connect Models**: Model providers (Anthropic, OpenAI, Bedrock, self-hosted) are configured at the Broker, optionally composed into pools for failover or cost routing. Per-call policy and credential injection apply at the model boundary, with a uniform audit vocabulary across providers. - **Authorize Calls**: Rules are defined at the right scope (org, tenant, workspace, agent), simulated against replayed traffic, and shipped versioned through CI/CD. Authorization is fail-closed and forbid-wins by default — policy that enforces, not policy that asks. - **Observe Events**: Every governed action emits an immutable audit event with full context: agent, caller chain, tool or model, arguments, policy version, outcome. Audit is the record — queryable from the UI, CLI, and API, and exportable in OCSF, CEF, or CSV. Eventing is the reflex: selected facts projected onto a public-safe versioned contract and delivered to other systems by signed webhook. ## Platform The product, broken down by component. Each page covers what the component does, how it integrates, and what it looks like in practice. - [Platform overview](https://www.domesystems.ai/platform): The Dome Platform — three control points (Registry, Gateway, Broker) on a control plane of access, authorization, and audit. The architectural model and how the pieces compose. - [Platform resources](https://www.domesystems.ai/platform#resources): The resources Dome is built from, grouped by Connect, Govern and Operate: agents, callers, tools, gateways, models, pools, rules, guards, quotas, audits, webhooks and integrations. Registry, Gateway and Broker are compositions of these. - [Agent Registry](https://www.domesystems.ai/platform/registry): The system of record for every agent. Registration, capability declaration, lifecycle states, and the credential root of trust for downstream calls. - [Tool Gateway](https://www.domesystems.ai/platform/gateway): The enforcement point for every tool call an agent makes. Backend attachment, per-call policy, credential injection at egress, response filtering, and a single governed path for every API, MCP server, or internal service an agent can reach. - [Model Broker](https://www.domesystems.ai/platform/broker): The enforcement point for every model call. OpenAI- and Anthropic-compatible API surface, per-call policy, credential injection, pool composition for failover and cost routing, and a uniform audit vocabulary across providers. - [Access](https://www.domesystems.ai/platform/access): Authentication and identity propagation across the call chain. The agent authenticates with the credential issued at registration; the end user it acts for is asserted on a header and verified (OIDC or HMAC, configured per agent) rather than trusted. Both identities reach the authorization decision, the audit record, and the upstream call — so a rule can require a verified caller, scope by directory group, or deny on live claims such as a terminated status. - [Authorization](https://www.domesystems.ai/platform/authorization): Rules evaluated at the call boundary on the platform itself — fail-closed, forbid-wins, across four scopes (org, tenant, workspace, agent). Includes simulation against replayed traffic and versioned rollout. - [Audit](https://www.domesystems.ai/platform/audit): Immutable events across all three control points, with one vocabulary. Full context — agent, caller chain, target, policy version, outcome — queryable from the UI, CLI, and API, and exportable in OCSF, CEF, or CSV. - [Operator surfaces](https://www.domesystems.ai/platform/operator): How developers and platform teams drive the platform. The Python SDK, CLI, REST API, and an MCP surface that exposes Dome itself to AI assistants for triage and review. - [Manage](https://www.domesystems.ai/manage): Org-down administration. Tenants, workspaces, defaults, and per-scope overrides, administered consistently across every component. - [Webhooks](https://www.domesystems.ai/platform/webhooks): Signed event delivery from Dome to the systems you already run. Subscriptions filter by type, deliveries follow Standard Webhooks, and failures replay without duplicating work. - [Integrations](https://www.domesystems.ai/integrations): How Dome composes with the systems already in production — IdPs, credential stores, observability platforms, and CI/CD pipelines. The principle is to integrate outward rather than replace. Includes Events: a published catalog of versioned event types, delivered by signed webhook with retries, a delivery ledger, replay, and per-destination circuit breaking. ## Solutions How enterprises use Dome: the strategy, the patterns, the teams, the use cases and the industries. - [Own your AI](https://www.domesystems.ai/solutions): Deliver an agent operating model. Enterprises that want to own their AI strategy build their own agents, connect them to their own tools and data, and tune their own models. Owning them means owning their operations, which a SaaS vendor used to carry. Dome is the platform for running all of it consistently, with a maturity model from Experimental to Adopting to Standardizing. - [Forward deployed engineering](https://www.domesystems.ai/forward-deployed-engineering): Dome's engineers work with your platform team to get the first agent governed on your own systems, and a pattern your teams repeat for every agent after it. **By pattern** (golden paths: approved patterns with identity, rules and audit already wired in): - [Business patterns](https://www.domesystems.ai/solutions/business-patterns): Building the agentic enterprise. The two directions agents cross your boundary: agents the business consumes, reaching your systems, and agents the product ships, where customers' agents reach your product. One platform and one audit record under both. - [Application patterns](https://www.domesystems.ai/solutions/application-patterns): Standardize agentic apps. Four golden paths, an Interactive Assistant, a Scheduled Job, a Developer Harness and an External Service, each wired from the same resources. **By role:** - [For Platform Teams](https://www.domesystems.ai/solutions/for/platform-teams): Shared services for internal business units. One operations layer across the estate, self-service for builders without losing the audit trail. - [For App Dev Teams](https://www.domesystems.ai/solutions/for/app-dev-teams): Start from the golden path for the agent you are building, and inherit identity, access and audit. - [For Systems Integrators](https://www.domesystems.ai/solutions/for/systems-integrators): Build governed agent practices for your clients on Dome. - [For Executives](https://www.domesystems.ai/solutions/for/executives): Governance of the agentic estate, and the operational evidence behind it. **By use case:** - [Onboard agents](https://www.domesystems.ai/solutions/use-cases/onboard-agents): Using Dome's Agent Registry to bring every agent under one tenant: one record per agent, its credential, the callers it acts for, the rules that bound it, and the audit of what it did. - [Consolidate tool access](https://www.domesystems.ai/solutions/use-cases/consolidate-tool-access): Using Dome's MCP gateway to put every tool call behind one boundary. Limit access, enforce policy, and audit every action without rewriting the tools or the agents. - [Broker model access](https://www.domesystems.ai/solutions/use-cases/broker-model-access): Using Dome's Model Broker to route model traffic on cost, policy and availability without changing the agent. **By industry:** - [Industries](https://www.domesystems.ai/industries): AI agent governance by industry: example agents on real systems, the controls on them, and the regulations they answer. - [AI agents for financial services](https://www.domesystems.ai/industries/finance), with pages for [fintech](https://www.domesystems.ai/industries/finance/fintech), [banking and lending](https://www.domesystems.ai/industries/finance/banking-lending), [payments and spend management](https://www.domesystems.ai/industries/finance/payments), [wealth and asset management](https://www.domesystems.ai/industries/finance/wealth-management), and [capital markets and digital assets](https://www.domesystems.ai/industries/finance/capital-markets). - [AI agents in healthcare](https://www.domesystems.ai/industries/healthcare), [insurance claims](https://www.domesystems.ai/industries/insurance), [law firms](https://www.domesystems.ai/industries/legal), [software companies](https://www.domesystems.ai/industries/technology), [professional services firms](https://www.domesystems.ai/industries/professional-services) and [gaming and sports betting](https://www.domesystems.ai/industries/gaming). - [AI agents for retail](https://www.domesystems.ai/industries/retail), with pages for e-commerce, merchandising and planning, store operations, and supply chain and fulfillment. ## Category guides Explainers for the categories Dome's control points sit in. Each answers the question first, maps the landscape honestly, then shows how Dome approaches it. - [What is an MCP gateway?](https://www.domesystems.ai/mcp-gateway): An MCP gateway is a single endpoint between AI agents and the Model Context Protocol servers they call — access control, credential injection at egress, response filtering, and an audit record per call. Covers what one does, where implementations differ (server-level vs tool-level control, whether the caller's identity reaches the authorization decision, whether model traffic is governed too), a map of the category (MintMCP, Docker MCP Gateway, Kong AI Gateway, Dome), and how Dome's Tool Gateway approaches it. Links to the field guide *Agents Need to Talk to Your Systems* for the configuration detail. - [What is a model router?](https://www.domesystems.ai/llm-router): A model router is a single endpoint between agents and the model providers they call — one API shape, routing on cost or latency or capability, failover, credential injection, and normalized usage reporting. Covers where implementations differ (identity-scoped vs key-scoped spend caps, policy per call vs configuration per key, what the audit record contains), a map of the category (LiteLLM, Prisma AIRS, Kong AI Gateway, OpenRouter, Dome), and how Dome's Model Broker approaches it. Links to the field guide *Agents Need to Talk to Models* for the configuration detail. Dome's position across both: routing in service of governance, not the other way round. Several products in each category compose with Dome rather than replace it. ## Perspectives — long-form arguments and field guides Two registers. **Arguments** set out the framework underneath Dome's positioning, for leaders setting direction. **Field guides** are configuration-level walkthroughs for the platform teams doing the work. Each has a web version; most have a downloadable PDF. Nothing is gated. ### Field guides - **[So You're Building an Enterprise Agent Hub](https://www.domesystems.ai/perspectives/enterprise-agent-hub)** ([PDF](https://www.domesystems.ai/papers/enterprise-agent-hub.pdf)) — A technical guide to building an internal agent platform on Dome's APIs. The shared-responsibility split between the runtime you build and the governance substrate you consume, and how the build-time and runtime call sequences differ. Then the five responsibilities in turn: identify (agent lifecycle, act-as identity), authorize (the Cedar entity model, rules you author versus grants your platform generates, forbid-wins across scopes), route models, broker tools, and account. Closes with two reference patterns — the Self-Service Agent Platform and the Purpose-Built Agent Service — plus integration and rollout sequencing and the common failure modes. - **[Agents Need to Talk to Your Systems](https://www.domesystems.ai/perspectives/mcp-gateway-field-guide)** ([PDF](https://www.domesystems.ai/papers/mcp-gateway-field-guide.pdf)) — A field guide to the Tool Gateway. What a governed tool call is, connecting a system (transport, authentication, OAuth, outbound headers), composing a catalog, six patterns for shaping reach with Gateways, two shapes for per-person reach, choosing how many Gateways, governing what comes back with Guards, and what lands in the audit record. - **[Agents Need to Talk to Models](https://www.domesystems.ai/perspectives/llm-router-field-guide)** ([PDF](https://www.domesystems.ai/papers/llm-router-field-guide.pdf)) — A field guide to the Model Broker. What a governed model call is, connecting a provider, building pools (members, routing strategies, failover, caching), expressing model choice as routing policy with the `match_when` dialect, seven routing patterns, spend caps and the difference between spilling budgets and rejecting ceilings, and what lands in the record. ### Arguments - **[Another Governance Layer, Again](https://www.domesystems.ai/perspectives/governance-layer)** ([PDF](https://www.domesystems.ai/papers/governance-layer.pdf)) — The anchor paper. Every enterprise computing era produces a new governance layer purpose-built for its patterns of access and action. The agent era is no different, except the patterns are probabilistic, multi-runtime, and moving faster than any that came before. Defines the agent, maps the five surfaces where agents operate, names the governance gap, and proposes a Connect/Secure/Operate blueprint. - **[Toward Enterprise Agentic Operations](https://www.domesystems.ai/perspectives/enterprise-agentic-operations)** ([PDF](https://www.domesystems.ai/papers/enterprise-agentic-operations.pdf)) — A maturity model for agentic adoption: Experimental → Adopting → Standardizing. What each stage looks like, the cost and risk profile of staying in it, and the operational shifts that produce the standardized stage. The executive-facing companion to the anchor paper. - **[The New Shadow IT](https://www.domesystems.ai/perspectives/velocity-engineering)** — How "velocity engineering" (non-engineers building functional agents with LLMs in hours) creates structural governance tension, why restriction fails as a response, and why the answer is consistent operations rather than blocking. The cultural and organizational lens on the same problem. - **[The Scarcity Isn't Code Anymore](https://www.domesystems.ai/perspectives/economic-argument)** — As code production commoditizes, value migrates to governance — the management plane that SaaS vendors used to bundle and that enterprises now have to provide themselves. The economic argument for treating governance as a durable platform. - [Index of all perspectives](https://www.domesystems.ai/perspectives) ## Company - **Founded**: 2024 - **Founders**: Dave McJannet (CEO, former CEO of HashiCorp) and Marc Holmes (COO, former VP Marketing at HashiCorp and Docker) - **Investors**: Redpoint Ventures, Bessemer Venture Partners, Mango Capital - **Website**: https://www.domesystems.ai - **Documentation**: https://docs.domesystems.ai - **About the company**: https://www.domesystems.ai/about - **Contact**: hello@domesystems.ai ## Pricing - [Pricing](https://www.domesystems.ai/pricing): Four tiers — Free, Pro, Team, Enterprise. Every tier carries the whole platform; Free is Pro without a card on file, stopping at a monthly allowance instead of billing. Usage is metered per governed tool call, and the tokens passing through the Broker are charged at infrastructure cost rather than at value — Dome charges for governance and passes compute through. Enterprise adds self-managed and hybrid deployment, multiple organizations, custom permissions, and unlimited audit retention. **Enterprise publishes no rates** — it is priced per organization against a prepaid commit and sold through contact rather than self-serve. Discounting is a tier privilege: Pro pays published rates, Team earns volume discount pricing (VDP), Enterprise gets a deeper ladder plus the commit. - [Pricing enquiry](https://www.domesystems.ai/contact/pricing): Where Enterprise and volume-discount conversations start. Everything below Enterprise is self-serve at the published rates. ## Optional - [Updates](https://www.domesystems.ai/updates): Product updates and news. - [Contact](https://www.domesystems.ai/contact): General inquiries. - [Careers](https://www.domesystems.ai/careers): Open roles. - [Subscribe](https://www.domesystems.ai/subscribe): Updates from Dome. - [Privacy](https://www.domesystems.ai/privacy): Privacy policy. - [Terms](https://www.domesystems.ai/terms): Standard Terms and Conditions — the customer agreement governing use of the platform. - [DPA](https://www.domesystems.ai/dpa): Data Processing Agreement — Dome as processor of Customer Personal Data. Subprocessors and security measures at trust.domesystems.ai.