Dome Systems

GPT and Dome

Run GPT-6 from OpenAI and Azure under one name.

Serve GPT from OpenAI directly and from your Azure OpenAI deployment behind one pool. Agents ask for gpt-6-sol, and the Broker tries Azure when OpenAI fails. Rules send legal work to the zero-retention deployment.

PeopleAgentsDomePool: gpt-6-solCallersPeopleAgentscontract-reviewerAgentssupport-agentAgentssales-assistantGatewaysprod-gatewayOpenAIPriority 0Azure OpenAIPriority 1RulesGuardsAuditsaudit-trail
support-agent→gpt-6-sol· as j.lindqvistAllowed

How Dome helps

Dome provides model brokering and routing for GPT

OpenAI first, Azure next

Pool the OpenAI connection and your Azure deployment under gpt-6-sol. When OpenAI fails, the call goes to Azure.

Sensitive work on the right deployment

Tag the Azure connection with its retention terms. A rule keeps legal work off any connection without them.

Spend by agent

Cap each agent's monthly provider spend. The sales assistant can't eat the support team's budget.

Get started

GPT with failover in five steps

Connect OpenAI and Azure, pool the connections in priority order, and point your agents at the Gateway. Provider keys stay in Dome.

  1. 01

    Connect OpenAI

    The key goes into Dome's vault and is sent as a bearer token at call time. Agents never hold it.

    $ dome models add gpt-openai \
    --provider openai \
    --model gpt-6-sol \
    --api-key "$OPENAI_API_KEY" \
    --gateway prod-gateway
  2. 02

    Connect Azure OpenAI

    Azure needs your resource endpoint, the deployment name and an API version. The key is sent as the api-key header.

    $ dome models add gpt-azure \
    --provider azure_openai \
    --model gpt-6-sol \
    --provider-config '{"endpoint":"https://contoso-eu.openai.azure.com","deployment":"gpt-6-sol","api_version":"2024-10-21"}' \
    --api-key "$AZURE_OPENAI_API_KEY" \
    --attributes '{"retention":"zero"}' \
    --gateway prod-gateway
  3. 03

    Pool them for failover

    Members are tried in priority order. Name the pool for the model and agents need no other change.

    $ dome models pool create gpt-6-sol \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add gpt-6-sol gpt-openai --priority 0
    $ dome models pool member add gpt-6-sol gpt-azure --priority 1
  4. 04

    Point your agent at the Gateway

    The OpenAI SDK takes the Gateway URL as its base. The agent's Dome key replaces the provider key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="gpt-6-sol",
    messages=[{"role": "user", "content": "Summarize this call transcript."}],
    )
  5. 05

    Cap spend per agent

    An agent quota counts every model call that agent makes, through any pool.

    $ dome quotas set --subject agent --agent sales-assistant \
    --dimension llm --unit provider_usd --limit 200 --window monthly

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about GPT itself, see OpenAI's documentation.

Rules

Legal work stays on zero-retention connections

When the person an agent acts for is in legal, only connections tagged retention: zero are allowed. Everyone else can use either provider.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when {
principal has act_as &&
principal.act_as.groups.contains("legal")
}
unless { resource has retention && resource.retention == "zero" };

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Connection

agent contract-reviewer · acting as e.walsh
llm:invoke(model: "gpt-azure")
  1. Agentcontract-reviewer is registered and active
  2. Callere.walsh verified, groups: legal
  3. RuleConnection is tagged retention: zero
DecisionAllowed

Agent workflow

Bringing it together

Connecting GPT to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Which providers serve GPT through Dome?

OpenAI directly, and Azure OpenAI through your own deployment. Both can sit in one pool.

Do agents need different code for Azure and OpenAI?

No. Agents send the pool's name to the Gateway, and Dome builds each provider's request.

What happens when a new GPT model ships?

Add a connection for the new model id, and a new Azure deployment if you use one. Swap them into the pool.

Does the Responses API work through Dome?

Yes, on OpenAI connections. Azure OpenAI connections serve chat completions and embeddings.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.