Dome Systems

Azure OpenAI and Dome

Your Azure OpenAI deployments, governed per call.

Connect each Azure OpenAI deployment to Dome with its endpoint, deployment name and API version. The key stays in Dome's vault, and agents call the Gateway with their own keys. Rules decide which people's work runs on which deployment.

PeopleAgentsDomeAzure OpenAI deploymentsCallersPeopleAgentshr-assistantAgentssupport-agentAgentsfinance-agentGatewaysprod-gatewaycontoso-eugpt-6-sol, region: eucontoso-usgpt-6-sol, region: usOpenAIgpt-6-solRulesGuardsAuditsaudit-trail
hr-assistant→gpt-azure-eu· as l.moreauAllowed

How Dome helps

Dome provides model brokering and routing for Azure OpenAI

Azure's api-key, kept by Dome

Dome sets the api-key header from its vault on every call. Agents authenticate with their own Dome keys.

EU work on EU deployments

Tag each deployment with its region. A rule keeps EU staff's calls on EU deployments.

Azure behind OpenAI, or the reverse

Pool a deployment with OpenAI's API for the same model, in either order. The second member covers the first.

Get started

Connect Azure OpenAI in three steps

Add each deployment, pool it with OpenAI if you want cover, and let agents call the Gateway.

  1. 01

    Add the deployment

    The provider id is azure_openai. Endpoint, deployment and api_version are all required: Azure picks the model from the deployment.

    $ dome models add gpt-azure-eu \
    --provider azure_openai \
    --model gpt-6-sol \
    --provider-config '{"endpoint":"https://contoso-eu.openai.azure.com","deployment":"gpt-6-sol","api_version":"2024-10-21"}' \
    --api-key "$AZURE_OPENAI_API_KEY" \
    --attributes '{"region":"eu"}' \
    --gateway prod-gateway
  2. 02

    Pool it with OpenAI

    The EU deployment goes first and OpenAI second. Agents address gpt-6-sol, the pool.

    $ dome models pool create gpt-6-sol \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add gpt-6-sol gpt-azure-eu --priority 0
    $ dome models pool member add gpt-6-sol gpt-openai --priority 1
  3. 03

    Point your agent at the Gateway

    Use the standard OpenAI SDK, not the Azure client. The agent's Dome key replaces the Azure key.

    from openai import OpenAI
     
    client = OpenAI(base_url=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)
    client.chat.completions.create(
    model="gpt-6-sol",
    messages=[{"role": "user", "content": "Summarize this policy for a new hire."}],
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Azure OpenAI itself, see Microsoft's documentation.

Rules

EU staff stay on EU deployments

Calls made for anyone in eu-staff are allowed only on deployments tagged region: eu. Dome reads the group from that person's identity token.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when {
principal has act_as &&
principal.act_as.groups.contains("eu-staff")
}
unless { resource has region && resource.region == "eu" };

Agent workflow

Bringing it together

Connecting Azure OpenAI to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

What does Dome need to call Azure OpenAI?

Your resource endpoint, the deployment name, an API version and a key. Dome builds the deployment URL from them.

Which header carries the Azure key?

The api-key header, not Authorization. Dome sets it from the key in its vault.

Which Azure OpenAI operations work through Dome?

Chat completions and embeddings. The Responses API is not served on Azure connections.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.