Dome Systems

Copilot Studio MCP and Dome

Build agents in Copilot Studio. Decide what they call.

Copilot Studio connects agents to MCP servers by URL, with an API key in a header. Add a Dome Gateway that way and the agent reaches only the tools its rules allow. Every call lands in Dome's audit trail.

Employees in TeamsAgentsDomeTools & modelsCallersEmployees in TeamsAgentshelpdesk-copilotAgentsonboarding-copilotAgentsticket-summarizerGatewaysprod-gatewayAtlassianMCP serverInternal toolsMCP serversclaude-sonnetModel poolRulesGuardsAuditsaudit-trail
helpdesk-copilot→atlassian/searchJiraIssuesUsingJql· scheduledAllowed

How Dome helps

Dome provides governance for every Microsoft Copilot Studio tool and model call

A URL and a header

The onboarding wizard takes the Gateway's MCP URL and an API key sent in the Authorization header. The key is a Dome agent key.

Tools named, not inherited

Rules list the tools each Copilot Studio agent may call. Anything else on the Gateway is refused.

Tool calls governed, models not

Copilot Studio runs its own models, and their calls don't pass through Dome. Every tool call does.

Get started

Copilot Studio on a Gateway in three steps

Register an agent in Dome, then add the Gateway in Copilot Studio's MCP onboarding wizard with the agent's key. The Dome commands were run against a workspace; the Copilot Studio steps come from Microsoft's docs.

  1. 01

    Register an agent and issue its key

    One Dome agent for each Copilot Studio agent you want to tell apart.

    $ dome agents register --name helpdesk-copilot --gateway prod-gateway
    $ dome agents create-key helpdesk-copilot --name copilot-studio
    $ dome rules apply helpdesk-copilot.cedar --agent helpdesk-copilot --name jira-helpdesk
  2. 02

    Copy the Gateway's MCP URL

    It's endpoints.mcp_url in the output. Copilot Studio supports the Streamable HTTP transport, and so does the Gateway.

    $ dome gateways get prod-gateway --json
  3. 03

    Add the Gateway in Copilot Studio

    On the agent's Tools page, choose Add a tool, New tool, then Model Context Protocol. Enter the URL, pick API key, type Header, header name Authorization. When you create the connection, enter Bearer followed by the agent key.

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Microsoft Copilot Studio itself, see Microsoft's documentation.

Rules

File tickets, read the knowledge base

The permit lets the agent discover tools and call Atlassian. The forbid refuses every Atlassian tool except four: search, read and create Jira issues, and read Confluence.

permit (principal, action == Dome::Action::"mcp:discover", resource);
 
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "atlassian" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "atlassian" }
unless {
["searchJiraIssuesUsingJql", "getJiraIssue", "createJiraIssue", "getConfluenceContent"]
.contains(resource.tool_name)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Call

agent helpdesk-copilot · scheduled
atlassian/createJiraIssue(cloudId: "7f6c3e2a-1d4b-4c8e-9a0f-2b5d8e1c4a9f")
  1. Agenthelpdesk-copilot is registered and active
  2. KeyBearer key from the Copilot Studio connection is valid
  3. RulecreateJiraIssue is on the list
DecisionAllowed

Agent workflow

Bringing it together

Connecting Microsoft Copilot Studio to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Agent

Runtime

Microsoft Copilot Studio

This page

Client

Claude Code

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Can Copilot Studio connect to a remote MCP server?

Yes. Its MCP onboarding wizard takes a server URL over Streamable HTTP, with no authentication, an API key, or OAuth 2.0.

What goes in the API key field for a Dome Gateway?

Bearer, a space, then the Dome agent key, with Authorization as the header name. A request without it gets a 401.

Does Dome see which employee asked?

No. With an API key, Dome sees the Copilot Studio agent, so audit names the agent.

Do Copilot Studio's model calls go through Dome?

No. Dome governs the tool calls the agent makes through the Gateway.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.