Dome Systems

CrewAI agents and Dome

Keep your crew. Govern every call it makes.

A crew is several agents, and Dome can tell them apart. Give each one an LLM pointed at the Broker, the Gateway as its MCP server, and its own Dome key. Roles, tasks and process stay as written, and rules decide each member's calls.

PeopleAgentsDomeTools & modelsCallersPeopleAgentsresearcherAgentsanalystAgentswriterGatewaysprod-gatewaySalesforceMCP serverSnowflakeMCP serverclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
researcher→salesforce/query· as m.ferreiraAllowed

How Dome helps

Dome provides governance for every CrewAI tool and model call

Roles and tasks stay as they are

Agents, tasks and process are unchanged. Each agent's LLM and MCP server change.

A key per agent

Give each crew member its own Dome key and rules can tell them apart. The researcher can read what the writer cannot.

Who in the crew did it

Audit records each LLM and tool call against the crew member that made it, and the person it acted for.

Get started

CrewAI on Dome in two changes

Per agent: a crewai.LLM on the Broker and an MCPServerHTTP on the Gateway. The crew definition is untouched.

  1. 01

    Install CrewAI

    CrewAI includes its MCP client. Python 3.10 to 3.13.

    $ pip install crewai
  2. 02

    Load tools from the Gateway

    Each agent's mcps list takes the Gateway, and sees the tools that agent's key is granted.

    from crewai.mcp import MCPServerHTTP
     
    dome = MCPServerHTTP(
    url=f"{GATEWAY_URL}/mcp",
    headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},
    )
  3. 03

    Call models through the Broker

    An OpenAI-compatible LLM with the Gateway as its base URL. The model name is a pool.

    from crewai import LLM
     
    llm = LLM(
    model="openai/claude-opus-5-5",
    base_url=f"{GATEWAY_URL}/v1",
    api_key=DOME_AGENT_KEY,
    )

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about CrewAI itself, see CrewAI's documentation.

Example agents

One agent, end to end

A one-agent crew: the LLM points at the Broker and MCPServerHTTP points at the Gateway. Add crew members and each gets its own Dome key.

researcher

Answer questions about the code

The crew's one task is the question. kickoff() runs it through the GitHub tools, each call decided at the Gateway, each model call routed by the Broker.

from crewai import LLM, Agent, Crew, Task
from crewai.mcp import MCPServerHTTP
 
# Model: a pool on the Broker, through the OpenAI-compatible endpoint
llm = LLM(
model="openai/claude-opus-5-5",
base_url=f"{GATEWAY_URL}/v1",
api_key=DOME_AGENT_KEY,
)
 
# Tools: whatever this agent is granted on the Gateway
dome = MCPServerHTTP(
url=f"{GATEWAY_URL}/mcp",
headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},
)
 
researcher = Agent(
role="researcher",
goal="Answer questions about the code",
backstory="Searches repositories before answering.",
llm=llm,
mcps=[dome],
)
 
task = Task(
description="Where is rate limiting handled?",
expected_output="The files and functions that handle rate limiting.",
agent=researcher,
)
 
result = Crew(agents=[researcher], tasks=[task]).kickoff()
print(result.raw)

Agent workflow

Bringing it together

Connecting CrewAI crews to tools, models, and identity in Dome completes a governed agent application.

Dome

Agent

Runtime

CrewAI

This page

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How do I use a custom LLM base URL in CrewAI?

Pass base_url and api_key to crewai.LLM, with the model as openai/ plus the pool name. Dome's /v1 endpoint is OpenAI-compatible.

How do I connect CrewAI to a remote MCP server?

Give the agent an MCPServerHTTP in its mcps list, with the Gateway's /mcp URL and the Dome key as a bearer token.

Can each agent in a crew have different permissions?

Yes. Register each agent in Dome with its own key, and rules decide per agent.

Do rules run inside the crew?

No. They run at the Gateway, on every LLM and tool call. A refused call comes back as a 403 with the reason.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.