Dome Systems

Vertex AI Agent Engine and Dome

Deploy on Google Cloud. Govern every call the agent makes.

Agent Engine, now Agent Runtime in Gemini Enterprise Agent Platform, hosts agent code you write. Give the agent a Dome key and point its tools and model at the Gateway. Dome decides every call and records it against the agent.

Support teamAgentsDomeTools & modelsCallersSupport teamAgentssupport-triagerAgentsticket-summarizerAgentskb-writerGatewaysprod-gatewayLinearMCP serverInternal toolsMCP serversclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
support-triager→claude-opus-5-5· scheduledAllowed

How Dome helps

Dome provides governance for every Vertex AI Agent Engine tool and model call

Your code, your endpoints

Agent Runtime runs the agent you deploy, in ADK, LangGraph or your own code. Its tools and model point at the Gateway.

The key in Secret Manager

The Dome key reaches the agent as an environment variable from Secret Manager. It is the only credential the agent holds.

Every call on the record

Tool and model calls land in one audit trail, against the agent. The same rules apply wherever else the agent runs.

Get started

Agent Engine on Dome in three steps

Register the agent in Dome, pass its key from Secret Manager, and point its tools and model at the Gateway. The Dome commands were run against a workspace; the Google Cloud side comes from Google's docs.

  1. 01

    Register an agent and issue its key

    Then store the key in Secret Manager.

    $ dome agents register --name support-triager --gateway prod-gateway
    $ dome agents create-key support-triager --name agent-runtime
    $ dome rules apply support-triager.cedar --agent support-triager --name linear-support-only
  2. 02

    Pass the key at deploy

    Agent Runtime's env_vars can reference a Secret Manager secret. The agent reads it from the environment.

    env_vars = {
    "GATEWAY_URL": "https://<gateway-host>/gateways/<gateway-id>",
    "DOME_AGENT_KEY": {"secret": "dome-support-triager", "version": "1"},
    }
  3. 03

    Point tools and model at the Gateway

    In ADK, an MCP toolset for tools and LiteLLM for the model. The model name is a pool.

    import os
    from google.adk.models.lite_llm import LiteLlm
    from google.adk.tools.mcp_tool import McpToolset, StreamableHTTPConnectionParams
     
    GATEWAY_URL, DOME_AGENT_KEY = os.environ["GATEWAY_URL"], os.environ["DOME_AGENT_KEY"]
     
    tools = McpToolset(connection_params=StreamableHTTPConnectionParams(
    url=f"{GATEWAY_URL}/mcp",
    headers={"Authorization": f"Bearer {DOME_AGENT_KEY}"},
    ))
    model = LiteLlm(model="openai/claude-opus-5-5", api_base=f"{GATEWAY_URL}/v1", api_key=DOME_AGENT_KEY)

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Vertex AI Agent Engine itself, see Google Cloud's documentation.

Rules

File issues for Support only

The permit lets the agent discover tools and call Linear. The forbid refuses any save_issue that doesn't name the Support team.

permit (principal, action == Dome::Action::"mcp:discover", resource);
 
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "linear" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "linear" &&
resource.tool_name == "save_issue" &&
!(resource has arguments && resource.arguments has team &&
resource.arguments.team == "Support")
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Team

agent support-triager · scheduled
linear/save_issue(team: "Support", title: "SSO login loops for Okta users")
  1. Agentsupport-triager is registered and active
  2. KeyBearer key from Secret Manager is valid
  3. RuleIssues for Support are allowed
DecisionAllowed

Agent workflow

Bringing it together

Connecting agents on Vertex AI Agent Engine to registered tools, models, and identity in Dome completes a governed agent application.

Dome

Agent

Runtime

Vertex AI Agent Engine

This page

Runtime

Google ADK

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

Is Vertex AI Agent Engine now Agent Runtime?

Yes. Google renamed it Agent Runtime in April 2026, as part of Gemini Enterprise Agent Platform.

Which frameworks work with Dome on Agent Runtime?

Any that can load MCP tools over HTTP with a header and call an OpenAI- or Anthropic-compatible endpoint. ADK, LangGraph and LangChain all can.

Where should the Dome key live?

In Secret Manager, passed to the agent through env_vars at deploy. Revoke it in Dome and the deployed agent's calls stop.

Can the agent still use Gemini?

Yes. Add Gemini to a pool and name the pool as the model, and Gemini calls go through the Broker.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.