Dome Systems
Agent governance platform that registers every agent, routes its tool and model calls through a governed gateway and model broker, authorizes each call against Cedar rules before it runs, and records an immutable audit event for every action.
Dome Systems sells a governance platform for AI agents, generally available and self serve. Every agent gets a registry record with an owner, a lifecycle and a credential. Its tool calls go through a Tool Gateway and its model calls through a Model Broker, so the agent never holds the upstream credentials. Each call is authorized against Cedar rules before it runs, fail closed and forbid wins, with rules scoped to the organization, tenant, workspace or agent, simulated against replayed traffic and shipped as versioned code. Guards inspect and redact content on tool and model connections, and quotas cap spend, tokens or calls.
The Model Broker lets the customer connect providers with its own keys and pool them for failover and cost routing. Every governed action lands as an immutable audit event with the agent, caller chain, target, arguments, policy version and outcome, queryable from the UI, CLI, API and MCP server and exportable to a SIEM. Admins control the platform through built in and custom roles and scoped API keys, and the end user an agent acts for is verified instead of trusted. Dome is driven through Go and Python SDKs, a CLI, a REST API and an MCP server.
Dome fits platform and security teams that want one place to register, authorize and audit agents built by different teams on different runtimes. It is a governance layer, not an agent builder or host. It does not run workflows, ground agents in knowledge, give them memory or start them, and it runs as a hosted service with no self hosted option. Pricing is published, from a free tier to Pro and Team plans billed by usage.
Vendor details
Canonical URL
https://www.domesystems.ai/
Category
Agent infrastructure
Subcategory
Agent governance control plane
Funding status
Independent. Founded in 2024 and backed by Redpoint Ventures, Bessemer Venture Partners and Mango Capital, per its own site.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Admins attach MCP servers, REST APIs and internal services to the Tool Gateway with their upstream authentication, and model providers (Anthropic, OpenAI, Bedrock or self hosted) to the Model Broker. End user identity is verified through OIDC or HMAC providers, audit exports to SIEMs as OCSF, CEF or CSV, and signed webhooks deliver events to other systems. Cursor, Claude Code and Codex can sign in and call tools through a Gateway.
In practice
Teams across the company are shipping agents on different runtimes and nobody can list them. Each agent registers with Dome, gets an owner and a credential, and shows up in one registry.
A support agent should read tickets but never delete them. A Cedar rule scoped to that agent allows the read tool and forbids the delete, and Dome denies the call before it reaches the ticketing system.
Finance wants model spend under control. The Model Broker routes calls across provider pools on cost and policy, and quotas cap tokens per agent.
Sources & related URLs
Agentic Index coverage score
6.5 / 14 capabilities · 46%
| Integrations & Tool Calling | Full |
|---|---|
|
The Tool Gateway is how agents act on outside systems. Admins attach MCP servers, REST APIs and internal services with their upstream authentication, OAuth included, and tools appear in a catalog for each agent, filtered by policy. Each call goes out through Dome with the credential injected at egress, so the agent never holds it, and customers can add tools of their own. SourceDome Systems, domesystems.ai llms.txt (platform/gateway) and docs.domesystems.ai llms.txt (connect/resources/tools)read 2026-09-25 |
|
| Workflow Orchestration | Not documented |
|
The agent's own code owns the loop of model and tool calls, its steps and any handoffs. Dome sits at the call boundary and governs those calls without running the work. The agent lifecycle, from provisioned and active to suspended and revoked, is a state kept in the registry, and Dome has no workflow model. SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txt (concepts/agents/agent-lifecycle)read 2026-09-25 |
|
| Knowledge Grounding & RAG | Not documented |
|
Tool and model calls are governed, but none of the customer's documents are indexed for an agent to ground its answers on. Guards inspect content as it passes through and do not retrieve anything from the customer's corpus. SourceDome Systems, domesystems.ai llms.txtread 2026-09-25 |
|
| Human Oversight & Guardrails | Full |
|
Every tool and model call is checked against Cedar rules at the call boundary before it executes, failing closed with forbid winning by default. Rules can be scoped from the organization and tenant down to a workspace or a single agent, and they ship as versioned code. Guards inspect, redact and constrain content on tool and model connections, and quotas cap spend, tokens or calls. These controls stop an action outright. Decisions are made by policy, and Dome names no step where a person approves an action. SourceDome Systems, domesystems.ai llms.txt (platform/authorization) and docs.domesystems.ai llms.txt (govern/guards, reference/mcp/quotas)read 2026-09-25 |
|
| Security, Identity & Governance | Full |
|
Platform RBAC has built in and custom roles across organization, tenant and workspace scopes, with scoped platform API keys, all kept separate from runtime agent authorization. Every agent authenticates with the credential issued at registration. The end user an agent acts for is verified per agent through OIDC or HMAC instead of being trusted, so both identities reach each Cedar authorization decision and the audit record. Tools and models are reachable only through Gateways an admin grants, with upstream credentials injected at egress, so tool access is held to what is needed. Dome names no attestation. For security measures the DPA points to trust.domesystems.ai, a Vanta trust center. SourceDome Systems, docs.domesystems.ai llms.txt (manage/access, reference/permissions, concepts/platform/permissions, connect/agents/delegated) and domesystems.ai llms.txt (platform/access, dpa), plus trust.domesystems.airead 2026-09-25 |
|
| Observability & Auditability | Full |
|
Every governed action emits an immutable audit event recording the agent, the caller chain and the tool or model, along with arguments, policy version and outcome, in one vocabulary across tool and model calls. Events can be queried from the UI and CLI or through the API and MCP server, exported as OCSF, CEF or CSV, and streamed continuously to a SIEM or exported in scheduled batches. SourceDome Systems, domesystems.ai llms.txt (platform/audit) and docs.domesystems.ai llms.txt (manage/export, reference/events/catalog)read 2026-09-25 |
|
| Memory & State Persistence | Not documented |
|
The registry, rules, quotas and audit events are records about agents. The platform and people apply or read them, and the agent never reads them as context to decide. Model Broker pools can cache responses to save cost and latency. Dome names no memory layer. SourceDome Systems, domesystems.ai llms.txt (platform/registry, platform/broker)read 2026-09-25 |
|
| Deployment & Data Residency | Not documented |
|
Four hosted tiers are sold. No hosting region is published, and no tier runs Dome itself in a VPC, in the customer's own environment or self hosted. Tenants are isolated logical environments inside an organization. The governed agents can run on any cloud or runtime, but Dome itself runs as a hosted service. SourceDome Systems, domesystems.ai/pricing and llms.txt, and docs.domesystems.ai llms.txtread 2026-09-25 |
|
| Prebuilt Agents / Templates / Packs | Not documented |
|
No ready made agents, workflows or templates ship. Tutorials and field guides walk a customer through building and deploying its own agents. Rules, guards and gateways are objects the customer writes. SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txt (tutorials)read 2026-09-25 |
|
| Triggers & Channel Coverage | Not documented |
|
The customer's own scheduler, queue or event bus supplies the work, and Dome does not start agents. In Dome's event driven deployment example, an EventBridge schedule fires a Lambda, and retries and concurrency belong to that trigger. Dome governs the tool call the handler then makes. Signed webhooks send Dome's own audit events outward and wake no agent. SourceDome Systems, docs.domesystems.ai/tutorials/production/deploy-your-agent/event-driven and llms.txt (operate/webhooks)read 2026-09-25 |
|
| Model Flexibility & Routing | Full |
|
The Model Broker puts model choice with the customer. Admins connect providers such as Anthropic, OpenAI and Bedrock, or self hosted models, with their own credentials behind an API compatible with OpenAI and Anthropic. They compose them into pools with routing strategies, failover and caching, and set model choice as routing policy for each call. SourceDome Systems, domesystems.ai llms.txt (platform/broker, llm-router field guide) and docs.domesystems.ai llms.txt (reference/mcp/models and pools)read 2026-09-25 |
|
| APIs / SDKs / MCP Extensibility | Full |
|
Go and Python SDKs, a CLI and a REST API with a published reference drive the platform, with rules simulation at POST /v1/rules/simulate among the endpoints. An MCP server exposes Dome itself, with tools that register agents and attach tools and models, write rules, guards and quotas, and query audit. SourceDome Systems, docs.domesystems.ai llms.txt (reference/surfaces/api, sdk, mcp and the MCP server reference) and domesystems.ai llms.txt (platform/operator)read 2026-09-25 |
|
| Testing, Debugging & Optimization | Partial |
|
Authorization rules can be simulated against real replayed traffic and synthetic scenarios before they reach production, through the UI, CLI and API, and rules ship versioned through CI/CD. Simulation gates rule changes in the release path and shows how a new rule would decide the agent's calls. Dome names nothing that scores or tests the agent's own output. SourceDome Systems, docs.domesystems.ai llms.txt (govern/rules/simulate, cli/secure/rules, api simulate) and domesystems.ai llms.txtread 2026-09-25 |
|
| Browser / Computer-use | Not documented |
|
Dome governs agents' tool and model calls and does not operate a browser or a computer. SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txtread 2026-09-25 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free (~5,000 actions/mo) · Pro $29/workspace · Team $299/mo · plus $1.43–$1.72 per 1,000 governed actions
platform fee per workspace or per month, plus governed actions (per 1,000) and tokens observed (per million)
What is public
All four tiers, meter rates, per-tier limits (agents, tools, gateways, models, pools, quotas, webhooks, users) and billing rules are public; Enterprise is quoted.
Billing mechanics
A platform fee (Pro per workspace, Team per month) covers access; usage is billed on two meters, governed actions per 1,000 (one agent's attempt to use one tool or model) and tokens per million. Completed and policy-denied calls count; calls that fail before governance do not, and registration and simulation are free.
Cost watchouts
Governed actions that policy denies are still billed, and tokens passing through the Model Broker are metered on top of the platform fee.
Variable cost rationale
As a control plane governing every agent and tool call, cost likely scales with the size of the agent estate and call volume, though no metered axis is published.
Additional watchouts
Denied calls count as governed actions, so a noisy agent hitting its rules still costs money.
Overage / add-ons
Free stops at its allowance; paid tiers bill governed actions and tokens as consumed
Sales call required
Mixed (some tiers require a call)
Free / trial
Free tier with roughly 5,000 governed actions a month and a hard stop instead of a bill; no card needed
Lowest paid plan
Pro, $29 per workspace, plus usage
Key ambiguities
What the Pro workspace fee covers per month, and Enterprise commit terms.
Missing data
Enterprise pricing.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents, with one key to 110+…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Dome Systems
The closest documented capability profiles to Dome Systems among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Arcade7.5 / 14Adds documented Deployment & Data Residency
- Clawvisor6.5 / 14Adds documented Deployment & Data ResidencyDome Systems vs Clawvisor →
- Nevermined4.5 / 14A lighter documented profile than Dome Systems
- Portkey7.5 / 14Adds documented Deployment & Data Residency
- Skyfire4.5 / 14A lighter documented profile than Dome Systems
- Helicone8.0 / 14Adds documented Deployment & Data Residency and Triggers & Channel Coverage
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded