Back to vendors
D

Dome Systems

Visit site
Entry priceFree (~5,000 actions/mo) · Pro $29/workspace · Team $299/mo · plus $1.43–$1.72 per 1,000 governed actionsFull pricing detail

Agent governance platform that registers every agent, routes its tool and model calls through a governed gateway and model broker, authorizes each call against Cedar rules before it runs, and records an immutable audit event for every action.

Dome Systems sells a governance platform for AI agents, generally available and self serve. Every agent gets a registry record with an owner, a lifecycle and a credential. Its tool calls go through a Tool Gateway and its model calls through a Model Broker, so the agent never holds the upstream credentials. Each call is authorized against Cedar rules before it runs, fail closed and forbid wins, with rules scoped to the organization, tenant, workspace or agent, simulated against replayed traffic and shipped as versioned code. Guards inspect and redact content on tool and model connections, and quotas cap spend, tokens or calls.

The Model Broker lets the customer connect providers with its own keys and pool them for failover and cost routing. Every governed action lands as an immutable audit event with the agent, caller chain, target, arguments, policy version and outcome, queryable from the UI, CLI, API and MCP server and exportable to a SIEM. Admins control the platform through built in and custom roles and scoped API keys, and the end user an agent acts for is verified instead of trusted. Dome is driven through Go and Python SDKs, a CLI, a REST API and an MCP server.

Dome fits platform and security teams that want one place to register, authorize and audit agents built by different teams on different runtimes. It is a governance layer, not an agent builder or host. It does not run workflows, ground agents in knowledge, give them memory or start them, and it runs as a hosted service with no self hosted option. Pricing is published, from a free tier to Pro and Team plans billed by usage.

Vendor details

Canonical URL

https://www.domesystems.ai/

Category

Agent infrastructure

Subcategory

Agent governance control plane

Funding status

Independent. Founded in 2024 and backed by Redpoint Ventures, Bessemer Venture Partners and Mango Capital, per its own site.

Company status

independent

Use cases & customers

Primary use cases

Agent governance and access controlTool call policy enforcementAgent identity and credential managementAgent audit and observabilityEnterprise agent estate operations

Target customers

Enterprises building internal AI platformsPlatform and security teamsRegulated enterprises deploying agents

Deployment options

Cloud

Integrations

Admins attach MCP servers, REST APIs and internal services to the Tool Gateway with their upstream authentication, and model providers (Anthropic, OpenAI, Bedrock or self hosted) to the Model Broker. End user identity is verified through OIDC or HMAC providers, audit exports to SIEMs as OCSF, CEF or CSV, and signed webhooks deliver events to other systems. Cursor, Claude Code and Codex can sign in and call tools through a Gateway.

In practice

Teams across the company are shipping agents on different runtimes and nobody can list them. Each agent registers with Dome, gets an owner and a credential, and shows up in one registry.

A support agent should read tickets but never delete them. A Cedar rule scoped to that agent allows the read tool and forbids the delete, and Dome denies the call before it reaches the ticketing system.

Finance wants model spend under control. The Model Broker routes calls across provider pools on cost and policy, and quotas cap tokens per agent.

Agentic Index coverage score

6.5 / 14 capabilities · 46%

Integrations & Tool Calling Full

The Tool Gateway is how agents act on outside systems. Admins attach MCP servers, REST APIs and internal services with their upstream authentication, OAuth included, and tools appear in a catalog for each agent, filtered by policy. Each call goes out through Dome with the credential injected at egress, so the agent never holds it, and customers can add tools of their own.

SourceDome Systems, domesystems.ai llms.txt (platform/gateway) and docs.domesystems.ai llms.txt (connect/resources/tools)read 2026-09-25

Workflow Orchestration Not documented

The agent's own code owns the loop of model and tool calls, its steps and any handoffs. Dome sits at the call boundary and governs those calls without running the work. The agent lifecycle, from provisioned and active to suspended and revoked, is a state kept in the registry, and Dome has no workflow model.

SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txt (concepts/agents/agent-lifecycle)read 2026-09-25

Knowledge Grounding & RAG Not documented

Tool and model calls are governed, but none of the customer's documents are indexed for an agent to ground its answers on. Guards inspect content as it passes through and do not retrieve anything from the customer's corpus.

SourceDome Systems, domesystems.ai llms.txtread 2026-09-25

Human Oversight & Guardrails Full

Every tool and model call is checked against Cedar rules at the call boundary before it executes, failing closed with forbid winning by default. Rules can be scoped from the organization and tenant down to a workspace or a single agent, and they ship as versioned code. Guards inspect, redact and constrain content on tool and model connections, and quotas cap spend, tokens or calls. These controls stop an action outright. Decisions are made by policy, and Dome names no step where a person approves an action.

SourceDome Systems, domesystems.ai llms.txt (platform/authorization) and docs.domesystems.ai llms.txt (govern/guards, reference/mcp/quotas)read 2026-09-25

Security, Identity & Governance Full

Platform RBAC has built in and custom roles across organization, tenant and workspace scopes, with scoped platform API keys, all kept separate from runtime agent authorization. Every agent authenticates with the credential issued at registration. The end user an agent acts for is verified per agent through OIDC or HMAC instead of being trusted, so both identities reach each Cedar authorization decision and the audit record. Tools and models are reachable only through Gateways an admin grants, with upstream credentials injected at egress, so tool access is held to what is needed.

Dome names no attestation. For security measures the DPA points to trust.domesystems.ai, a Vanta trust center.

SourceDome Systems, docs.domesystems.ai llms.txt (manage/access, reference/permissions, concepts/platform/permissions, connect/agents/delegated) and domesystems.ai llms.txt (platform/access, dpa), plus trust.domesystems.airead 2026-09-25

Observability & Auditability Full

Every governed action emits an immutable audit event recording the agent, the caller chain and the tool or model, along with arguments, policy version and outcome, in one vocabulary across tool and model calls. Events can be queried from the UI and CLI or through the API and MCP server, exported as OCSF, CEF or CSV, and streamed continuously to a SIEM or exported in scheduled batches.

SourceDome Systems, domesystems.ai llms.txt (platform/audit) and docs.domesystems.ai llms.txt (manage/export, reference/events/catalog)read 2026-09-25

Memory & State Persistence Not documented

The registry, rules, quotas and audit events are records about agents. The platform and people apply or read them, and the agent never reads them as context to decide. Model Broker pools can cache responses to save cost and latency. Dome names no memory layer.

SourceDome Systems, domesystems.ai llms.txt (platform/registry, platform/broker)read 2026-09-25

Deployment & Data Residency Not documented

Four hosted tiers are sold. No hosting region is published, and no tier runs Dome itself in a VPC, in the customer's own environment or self hosted. Tenants are isolated logical environments inside an organization. The governed agents can run on any cloud or runtime, but Dome itself runs as a hosted service.

SourceDome Systems, domesystems.ai/pricing and llms.txt, and docs.domesystems.ai llms.txtread 2026-09-25

Prebuilt Agents / Templates / Packs Not documented

No ready made agents, workflows or templates ship. Tutorials and field guides walk a customer through building and deploying its own agents. Rules, guards and gateways are objects the customer writes.

SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txt (tutorials)read 2026-09-25

Triggers & Channel Coverage Not documented

The customer's own scheduler, queue or event bus supplies the work, and Dome does not start agents. In Dome's event driven deployment example, an EventBridge schedule fires a Lambda, and retries and concurrency belong to that trigger. Dome governs the tool call the handler then makes. Signed webhooks send Dome's own audit events outward and wake no agent.

SourceDome Systems, docs.domesystems.ai/tutorials/production/deploy-your-agent/event-driven and llms.txt (operate/webhooks)read 2026-09-25

Model Flexibility & Routing Full

The Model Broker puts model choice with the customer. Admins connect providers such as Anthropic, OpenAI and Bedrock, or self hosted models, with their own credentials behind an API compatible with OpenAI and Anthropic. They compose them into pools with routing strategies, failover and caching, and set model choice as routing policy for each call.

SourceDome Systems, domesystems.ai llms.txt (platform/broker, llm-router field guide) and docs.domesystems.ai llms.txt (reference/mcp/models and pools)read 2026-09-25

APIs / SDKs / MCP Extensibility Full

Go and Python SDKs, a CLI and a REST API with a published reference drive the platform, with rules simulation at POST /v1/rules/simulate among the endpoints. An MCP server exposes Dome itself, with tools that register agents and attach tools and models, write rules, guards and quotas, and query audit.

SourceDome Systems, docs.domesystems.ai llms.txt (reference/surfaces/api, sdk, mcp and the MCP server reference) and domesystems.ai llms.txt (platform/operator)read 2026-09-25

Testing, Debugging & Optimization Partial

Authorization rules can be simulated against real replayed traffic and synthetic scenarios before they reach production, through the UI, CLI and API, and rules ship versioned through CI/CD. Simulation gates rule changes in the release path and shows how a new rule would decide the agent's calls. Dome names nothing that scores or tests the agent's own output.

SourceDome Systems, docs.domesystems.ai llms.txt (govern/rules/simulate, cli/secure/rules, api simulate) and domesystems.ai llms.txtread 2026-09-25

Browser / Computer-use Not documented

Dome governs agents' tool and model calls and does not operate a browser or a computer.

SourceDome Systems, domesystems.ai llms.txt and docs.domesystems.ai llms.txtread 2026-09-25

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Free (~5,000 actions/mo) · Pro $29/workspace · Team $299/mo · plus $1.43–$1.72 per 1,000 governed actions

platform fee per workspace or per month, plus governed actions (per 1,000) and tokens observed (per million)

Free tier

What is public

All four tiers, meter rates, per-tier limits (agents, tools, gateways, models, pools, quotas, webhooks, users) and billing rules are public; Enterprise is quoted.

Billing mechanics

A platform fee (Pro per workspace, Team per month) covers access; usage is billed on two meters, governed actions per 1,000 (one agent's attempt to use one tool or model) and tokens per million. Completed and policy-denied calls count; calls that fail before governance do not, and registration and simulation are free.

Cost watchouts

Governed actions that policy denies are still billed, and tokens passing through the Model Broker are metered on top of the platform fee.

Variable cost rationale

As a control plane governing every agent and tool call, cost likely scales with the size of the agent estate and call volume, though no metered axis is published.

Additional watchouts

Denied calls count as governed actions, so a noisy agent hitting its rules still costs money.

Overage / add-ons

Free stops at its allowance; paid tiers bill governed actions and tokens as consumed

Sales call required

Mixed (some tiers require a call)

Free / trial

Free tier with roughly 5,000 governed actions a month and a hard stop instead of a bill; no card needed

Lowest paid plan

Pro, $29 per workspace, plus usage

Key ambiguities

What the Pro workspace fee covers per month, and Enterprise commit terms.

Missing data

Enterprise pricing.

Agentic Index verified 2026-09-25

Alternatives to Dome Systems

The closest documented capability profiles to Dome Systems among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Arcade7.5 / 14Adds documented Deployment & Data Residency
  • Clawvisor6.5 / 14Adds documented Deployment & Data ResidencyDome Systems vs Clawvisor →
  • Nevermined4.5 / 14A lighter documented profile than Dome Systems
  • Portkey7.5 / 14Adds documented Deployment & Data Residency
  • Skyfire4.5 / 14A lighter documented profile than Dome Systems
  • Helicone8.0 / 14Adds documented Deployment & Data Residency and Triggers & Channel Coverage

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.