Dome Systems
Core concepts

Core concepts

How Dome governs agents, resources, and requests

Core concepts explain what each Dome piece is, how the pieces fit together, and when to choose one design over another.

Dome separates components you define (agents, resources, Gateways), controls you apply to traffic (Rules, Guards, Quotas), and audit that records what happened. Agents reach tools and models through a Gateway while Dome holds the upstream credentials. On each call, the controls decide what is allowed, what content may pass, and how much spend is left.

If you have not picked a role yet, start with Personas or What is Dome?.

Read in dependency order

From the system map down to the evidence trail:

  1. Architecture covers components, controls, audit, and the request path.
  2. Scopes explains organization → tenant → workspace isolation.
  3. Identity Patterns compares standing vs delegated identity.
  4. Agents, Resources, and Gateways are the components you define.
  5. Rules, Guards, and Quotas are the controls that govern traffic.
  6. Audit events is the evidence trail across both planes.

Architecture

The system map and request path.

Identity

Choose how an agent presents itself before you wire credentials.

Components

Things you define so a workload can reach tools and models.

Controls

Things you apply after a call is admitted.

Platform and audit

Tenancy boundaries, who may administer Dome, and the evidence left behind.

Next steps

On this page

Was this page helpful?