Dome Systems

Govern

Authorize actions, filter content, and set usage limits for governed agent traffic

Govern applies the controls that decide what agents can do, what content may pass, and how much spend is allowed. You authorize with Rules, inspect traffic with Guards, and cap model spend with Quotas.

The three controls

At runtime, Dome evaluates applicable Quotas, then Rules, then Guards on the content path. Each control fails closed: exhausted limits, unavailable authorization, and blocking Guards stop the request or response. Exhausted total caps reject the call, while exhausted model budgets can spill to another pool member.

See Architecture for where these controls sit in the request path.

Typical workflow

  1. Authorize access by writing, validating, simulating, and applying Cedar Rules.
  2. Create Guards and assign Filters to the connections that need inspection.
  3. Set usage limits at the scopes that own the budget.

Afterward you can revise Rules, roll Filters forward or back, and adjust Quotas without rewiring Connect entities.

Next steps

On this page

Was this page helpful?