Manage
Configure platform defaults, access, environments, integrations, data exports, and billing
Manage administers the Dome platform: workspace defaults, who can administer Dome, tenants and workspaces, enterprise identity and secrets, and audit export.
If you are standing up a new boundary, start with Environments. The other pages assume a workspace already exists.
What you administer
Environments
Create tenants and workspaces, select a CLI context, or provision a disposable sandbox.
Settings
Set workspace defaults such as audit retention, policy refresh, and rule-bundle history.
Access
Assign workspace roles and scoped platform API keys for people and automation.
Integrations
Connect SSO for platform users and store secrets Dome injects at egress.
Export
Send retained audit records to your SIEM or object store, in batches or via continuous streaming.
Billing
Review plan status, usage, seats, and invoices.
These grants and settings are platform administration only. They do not authorize agent tool or model calls, attach agent-facing resources, or replace investigation under Operate. See Scopes for tenancy boundaries and Permissions for platform RBAC versus runtime agent authorization.
Typical workflow
- Prepare environments to create tenants and workspaces, select a CLI context, or provision a sandbox.
- Configure platform to set workspace defaults and review configuration changes in audit.
- Manage access to assign workspace members and create or revoke scoped platform API keys.
- Integrate systems to configure single sign-on and store integration secrets.
- Export data to choose a format, configure a destination, schedule runs, and monitor forwarder health.
- Review billing for plan status, usage, and invoices.