Dome Systems

Integrations

Connect supported audit destinations and configure organization single sign-on

Connect supported audit destinations and configure organization single sign-on. Keep provider credentials in Dome's secret store instead of agent code or shell history.

Supported integrations

The workspace integration catalog currently supports four provider-backed destinations:

IntegrationUse it forDelivery
DatadogExport audit records and stream new audit evidenceBatch export and continuous streaming
Grafana LokiStream new audit evidence to Grafana Cloud Logs or LokiContinuous streaming
Amazon S3Export retained audit records to object storageBatch export
Google Cloud StorageExport retained audit records to object storageBatch export

The catalog can show entries that are unavailable in your deployment. Use this list as the implementation-backed support matrix.

Configure an integration

  1. Open Manage → Integrations in the dashboard.
  2. Select a provider card.
  3. Enter the provider configuration and credential.
  4. Select Connect.

Dome stores the configuration in its secret store. The dashboard does not return saved credential values.

Use Export data to create batch exports. Enable or manage continuous Datadog and Grafana Loki streams from the connected integration's Streaming tab.

Permissions and limits

PermissionGrants
integrations.viewView the catalog and connected instances
integrations.manageConnect, edit, and disconnect workspace integrations

Your plan limits integration instances per workspace. Reaching that limit prevents new connections but preserves access to connected instances.

Identity providers

Enterprise SSO connects the identity provider your organization already uses to the Dome Dashboard and CLI. Configure a guided connection for common providers or bring your own SAML or OIDC configuration.

CapabilitySupport
Guided provider setupCommon identity providers, including Okta, Microsoft Entra ID, Google, ADP, Auth0, CAS, ClassLink, and Cloudflare
Custom SAMLAny compatible SAML 2.0 identity provider
Custom OIDCAny compatible OpenID Connect identity provider

Use the provider picker to search the available guided configurations. Select Custom SAML or Custom OIDC when your provider is not listed.

Single sign-on is organization-scoped: one configured connection applies to every tenant and workspace in that organization. Platform API keys remain available for CI and other non-interactive automation.

Configure single sign-on

Configure the connection through Settings → Single Sign-On in the dashboard.

  • Requires organization config.manage.
  • Requires an organization plan with enterprise SSO enabled.
  • Opens a guided administrator setup flow for the corporate connection.
  • Requires a verified organization domain before you can require SSO for that domain.
  • Requires an active SSO connection before you can enforce the requirement.

Disabling required SSO remains available if the plan or provider changes. This keeps an organization from being locked behind an unavailable connection.

Keep identity paths separate

PathPurpose
Enterprise SSOSign platform users into the Dome Dashboard and CLI
Delegated Act-AsCarry an end user beside an agent credential
Interactive OAuthLet a human MCP client use one designated agent through a Gateway

Agent identities and Act-As verification are separate from platform SSO. Configure OIDC or HMAC verification under Callers.

Agent-facing integrations use their own connection surfaces:

On this page

Was this page helpful?