Why AgenticDome

When AI stops advising and starts acting, security needs a new decision point.

AgenticDome adds independent action governance at supported runtime boundaries. It helps organizations decide whether this authenticated actor, through this agent, should perform this exact action now.

The action-authority gap

Authentication proves access authority. It does not prove business appropriateness.

An agent can use a valid identity, an approved tool and a schema-valid request while acting on poisoned context, excessive delegation or a misunderstood objective. The final action still needs a decision in the context of the current user, agent, purpose and business policy.

01

Identity remains authoritative

Keep the identity provider responsible for principals, credentials, scopes, conditional access and downstream entitlements.

02

Agents introduce interpretation

Planning, retrieval, memory, tool selection and delegation create decisions after access was originally granted.

03

Action policy closes the gap

Evaluate the final protected action while the application can still block, redirect or safely handle it.

A complementary control model

One security architecture. Distinct responsibilities.

AgenticDome is designed to complement native controls, not compete with everything around them.

Identity and access

Who or what is authenticated, and what may it reach?

AgenticDome receives trusted identity context; it does not replace the identity provider.

Platform governance

Which environments, tools, connectors and data sources are available?

AgenticDome uses supported platform extension points where an independent decision is available.

Framework and protocol

Is the request well formed, routable and compatible?

AgenticDome attaches at documented execution boundaries; it does not replace OAuth, MCP security or secure servers.

Action governance

Should this protected actor and agent perform this exact action now?

This is AgenticDome's specialised control point: pre-execution policy and structured outcomes.

From builder to governed estate

Framework freedom for teams. Consistent action authority for the organisation.

A developer may begin with one Python agent. A SaaS provider needs tenant separation. An enterprise may operate Microsoft, MCP, cloud and custom agents at the same time. AgenticDome keeps the action-policy meaning consistent across supported paths.

Developers

Start with a public package and a network-free demonstration, then verify the real application boundary.

SaaS providers

Separate tenant policy from product logic and govern protected actions across customer workloads.

Enterprise teams

Apply a common action vocabulary across supported frameworks, platforms and business systems.

Sovereign operators

Align the contracted enforcement runtime with an approved customer-controlled deployment boundary.

Supported ecosystem paths

Use the native or application-controlled boundary appropriate to each stack.

Configure the tenant's action policy centrally. Then attach each application or runtime once at its main supported execution boundary—rather than rebuilding security logic inside every agent, tool or workflow.

SDKs, plugins and custom stacks

Choose the package that matches the runtime. The policy and decision model remain central; the attachment point changes with the framework.

  • Python: CrewAI, LangGraph/LangChain, PydanticAI, Agno, OpenAI Agents, Claude Agent SDK, smolagents, AutoGen, Google ADK, LlamaIndex and custom Python.
  • TypeScript: agenticdome-sdk for Node.js services and application-controlled MCP, A2A and custom dispatchers.
  • OpenClaw: the separate agenticdome-openclaw-security plugin attaches native prompt, pre-tool and transcript-persistence hooks.
  • Microsoft cloud: selectable wrapper patterns for Microsoft Agent Framework and AI Foundry run, workflow and tool boundaries.
  • AWS: Bedrock wrappers for runtime calls, agent invocation and application-controlled action-group handling.

Microsoft Copilot Studio

For eligible generative-orchestration agents, Microsoft's external threat-detection path can request an allow-or-block decision before proposed tool execution.

Explore the Microsoft path
  • Uses Microsoft's documented external-provider contract
  • Complements Microsoft-native prompt and platform protections
  • Configured per intended Power Platform environment
  • Currently a Microsoft preview and skipped for classic agents
Deployment choice

Control the boundary as the organisation's requirements mature.

Runtime placement is an explicit commercial and architecture decision. It is not inferred from source code or implied by the word “sovereign”.

01

Managed regional

A tenant is assigned a managed runtime in an available supported geographic region.

02

Dedicated

A dedicated runtime supports customer-specific isolation, capacity and availability requirements under contract.

03

Customer-controlled

A contracted runtime can be placed within an approved customer VPC, cloud or on-premises boundary with agreed responsibilities.

Set policy centrally. Attach the runtime once. Govern continuously.

AgenticDome is designed as a reusable action decision point. After a supported runtime is onboarded at its main execution boundary, interactions that pass through that attachment are intercepted and evaluated automatically—without adding policy logic to every individual tool call.

01 · Configure

Define tenant policy once

Establish identities, governed actions, delegation constraints, outcomes, and failure behavior centrally.

02 · Attach

Instrument the main boundary

Enable the native plugin, provider, SDK wrapper or gateway where the runtime actually dispatches work.

03 · Intercept

Evaluate routed interactions

The attachment sends supported prompts, tool proposals or action context for a decision before impact.

04 · Enforce

Apply one decision model

Allow, block or safely handle the action and retain structured evidence across supported stacks.

OpenClawInstall and enable the native plugin once for the intended workspace/runtime; its supported prompt, pre-tool and transcript hooks become the interception points.
Microsoft Copilot StudioConfigure AgenticDome as the external threat-detection provider in each intended Power Platform environment; eligible generative-orchestration tool calls are evaluated through Microsoft's provider path.
AI Foundry, Agent Framework and Python frameworksPlace the appropriate wrapper or callback at the application's run, workflow or tool assembly boundary so protected work uses the same central decision service.
AWS Bedrock, TypeScript, MCP and custom servicesWrap the runtime invocation, action-group handler, actual dispatcher or gateway that holds authority to create the side effect.
Public evidence, not market theatre

The case for runtime governance is independently visible.

These sources support the market need. They are not presented as customer claims, certifications or proof that AgenticDome alone satisfies a framework.

Microsoft adoption and extension point

Microsoft reported broad Copilot Studio adoption and separately documents external evaluation before eligible tool invocations.

OWASP agentic risks

OWASP's 2026 framework covers goal hijacking, tool misuse, privilege abuse, unsafe inter-agent communication and related risks.

ASD-led joint guidance

The guidance recommends least privilege, runtime authentication, controlled delegation, monitoring and human approval for high-impact actions.

Trust through precision

What AgenticDome does—and what it does not claim.

Automatic after attachment—not universal before it

Central onboarding avoids per-interaction integration work, but coverage applies to interactions routed through the attached SDK, plugin, provider, wrapper, or gateway. An alternate raw or uninstrumented execution path can bypass application-layer enforcement. Teams should attach each real authority-bearing path once, remove or constrain bypass routes, and verify allowed, blocked, timeout, and failure behavior.

Defence-in-depth boundary

AgenticDome complements IAM, platform controls, OAuth and MCP protocol security, secure tool implementation, sandboxing, workload isolation, egress control, secrets management, model evaluation, monitoring, incident response and accountable human oversight. It does not replace them or make an organisation compliant by itself.

Secure the first action. Then scale the policy.

Start with one protected tool call and one demonstrable decision. Expand when the integration and operating boundary are proven.