Discover bounded paths
Correlate workloads, agents, tools, runtime and scan evidence while private interception analysis remains outside the public SDK.
Read the discovery model →AgenticDome unifies application decisions, workload intelligence and governed network evidence to distinguish protected execution from suspected bypass, authorize consequential actions before impact and preserve an evidence chain across enterprise, cloud and sovereign AI estates.
Connect rich SDK and platform decisions with eBPF-powered runtime discovery and Envoy authorization evidence. AgenticDome correlates the result into protected execution, suspected bypass and investigation-ready activity.
Runtime enforcement is the beginning. AgenticDome connects discovery, live attachment evidence, exact-action authorization, controlled policy release and outcome verification without putting proprietary analysis or raw sensitive evidence into the public SDK.
Correlate workloads, agents, tools, runtime and scan evidence while private interception analysis remains outside the public SDK.
Read the discovery model →Signed startup manifests and fresh hook heartbeats compare declared and observed protection points and expose exact gaps.
Read about runtime coverage →A short-lived, single-use Action Passport binds actor, purpose, action, destination, delegation, policy version and trust epoch.
Read the protocol →The supported gateway or executor checks expiry, replay, delegation and destination before allowing the business side effect.
See the receiving boundary →Move from an immutable tenant draft through bounded impact projection, deterministic canary and explicit promotion.
Read the release model →Keep SDK-reported, gateway-observed and optional destination-attested outcomes distinct and machine-verifiable.
Read about outcome evidence →AgenticDome connects application, workload and network evidence so teams can discover emerging activity, recognize protected execution, govern consequential actions and respond with confidence.
Combine SDK, platform and eBPF-powered workload evidence to surface agent, process, tool and destination patterns across selected estates.
Apply tenant policy to the actor, purpose, tool, arguments, destination and delegation before business impact.
Distinguish SDK-protected, gateway-verified, suspected-bypass and investigation-ready activity without losing source context.
Review a non-active draft, project impact, canary by stable action chain and promote only with tenant approval.
Use bounded content evidence and tenant labels, plus approval-gated Microsoft knowledge-permission remediation.
Bring runtime findings into security overview, action activity, live operations, topology, analytics and a consistent response workflow.
Use Integration Copilot to identify the right SDK, supported integration boundary and verification steps, then test allowed and blocked paths before production.
Start with the SDK →Apply tenant-scoped action controls around tools, delegation and supported outputs without hard-coding every customer's policy.
Protect a SaaS product →Begin with the workflows that create the most business impact, then expand coverage as agent access and autonomy grow.
Explore business use cases →Give different teams framework freedom while security maintains one meaning for authority, delegation and evidence.
See the enterprise model →Align the contracted runtime enforcement path with an approved customer-controlled VPC, cloud or on-premises boundary.
Explore deployment choices →AgenticDome works at application-controlled boundaries where the protected workflow can still prevent the side effect. It does not require teams to replace their model, framework, identity provider, cloud or business system.
Attach the documented SDK, framework hook, Microsoft integration or controlled gateway at the point that can enforce a decision.
Use trusted context such as the authenticated actor, agent, purpose, target tool, final arguments and delegation.
Apply the returned decision before execution and retain structured outcomes for investigation and governance.
Select a framework to see its documented attachment pattern. Start with the public, network-free Python simulation or inspect the TypeScript and OpenClaw packages. For live enforcement, connect the protected application boundary to the tenant's assigned runtime and test the real allowed, blocked and unavailable paths. A package installation is not presented as proof of coverage: compatible workloads can report signed hook manifests and fresh heartbeats so customers can compare expected and observed protection points.
Python SDK · TypeScript SDK · OpenClaw plugin. They carry bounded public contracts; proprietary interception analysis remains in private AgenticDome services. Use the tabs for one concise attachment example, then continue to developer documentation for compatibility, timeout, failure and release-parity semantics.
# Install the stable Python SDK support for your framework from PyPI.
pip install agenticdome-python-sdk[crewai]
# Zero-account, network-free trial.
agenticdome-demo --framework crewai --scenario refund_hijack
# Production: configure the tenant's assigned runtime sidecar (not the admin/control-plane URL).
export AGENTICDOME_API_BASE="https://your-sidecar.example.com"
export AGENTICDOME_API_KEY="your_api_key"
export AGENTICDOME_TENANT_ID="your_tenant_id"
# Register runtime protection in your app bootstrap.
import agenticdome_sdk.crewai
# The import attaches live runtime protection when your application starts.
An authenticated agent can hold a valid token, reach an approved tool and submit a schema-valid request—yet still attempt the wrong action. AgenticDome adds a separate decision using business context available at the protected execution boundary.
Keep your identity provider authoritative for authentication, scopes, conditional access, credential lifecycle and downstream entitlements.
Agents plan, retrieve, delegate and invoke tools. A valid capability can be used for a purpose, amount, destination or sequence that the business should not approve.
Evaluate the authenticated actor, agent, purpose, target, final arguments and delegation immediately before the action creates impact.
Identity answers who can connect. An action decision answers whether this exact action should proceed now.
The strongest public guidance does not suggest replacing identity, platform security or human oversight. It calls for those controls to extend into the live execution path of autonomous systems.
Identity, platform governance, protocol security and framework validation remain essential. AgenticDome adds a specialised decision at the point where authenticated capability becomes business impact.
Use AgenticDome where an agent can invoke a tool, execute a workflow, delegate authority, cross a trust boundary or return sensitive content. The application must route that path through a supported control boundary and enforce the returned result.
| Security layer | Question it answers | Keep it for | AgenticDome contribution |
|---|---|---|---|
|
Identity and access Required foundation |
Who or what is authenticated, and what can it access? | Principals, credentials, scopes, conditional access and downstream entitlements. | Use authenticated identity as trusted context in the exact action decision. |
|
Platform governance Microsoft · cloud · SaaS |
Which environments, connectors, tools and data sources are available? | Administrative policy, environment isolation, data governance and native monitoring. | Evaluate eligible proposed actions through supported platform extension points. |
|
Framework and protocol SDK · MCP · orchestration |
Is the call well formed, routable and compatible with the runtime? | Schema validation, orchestration, transport security, OAuth and secure server implementation. | Apply customer policy to the final proposed action and available business context. |
|
Action governance AgenticDome |
Should this protected actor and agent perform this exact action now? | Pre-execution action policy, supported delegation checks, output controls and structured outcomes. | Return an enforceable decision before the application permits the protected side effect. |
AgenticDome focuses on the execution boundaries that matter most: agent frameworks, model runtimes, tool gateways, OpenClaw workspaces, and service-side SDK integrations where AI systems can read data, call tools, delegate tasks, stream output, or cross trust boundaries.
Let engineering teams choose CrewAI, LangGraph, Microsoft, OpenAI, Claude, Agno, or custom Python while the enterprise keeps one policy meaning for identity, tools, delegation, sensitive output, and evidence.
A safe first prompt can become an unsafe action after poisoned retrieval or a privileged graph transition. AgenticDome turns those later workflow stages into enforceable checkpoints.
Cloud IAM establishes what a workload can reach. AgenticDome adds whether this actor, through this agent, should use those permissions for this exact action now.
Use Microsoft’s native external threat-detection path to ask AgenticDome for an independent allow-or-block decision before an eligible generative agent invokes a tool—without rewriting each covered tool.
MCP standardizes connection and discovery. AgenticDome adds the missing business decision: should this actor and agent invoke this tool with these arguments now?
Do not let installation become permanent trust. The npm agenticdome-openclaw-security plugin enforces policy through native runtime hooks; the PyPI agenticdome CLI guides source-free onboarding and verifies the protected tenant path.
Turn the Node.js dispatcher that holds the credential and sends the real business request into an action firewall with agenticdome-sdk.
Choose a supported managed path, a dedicated runtime or a contracted customer-controlled deployment. Availability, responsibilities, retention and assurance requirements depend on the selected plan and architecture.
Connect supported workloads to the tenant's assigned runtime in an available published region.
Use a dedicated runtime when customer-specific capacity, availability or trust-boundary requirements justify it.
Place the enforcement runtime within an approved customer VPC, cloud or on-premises boundary under agreed operating responsibilities.
AgenticDome adds an enforceable decision before consequential actions create impact—without asking teams to abandon the platforms, frameworks and identity controls they already use. As CEOs scale AI agents and boards oversee the resulting autonomy, action-level control becomes a business-accountability issue—not only a developer concern.
In IBM's 2025 study of 2,000 CEOs, 61% said they were actively adopting AI agents and preparing to implement them at scale. IBM study →
Joint ASD-led guidance says autonomous actions introduce new security, governance, and accountability risks, and recommends a centralized policy decision point for each request. Government guidance →
Deloitte's 2025 survey found 66% of respondents said their boards had limited or no AI knowledge or experience; 31% said AI was not yet on the board agenda. Deloitte survey →
Turn agent autonomy into a governed business decision with a named control boundary, accountable ownership, and evidence that can be reviewed.
Reduce the risk that valid identities and approved tools are used to produce invalid business outcomes.
Bring your existing agent project. Integration Copilot helps identify the appropriate SDK, compatible integration boundary and verification steps—without forcing framework standardisation.
Separate customer policy from application logic and create a consistent protected boundary around high-impact actions.
Move beyond post-hoc auditing and make protected agent actions visible in terms the business can govern.
Existing customers should sign in through their assigned region. New customers can review the currently published regional entry points.
SDKs and platform integrations contribute rich action context. Runtime Grid expands the operating picture with privacy-bounded workload discovery and governed egress evidence. AgenticDome correlates those layers with identity, platform and response controls so security teams can move from emerging activity to trusted execution through one policy and evidence model.
AgenticDome combines fast deterministic policy paths, local gateway authorization options and regional deployment choices. Deployment validation establishes the performance profile for the customer’s workloads, network and evidence requirements.
Yes. Teams can align monitor, fail-open and fail-closed behaviour with development, business-critical and high-assurance journeys, then validate the selected posture before promotion.
AgenticDome supports privacy-bounded evidence, configurable content decisions and regional, dedicated or sovereign operating models. The deployment design records the approved data fields, location, retention and support-access model.
Yes. Runtime Grid’s default evidence model uses structured workload, destination and authorization metadata. Content-aware application controls can be selected separately where richer inspection is appropriate.
Dedicated and customer-controlled runtime patterns are available for enterprise and sovereign architectures, with agreed operational ownership, connectivity and assurance requirements.
One distinct billable action identifier recorded at an enforcement point is one verified action. Duplicate telemetry with the same identifier is de-duplicated. See the worked example on Pricing.
Start with one agent, one tool and one demonstrable decision. Expand to shared governance across teams, platforms, customers and deployment boundaries.