An office computer still needs updates, backups, and access controls. A cloud environment can have strict isolation and audit records. Security depends on how the system is configured and maintained as well as where it sits.

Data and Permissions

Map the data and actions

Before choosing infrastructure, map the information the agent will read, where it lives, and whether it may leave the current network. List the systems it will use, the actions it will take, and where activity logs will be stored. That map shows what the deployment needs to protect.

When Local Fits

When on premises or a dedicated environment fits

  • Your core data must remain inside the company network or in a specified region.
  • The agent must connect to ERP, equipment, or file servers available only on the internal network.
  • Essential local tasks need to continue during an internet outage.
  • Your team or service provider can manage servers, accounts, updates, backups, monitoring, and incidents.
  • Regulations or customer contracts set specific data location and access requirements.

When Cloud Fits

When the cloud fits

  • Most tools you need are already in the cloud: email, spreadsheets, CRM, or social platforms.
  • Workload varies, so you need flexible capacity or resources billed by usage.
  • Teams in different locations need shared access.
  • Your business has no dedicated staff to maintain on-premises servers.
  • You want to test a workflow quickly with limited initial infrastructure costs.

A Hybrid Setup

When a hybrid setup makes sense

In a hybrid setup, the workflow and some models may run in the cloud while a connector controls access to information inside the company network. Another option is to prepare data on premises and send only the necessary processed information to an external model. High-risk actions can wait for approval in a local system before running.

Hybrid setups add connections and maintenance work. Use one when the data and access requirements justify that complexity.

01

Data: Sensitivity level, location, retention period, and whether cross-border transfer is allowed.

02

Systems: Whether internal or cloud systems provide stable interfaces and dedicated accounts.

03

Actions: The permissions required for read-only access, writing, publishing, payments, and equipment control.

04

Maintenance: Who owns patching, secrets, backups, monitoring, and incident handling.

05

Operations: Network, latency, workload, and availability requirements.

06

Compliance: Industry regulations, customer contracts, and internal company policies.

Access and Logs

Secure the whole system

An agent also uses accounts, browsers, files, and business systems. Running the model on premises does little to address excessive write access, exposed credentials, or missing logs. Limit permissions, require approval for sensitive actions, isolate execution, and record what happens wherever the system runs.

For the pilot: Where your data requirements allow it, test the workflow with de-identified or limited-scope data while planning the eventual deployment. Establish whether the task is worth automating before committing to infrastructure your team will have to maintain.

Ongoing Maintenance

Decide who will maintain it

On-premises systems need someone to maintain the infrastructure. Cloud systems still need account, permission, cost, and service management. Whichever you choose, name an owner who can keep the system current and respond when something fails.

We design deployment around your data, existing systems, and approval responsibilities. Share your requirements and we’ll help you work through the options.

Discuss your deployment needsContinue readingWhat can an AI agent do for your business? →