Managed
A provider operates agreed parts of the service, commonly hosting, updates, monitoring and support. The contract must still identify exclusions, response expectations and customer responsibilities.
AI agent operating guide
The software can be identical while the day-to-day risk is completely different. The real choice is who owns hosting, updates, credentials, monitoring, recovery and support—and whether they can do that work reliably after launch.
Find the right operating modelThree practical models
“Managed” and “self-hosted” are not quality ratings. Either can be a sound choice when ownership is explicit and the operator has the capability to meet it.
A provider operates agreed parts of the service, commonly hosting, updates, monitoring and support. The contract must still identify exclusions, response expectations and customer responsibilities.
Your organisation runs the agent on infrastructure it controls. This gives direct control but also creates ongoing work across the host, application, integrations, credentials and recovery.
You may own the accounts or infrastructure while a specialist configures and supports the agent. This can work well when the division of responsibility is written down and regularly tested.
Responsibility map
Gaps appear when both parties assume the other is handling the same control. Put an owner and evidence beside every item.
Who provisions the server, monitors uptime, restores service and communicates incidents? Self-hosting puts more of this work on your team; a managed contract should state what the provider actually covers.
The runtime, operating system, plugins and dependencies all change. Decide who reviews releases, applies patches, tests changes and responds to a security advisory.
Name the owner of model, messaging and integration accounts. Use least access, multi-factor authentication where available, and a process for rotating or revoking secrets.
A backup is only useful if its scope, retention and restore process are known. Include agent configuration, approved knowledge, state and any records required to resume the workflow.
Someone must monitor failures, investigate unexpected outputs and approve high-impact actions. Managed infrastructure does not transfer responsibility for the business decision.
Agree what can be exported, which accounts remain yours, how access is removed and what support is available if you move provider or bring the service in-house.
Managed may fit when
Self-hosting may fit when
Downloading open-source software is the first step, not the operating model. Include staff time, after-hours failures, testing and recovery when comparing self-hosting with a managed quote.
Data location
A self-hosted agent can still send prompts, attachments and metadata to an overseas model API, messaging platform, monitoring service or backup provider. A managed agent could use Australian infrastructure or infrastructure elsewhere. Verify the complete data flow and the relevant provider terms instead of relying on the deployment label.
Australian Signals Directorate guidance describes cloud security as a shared responsibility: the provider and customer each retain work, and the division depends on the service. Your organisation remains responsible for understanding its part, including data, access, configuration, backups and incident response where applicable.
Read Australian cloud security guidanceTotal cost
A managed quote may bundle work that is invisible in a self-hosted hosting bill. Compare both options over the same period using setup, infrastructure, model and platform usage, monitoring, support, updates, backup, internal labour and likely change work.
Ask what happens when the agent stops, a provider changes an API, a credential is exposed or an output is wrong. The better operating model is the one your organisation can sustain and verify—not simply the one with the lowest first-month number.
Choose with the responsibilities visible