Basics / 12 June 2026 / 6 min

Cloud, team or local perimeter: how to choose the execution environment

Cloud for demonstrations, Team for the team, Local for sensitive data. We break down the three execution perimeters of agents and the rules of choice.

Short answer: The project provides three perimeters: Cloud — demonstration and tasks without sensitive data, Team — team roles, shared artifacts and a decision journal, Local — your own perimeter for data that must not leave the company. The concrete option depends on the agent and is fixed before launch.

What an execution perimeter is

The perimeter is the answer to three questions: where the data is processed, who besides you can see it and which actions are allowed for the agent. In the agent passport the perimeter and validation are one of the mandatory fields, so the execution environment is discussed before launch, not after.

Three perimeters

PerimeterWhat it is forNature of data
CloudDemonstration and individual tasksWithout sensitive data
TeamTeam roles, shared artifacts, decision journalInternal working materials
LocalThe company's own perimeterTrade secrets, personal data

The local perimeter is designed after a technical investigation: the hardware composition, the integrations and the security requirements are clarified for the task. For some subagents — for example, the legal RAG navigator and the database consultant — the local or cloud mode is chosen by the user themselves.

How to choose

  • The data must not leave the company — the local perimeter: meeting recordings, contracts, database metrics stay inside the perimeter.
  • The result is checked by several people — the team perimeter: roles, shared artifacts and the decision journal.
  • The task is one-off or for demonstration — the cloud perimeter: a quick look at the form of the result without handing over sensitive data.

What is fixed before launch

Regardless of the perimeter, before connection the sources, the allowed actions, the processing perimeter and the retention period are set. Unnecessary sources are not connected, and disputed decisions stop and wait for human confirmation — this is part of the project's security principles.

Boundaries

The local perimeter is not a button but a project: it is designed after the investigation of the infrastructure. If the investigation shows that local deployment is excessive, the honest answer is to stay in the team or cloud perimeter.

Read also: How much does it cost to implement an AI agent: three engagement models · Who needs an AI agent: four roles and their result

Questions and answers

Can I start in the cloud and move to the local perimeter?

Yes, if the agent supports both modes. For agents, local deployment is designed after a technical investigation of the company's infrastructure.

What happens to the data in the demo run?

The demonstration uses synthetic materials and does not process customer data — your materials do not take part in the demo.

Who sets the agent's permissions?

The sources, the allowed actions, the processing perimeter and the retention period are fixed before launch together with the customer and reflected in the passport.

What is the local perimeter?

A local perimeter is a deployment on the customer's computer or server. If the approved configuration does not use external integrations, materials are not sent to external services; hardware requirements are confirmed before launch.

When is the cloud perimeter chosen?

When availability and scale matter more than local processing; the perimeter is agreed before launch and fixed in the passport.

What is the team perimeter?

A deployment for several roles of the team: the shared decision journal and the access rights are set before launch.

Can the perimeter be changed after launch?

The processing perimeter is a field of the passport; a change is possible by an explicit decision with an update of the passport and the journal.

Who decides which perimeter is needed?

The customer together with the contractor after the investigation: the data, the confidentiality requirements and the infrastructure are taken into account.

How is the perimeter related to Federal Law 152-FZ?

A local perimeter alone does not establish compliance with Federal Law No. 152-FZ. For each deployment, the operator and processor roles, databases, access controls, external integrations, and other legal requirements must be assessed separately.

Does the perimeter affect the composition of the passport?

No: the passport of eight fields is the same for all perimeters — the value of the "perimeter" field and the related permissions change.

First step

Choose a ready-made solution or describe your process.

Pick one of the twelve agents and subagents, or fill in the questionnaire for custom development.

Search agentseffect.com

Quick links