What an execution perimeter is
The perimeter is the answer to three questions: where the data is processed, who besides you can see it and which actions are allowed for the agent. In the agent passport the perimeter and validation are one of the mandatory fields, so the execution environment is discussed before launch, not after.
Three perimeters
| Perimeter | What it is for | Nature of data |
|---|---|---|
| Cloud | Demonstration and individual tasks | Without sensitive data |
| Team | Team roles, shared artifacts, decision journal | Internal working materials |
| Local | The company's own perimeter | Trade secrets, personal data |
The local perimeter is designed after a technical investigation: the hardware composition, the integrations and the security requirements are clarified for the task. For some subagents — for example, the legal RAG navigator and the database consultant — the local or cloud mode is chosen by the user themselves.
How to choose
- The data must not leave the company — the local perimeter: meeting recordings, contracts, database metrics stay inside the perimeter.
- The result is checked by several people — the team perimeter: roles, shared artifacts and the decision journal.
- The task is one-off or for demonstration — the cloud perimeter: a quick look at the form of the result without handing over sensitive data.
What is fixed before launch
Regardless of the perimeter, before connection the sources, the allowed actions, the processing perimeter and the retention period are set. Unnecessary sources are not connected, and disputed decisions stop and wait for human confirmation — this is part of the project's security principles.
Boundaries
The local perimeter is not a button but a project: it is designed after the investigation of the infrastructure. If the investigation shows that local deployment is excessive, the honest answer is to stay in the team or cloud perimeter.
Questions and answers
Can I start in the cloud and move to the local perimeter?
Yes, if the agent supports both modes. For agents, local deployment is designed after a technical investigation of the company's infrastructure.
What happens to the data in the demo run?
The demonstration uses synthetic materials and does not process customer data — your materials do not take part in the demo.
Who sets the agent's permissions?
The sources, the allowed actions, the processing perimeter and the retention period are fixed before launch together with the customer and reflected in the passport.
What is the local perimeter?
A local perimeter is a deployment on the customer's computer or server. If the approved configuration does not use external integrations, materials are not sent to external services; hardware requirements are confirmed before launch.
When is the cloud perimeter chosen?
When availability and scale matter more than local processing; the perimeter is agreed before launch and fixed in the passport.
What is the team perimeter?
A deployment for several roles of the team: the shared decision journal and the access rights are set before launch.
Can the perimeter be changed after launch?
The processing perimeter is a field of the passport; a change is possible by an explicit decision with an update of the passport and the journal.
Who decides which perimeter is needed?
The customer together with the contractor after the investigation: the data, the confidentiality requirements and the infrastructure are taken into account.
How is the perimeter related to Federal Law 152-FZ?
A local perimeter alone does not establish compliance with Federal Law No. 152-FZ. For each deployment, the operator and processor roles, databases, access controls, external integrations, and other legal requirements must be assessed separately.
Does the perimeter affect the composition of the passport?
No: the passport of eight fields is the same for all perimeters — the value of the "perimeter" field and the related permissions change.