Factory

Factory Private

Enterprise AI

Self-hosted AI agents and control-plane ownership

September 18, 2026 - 2 minute read

Installing a coding agent locally and operating the service behind its sessions are different jobs. The control plane coordinates sessions and supporting services. Self-hosted AI agents can put that service under the customer's control, which also makes its updates, availability, and recovery part of the customer's operating work.

Before choosing customer hosting, identify the team that would restore the control plane after a failed upgrade and the process it would use. An internal model key or a local executable cannot answer that operational question.

Self-hosted AI agents change who operates the system

Factory offers a managed control plane and a customer-owned alternative. Factory Managed provides hosted orchestration and operations while Droids can run across existing development environments.

Factory Private puts the control plane in customer infrastructure. The published comparison identifies differences in ownership, data boundary, and access controls.

Best for

Teams that want Factory-managed operations and analytics.

Data boundary

Customer content is tenant-isolated within Factory’s managed environment.

Security and access

Enterprise Controls govern models, access, telemetry, and autonomy.

Control plane

Factory-hosted.

Droid execution

Local machines, CI/CD, BYOM, or Factory-managed Droid Computers.

Operations and updates

Factory operates the control plane. Your team operates local and CI environments.

Telemetry and analytics

Factory Analytics or OpenTelemetry export.

Best for

Teams that need Factory in their VPC or on-premises environment.

Data boundary

Customer data remains in your environment.

Security and access

Your IAM, network, and security controls govern the deployment.

Control plane

Customer-hosted.

Droid execution

Local machines, CI/CD, and your BYOM infrastructure.

Operations and updates

Your team operates the deployment and controls updates.

Telemetry and analytics

Factory telemetry and OpenTelemetry export to your collector.

The ownership choice sets the operator's responsibilities. Model routing and execution permissions still need their own configuration, whichever control plane the organization uses.

Review self-hosted AI agents beyond the model key

Bringing an approved model does not move every supporting service into the customer network. Factory's sovereign software development whitepaper distinguishes Managed control-plane and session-data hosting from Private's customer-hosted placement.

Review session handling separately from inference. Record where context is stored, which model service receives requests, and what the gateway logs. Include retries, fallbacks, and support diagnostics in the diagram.

Factory's deployment documentation describes the runtime and traffic differences between cloud-managed, hybrid, and airgapped patterns. Use the intended pattern to test the complete workflow, not just its first successful model response.

Budget for the responsibilities that move

Operating a private control plane requires a release and recovery process. For example, rehearse an update in a disposable environment, then restore the previous approved configuration and run a known task. A successful recovery should not depend on undocumented steps in one administrator's shell.

The model service needs an owner too. A new model version can alter task behavior even when the agent build stays fixed. Keep representative validation tasks and review the results before promotion.

Monitor the dependency that can stop work. Adding execution machines will not repair a saturated inference service or an unavailable internal package mirror. Distinguish those failures from agent errors so the response goes to the team that can resolve them.

Support access also belongs in the plan. Agree on which diagnostics may leave the environment, how sensitive content is removed, and who approves release. Avoid making troubleshooting an undocumented exception to the boundary.

Treat disconnected operation as its own requirement

Airgapped operation adds a no-runtime-connectivity requirement. Factory's airgap build uses customer-configured models and disables Factory-bound services. Cloud-dependent features such as Slack integration and hosted analytics are unavailable.

Before developers depend on the service, make sure another operator can promote an update, recover a failed one, and collect permitted diagnostics. Those procedures determine whether customer control is usable when the system needs maintenance.

Read the Sovereign Software Development White Paper

A deployment and governance framework for the world's most important systems, from managed to air-gapped.

Read the white paper

Arrow Right Icon

Further reading

Talk with Factory

Discuss your team’s software development, privacy, or deployment requirements.

Contact us

Ready to build the software of the future?

Start building

Arrow Right Icon