Compare/Build it yourself
Your team could build this. The question is whether they should.
This is the comparison we take most seriously, because for a company with a strong platform team it is often the right answer for part of the work.
Stated fairly
What building gets you, and what it costs.
Building it yourself
- Exactly the semantics your business uses, with no vendor's model of your domain in the way
- No procurement, no security review of a third party, no renewal conversation
- Your team learns the problem deeply, which is worth something on its own
- Full control over sequencing, so the piece you need in March is the piece built first
- No dependency on a company at our stage, which is a legitimate thing to weigh
What it usually runs into
- The interesting part is a fortnight. The governance, audit, sandboxing and identity work underneath is most of a year and none of it is differentiating
- Keeping a context layer current as schemas drift is a permanent job, not a project with an end date
- The people who could build it are the people you least want doing it, and they are the hardest to replace
- An evaluation harness that gates promotions is the piece teams always plan and rarely reach
- The first version works. The failure arrives in month seven, with no alarm, as answers that are confidently out of date
Build the parts that encode your business. Buy the floor those parts stand on.
the same split every company made about databases, queues and identityWhere we would draw the line
Five pieces, and who should own each one.
This is not a list where everything lands on our side. Two of the five belong to you permanently, and a vendor who tells you otherwise is selling you a dependency you will resent.
Your domain semanticswhat things mean here
Which table is authoritative, what an exception means, which rule exists because of an incident in 2019.
yours
Your evaluation caseswhat good looks like
The ten hard ones with the answer you would have given.
yours
The governed dooridentity, scope, audit
Separately revocable credential surfaces, roles across every transport, denials logged, egress control, a kill switch that needs no deploy.
the floor
Profiling and keeping it currentthe part that decays
Reading schemas and samples, binding metrics to real columns with invariants, re-running on a schedule, and escalating what it cannot decide.
the floor
Sandboxed build and deployso non-engineers can ship
Build scanning, scoped tokens, an internal URL behind an egress path, an audit row per deploy.
the floor
What happens to builds like this
Measured by people with no stake in the decision.
None of this is our research and none of it is about us. It is worth knowing before you scope the work, because the failure mode it describes is the one that eats the timeline.
40%
of agentic AI projects are expected to be cancelled by 2027, on integration cost that was never in the pilot budget.
Gartner · 2025
95%
of enterprise generative AI pilots deliver no measurable impact, with the gap in the integration and learning layer rather than the model.
MIT · 2025
2×
the success rate for platforms bought from a vendor compared with equivalent internal builds, in the same MIT study.
MIT · 2025
The argument against us
The real risk of buying is that you are buying from a company our size.
That is a fair objection and we would rather answer it here than have it raised in month three. The structural answer is that the default install runs entirely inside your infrastructure, with no runtime dependency on us and nothing that stops working if we do. Source escrow and air-gapped continuity terms can be written into the agreement.
The second answer is that the material this accumulates, the profiles, the corrections, the traces and the evaluation cases, sits in your systems in your tenancy throughout.
How the deployment boundary actually works →Bring your build plan.
If your team has already scoped this internally, that document is the most useful thing you can put on the call.