Agent Stack Map
The argument 'our own client on our own model versus a vendor agent over an API' conflates independent decisions. Harness, model and tools are chosen separately: each axis carries its own data path, cost, failure point and vendor lock-in.
Eight repeatable configurations sit on the data-path and authority axes — from a self-hosted stack in an air-gapped perimeter to a personal setup wired to external MCP servers. They carry no universal ranking: air-gap demands the first, pilot speed leads to the fifth, corporate actions to the fourth, high risk to the seventh.
So the organizational outcome is not a winner but a portfolio with statuses: a working core, the next step after evals, restricted perimeters, high-risk execution and a sandbox. The company owns the gateways, identity, policy and traces, while clients and models stay replaceable.
Decompose your stack along three axes: harness, model, and tools — each is chosen independently.
Answer three questions: does data leave the perimeter, are internal actions required, do you have scale and evals.
Assign every configuration a portfolio status per scenario and data class, not once for the whole company.