How to decide

Build, buy, or operate? How agents actually get deployed, and where each model breaks.

Every company is putting agents into business units one at a time, and every unit hits the same question: build it, buy it, or have someone run it. Six models. What each one owns, what each one governs, when each one fits. Ours is first. The comparison is straight.

Back to mabry.ai

What build versus buy misses: production

The build-or-buy debate happens at the demo. The decision that matters happens after it. Three things get missed.

01 · A demo isn't a system

The pilot works because someone is watching. In production, agents need monitoring, fresh data, permissions that stay right as people change roles, and a log that holds up months later. Build it and that's your job now. Buy it and it's still your job; you bought the feature, not the operation.

02 · Buying moves the work, not the risk

Whatever you license, you are still the controller of the data and the sender of every message. The vendor's defaults become your exposure. Most point tools send on their own by default and read more of your CRM than they need.

03 · Governance is the biggest exposure a company takes on with agents

Not the model. Not the cost. A wrong message to a regulated buyer, a contact touched twice by two systems, a record changed with nobody able to say why. Those end programs, and neither building nor buying includes the controls by default. That is the gap operate closes, and it's why the security-review table below decides more deals than the feature table.

The six models, side by side

CriteriaOperate (Mabry)Point toolPlatform + engineerAgencyStrategy firmIntegrator
What you getAn operated intelligence platform in your systemsSoftware for one job (an AI SDR, an AI support agent)An automation platform and someone to build on itA team running the activityDiagnosis and a planAn enterprise AI platform, implemented
Time to first resultWeeksDaysTwo quartersWeeksMonths, then someone buildsQuarters
Who decides the strategyYou, with our strategy team, who then stayYou, aloneYou, after they rampMostly themThem, then they leaveA steering committee
What you own afterEverything in your systems, plus the documentationSeatsEverything, eventuallyThe meetingsThe documentThe platform, and the invoices
Who approves each actionYour person, enforced in the platformUsually nobody, by defaultWhatever they configureTheir operatorNot applicableWhatever's configured
What a security review findsWrite-only into your CRM, no credentials held, an exportable logVendor terms; you're the controllerYour accounts, your controlsTheir process, their toolsNothing to review yetA large surface, a long questionnaire

Each one, honestly

1. Operate, with Mabry

An operated AI platform · strategy built in · your systems, your approval
What you get

Our platform, running in your systems on your connectors. We design the motion, deploy the agents, run the cadence, and answer for the number. Your people approve every action. Working in weeks, built to scale in production without scaling your exposure.

What you don't

The platform's method. You get finished, sourced work, never the rubric, the prompts, or the sources. And no volume promises; targets are set against your own baseline.

Right answer when

Most B2B cases. Named accounts, a buyer with a security team, a motion that has to scale. You want strategy, platform, and governance from day one, and you don't want to hire a team to run it.

Wrong answer when

You want a tool nobody is accountable for, or you don't intend to review what goes out. A point tool is cheaper. The exposure is yours.

2. Buy a point tool for the function

Software · seats · an AI SDR, an AI support agent, an AI contract reviewer
What you get

A product that does one job at volume for a monthly fee per seat. Live in days. A dashboard of activity. In sales, the AI SDR is the best-known example.

What you don't

Anyone deciding which accounts, why now, or what the message should argue. The product is the motion. Governance is whatever the vendor's settings allow, and most send on their own by default.

Right answer when

A wide, undifferentiated market, a simple offer, an ops person who understands deliverability, and no one who will ever audit what was sent. You accept the exposure yourself. Rare in B2B.

Wrong answer when

Your book is named accounts, your buyers are regulated, or a bad send costs more than a missed one. Then autonomy is the risk, not the feature.

3. Buy a platform and build on it in-house

Headcount · one engineer · an automation platform
What you get

Someone who owns the stack full time, learns your business, and stays. Over two years this is the best option for a company that will keep investing in it.

What you don't

The first year. Good engineers are scarce, take a quarter to hire and a quarter to ramp, and one person cannot also be the strategist, the enablement lead, and the governance function. The platform ships no approval step; they build one, or don't.

Right answer when

You already have the engineer, the strategy is settled, and you are prepared to build and maintain the governance yourself. Most teams find the governance is the part they underestimated.

Wrong answer when

You need the system before you can justify the hire, or you need the design work done before the person arrives.

4. Hire an agency to run the activity

Service · activity · monthly retainer
What you get

A team that runs it for you: lists, sequences, replies handled, meetings booked. Results in weeks. Someone to call when the number is off.

What you don't

Anything that stays when they leave. The lists, the sequences, and the learning live in their tools. Your CRM gets the meetings, not the system that produced them.

Right answer when

You need activity for a short window and do not intend to keep the capability. You are comfortable with the learning, the lists, and the system leaving when the retainer ends.

Wrong answer when

You want to own the motion in twelve months, or the work is complex enough that whoever does it needs to understand the business.

5. Hire a strategy firm to design it

Advisory · deliverables · project fee
What you get

Senior people who diagnose the function, design the operating model, and hand you a plan with the reasoning behind it. Board-ready.

What you don't

The system. The deck describes it; someone else has to build it, and by then the people who designed it are on the next engagement. That gap is where most of these plans die.

Right answer when

The board needs an outside view on an organizational decision, and you already have the team that will build and run what is recommended. Without that team, the plan is a document.

Wrong answer when

You don't have the builders. Then the plan is the most expensive document in the company.

6. Hire an integrator to implement an enterprise AI platform

Program · a bench · a platform licence plus services
What you get

Breadth. A platform that spans functions, a partner with a bench, a program office, and a roadmap measured in quarters.

What you don't

Speed, or a small surface. The security questionnaire is long because the platform touches everything. Governance is a configuration project. The people who designed it are rarely the people who run it.

Right answer when

You are a large enterprise standardizing agents across many functions at once, with a CIO program office, a multi-year budget, and the patience for a program measured in quarters.

Wrong answer when

You need one business unit working in weeks, with a surface your security team can read in an afternoon.

What a security review asks each model

If your buyers are in financial services, insurance, healthcare, or anywhere with a compliance function, this section decides the choice. Your security team, or your customer's, will ask the same five questions of whatever you pick.

The questionOperate (Mabry)Point toolPlatform + engineerAgencyIntegrator
Who holds our credentials?You. We hold none. Approved work is handed to your workspace to write.The vendorYouThe agencyThe platform, and the partner during the build
Can it act without a person?No. The approval is enforced in the platform and cannot be switched off.Yes, by defaultDepends on the buildYes, their operatorDepends on the configuration
What can it do to our CRM?Create records and notes. It cannot read a record.Read and writeWhatever scopes were grantedWhatever you gave themBroad by design
Can we prove who was contacted, when, why?Yes. Every action is logged, and the log exports.Export, maybeIf they built a ledgerAsk themUsually, somewhere
What happens when we stop?You keep everything in your systems; your data on our side is destroyed and confirmed in writing.Seats endYou keep everythingEverything leaves with themA decommissioning project

Only one column answers all five on day one. The others can get there, on your dime: you build the approval step, you cut the permissions, you keep the log, you plan the exit. We built the platform to answer these five before the first agent runs, because in regulated markets the meeting after the demo is where the deal is won or lost.

Show me your stack

The model you choose matters less than whether your systems can be governed. Three checks to run on yourselves before choosing anything.

01 · One system of record per record type?

If two systems both claim to own the contact, no agent can reconcile them and no approval step can protect them. Name the owner of each record type first.

02 · Does anything touching those systems have permissions it doesn't need?

Open the integrations page of your CRM. Anything with read and write that only needs write, or full access that only needs one object, is where an agent incident will start.

03 · Can you export a log of what agents did last week?

If the answer is no, you have automation you can't audit. That is the thing a security reviewer will find first, whichever model you chose.

What operate means

Buy the systems of record. Your CRM, your mail, your chat. They get more valuable as agents multiply, because that's where permissions live.

Build what's yours. Your playbook, your language, your rules for who gets contacted and how. No vendor should own that.

Operate the intelligence layer. A platform that watches, researches, scores, and drafts inside your systems, under your approval, run by people who answer for it. That's how a company scales agents without scaling exposure: the governance travels with the platform instead of being rebuilt for every function. You own everything it leaves in your systems. You never hold the platform's method. We never hold your credentials or your data.

Four questions that usually settle it

01 · Activity or a motion?

If all you need is activity this month and nobody will ever audit it, a tool or an agency will produce it. Every other case needs a motion you own and someone who answers for it. That's model 1.

02 · Does anyone review what goes out?

If yes, because your buyers are regulated or a wrong message costs a relationship, the approval has to live in the system, not in a policy memo. Model 1 is the only one that ships with it. If no, the exposure is yours.

03 · Who owns it in twelve months?

If us, model 1. Everything the platform produces stays in your systems, and the platform keeps running. A tool leaves you seats. An agency leaves with its tools. A strategy firm leaves a document.

04 · Is the strategy settled?

If it isn't, model 1. The strategy is built in, by the people who deploy and run it. If it is and you have the engineer, you can build. Plan for the governance. It's the part every team underestimates.

Questions we get asked about this

Can we start with an AI SDR tool and add governance later?

You can add a review step to most tools. What you can't add later is a log of everything already sent, and you can't un-send it. If review is ever going to matter, build for it first.

Isn't operating just a managed service?

A managed service runs your tools. We run our platform, inside your systems, and the platform enforces the rules: the approval, the write-only connection, the evidence floor. The difference shows up in the security review, not the brochure.

Why not just hire a GTM engineer now?

If you can find one and the motion is proven, do. Operating first means that hire inherits a running system and its documentation instead of a blank platform.

Why not an agency?

An agency rents you activity in its own tools. When it leaves, the system leaves with it. Operating puts a platform in your systems, under your approval, that stays and scales, with strategy and governance built in.

How does the human approval actually work?

Agents research, check the system of record, enrich, and draft. A person on your team sees the draft and clicks approve, edit, or reject. The decision is recorded in the platform. Nothing moves into your CRM until it's approved.

Which model should a founder-led company choose?

If you're still doing every demo yourself, fix that first. Then operate: the motion designed, the platform running in your systems, and someone who answers for the result, without hiring a team to run it.

Back to mabry.ai
Start here

Bring us the motion that matters most.

In one working session we'll show you the motion running on the platform, before you spend a dollar. If it isn't revenue, say so. The platform doesn't care, and we'll tell you straight whether we've done it before.

Request a working session →

First session is a working session, not a pitch  ·  Your data never leaves your stack  ·  If we're not the right fit, we'll tell you on the first call.