Skip to main content
ai-agentsaiagentic-ai+2

Build vs Buy AI Agents: Draw the Line at Write Access

A read-only staff agent is ₹4L–₹6L in 5–8 weeks. Write access to your system of record is ₹14L–₹18L. That gap is what decides build vs buy AI agents.

A staff-facing agent that only reads sits in a published band of ₹4L – ₹6L and ships in five to eight weeks. Give that same agent write access to one system of record and the band we publish is ₹14L – ₹18L over three to four months. Both rows are on our AI agent cost guide, and the distance between them is the whole of build vs buy AI agents. The agent bundled into your productivity suite already does the first job, for the price of seats your finance team has already signed for. It will never do the second.

Six of the largest labs shipped the same desktop agent inside 120 days. Each one reads local files, drives a browser, holds context across several days, and hands back finished output instead of suggestions. Nobody is winning on the harness. Every one of those harnesses reaches your files and your browser, and none of them reaches your system of record, which is where the ₹14L sits.

What the agent in your productivity suite already handles

Anything where the material arrives attached to the task. Summarize the contract. Pull the figures out of the spreadsheet and lay them into the deck. Read the thread and draft the reply. The vendor’s agent does that work acceptably today and will keep getting better without sending you an invoice.

Commissioning a build for that class of work sets money on fire. Before you scope anything, take the tasks at the top of the list you were going to bring to an agency and hand them to the agent you are already paying for. Count how many come back finished.

Build vs buy AI agents: the line sits at write access

Reading generalizes. Acting does not.

An agent that issues the refund needs a route into your system of record, and a credential scoped to that route and nothing wider. Vendors ship the route as a connector; the credential is yours to cut. Separately, somebody at your end has to write down which actions stop for a human signature, because no vendor setting decides that for you.

A connector authorized as the employee gives the agent everything that employee can do. A scoped agent identity holds its own token against an allowlist of endpoints you name. That distinction gets enforced in your API and integration layer, and that layer has to be able to express a per-route allowlist before any agent is handed a write credential. If it cannot, that work comes first and carries its own price.

The signature rule is one line of policy and several weeks of build. “A refund above your limit waits for a person” means a queue somebody watches, a notification that actually reaches them, an audit record of what they decided, and defined behavior when the request times out unanswered. Four pieces of software behind one sentence of policy, and it is the largest single reason the write-capable band starts where it does.

There is a cheap test for whether you have drawn the line yet. Assume something in the agent’s context has convinced it to do the worst thing its credential permits, and write that worst outcome down as a single sentence. If the sentence will not finish, the scope has not been narrowed enough to build against.

Why a general agent cannot read your proprietary fields

Your CRM has custom fields nobody outside your company has ever seen. The agent can read their labels. It cannot know that stage four means legal has the paperwork, that a blank close date means the deal stalled rather than arrived yesterday, or that your ops team has been writing exception codes into a free-text notes field because nobody ever built the column.

That knowledge lives in people’s heads and in the shape of your data. A frontier model reading through a generic connector produces answers that are fluent and wrong in ways nobody on your team catches at a glance.

Fixing it means a retrieval layer over your own sources, with every answer cited back to the document it came from so a person can check it. That is the substance of custom AI versus a SaaS AI feature. Most of what the ₹4L – ₹6L band pays for is the encoding: field by field, someone writes down what each value means to your business, and the retrieval layer answers from that written definition.

Will your team actually use an AI agent?

Enterprise software has a long record of licenses that never became habits, and agents have a harder job than most software does. The pitch asks a finance analyst or an HR lead to do what engineers spent two years learning: delegate a multi-step task, supervise something working on it, notice the moment it goes off the rails, and then trust an output that was never produced one keystroke at a time.

That is a behavior change, and it arrives without the scaffolding non-engineers already work inside — approvals, and an audit trail somebody signs. The vendor’s agent is optimized for a demo where one person delegates one task and reviews it themselves. Your org runs on queues and sign-offs, and the agent has no idea either exists.

Budget the adoption work explicitly, then measure it one way only. Pick one team and one recurring task, and check at the end of the month whether that task actually left somebody’s queue.

What ₹14L – ₹18L actually buys you

You get a full trace of every step, tool call and argument, so when a customer disputes what the agent told them, support can read back the actual run. You get a written guardrail config listing permitted tools, the spend ceiling per run, and the actions that wait for approval — the document your risk review will ask for by name. You get an evaluation set of real tasks scored before launch. And you get an escalation path naming the role who signs when the agent is unsure. Those are artifacts, and you own all of them.

That set is what the customer-facing tier is paying for. The read-only tier at ₹4L – ₹6L buys retrieval with citations behind your SSO and a small admin view for reading transcripts, and it takes no action that changes a record. Purpose-built agents earn the jump between those two bands wherever a wrong action carries a cash value.

A version change from your model provider does not have to produce an error to change an outcome. A different tool choice on the same input is enough, and nothing in your logs will flag it. That is what the scored task set catches: you re-run it and diff the tool calls. With a bundled agent you file a support ticket and wait for somebody to reply.

How to run a bundled agent and a built one without paying twice

Draw the division as a list of named tasks. A policy statement invites argument; a list gets audited.

The bundled agent takes work where the material comes with the request and the output is a draft a person then edits. The built agent takes work where the material lives inside your systems and the output changes a record — an invoice exception traced back through three systems and a resolution drafted, held for sign-off before it sends.

Interrogate that second list once more before anyone quotes it. Work that follows fixed rules in a fixed sequence wants a defined workflow, not an agent, and a workflow is cheaper to build and predictable in a way no agent will ever be. Settle the agents versus automation trade-off before anybody writes a tool definition. It moves the budget further than the choice of model does.

The agent work we turn down

A general-purpose company assistant. It duplicates what your suite already ships, minus the context graph the vendor gets from owning your calendar and document store. You would be paying us to lose that fight.

An agent whose job is summarizing documents you hand it. The capability is bundled now, and it will keep improving on somebody else’s roadmap and somebody else’s budget.

An agent over a knowledge base that exists only in people’s heads. There is nothing to ground the answers in. The honest sequence is to write the knowledge down first, which is a documentation project, and not one you need us for.

An agent that writes into a system whose API cannot express a per-route allowlist. The only credential we could hand it would be the employee’s whole permission set, and no guardrail config repairs that. The integration work comes first, on its own timeline and with its own price, and we would rather say so in the discovery call than find it in week six.

An agent with write access to a system of record and no named human who signs off when it is unsure. Not a role, and not a team inbox. A person, with a name, who can be found on a Tuesday afternoon. If nobody in the room can say who that is, the scope has not settled, and we would rather establish that in week three of a pilot than in month four of a ₹14L build.

Have a project in mind?

Fixed price after a paid discovery — no hourly billing. A real engineer reads every enquiry, and we reply within 24 hours.