Agent-User
Deployment & Model Integration

Three deployment modes: on-prem, hybrid, multi-cloud

Agent-User Runtime runs locally by default and can be upgraded to a fully private deployment or hybrid cloud. The model layer simultaneously integrates external public model APIs, private local models, enterprise cloud LLMs, and custom LLMs — all under unified governance and context policy.

Deployment topology · private + clienton-prem · offline
Cloud · enterprise
01Admin console
02Model routing gateway
03Approval / workflow service
04Identity / permissions
05Audit / billing
Client · employee device
01Desktop app (Electron)
02Local knowledge index
03Skill sandbox
04Local model inference
05Credential custody
Offline / restricted mode: no internet

Three deployment modes

From pure on-prem to full privatization — covers every compliance and business need.

Pure on-prem

Desktop Runtime can run offline; models can be invoked privately on local infrastructure; external network calls can be disabled by configuration.

  • Works in disconnected environments for high-sensitivity assessment
  • Models deployed on intranet / mainstream GPU clusters
  • Configurable data-residency policy to avoid default uploads
  • Supports SM cryptography and local KMS custody

Hybrid cloud

Desktop Runtime + enterprise cloud control plane; smart routing between local and external models.

  • Local Runtime handles core tasks
  • Cloud control plane syncs policy and audit
  • External model APIs optional for non-sensitive tasks
  • Unified SSO + unified audit logs

Multi-cloud federation

Federated governance across multiple cloud providers and LLM vendors; auto-routing by data sensitivity.

  • Public cloud / private cloud / private IDC hybrid access
  • Provider adapters (Qwen / DeepSeek / Doubao / OpenAI-compatible)
  • HITL approval queue + budget gates
  • Data classification auto-selects model and storage location

Deployment architecture

Six layers from client to model to enterprise integration — fully observable and governable.

01Client

Electron Desktop / Browser

02Desktop Runtime

Node.js · five-layer security bridge

03LLM Gateway

Unified routing · context policy · redaction

04Model Matrix

Qwen · DeepSeek · Doubao · external vendor APIs · Private LLM

05Enterprise Integrations

SSO · KMS · audit delivery

06Security / Compliance

Classified protection · cryptography capability · key custody

Traffic enters the Runtime from the client and is routed through the LLM Gateway to the model matrix, governed end to end by SSO, KMS, and audit controls.

Model integration matrix

Single Runtime entry, policy-based routing to different model layers.

ModelTypeUse case
External vendor LLM APIs
External public model APIGeneral Q&A, document processing, code generation
On-prem private model
On-prem deploymentHigh-sensitivity data, classified industries, SOEs
Enterprise cloud LLM
Enterprise-dedicated cloud modelMedium-sensitivity scenarios, cross-region teams
Custom / industry vertical LLM
Self-developed or custom modelIndustry know-how, finance / legal / manufacturing

Enterprise integration

Can connect with existing identity, key-management, and audit systems.

SSO single sign-on

Supports OIDC / SAML 2.0, integrates with AD / LDAP / Feishu / DingTalk / WeCom / Okta / Azure AD.

KMS key custody

Model credentials and knowledge-base encryption keys go through enterprise KMS (AWS KMS / Aliyun KMS / HashiCorp Vault / SM HSM); no plaintext locally.

Audit log shipping

JSONL audit events shipped in real time to SYSLOG / Kafka / SIEM (Splunk / Aliyun SLS / Tencent CLS), with SM signature support.

LDAP / OU sync

Org structure auto-synced to Agent-User's multi-tier permission matrix (enterprise / department / business line / role).

Security & compliance

Designed for ToB / ToG high-compliance scenarios.

  • Designed for MLPS 3.0 technical assessment
  • Can align with ISO 27001 information-security management requirements
  • Can connect SM2 / SM3 / SM4 capabilities by project need
  • Configurable data-residency and zero-trust access policies
  • Supports audit signing and traceability design
  • Supports tenant isolation and end-to-end encryption design

Get the deployment white paper / apply for POC

We provide end-to-end services from requirements analysis, solution design, POC validation to go-live and O&M.