🏢 Lesson 9.3: Hosting Private Agents for Teams
🎯 Learning Objectives
By the end of this lesson, learners will be able to:
-
Understand what it means to host private AI agents for internal team use
-
Set up authentication and role-based access control
-
Deploy a private AI chatbot or assistant that runs securely in team environments
-
Choose between self-hosting or private cloud options for secure collaboration
🧠 Why Host AI Agents Privately?
Most AI chatbots and assistants are built for public-facing use. However, in real-world business scenarios, companies often need internal AI agents to:
-
Access confidential documents (e.g., reports, manuals, legal files)
-
Assist teams with knowledge retrieval
-
Automate internal workflows securely
-
Comply with privacy, GDPR, or data residency requirements
Hosting these agents privately ensures that only authorized team members can interact with the system and access its data.
🏗️ Key Features of a Private AI Agent
| Feature | Purpose |
|---|---|
| 🔐 User authentication | Limit access to team members only |
| 🧠 Memory per user/session | Preserve conversation history |
| 📁 Secure file access | Read PDFs, emails, docs without exposure |
| ⚙️ Role-based responses | Show different info based on role (HR, Sales, Support) |
| 📊 Logging & monitoring | Track usage and troubleshoot |
🛠️ Step-by-Step: Hosting a Private AI Agent
✅ 1. Choose Your Hosting Environment
You have two primary options:
| Option | Description |
|---|---|
| Self-hosted | Host on your own VPS/server (e.g., DigitalOcean, Linode) |
| Private cloud | Use Render, AWS, or Hugging Face Spaces (set as private) |
✅ 2. Add User Authentication
You can implement basic username/password login or use third-party login (Google OAuth, GitHub OAuth, etc.)
Option 1: Basic Auth (FastAPI)
from fastapi import Depends, HTTPException, status
from fastapi.security import HTTPBasic, HTTPBasicCredentials
security = HTTPBasic()
def authenticate(credentials: HTTPBasicCredentials = Depends(security)):
if credentials.username != "admin" or credentials.password != "password":
raise HTTPException(status_code=401, detail="Invalid credentials")
Option 2: Streamlit Login
Use streamlit-authenticator library for simple login in Streamlit apps:
pip install streamlit-authenticator
✅ 3. Set Up Role-Based Access
Assign different permissions or data access based on the user’s role.
users = {
"alice": {"password": "hr123", "role": "HR"},
"bob": {"password": "sales456", "role": "Sales"},
}
if user["role"] == "HR":
response = agent.ask("Show employee leave data")
elif user["role"] == "Sales":
response = agent.ask("Show sales figures")
✅ 4. Run with Session Memory
Maintain private conversations using LangChain memory components:
from langchain.memory import ConversationBufferMemory
memory = ConversationBufferMemory(return_messages=True)
agent = initialize_agent(..., memory=memory)
Each user can have their own memory session.
✅ 5. File Access and Uploads
Allow each user to upload their own documents (PDFs, Word, CSV) without making them public.
-
Use
GradioorStreamlitfile uploaders -
Store files temporarily in isolated folders
-
Use LangChain or PyMuPDF to read the uploaded content securely
✅ 6. Deploy Behind a Firewall (Optional)
For high-security environments:
-
Run the app behind a VPN
-
Use a reverse proxy like NGINX
-
Set firewall rules to restrict public access
💡 Use Case Examples
| Use Case | Agent Behavior |
|---|---|
| HR Assistant | Answers employee questions privately |
| Sales Dashboard Bot | Retrieves and summarizes CRM info for logged-in reps |
| Legal Document Assistant | Searches uploaded legal docs, only for attorneys |
| Engineering FAQ Bot | Serves only engineering resources to dev team |
🔐 Data Privacy & Compliance Tips
-
Always encrypt passwords and use HTTPS
-
Avoid logging sensitive user inputs unless anonymized
-
If dealing with PII or proprietary data, consider on-premise hosting
-
Ensure compliance with GDPR, HIPAA, or company policy
🧪 Testing the Private Agent
-
Create multiple test accounts (e.g., HR, Sales)
-
Login as each and test:
-
Different agent responses per role
-
File upload and memory functionality
-
Access control restrictions
-
✅ Recap
| Step | Purpose |
|---|---|
| Add authentication | Control who uses the bot |
| Use session memory | Track individual user interactions |
| Limit file access | Prevent data leakage |
| Deploy securely | Behind firewall, password, or VPN |
📦 Assignment
Deploy a private version of your AI assistant using basic auth or login. Allow only verified team members to chat and upload files. Share screenshots and test feedback.
54
