🏢 Lesson 9.3: Hosting Private Agents for Teams

 

🏢 Lesson 9.3: Hosting Private Agents for Teams


🎯 Learning Objectives

By the end of this lesson, learners will be able to:

  • Understand what it means to host private AI agents for internal team use

  • Set up authentication and role-based access control

  • Deploy a private AI chatbot or assistant that runs securely in team environments

  • Choose between self-hosting or private cloud options for secure collaboration


🧠 Why Host AI Agents Privately?

Most AI chatbots and assistants are built for public-facing use. However, in real-world business scenarios, companies often need internal AI agents to:

  • Access confidential documents (e.g., reports, manuals, legal files)

  • Assist teams with knowledge retrieval

  • Automate internal workflows securely

  • Comply with privacy, GDPR, or data residency requirements

Hosting these agents privately ensures that only authorized team members can interact with the system and access its data.


🏗️ Key Features of a Private AI Agent

Feature Purpose
🔐 User authentication Limit access to team members only
🧠 Memory per user/session Preserve conversation history
📁 Secure file access Read PDFs, emails, docs without exposure
⚙️ Role-based responses Show different info based on role (HR, Sales, Support)
📊 Logging & monitoring Track usage and troubleshoot

🛠️ Step-by-Step: Hosting a Private AI Agent


✅ 1. Choose Your Hosting Environment

You have two primary options:

Option Description
Self-hosted Host on your own VPS/server (e.g., DigitalOcean, Linode)
Private cloud Use Render, AWS, or Hugging Face Spaces (set as private)

✅ 2. Add User Authentication

You can implement basic username/password login or use third-party login (Google OAuth, GitHub OAuth, etc.)

Option 1: Basic Auth (FastAPI)

from fastapi import Depends, HTTPException, status
from fastapi.security import HTTPBasic, HTTPBasicCredentials

security = HTTPBasic()

def authenticate(credentials: HTTPBasicCredentials = Depends(security)):
    if credentials.username != "admin" or credentials.password != "password":
        raise HTTPException(status_code=401, detail="Invalid credentials")

Option 2: Streamlit Login

Use streamlit-authenticator library for simple login in Streamlit apps:

pip install streamlit-authenticator

✅ 3. Set Up Role-Based Access

Assign different permissions or data access based on the user’s role.

users = {
    "alice": {"password": "hr123", "role": "HR"},
    "bob": {"password": "sales456", "role": "Sales"},
}

if user["role"] == "HR":
    response = agent.ask("Show employee leave data")
elif user["role"] == "Sales":
    response = agent.ask("Show sales figures")

✅ 4. Run with Session Memory

Maintain private conversations using LangChain memory components:

from langchain.memory import ConversationBufferMemory

memory = ConversationBufferMemory(return_messages=True)
agent = initialize_agent(..., memory=memory)

Each user can have their own memory session.


✅ 5. File Access and Uploads

Allow each user to upload their own documents (PDFs, Word, CSV) without making them public.

  • Use Gradio or Streamlit file uploaders

  • Store files temporarily in isolated folders

  • Use LangChain or PyMuPDF to read the uploaded content securely


✅ 6. Deploy Behind a Firewall (Optional)

For high-security environments:

  • Run the app behind a VPN

  • Use a reverse proxy like NGINX

  • Set firewall rules to restrict public access


💡 Use Case Examples

Use Case Agent Behavior
HR Assistant Answers employee questions privately
Sales Dashboard Bot Retrieves and summarizes CRM info for logged-in reps
Legal Document Assistant Searches uploaded legal docs, only for attorneys
Engineering FAQ Bot Serves only engineering resources to dev team

🔐 Data Privacy & Compliance Tips

  • Always encrypt passwords and use HTTPS

  • Avoid logging sensitive user inputs unless anonymized

  • If dealing with PII or proprietary data, consider on-premise hosting

  • Ensure compliance with GDPR, HIPAA, or company policy


🧪 Testing the Private Agent

  1. Create multiple test accounts (e.g., HR, Sales)

  2. Login as each and test:

    • Different agent responses per role

    • File upload and memory functionality

    • Access control restrictions


✅ Recap

Step Purpose
Add authentication Control who uses the bot
Use session memory Track individual user interactions
Limit file access Prevent data leakage
Deploy securely Behind firewall, password, or VPN

📦 Assignment

Deploy a private version of your AI assistant using basic auth or login. Allow only verified team members to chat and upload files. Share screenshots and test feedback.


 

54