Which path should I choose?
Choose the path based on who needs access, how much operational work you want, and where the vault engine should live.
Choose local-only daemon if
Section titled “Choose local-only daemon if”- You are working solo.
- You want the open-source daemon path.
- You are comfortable managing the machine, backups, and access yourself.
- You do not need Cloud login, org membership, relay, presence, or team access.
- Your agents can run on the daemon machine or another private-network client you intentionally trust.
- You need a path that works without a KB-1 Cloud account.
Success signal: KB-1 runs on your machine and agents can access it locally.
Choose self-hosted full experience if
Section titled “Choose self-hosted full experience if”- You want the vault engine to stay on your own machine.
- You still want people and agents to log into KB-1 Cloud.
- You need organization identity, signed entry, remote reach, presence, or team access.
- You are comfortable operating the machine that owns the vault.
Success signal: your vault engine is self-hosted, but teammates and agents enter through the KB-1 Cloud login surface.
This is not the same as local-only. Self-hosted full experience keeps the vault home local, but the shared product surface still starts with Cloud login. Use it when local custody matters but you want access from anywhere, agents that are not colocated with the daemon, or Cloud users and organizations.
Choose Hosted if
Section titled “Choose Hosted if”- You want KB-1 to operate the vault runtime for you.
- You value convenience over running an always-on machine.
- You want the same Cloud login surface without managing daemon lifecycle.
- You want managed durability and wake behavior.
Success signal: you log into KB-1 Cloud and open a vault engine operated by KB-1.
Hosted is the path where Cloud login and vault operation are both handled by KB-1.
Decision table
Section titled “Decision table”| Need | Best path |
|---|---|
| Maximum local custody for solo work | Local-only daemon |
| Team access while keeping content on your machine | Self-hosted full experience |
| Remote access to a self-hosted daemon | Self-hosted full experience |
| Agents that are not on the daemon machine or trusted private network | Self-hosted full experience |
| Lowest operational burden | Hosted |
| Agent access through a shared org | Self-hosted or Hosted |
| No Cloud account | Local-only daemon |
If you are unsure, start with the path that matches your custody requirement. You can connect Cloud relay or move to Hosted when the team workflow becomes clearer.