IndustryComparison
Top 10 managed agent orchestration platforms for enterprises in 2026
AgentCore, Foundry, Google's Agent Platform, LangSmith, Agentforce, ServiceNow and four more ranked on runtime, identity, memory, MCP and A2A, lock-in, audit, pricing and data residency.

A managed agent platform is the place where an enterprise’s agents actually run: an isolated runtime that starts a session, gives the agent an identity, keeps its memory, connects it to tools and other agents, records what it did and sends a bill. In 2025 most of these products were previews. By October 2026 the three hyperscalers have generally available runtimes, the large SaaS suites have rebuilt themselves around agents, and the framework vendors have turned their libraries into hosted products with self-hosted editions.
That convergence makes the choice harder, not easier. The feature lists now look alike: every serious entry claims session isolation, memory, MCP tools and some form of agent-to-agent protocol. What still differs is whose identity system the agent lives in, where its data can sit, which models it can call without friction, how it is billed, and how painful it is to leave. This ranking is for platform, security and architecture leads who have to pick one, or more often several, and still keep governance consistent.
The ten entries below are read from each vendor’s own documentation, pricing pages and announcements as of October 2026. A companion piece ranks the open-source agent orchestration frameworks that many of these platforms host; this one is about the managed services.
How we ranked managed agent platforms
We scored each platform on nine criteria that decide whether an agent can go to production in a regulated enterprise, then weighted them by how hard each is to fix later.
| Criterion | What we looked for | Why it is hard to change later |
|---|---|---|
| Runtime and scaling | Session isolation, maximum run length, scale to zero, cold starts | Long-running agents break on short caps |
| Identity and permissions | A distinct identity per agent, delegated (on-behalf-of) access, IAM integration | Identity is wired into every tool permission |
| Memory | Managed short- and long-term memory, retention controls | Memory formats rarely export cleanly |
| Tools, MCP and A2A | MCP client and server support, A2A version, tool gateway | Protocols decide what the agent can reach |
| Model choice and lock-in | Models outside the vendor’s own, framework portability | The deepest form of lock-in |
| Governance and audit | Policy engine, tool-call authorisation, registries, audit trail | Auditors ask for this first |
| Observability | OpenTelemetry output, traces per tool call, cost attribution | Needed to debug and to bill back |
| Pricing model | Published rates, predictability, what is metered | Determines the unit economics of every agent |
| Data residency | Regions, EU options, self-hosted or hybrid editions | Often a hard constraint, not a preference |
Breadth of the platform counted for more than any single feature. A runtime that does identity, memory, tools and policy well but only in one cloud still beat a narrower product with more flexible hosting, because most enterprise buyers already have a cloud. Where we could not verify a feature from a primary source, we treated it as absent.

Figure 1: The family a platform belongs to predicts most of its trade-offs before any feature is compared.
The contenders at a glance
| Rank | Platform | Type and licence | Deployment | Best fit |
|---|---|---|---|---|
| 1 | Amazon Bedrock AgentCore | Cloud agent runtime, proprietary | AWS regions, serverless | AWS estates wanting any framework and any model |
| 2 | Microsoft Foundry Agent Service | Cloud agent runtime, proprietary | 31 Azure regions for hosted agents | Microsoft 365 and Entra shops |
| 3 | Gemini Enterprise Agent Platform | Cloud agent runtime, proprietary | 23 Google Cloud regions | Google Cloud teams, long-running agents |
| 4 | LangSmith Deployment | Framework platform, proprietary over MIT libraries | Cloud (US or EU), hybrid, self-hosted | Engineering teams wanting portability across clouds |
| 5 | Salesforce Agentforce 360 | Enterprise suite, proprietary | Salesforce cloud | Sales, service and commerce agents on CRM data |
| 6 | ServiceNow AI Agents | Enterprise suite, proprietary | ServiceNow instances | IT, HR and operations workflows, cross-vendor oversight |
| 7 | OpenAI Agents SDK and Agents API | Framework plus hosted beta, SDK open source | OpenAI-hosted (US only) or self-run SDK | Teams building on OpenAI models with code |
| 8 | CrewAI AMP | Framework platform, proprietary over MIT library | AMP Cloud, private VPC, self-hosted Factory | Multi-agent crews with A2A |
| 9 | n8n | Workflow builder, Sustainable Use License | Cloud (Frankfurt) or self-hosted | Automation-heavy agents across 1,500+ integrations |
| 10 | Dify | Workflow builder, Dify Open Source License | Cloud (AWS US-East), dedicated, VPC, self-hosted | Low-code agent and RAG apps |
The tenth place was close. Microsoft Copilot Studio and Zapier Agents both have large installed bases, but both sit closer to end-user automation than to a runtime an engineering team deploys onto, so we left them out.
1. Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is a set of managed services for running agents built with any framework and any model: Runtime, Gateway, Identity, Memory, Policy, Observability and a registry. It became generally available on 13 October 2025 in nine regions and has since added Bangkok, Malaysia, Milan and Spain.
Runtime. Each session runs in its own microVM with dedicated CPU, memory and filesystem; sessions last up to eight hours or end after 15 minutes of inactivity, after which the microVM is destroyed and its memory cleared, according to the Runtime documentation. The runtime speaks HTTP, MCP and A2A, and callers authenticate with IAM SigV4 or OAuth 2.0 from Cognito, Okta or Entra ID.
Identity, tools and policy. Agents call out with OAuth or API keys, either on behalf of a user or autonomously. Gateway turns APIs and Lambda functions into MCP tools and connects existing MCP servers. Policy reached general availability on 3 March 2026: rules written in natural language compile to Cedar and are checked by Gateway on every tool call. That is the most concrete tool-call authorisation model of any entry here.
Models and frameworks. AgentCore accepts models inside and outside Bedrock and frameworks including LangGraph, CrewAI, LlamaIndex, Google ADK, the OpenAI Agents SDK and Strands. Observability goes to CloudWatch with OpenTelemetry-compatible output.
Pricing. The pricing page lists Runtime at $0.0895 per vCPU-hour and $0.00945 per GB-hour on the first-generation platform, Gateway at $0.005 per 1,000 invocations, long-term memory at $0.75 per 1,000 records a month and Policy at $0.000025 per request.
Limitations. The eight-hour session cap rules out some long-running agents without checkpointing. The faster second-generation runtime costs more ($0.1276 per vCPU-hour), is in only five regions and cannot yet be selected through CloudFormation or CDK. AWS’s developer guide now names the policy language “Dogwood (Cedar-compatible)” while the GA notice says Cedar, which is worth confirming before writing policies.
Best fit: AWS-standardised enterprises that want framework and model freedom inside their existing IAM, VPC and audit setup.
2. Microsoft Foundry Agent Service
Microsoft Foundry Agent Service is Microsoft’s managed runtime for prompt, voice and hosted agents; the documentation now uses “Microsoft Foundry” where it used to say Azure AI Foundry. Hosted Agents and Toolboxes became generally available on 9 July 2026.
Runtime. A hosted agent session runs in its own VM-isolated sandbox at 0.5, 1 or 2 vCPUs, with up to 20 GiB of disk. Idle timeout is configurable from 2 to 60 minutes; compute scales to zero and session files are restored on resume, and sessions are deleted after 30 days without activity.
Identity. This is Foundry’s strongest point. Every agent gets a Microsoft Entra Agent ID, supports on-behalf-of and app-only flows, and falls under Conditional Access and identity protection in the Entra admin centre. For a company whose access reviews already run in Entra, agents arrive in the same console as people.
Tools and protocols. The service overview lists Toolboxes that expose an agent’s tools through one managed MCP endpoint, support for remote MCP servers, and A2A v1.0 as generally available. Hosted agents can be written with Microsoft Agent Framework, LangGraph, the OpenAI Agents SDK, the Anthropic Agent SDK or custom code. Traces go to Application Insights as OpenTelemetry by default.
Pricing. Microsoft’s pricing page shows placeholders for hosted-agent rates and says prompt and workflow agents carry no charge beyond model and tool use. Azure’s public retail-prices API lists hosted compute in East US at $0.0994 per vCPU-hour and $0.0118 per GiB-hour, with long-term memory at $0.25 per 1,000 memories a month.
Limitations. Hosted agents are Python and C# only. There is no traffic splitting between agent versions, and publishing an agent issues a new identity whose role assignments must be redone. Managed memory was in public preview at Build in June 2026, and we could not confirm a later GA.
Best fit: organisations on Microsoft 365 and Entra that want agent identities governed exactly like employee identities.
3. Google Gemini Enterprise Agent Platform
Google renamed Vertex AI as Gemini Enterprise Agent Platform on 23 April 2026, and the hosting layer formerly known as Vertex AI Agent Engine is now Agent Runtime. Agent Runtime, Memory Bank and Agent Identity were announced as generally available on 30 July 2026. The separate Gemini Enterprise product is the employee-facing app, not the runtime.
Runtime. Agent Runtime is serverless, claims sub-second cold starts and lets agents run continuously for up to seven days, the longest documented run length in this list. Idle time between turns is not billed.
Identity. Each agent receives a SPIFFE-based identity with an x509 certificate and certificate-bound tokens, governed by ordinary IAM allow, deny and principal-access-boundary policies, per the agent identity documentation. Each new deployment creates a new principal, and legacy Cloud Storage bucket roles are not supported.
Tools, models and governance. ADK is fully supported, with managed templates for LangChain, LangGraph, AG2 and LlamaIndex and a custom template for CrewAI or anything else. Model Garden lists more than 200 models including Anthropic’s. Agent Gateway combines IAM conditions with natural-language rules and Model Armor screening for prompt injection and tool poisoning; an Agent Registry tracks agents and tools. A2A is still marked preview in the runtime docs. Observability uses OpenTelemetry GenAI semantic conventions with Cloud Trace.
Pricing and residency. The pricing page lists $0.085 per vCPU-hour and $0.009 per GiB-hour, with 50 free vCPU-hours a month; Agent Gateway costs one vCPU-hour per 15,000 calls and Memory Bank one vCPU-hour per million writes. Agent Runtime runs in 23 regions, including seven in Europe, with data at rest kept in the chosen region.
Limitations. Customer-managed encryption keys do not work with global endpoints, Memory Bank and Agent Gateway are missing from several Asia-Pacific regions, and many APIs are still v1beta1. The rename also means older Vertex tutorials and Terraform modules need checking.
Best fit: Google Cloud customers, and any team whose agents need to run for days rather than hours.
4. LangSmith Deployment
LangSmith Deployment, formerly LangGraph Platform, is LangChain’s hosted runtime for agents, built around an Agent Server that models work as assistants, threads and runs with durable execution. Despite the LangGraph heritage, the deployment docs describe it as framework-agnostic, listing LangGraph, LangChain, Google ADK, the Claude Agent SDK, Strands, CrewAI and AutoGen.
Hosting. This is the most flexible entry among those that are fully managed. Four models are offered: cloud managed by LangChain in the US or EU, a hybrid with LangChain’s control plane and the customer’s data plane, fully self-hosted on Kubernetes, and a standalone Agent Server in Docker with no control plane.
Protocols. Agent Server exposes an MCP endpoint at /mcp using Streamable HTTP, so a deployed agent becomes a tool for any MCP client, and an A2A endpoint at /a2a/{assistant_id} that speaks A2A v1.0 and still accepts v0.3 method names. A2A conversation IDs are mapped to LangSmith threads, so multi-agent traces stay grouped.
Observability and governance. Tracing is the product LangSmith started as, and it remains the best-integrated tracing of any entry. Identity and governance are thinner: SSO and RBAC are present, but there is no equivalent of an Entra Agent ID or a Cedar policy check on tool calls.
Pricing. The pricing page lists Developer at $0 per seat, Plus at $39 per seat a month with one free small serverless deployment, and custom Enterprise pricing for hybrid and self-hosted. Deployments are metered in LangSmith Standard Units at $1 each: runtime compute at 0.0675 LSU per vCPU-hour, memory at 0.009 LSU per GiB-hour and database compute at 0.177 LSU per vCPU-hour. Older per-node and uptime pricing was retired, with existing customers grandfathered until 1 October 2026.
Limitations. Identity and permissions must be built from the customer’s own IdP and secrets store. Self-hosting is enterprise-only. Teams coming from per-run billing should rebuild their cost model, because the switch to resource metering changes which workloads are cheap.
Best fit: engineering-led teams that want one agent runtime across clouds, or a self-hosted runtime with first-class tracing.
5. Salesforce Agentforce 360
Agentforce 360 is Salesforce’s agent platform, made generally available on 13 October 2025. It bundles the Atlas Reasoning Engine, Data 360, Customer 360 applications and Slack, with Agentforce Builder for natural-language agent design and Agent Script for mixing deterministic steps with model reasoning.
Strengths. Agents run next to the CRM records, sharing rules and field-level permissions the company already maintains, which is the hardest thing to replicate on a general-purpose runtime. The Agentforce 3 release added a Command Center for monitoring built on OpenTelemetry, a native MCP client that connects agents to any MCP-compliant server, and MuleSoft tooling to expose APIs to agents. Salesforce also hosts Anthropic’s Claude via Amazon Bedrock inside its trust boundary, and claimed 50 per cent lower latency since January 2025.
Pricing. The pricing page offers several models. Flex Credits cost $500 per 100,000; a standard action uses 20 credits ($0.10) and a voice action 30. Customer-facing agents can instead be billed at $2 per conversation. Per-user add-ons cost $125 a month for Sales, Service and Field Service and $150 for Industries clouds with unmetered employee use, and Agentforce editions start at $550 per user a month including 2.75 million Flex Credits per org a year.
Limitations. Model choice is the narrowest among the top six: agents use the models Salesforce hosts or brokers, not an arbitrary endpoint. Agents built here are Salesforce artefacts and do not move to another runtime. The flexibility of the pricing is also its difficulty: the same workload can cost very different amounts depending on which model is chosen. At 5,000 conversations a month with three actions each, Flex Credits come to $1,500, against $10,000 under per-conversation billing.
Best fit: companies whose agents will mostly read and write Salesforce data for sales, service and commerce.
6. ServiceNow AI Agents and AI Control Tower
ServiceNow’s agent stack combines AI Agent Studio for building, AI Agent Orchestrator for coordinating multiple agents, and AI Control Tower for governing them. Its distinguishing feature is that Control Tower is designed to oversee agents running elsewhere.
Strengths. The May 2026 expansion of AI Control Tower added discovery through 30 integrations including AWS, Google Cloud, Azure, SAP, Oracle and Workday; runtime observability from the Traceloop acquisition; five risk frameworks aligned to NIST and the EU AI Act; and identity governance through Veza that can detect and stop agents acting beyond their permissions. On protocols, ServiceNow’s MCP and A2A guide documents an MCP client and server (protocol version 2025-06-18, Streamable HTTP or SSE, OAuth 2.1 or API keys) and A2A v0.3, from Zurich Patch 4 and Yokohama Patch 11.
Pricing. ServiceNow does not publish list prices. AI agent capabilities are included with Pro Plus and Enterprise Plus packages, and usage is metered in “assists” on top of the subscription. A2A requires a Pro Plus or Enterprise SKU with Now Assist.
Limitations. Assist consumption per interaction varies, which makes bills hard to forecast. The MCP client does not support stdio servers, so local tools need a remote wrapper. Several Control Tower enhancements were in ServiceNow’s Innovation Lab in May with general availability expected in August 2026; buyers should confirm which features are GA on their instance and release.
Best fit: enterprises that run IT, HR and operations on ServiceNow and want one governance console that also inventories agents on the hyperscaler runtimes.
7. OpenAI Agents SDK and Agents API
OpenAI’s agent story changed sharply in 2026. AgentKit paired a visual Agent Builder with the Agents SDK and evaluation tooling. OpenAI’s deprecations page now says Agent Builder was deprecated on 3 June 2026 and shuts down on 30 November 2026, with Evals going read-only on 31 October; the Assistants API was removed on 26 August 2026. The replacements are the Agents SDK and a new hosted Agents API.
Strengths. The Agents API, in public beta since 10 September 2026, runs a stateful agent loop in OpenAI-hosted or self-hosted sandboxes, with computer use added on 29 September. The Agents SDK is open source, supports MCP, guardrails and tracing with OpenTelemetry-compatible processors, persists sessions to SQLite, Redis, MongoDB and others, and can call other providers’ models through adapters. For teams already building on OpenAI models, it is the shortest path from prototype to a hosted agent.
Pricing. Hosted containers cost $0.03 per 20-minute session at 1 GB, rising to $1.92 at 64 GB; web search is $10 per 1,000 calls and file search $2.50 per 1,000, plus model tokens.
Limitations. The hosted Agents API is a beta with US data residency only and no Zero Data Retention option, which rules it out for many regulated workloads. We found no documented agent identity or OAuth model beyond API keys, no A2A support and no published maximum run duration. Companies that built visual workflows in Agent Builder face a migration within weeks. The ranking reflects that churn, not the quality of the models.
Best fit: product teams building in code on OpenAI models who can accept US-only hosting, or who will run the SDK on their own infrastructure.
8. CrewAI AMP
CrewAI AMP (Agent Management Platform) is the managed home for agents built with the open-source CrewAI framework: deployment from GitHub, a CLI or the no-code Crew Studio, REST access, webhook streaming, a tool repository and execution traces.
Strengths. CrewAI has leaned furthest into multi-agent interoperability. A2A on AMP supports protocol versions 0.2 and 0.3 and, on deployment, provisions distributed state, authentication and endpoints at both the crew and the individual-agent level. AMP connects to MCP servers that are public, protected by API key or bearer token, or behind OAuth 2.0, and can export crews as MCP servers. Deployment options run from AMP Cloud to a private VPC to Factory, a self-hosted edition on AWS, Azure or GCP intended for data-residency requirements.
Pricing. The pricing page lists a free Basic tier with 50 workflow executions a month, tracing with OpenTelemetry and a usage dashboard. Everything else is Enterprise at a custom price: SSO with Entra or Okta, RBAC, workload identity, PII redaction, policies, private VPC or self-hosting, and a 45-day onboarding programme. A $25 Professional tier existed after the October 2025 launch and has since been removed.
Limitations. With no published mid-tier, cost is opaque until a sales conversation, and every governance feature that matters to an enterprise is behind the Enterprise contract. The platform is optimised for CrewAI’s crew-and-task abstraction; teams on other frameworks get less from it than from LangSmith or the hyperscalers.
Best fit: teams already committed to CrewAI that want multi-agent crews exposed over A2A, with a self-hosted path.
9. n8n
n8n is a workflow automation platform that has become an agent platform by making the agent a node: an AI Agent node with model, memory and tool sub-nodes, inside workflows that can reach more than 1,500 integrations. It is source-available under the Sustainable Use License, with enterprise features under a separate n8n Enterprise License.
Strengths. n8n uses MCP in both directions: the MCP Client Tool node lets an agent use tools from external servers, with bearer, header or OAuth2 authentication, and the MCP Server Trigger exposes n8n workflows as tools to any MCP client over SSE or Streamable HTTP with bearer or header authentication. Model choice is open across OpenAI, Anthropic, Google and open-weight models. For agents whose real work is moving data between SaaS systems, nothing else on this list has as many prebuilt connectors.
Pricing and residency. The pricing page lists Starter at €20 a month for 2,500 executions and Pro at €50 for 10,000 (annual billing), Business at €667 for 40,000 (self-hosted only), and custom Enterprise with log streaming, external secret stores and 200 or more concurrent executions. An execution is a workflow run regardless of node count, which makes agent costs easy to predict. Hosted data stays in Frankfurt; the Community Edition is free to self-host.
Limitations. n8n has no per-agent identity: agents act with the credentials stored in the workflow. In queue mode with several webhook replicas, MCP connections break unless /mcp traffic is pinned to one replica, according to the node documentation. The Sustainable Use License limits use to internal business purposes, so offering n8n to third parties as a paid service needs an Enterprise License.
Best fit: operations and automation teams that want agents embedded in integration-heavy workflows, especially in the EU or self-hosted.
10. Dify
Dify is a low-code platform for building agentic workflows, chat assistants and RAG pipelines, offered as Dify Cloud, a dedicated single-tenant service, a customer VPC deployment or self-hosted community edition. The repository carries the Dify Open Source License, based on Apache 2.0 with additional conditions.
Strengths. Dify’s visual builder covers the whole path from knowledge base to published app, and it supports hundreds of proprietary and open-weight models through provider plugins. Its MCP integration imports tools from MCP servers over HTTP with OAuth via dynamic client registration, manual OAuth credentials or custom headers, and Dify apps can themselves be published as MCP servers. Dify reports SOC 2 Type II and ISO 27001:2022 audits.
Pricing. The pricing page lists a free Sandbox with 200 message credits, Professional at $590 per workspace a year with 5,000 message credits a month and three members, and Team at $1,590 a year with 10,000 credits, 50 members and 200 apps. Enterprise, with SSO and multiple workspaces, is custom.
Limitations. Dify Cloud’s documentation says user data is stored on AWS in US-East, so EU teams need the dedicated, VPC or self-hosted options. As an MCP client it supports HTTP transport only. Identity, audit and policy are workspace-level rather than per-agent, and the licence’s extra conditions need legal review before multi-tenant use.
Best fit: business and product teams building assistants and RAG apps quickly, with a self-hosted path when data cannot leave.
What actually differs between managed agent platforms
Once the lists are laid side by side, five differences remain.
Identity is the real lock-in
The hyperscalers have each made the agent a first-class principal: AgentCore through IAM and OAuth, Foundry through Entra Agent ID, Google through SPIFFE certificates. That is good security practice, and it is also the stickiest part of the platform, because every tool permission is written against that identity. Suites inherit their own role models. Framework platforms and builders largely leave identity to the customer. Choose the identity system first and the runtime follows.
Run length and isolation
Documented maximums range from eight hours per session on AgentCore to seven days on Google’s Agent Runtime, with Foundry scaling idle sessions to zero and keeping them for 30 days. All three hyperscalers isolate sessions in a microVM or VM sandbox. Agents that wait on humans for approval, or batch jobs that run overnight, are where these numbers start to matter.
Protocol maturity
MCP is everywhere; A2A is not yet uniform. Foundry and LangSmith speak A2A v1.0, CrewAI and ServiceNow document v0.3, Google lists A2A as preview and OpenAI documents none. Teams planning cross-platform agent calls should test the specific version pair, not the protocol name. For background on MCP itself, see our MCP gateway explainer.
What is metered
| Platform family | Unit billed | Example list rate (Oct 2026) |
|---|---|---|
| AgentCore | vCPU-hour, GB-hour, per call | $0.0895 per vCPU-hour; $0.005 per 1,000 Gateway calls |
| Foundry hosted agents | vCPU-hour, GiB-hour | $0.0994 per vCPU-hour (East US) |
| Google Agent Runtime | vCPU-hour, GiB-hour | $0.085 per vCPU-hour; idle not billed |
| LangSmith Deployment | LSU per resource-hour, seats | 0.0675 LSU per vCPU-hour; Plus $39 per seat |
| Agentforce | Action, conversation or user | $0.10 per action; $2 per conversation |
| n8n | Workflow execution | €50 a month for 10,000 (Pro) |
| Dify | Message credits, workspace | $590 a year for 5,000 credits a month |
For a single agent session of one vCPU and 2 GB running for an hour, compute at list price is about $0.11 on AgentCore, $0.10 on Google and $0.12 on Foundry, before model tokens. Those differences are small next to model costs, which is why model choice and routing usually matter more to the bill than the runtime’s rate card. Our piece on inference prices covers that side.
Residency and self-hosting
Only the framework platforms and builders offer self-hosted or hybrid editions: LangSmith (hybrid and self-hosted), CrewAI (Factory), n8n (Community and Business) and Dify (community, VPC and dedicated). The hyperscalers offer regional choice instead, and the suites offer their own region programmes. OpenAI’s hosted Agents API is US-only.

Figure 2: Platforms own the runtime; a neutral layer underneath can own the policy, so it stays the same whichever platform an agent runs on.
Avoiding lock-in and keeping governance consistent across platforms
Most large companies will not pick one platform. Sales runs Agentforce, IT runs ServiceNow, the data team deploys to AgentCore or Foundry, an operations team builds in n8n, and developers run coding agents with local MCP servers on their laptops. Each platform has its own budget controls, guardrails, tool permissions and audit log, and none of them can see the others. The result is the same problem we described in our piece on shadow AI governance, applied to agents: policy written five times, in five formats, with gaps between them.
The fix is to separate the runtime from the policy. Every agent, wherever it runs, makes two kinds of outbound call: to a model and to tools. If both go through one neutral gateway, the policy for those calls is written once.
Bifrost, an open-source AI gateway written in Go by Maxim AI, is one way to build that layer. It is not a contender in this ranking because it does not host agents; it sits underneath them.
- Model traffic. Agents on AgentCore, Foundry, Google, LangSmith or n8n can point their model endpoint at Bifrost instead of a provider. Virtual keys then decide which providers and models each agent or team may use, with budgets that cascade from customer to team to key and rate limits per key. Swapping a model becomes a gateway change rather than a redeployment on each platform, which is the most direct defence against model lock-in.
- Tool traffic. As an MCP gateway, Bifrost acts as both an MCP client to internal servers and an MCP server to agents, with per-key tool filtering, OAuth to upstream servers and an Agent Mode for approved auto-execution, according to the MCP documentation. A Salesforce agent’s native MCP client and a CrewAI crew can reach the same internal tools through one allow-list and one audit trail.
- Policy and audit. Centralised AI governance covers RBAC, SSO with Okta, Entra or Google Workspace, SCIM provisioning and immutable audit logs exportable to a SIEM. Guardrails apply PII redaction, prompt-injection and secrets detection, or route checks to AWS Bedrock Guardrails, Azure Content Safety or Google Model Armor, so the same rule applies whichever runtime sent the request.
- Observability. Gateway-level observability emits OpenTelemetry traces with GenAI semantic conventions, Prometheus metrics and per-key cost, which gives finance one cost view across every platform’s agents.
The laptop is the gap that platform-level governance cannot close. Coding agents and desktop assistants with locally configured MCP servers never touch a managed runtime. Bifrost Edge, runs on macOS, Windows and Linux machines, is pushed by Jamf, Intune or Kandji, and routes chat apps, browser AI, coding agents and MCP servers through the same Bifrost policy. Its MCP governance builds an inventory of the MCP servers configured on each device, for clients including Claude Code, Codex, Cursor and Gemini CLI, and enforces allow or deny on the machine.
The added latency is negligible: Bifrost’s published benchmarks report 11 µs of gateway overhead at 5,000 requests per second on a t3.xlarge, so real-world latency is dominated by the model. Some platform-native controls, such as Agentforce’s record-level permissions or AgentCore’s Cedar checks on tool calls, should stay where they are, because they depend on context only the platform has. The gateway governs the traffic between platforms and the outside world; it does not replace each platform’s internal authorisation. Teams weighing self-hosted gateway options can compare them in this review of open-source LLM gateways for self-hosted deployments, and our own comparison of LLM gateways covers the trade-offs in detail.

Figure 3: The constraint that cannot move picks the platform; having more than one constraint is the case for a neutral layer.
Recommendations by constraint
You are standardised on AWS. Use Amazon Bedrock AgentCore. Its Cedar-based Policy on tool calls is the most concrete authorisation model available, and it does not restrict the model or framework. Plan for the eight-hour session cap.
Your identity system is Entra. Use Microsoft Foundry Agent Service. Agent identities appear in Entra beside employee identities, under the same Conditional Access rules. Confirm that Python or C# suits your team.
Your agents run for days, or you are on Google Cloud. Use Gemini Enterprise Agent Platform. The seven-day run length and unbilled idle time suit agents that wait on people. Check A2A preview status and regional gaps first.
You need one runtime across clouds, or self-hosting with strong tracing. Use LangSmith Deployment, in hybrid mode if the data plane must stay inside your network.
The agent’s job is your CRM or service desk. Use Agentforce 360 for Salesforce data and ServiceNow for IT and HR workflows. Model the cost under each pricing option before signing, because the gap between them is large.
You must self-host or keep data in the EU. Look at LangSmith (hybrid or self-hosted), CrewAI Factory, n8n (hosted in Frankfurt or self-hosted) and Dify (VPC or self-hosted).
You are building on OpenAI models. Use the open-source Agents SDK on your own infrastructure until the hosted Agents API leaves beta and offers residency outside the US. Migrate any Agent Builder workflows before 30 November 2026.
You will end up on several of these. Most enterprises will. Put a neutral gateway under model and MCP traffic from the start and extend it to employee machines, so that budgets, guardrails, tool allow-lists and audit logs do not fragment as platforms multiply. For framework-level choices inside each runtime, see our survey of agent frameworks.
The verdict
The managed agent platform market has consolidated faster than the agent frameworks underneath it. The three hyperscalers now offer comparable runtimes at comparable prices, and the real decision is which identity system and which data your agents will live with. The suites win wherever the data already lives in them. The framework platforms and builders are the route to self-hosting.
The ranking matters less than the architecture around it. A company that picks the best platform and writes all its policy inside it has bought a runtime and a lock-in at the same time. A company that keeps model and tool policy in a neutral layer can run three platforms today and change one next year without rewriting its governance.
Feature claims are drawn from public documentation and vendor announcements as of October 2026; check current docs before deciding.
Sources
- Amazon Bedrock AgentCore is now generally available Amazon Web Services
- How AgentCore Runtime works Amazon Web Services
- Amazon Bedrock AgentCore pricing Amazon Web Services
- Policy in Amazon Bedrock AgentCore is generally available Amazon Web Services
- What is Microsoft Foundry Agent Service? Microsoft
- Hosted agents in Foundry Agent Service Microsoft
- Agent identity concepts in Microsoft Foundry Microsoft
- Introducing Gemini Enterprise Agent Platform Google Cloud
- What's new in Gemini Enterprise Agent Platform Google Cloud
- Gemini Enterprise Agent Platform pricing Google Cloud
- Agent identity in Agent Runtime Google Cloud
- Agent Platform locations Google Cloud
- LangSmith pricing LangChain
- LangSmith Deployment overview LangChain
- A2A endpoint in Agent Server LangChain
- Welcome to the Agentic Enterprise: with Agentforce 360, Salesforce elevates human potential in the age of AI Salesforce
- Salesforce launches Agentforce 3 Salesforce
- Agentforce pricing Salesforce
- ServiceNow expands AI Control Tower to discover, observe, govern, secure and measure AI deployed across any system ServiceNow
- Enable MCP and A2A for your agentic workflows ServiceNow
- OpenAI API deprecations OpenAI
- Agents API overview OpenAI
- CrewAI pricing CrewAI
- A2A on AMP CrewAI
- n8n plans and pricing n8n
- n8n MCP Server Trigger node n8n
- Dify pricing LangGenius
- Dify MCP integration LangGenius
- Dify repository and licence LangGenius
- Bifrost MCP gateway overview Maxim AI
- Bifrost virtual keys Maxim AI
- Bifrost Edge overview Maxim AI
- Bifrost Edge MCP governance Maxim AI
Frequently asked questions
What is a managed agent orchestration platform?
A hosted service where a company builds, deploys and runs AI agents without operating the servers itself. It typically supplies an isolated runtime, an identity for each agent, short- and long-term memory, connections to tools over MCP, agent-to-agent calls over A2A, tracing and a pricing model. AgentCore, Foundry Agent Service, Agentforce and LangSmith Deployment are examples.
What is the best managed agent platform for enterprises in 2026?
There is no single winner. For teams already standardised on a hyperscaler, that cloud's runtime (Amazon Bedrock AgentCore, Microsoft Foundry Agent Service or Google's Gemini Enterprise Agent Platform) is usually right. For agents that act on CRM or IT service records, Agentforce or ServiceNow fit better. For self-hosting, LangSmith, CrewAI AMP, n8n and Dify are the options.
What happened to Vertex AI Agent Engine and Azure AI Foundry?
Google renamed Vertex AI as Gemini Enterprise Agent Platform on 23 April 2026, and Agent Engine's hosting layer is now called Agent Runtime. Microsoft's documentation now uses Microsoft Foundry and Foundry Agent Service in place of Azure AI Foundry. The underlying services continue under the new names.
Is OpenAI Agent Builder being discontinued?
Yes. OpenAI's deprecations page says Agent Builder was deprecated on 3 June 2026 and shuts down on 30 November 2026, and points users to the Agents SDK or ChatGPT Workspace Agents. OpenAI's newer hosted Agents API entered public beta on 10 September 2026 with US data residency only.
Which agent platforms support both MCP and A2A?
AgentCore Runtime speaks MCP and A2A; Foundry Agent Service lists A2A v1.0 as generally available with managed MCP toolboxes; Google's Agent Runtime supports MCP with A2A in preview; LangSmith's Agent Server exposes /mcp and /a2a endpoints; CrewAI AMP supports A2A 0.2 and 0.3; ServiceNow supports both from Zurich Patch 4. Agentforce has a native MCP client.
How do you avoid lock-in with a managed agent platform?
Keep the parts that encode policy outside the platform. Point agents' model calls and MCP tool calls at a neutral gateway such as Bifrost, so budgets, guardrails, tool allow-lists and audit logs live in one place, and keep agent logic in a portable framework rather than a proprietary visual builder.
How are managed agent platforms priced?
Three models dominate. Hyperscalers bill compute by vCPU-hour and GB-hour plus per-call fees for gateways and memory. Enterprise suites bill per action, per conversation or per user licence. Framework platforms and builders bill by seats, executions, credits or metered resources, with self-hosted editions priced separately.


