Three pods, six to nine people. Buy where the surface is commoditized, build where the security model lives, open-source the parts that need to outlive any one vendor — including yours.
Pod 1 — Platform (3–4): orchestrator, routing, audit, policy. Senior engineers, cross-cloud literacy, security-forward mindset. This is the load-bearing pod. The credential model and audit chain live here.
Pod 2 — Surfaces (2–3): Chat, Code, Flows or whatever the customer-facing modes are. Designers + engineers. This is where most of the perceived product lives.
Pod 3 — Trust (1–2): security, eval harnesses, compliance documentation, customer audits. Reports up to the same lead as Platform — no separate fiefdom.
Buy: model providers (don't train your own foundation model), observability, IdP. Build: orchestration, routing, audit, the security model that wraps everything. Open-source: the orchestrator core. Why? Because 94% of IT leaders fear AI vendor lock-in; the only durable answer is "the leverage is the agent, not the lock-in." We MIT'd the AgenticWork core as OpenAgentics for exactly this reason.
Hire shape: 2 staff+ engineers, 3–4 senior engineers, 1 design engineer, 1 trust/compliance engineer, 1 PM-of-record. ~$3M/yr fully loaded. This shipped real revenue inside one calendar quarter.