Architecture · · 7 min read
Local, cloud, or hybrid: map an agent's real data boundary
The location of the phone is the least useful architecture fact. Follow code, model context, tools, and control decisions instead.

A mobile app does not tell you whether a coding agent is local or cloud-based. The phone may be a remote control for a process on your laptop, a viewer for a cloud worker, or a client for a hybrid system where the agent loop and file tools live in different places. Even the word “local” can hide a model call to a hosted service. To understand privacy, availability, and failure behavior, follow four flows separately: repository source, model context, tool execution, and human control. A single arrow labeled “agent” is not a sufficient architecture diagram.
The official documentation we checked on October 3, 2026 describes distinct routes. Claude Code Remote Control exposes a local Claude Code process through the Claude app or web under its documented requirements. Cursor for iOS can start cloud agents and use Remote Control for work involving a personal machine; Cursor describes a cloud agent loop with tools that may execute on the user's computer in that route. OpenAI's Codex mobile preview describes connected machines and live state. GrantTap coordinates supported local agent executions through an encrypted relay between trusted devices. Each path can be appropriate. The decision depends on exactly which component receives code and commands.
Draw the repository path first
Ask where the authoritative checkout lives and how a worker reaches it. A local process reads a local repository directly. A cloud agent may clone a repository into a remote environment and produce a branch or pull request. A hybrid arrangement can keep file tools on the user's computer while a control loop runs elsewhere. Those patterns have different implications for network outages, uncommitted changes, dependencies, and secrets. If your work relies on a file that exists only on a laptop, a cloud clone cannot see it unless you deliberately transfer or commit it.
Cursor's cloud security documentation describes repository access via its Git provider integration and the cloud environment's data handling. Its mobile docs distinguish cloud workers and personal machines. Claude Remote Control keeps a local process relevant and documents what happens when its server stops. GrantTap's local control model depends on a paired computer and its installed provider integration. These are implementation boundaries, not moral labels. For a given Task, write down the checkout path, revision, and worker identity. A user should not have to infer them from a device icon or a friendly session title.

Follow model context separately from files
Where files are stored is not necessarily where model input is processed. A local agent can read local files, select excerpts, and send those excerpts to a remote model service. A cloud agent can keep a working copy in its own environment and call a model through the same provider's service. An encrypted control relay may protect messages in transit between a phone and computer without changing the model provider's own context path. Do not collapse these into the blanket statement “your code stays local.” That statement requires a precise definition of code, storage, processing, and retention.
Before adopting a route for sensitive work, inspect the provider's current data handling documentation and organization controls. Ask whether repository contents are copied, how long execution artifacts are retained, which model providers receive prompts, and which administrators can configure access. Cursor's security docs explicitly discuss Privacy Mode and the cloud storage needed for cloud agents; its legacy mode is a different configuration. Claude and Codex have their own account and service requirements. GrantTap does not replace those vendor terms merely by controlling a local execution. The honest answer is a map of participating services, with each service's current documentation attached.
Locate commands and credentials
Tool execution is the point where an agent changes the world. A shell command on a laptop sees that laptop's filesystem, network access, and environment variables. A command in a cloud VM sees the VM's configured secrets and repository clone. A hybrid route needs both sides to be available when a command is requested. This affects safety and reliability more directly than the phone's visual design. If a task uses production credentials, check which worker actually holds them and whether its network is restricted. Never assume an approval prompt alone creates a sandbox.
Cursor says its cloud agents run in dedicated machines and documents security controls for them. Its mobile route can direct work involving a personal computer under the documented Remote Control design. Claude Remote Control preserves a local tool environment for the connected process. GrantTap's local helper observes and controls supported provider activity on a paired computer; it does not make a cloud worker local. For every route, record one representative command, the machine that ran it, the permissions it had, and where the output was stored. If the product cannot expose that route, test it with a harmless file and network request before entrusting sensitive tasks to it.

Trace the control message
Human control is another path. A phone can receive a request via a provider service or an encrypted relay, but the decision needs to reach the execution runtime. If the phone loses connectivity, the runtime should follow its configured default, not guess an approval. If the computer is offline, the app should show a delayed or unknown state. If the provider uses a cloud worker, the relevant policy belongs to that worker's tool boundary. The strongest evidence is a host- or worker-side record that the proposed action was allowed or denied before it ran.
GrantTap separates the paired device network, Task policy, and the provider's own execution state. That distinction helps prevent a green relay indicator from being mistaken for a ready approval path. The screenshot here is a deterministic product capture; it is not a proof that an external provider's model context remained on a device. For your architecture review, disconnect one link at a time: phone, relay, local computer, or provider service. Record what continues and what stops. A design that reports uncertainty clearly during those interruptions is easier to operate than one that keeps showing a confident but stale status.
Choose according to the failure you can tolerate
Local work can preserve access to an uncommitted checkout and existing tools, but it needs an available computer. Cloud work can continue without the user's laptop, but requires its own repository access, environment, and data handling review. Hybrid work may combine familiar local tools with remote coordination, at the cost of more connections whose status must be understood. These are architectural tradeoffs, not a universal ranking. A team may use different paths for a scratch prototype, a private repository, and a production incident.
Run a small evaluation before standardizing one route. Start a Task, note the repository revision, lock the phone, disconnect the laptop, and inspect the resulting state. Then reconnect and verify the exact command, changed files, and test output. Repeat with a second provider only if your workflow actually uses it. Keep the resulting data-flow map alongside the provider docs and revisit it when the products change. The most useful mobile agent is the one whose execution and authority you can explain when something goes wrong, not merely the one whose screen looks most complete.
