{"title":"The Managed-Agent Compliance Gap: Where OpenAI’s New Agents API Can Actually Run","description":"At launch, the managed harness supports customer-controlled execution through self-hosting, but the OpenAI-managed control plane keeps agent sessions non-ZDR and U.S.-resident. That leaves no sampled configuration documented to combine ZDR, full-stack non-U.S. residency, retained sessions, and managed file-capable execution.","dataset_id":"spd:the-managed-agent-compliance-gap-where-openai-s-new-agents-api-can-actually-run-55aac41e","canonical_url":"https://superpowerdaily.com/research/the-managed-agent-compliance-gap-where-openai-s-new-agents-api-can-actually-run-55aac41e","version_url":"https://superpowerdaily.com/research/the-managed-agent-compliance-gap-where-openai-s-new-agents-api-can-actually-run-55aac41e","version":"v1","snapshot_hash":"d02923197e65636749df292fc0ab44aae8ce8fa08ba22566d644eca528e4d683","date_created":"2026-09-12T03:57:57.104Z","date_modified":"2026-09-12T03:57:57.104Z","license":{"name":"Superpower Daily data reuse terms","url":"https://superpowerdaily.com/terms"},"license_url":"https://superpowerdaily.com/terms","temporal_coverage":"2026-09-11","coverage_note":"This synthesis uses the supplied public evidence available by September 11, 2026. The sample covers 11 documented execution configurations and excludes private contractual controls and provider enterprise features not publicly documented.","measurement_technique":["Evidence-matrix plan: use rows for OpenAI-hosted, generic self-hosted/customer infrastructure, and each named provider; use columns for control-plane residency, ZDR eligibility, retained session state, execution location, VPC support, file/artifact location, deletion behavior, and provider dependency.","Classify each cell only as supported, incompatible, or unspecified from the supplied public documentation.","Treat OpenAI-managed agent sessions and execution environments as separate layers; do not infer execution-plane geography from the control-plane residency setting.","Count only the bounded launch sample: OpenAI-hosted, generic self-hosted, and nine named provider integrations.","Preserve provider-specific retention, residency, and VPC controls as unspecified where the launch documentation does not normalize them."],"methodology":["Evidence-matrix plan: use rows for OpenAI-hosted, generic self-hosted/customer infrastructure, and each named provider; use columns for control-plane residency, ZDR eligibility, retained session state, execution location, VPC support, file/artifact location, deletion behavior, and provider dependency.","Classify each cell only as supported, incompatible, or unspecified from the supplied public documentation.","Treat OpenAI-managed agent sessions and execution environments as separate layers; do not infer execution-plane geography from the control-plane residency setting.","Count only the bounded launch sample: OpenAI-hosted, generic self-hosted, and nine named provider integrations.","Preserve provider-specific retention, residency, and VPC controls as unspecified where the launch documentation does not normalize them."],"metrics":[{"label":"Verified observations","value":"18","detail":"16 measured fields"},{"label":"Supported claims","value":"9","detail":"9 material findings"},{"label":"Cited sources","value":"12","detail":"12 primary or authoritative"},{"label":"Research score","value":"86","detail":"Automated topic and evidence score"}],"columns":[{"key":"entity","label":"Entity"},{"key":"metric","label":"Metric"},{"key":"value","label":"Value"},{"key":"unit","label":"Unit"},{"key":"observed","label":"Observed"},{"key":"source","label":"Source"},{"key":"transform","label":"Transform"}],"data":[{"unit":null,"value":"until deleted","entity":"/v1/agents","metric":"application-state retention","source":"https://developers.openai.com/api/docs/guides/your-data","observed":"2026-09-11","transform":null},{"unit":null,"value":"until deleted or configured expiry","entity":"/v1/files","metric":"application-state retention","source":"https://developers.openai.com/api/docs/guides/your-data","observed":"2026-09-11","transform":null},{"unit":"configurations","value":"9 of 11","entity":"Launch compatibility sample","metric":"configurations requiring a third-party sandbox provider","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted","observed":"2026-09-11","transform":"Excluded OpenAI-hosted and generic customer-managed self-hosted execution."},{"unit":null,"value":"supported","entity":"Generic self-hosted execution","metric":"customer-VPC execution","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted","observed":"2026-09-11","transform":null},{"unit":null,"value":"incompatible; use self-hosted for a private network","entity":"OpenAI-hosted sandbox","metric":"customer-VPC execution","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted","observed":"2026-09-11","transform":null},{"unit":"days","value":"30 days","entity":"/v1/agents","metric":"default abuse-monitoring retention","source":"https://developers.openai.com/api/docs/guides/your-data","observed":"2026-09-11","transform":null},{"unit":null,"value":"API removal immediate; physical cleanup may continue asynchronously","entity":"Agents API session","metric":"deletion completion","source":"https://developers.openai.com/api/docs/guides/agents-api/sessions/manage","observed":"2026-09-11","transform":null},{"unit":"configurations","value":"11","entity":"Launch compatibility sample","metric":"execution configuration count","source":"https://openai.com/index/introducing-the-agents-api","observed":"2026-09-11","transform":"Counted OpenAI-hosted, generic self-hosted, and nine named provider integrations."},{"unit":"configurations","value":"0 of 11","entity":"Launch compatibility sample","metric":"full-stack non-U.S.-residency configurations","source":"https://developers.openai.com/api/docs/guides/agents-api/overview","observed":"2026-09-11","transform":"Counted only configurations regionalizing both OpenAI control-plane state and execution."},{"unit":"hours","value":"1 hour after activity and keep-alives stop","entity":"OpenAI-hosted sandbox","metric":"idle deletion threshold","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted","observed":"2026-09-11","transform":null},{"unit":"configurations","value":"1 of 11 configurations","entity":"Launch compatibility sample","metric":"OpenAI Artifacts API support","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/files","observed":"2026-09-11","transform":"Counted OpenAI-hosted as supported; generic self-hosted and nine provider configurations use provider or mounted storage."},{"unit":null,"value":"survives sandbox expiry; exact maximum unspecified; deletable","entity":"OpenAI-hosted artifact","metric":"post-sandbox lifetime","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/files","observed":"2026-09-11","transform":null},{"unit":"providers","value":"9","entity":"Named sandbox providers","metric":"provider count","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted","observed":"2026-09-11","transform":"Counted providers in the documentation table."},{"unit":"providers","value":"9 unspecified","entity":"Nine named providers","metric":"provider-specific VPC mapping","source":"https://openai.com/index/introducing-the-agents-api","observed":"2026-09-11","transform":"Compared the aggregate VPC statement with the provider setup guides; none mapped VPC support by provider."},{"unit":null,"value":"does not stop provider compute; separate cleanup required","entity":"Self-hosted environment","metric":"session deletion effect on compute","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/lifecycle","observed":"2026-09-11","transform":null},{"unit":null,"value":"across turns while the sandbox exists","entity":"OpenAI-hosted sandbox","metric":"workspace-file lifetime","source":"https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted","observed":"2026-09-11","transform":null},{"unit":"configurations","value":"0 of 11","entity":"Launch compatibility sample","metric":"ZDR-compatible configurations","source":"https://developers.openai.com/api/docs/guides/agents-api/overview","observed":"2026-09-11","transform":"Applied the documented Agents API-wide ZDR restriction to all sampled environment choices."},{"unit":"configurations","value":"11 of 11","entity":"Launch compatibility sample","metric":"ZDR-incompatible configurations","source":"https://developers.openai.com/api/docs/guides/your-data","observed":"2026-09-11","transform":"Applied /v1/agents ZDR ineligibility to all 11 configurations."}],"sources":[{"url":"https://developers.openai.com/api/docs/guides/agents-api/overview","name":"OpenAI","title":"Agents API | OpenAI API","records":2},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/providers/cloudflare","name":"OpenAI","title":"Cloudflare | OpenAI API","records":0},{"url":"https://developers.openai.com/api/docs/guides/your-data","name":"OpenAI","title":"Data controls in the OpenAI platform","records":4},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/providers/daytona","name":"OpenAI","title":"Daytona | OpenAI API","records":0},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/files","name":"OpenAI","title":"Files and artifacts | OpenAI API","records":2},{"url":"https://openai.com/index/introducing-the-agents-api","name":"OpenAI","title":"Introducing the Agents API","records":2},{"url":"https://developers.openai.com/api/docs/guides/agents-api/sessions/manage","name":"OpenAI","title":"Manage sessions | OpenAI API","records":1},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/providers/modal","name":"OpenAI","title":"Modal | OpenAI API","records":0},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted","name":"OpenAI","title":"OpenAI-hosted sandboxes","records":3},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/lifecycle","name":"OpenAI","title":"Sandbox lifecycle | OpenAI API","records":1},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted","name":"OpenAI","title":"Self-hosted sandboxes | OpenAI API","records":3},{"url":"https://developers.openai.com/api/docs/guides/agents-api/environments/providers/vercel","name":"OpenAI","title":"Vercel | OpenAI API","records":0}],"provenance":{"publisher":"Superpower Daily","source_count":12,"source_urls":["https://developers.openai.com/api/docs/guides/agents-api/overview","https://developers.openai.com/api/docs/guides/agents-api/environments/providers/cloudflare","https://developers.openai.com/api/docs/guides/your-data","https://developers.openai.com/api/docs/guides/agents-api/environments/providers/daytona","https://developers.openai.com/api/docs/guides/agents-api/environments/files","https://openai.com/index/introducing-the-agents-api","https://developers.openai.com/api/docs/guides/agents-api/sessions/manage","https://developers.openai.com/api/docs/guides/agents-api/environments/providers/modal","https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted","https://developers.openai.com/api/docs/guides/agents-api/environments/lifecycle","https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted","https://developers.openai.com/api/docs/guides/agents-api/environments/providers/vercel"],"methodology":["Evidence-matrix plan: use rows for OpenAI-hosted, generic self-hosted/customer infrastructure, and each named provider; use columns for control-plane residency, ZDR eligibility, retained session state, execution location, VPC support, file/artifact location, deletion behavior, and provider dependency.","Classify each cell only as supported, incompatible, or unspecified from the supplied public documentation.","Treat OpenAI-managed agent sessions and execution environments as separate layers; do not infer execution-plane geography from the control-plane residency setting.","Count only the bounded launch sample: OpenAI-hosted, generic self-hosted, and nine named provider integrations.","Preserve provider-specific retention, residency, and VPC controls as unspecified where the launch documentation does not normalize them."],"snapshot_hash":"d02923197e65636749df292fc0ab44aae8ce8fa08ba22566d644eca528e4d683"},"distributions":{"csv":"https://superpowerdaily.com/api/research/the-managed-agent-compliance-gap-where-openai-s-new-agents-api-can-actually-run-55aac41e?format=csv","json":"https://superpowerdaily.com/api/research/the-managed-agent-compliance-gap-where-openai-s-new-agents-api-can-actually-run-55aac41e?format=json"}}