vicigeeksimple guides
Browse
All guides

Running your system · Decision framework

Managed VICIdial hosting vs self-hosting: a decision framework, not a vendor ranking

Compare accountability, controls and evidence without treating marketing claims as operational proof.

Reader setup

Before you choose

List your constraints, required evidence and stop rules before you score options.

  1. Workload outline
  2. Recovery objectives
  3. Whoever will own the decision, even if that is only you
What you will prove
A traceable hosting-model comparison.
Safety boundary
Do not treat it as a vendor ranking, legal opinion, or price quote.

Reader path

How to use this article

  • Use it when: You are comparing options and need decision evidence before approval.
  • Expected result: Turn options into explicit acceptance criteria and documented stop conditions.
  • Start here: Score what is mandatory, keep unknowns visible, then decide only when risks are understood.

Choose the operating model that can prove your controls

Fast answer: choose managed hosting when its contract and evidence cover the operational controls you cannot staff, and self-host when you can reliably own patching, telephony, observability, recovery and security. Neither label proves quality by itself.

This is a decision framework, not a review or ranking. It assumes you have defined jurisdictions, call volumes, integrations, recording policy and recovery objectives; CRM means customer relationship management. It does not evaluate named providers or promise compliance.

This comparison assumes familiarity with VICIdial's own vocabulary, including Asterisk and carrier; the companion article “VICIdial terminology for complete beginners: users, phones, campaigns and leads” defines them for a first-time reader.

  • Prerequisites: a workload outline, recovery targets and a named business owner for each control.
  • Non-goal: this is not legal advice, a vendor ranking or a certification.
  • Require evidence dated to the proposed service.
Trace path · read left to right
01Requirements02Shared-responsibility evidence03Reversible decision

Visual walkthrough

Follow three real demo screens

Captured on an isolated VICIdial demo: Administration screens on September 24, 2026, and the idle Agent screen on August 11, 2026. Each caption states its own capture time, and every sanitized image helps you recognize a related screen; none proves that this article's call, command, or result occurred.
Step 1 · Find the main areas

Start at Administration home

Sanitized VICIdial Administration home page with navigation and aggregate system counts
Captured September 24, 2026 at 21:54:37 UTC on the authorized isolated demo. This is an orientation page with aggregate counts only; it is not a report and does not prove production activity or a completed call.
Step 2 · Map system administration

Use the Administration menu as a map

Sanitized VICIdial Administration menu showing phones, carriers, servers, system settings, and system statuses
Captured September 24, 2026 at 21:34:11 UTC on the authorized isolated demo. This menu is a navigation map only; it does not show that any system-wide setting was changed or verified.
Step 3 · Read platform identity

Confirm version and system-wide context

Sanitized VICIdial Modify System Settings page showing revision, schema, interface, SIP-stack, and API-related controls
Captured August 11, 2026 at 16:22:08 UTC on the authorized isolated demo. This is a read-only view of system-wide settings with no credentials or addresses; it does not prove that a setting was changed or that an API request succeeded.

Map shared responsibility down to the call path

Ask who owns OS patching, VICIdial/Asterisk changes, certificates, PJSIP/provider configuration, firewall rules, database care, recordings, access review, monitoring and incident response. “Fully managed” is incomplete until each item has an owner and escalation time.

For self-hosting, name people and coverage windows rather than an organization label. For managed service, ask whether you retain exports, configuration backup, audit access and a safe exit path. Complete this worksheet from contract language; an unassigned row is a stop condition.

  • Request the change-management and emergency-change process.
  • Confirm least-privilege administrative access.
  • Document data processors and support access boundaries.
Responsibility worksheet
control = certificate renewalmanaged_owner = [name or role]self_hosted_owner = [name or role]evidence_to_request = [dated test or document]escalation_time = [duration]
Not executed · worksheet or reference text

This sample is a template or reading aid, not a terminal command. There is no output to show.

Before you run it
Replace bracketed placeholders with roles, never personal contact data, in a private evaluation record.
Success looks like
Each control has one accountable owner and dated evidence.
Stop if
Stop selection when a required control has no owner or evidence.

Ask for testable evidence, not assurances

A credible candidate can describe backup scope, restore testing, RTO/RPO measurement, monitoring, patch cadence, vulnerability response, logging/redaction, region and subprocessor boundaries. Ask what was tested, when, under which assumptions, and what was not tested.

Distinguish source-present, configured, enabled and functionally-verified evidence. For example, a backup policy is source evidence; an encrypted job configured is not a successful restore; a recent scoped restore drill is functional evidence.

  • Request redacted operating-procedure and drill summaries.
  • Verify SLA exclusions and maintenance windows.
  • Avoid sending credentials or customer data during evaluation.

Compare total operating cost and risk

Compare more than monthly compute: include engineering coverage, on-call burden, audits, backups, egress, monitoring, carrier management, downtime exposure and migration effort. A low advertised fee can omit the control you most need.

Use the same workload and retention assumptions for each option. Treat quotes as dated inputs and include a contingency for growth, security remediation and a provider exit. This worksheet is a comparison template, not a price claim; leave a cost blank until a dated quote supplies it.

  • Create a one-year and two-year scenario.
  • Price recordings and restores explicitly.
  • Record every assumption next to the quote.
Like-for-like decision worksheet
option = [managed or self-hosted]compute_and_storage = [dated quote]on_call_coverage = [included or separate]restore_drill_evidence = [date or missing]exit_assistance = [contract term]open_risks = [list]
Not executed · worksheet or reference text

This sample is a template or reading aid, not a terminal command. There is no output to show.

Before you run it
Fill bracketed placeholders from current written terms and approved internal estimates.
Success looks like
Both options use the same assumptions and missing evidence is visible.
Stop if
Stop comparison if terms, recovery evidence or exit details are absent.

Make reversibility a selection criterion

Before signing, prove that you can export configuration and data in a usable format, obtain recordings under your authorization model, revoke access, and restore elsewhere. Run a bounded migration rehearsal using synthetic data if possible.

Stop if a candidate cannot identify backup ownership, recovery testing, administrator access controls, data location, breach notification path or termination procedure. The independent verification is a contractual review plus a scoped exercise, not a sales presentation.

  • Set acceptance criteria in the agreement.
  • Keep an offline contact/escalation roster.
  • Review the model after the first incident or restore drill.

Evidence ledger

Verification basis

  • No hosting vendor was tested, endorsed or ranked.
  • No single lab build establishes HA, production capacity, backup/restore or provider interoperability evidence for any hosting model.
  • This framework requires each candidate to provide its own dated, contractual evidence.

Primary references

Sources

  1. NIST Cybersecurity Framework 2.0NIST · accessed August 4, 2026
  2. CISA Secure by DesignCISA · accessed August 4, 2026
  3. VICIdial product overviewVICIdial · accessed August 4, 2026

Follow without guesswork

Get the next article

RSS is live now. Email delivery below is an explicit local preview and sends nothing.Open the RSS feed
Email preview only. The address stays in this browser and is never transmitted.