Smartflow for Hermes Agent

Smartflow for Hermes Agent puts a governed gateway between Hermes and its model providers. Smartflow Halo gives an individual hard spend caps and key custody. Smartflow gives a company central policy, approvals for actions that reach company systems, and a tamper-evident record.

Smartflow for Hermes Agent puts a governed gateway between Hermes and its model providers. Smartflow Halo gives an individual hard spend caps, keys that stay on the machine and a record of every call. Smartflow gives a company central policy, approvals for actions that reach company systems, and a tamper-evident record.

What is Hermes Agent?

Hermes Agent is an open-source agent from Nous Research, released February 25, 2026 under the MIT license. It runs on your server, keeps memory across sessions, writes and refines its own skills, and ships with a cron scheduler and a messaging gateway covering more than twenty platforms. It has more than sixty tools, including a terminal that can run commands locally, in containers or over SSH.

Two design choices shape how Hermes should be governed. It is built to run unattended on a schedule. And it changes itself: the skills it writes today shape what it does tomorrow.

What needs governing?

Spend. Hermes has no built-in spending cap; an open issue on the project asks for one. One user reported scheduled jobs calling a paid model unattended and spending about twenty dollars in a day with no budget limit in place.

Commands. Approvals default to smart mode. The --yolo flag turns checks off except for a hardline blocklist of destructive commands. Hermes's documentation states that dangerous-command checks are skipped when commands run in Docker and similar container backends, and that its controls are not a sandbox against a deliberately adversarial process.

Skills. The maintainers describe Skills Guard as a review aid; the boundary for third-party skills is the operator's review before install. Skills Hermes writes for itself deserve the same review, because they run with the same access.

Vulnerabilities. CVE-2026-53869, a DNS-rebinding flaw in the WebSocket endpoints, affected versions before 0.16.0. Keep Hermes current.

For an individual: Smartflow Halo

Smartflow Halo is a single binary that sits between Hermes and the model providers.

  • One command. halo hermes apply points Hermes at Halo. Hermes reads its provider from ~/.hermes/config.yaml, so the change lives there rather than in environment variables.
  • Hard caps for scheduled jobs. A soft cap warns and a hard cap refuses requests. Caps apply to cron runs exactly as they apply to conversations, and they work with no network connection.
  • Keys on the machine. Hermes gets a revocable virtual key. The provider key stays in the keychain or an encrypted vault.
  • A record of every call. Spend by agent, task and model, on a loopback dashboard. Nothing goes to APERION.

For a company: Smartflow

A Hermes instance connected to company email, messaging or systems acts with the authority of the person who set it up. Point it at the company's Smartflow endpoint with its own virtual key, issued to that person. Smartflow attributes each call to the key, redacts personal identifiers before prompts leave, allowlists the models and routes the key may use, applies Shield rules to the agent's tool calls, and records every call in a hash-chained, time-stamped log that exports to your SIEM. Tool calls that reach company systems outside policy pause for approval by a person with approval rights.

Action the agent attempts Outcome
A scheduled job that sends messages or email externally Held for approval
A change to a company system through MCP Held for approval, with step-up
A new skill that calls company systems Security review before first use
A call to a model outside the key's allowlist Refused

Commands Hermes runs in its own terminal do not pass through MCP. Govern them with Hermes's settings, below. Smartflow records the model's requests to run them, because those requests arrive in the model's responses.

Harden Hermes itself

  • Set approvals.mode to manual for any instance connected to a messaging gateway.
  • Keep cron_mode and unattended_mode at their default, deny, so a command that needs approval is refused when no one is there to give it.
  • Set HERMES_WRITE_SAFE_ROOT to confine where the agent can write files.
  • Set GATEWAY_ALLOWED_USERS to the people who may message the agent.
  • Do not rely on container backends for command checks.
  • Review every skill, including the ones Hermes writes for itself.

Should a company allow it?

A company can allow Hermes on work systems when every instance calls models through the company's Smartflow endpoint, every connection to a company system runs through Smartflow's MCP gateway, and the settings above are enforced. Scheduled jobs that act on company systems need a named owner, a budget and an approval rule before they run unattended.

Related: Smartflow for OpenClaw covers the other widely run self-hosted agent.

Quick answers

Does Hermes Agent have a spending cap?

Not built in. An open issue on the project requests one. Smartflow Halo adds a soft cap and a hard cap per agent, enforced on the machine, and they apply to scheduled jobs the same way they apply to conversations.

Are Hermes's approvals a sandbox?

Hermes's documentation says its controls are not a sandbox against a deliberately adversarial process, and that dangerous-command checks are skipped in container backends. Treat approvals as one layer. Confine file writes, allowlist who can message the agent, and route company connections through Smartflow.

How do I point Hermes at a gateway?

Set the provider in ~/.hermes/config.yaml, which Hermes treats as the single source of truth: provider: custom with a base_url for Halo or Smartflow. halo hermes apply writes the entry for you.

Download the full guide

The PDF adds provider configuration for Halo and Smartflow, a hardened configuration baseline, a decision map for scheduled jobs, and a checklist for companies deciding whether to allow Hermes on work systems.

Sources

Verified as of September 25, 2026.

Claude, Claude Code and Claude Cowork are products of Anthropic. OpenClaw is maintained by the OpenClaw Foundation. Hermes Agent is a project of Nous Research. APERION is not affiliated with or endorsed by these organizations.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs