Hermes Direct preview

Hermes separates role logic from data access in two clear layers.

The direct Hermes adapter is a Founding Partner Preview and maintainer path. The later customer path installs MarketingOS after successful Acquisition Verification and then attaches the dedicated Hermes profile through the stable MarketingOS-Manage launcher. The stock Hermes Agent 0.18.2 record verifies the plugin surface and uninstall. The separate 11 of 11 route record comes from a dedicated local Hermes 0.18.2 proof build with one deliberately carried compatibility commit. Its exact upstream and local identity is recorded in the hash bound receipt.

01

1. Install the verified product first

The later public customer path requires successful Acquisition Verification. Install-MarketingOS installs the product into the protected version store. Company, goal and workspace setup then use the stable starter.

02

2. Attach Hermes through the stable manager

The host agent calls MarketingOS-Manage attach-runtime with --runtime hermes, the absolute Hermes profile path, the exact Python interpreter and --hermes-profile marketingos. This stable interface has no --dry-run option.

03

3. Role logic remains directly callable

The installer creates twelve skills with twelve slash commands and the team bundle. delegate_task maps a specialist assignment to a native leaf session. Hermes does not create persistent named specialists like OpenClaw.

04

4. A dedicated profile protects the data layer

The native plugin is one owned MarketingOS entry inside a dedicated profile. The default profile, foreign plugins, memories, tasks and settings remain outside the MarketingOS ownership boundary.

05

5. Eleven data tools and no more

The plugin tool surface contains only the following allowlist. It provides no shell and no direct access to the Local Agent, tokens, file paths or SiteOne processes.

  • marketingos_action_propose
  • marketingos_action_status_get
  • marketingos_connectors_list
  • marketingos_goals_list
  • marketingos_observations_list
  • marketingos_outcomes_list
  • marketingos_receipt_get
  • marketingos_runtime_check_in
  • marketingos_siteone_crawl
  • marketingos_source_read
  • marketingos_workspace_context_get
06

6. Direct means trusted local work

The narrow data tool surface reduces reach but is not process containment. The Hermes Direct profile accepts trusted local workloads only and has no general external write path. The separate managed Google review candidate returns neither tokens nor provider access to Hermes or a model.

07

7. Hermes Secure stops before mutation

Hermes Secure is not available yet. The installer stops before mutation with hermes-secure-whole-process-unavailable and never falls back silently to Direct. A Docker terminal environment alone would not contain the Hermes process.

08

8. Plugin and specialist routes are verified separately

The stock Hermes Agent 0.18.2 record confirms eleven plugin tools, delegate_task as the only additional coordination tool, and verified uninstall. The dedicated local proof build with one deliberately carried compatibility commit executes all eleven installed specialist roles through native leaf sessions. Its exact build identity is recorded in the hash bound receipt. Every route produces a matching action, receipt and evidence record. Runtime parity remains partial.

Continue

Understand the two Hermes layers

Twelve skills, slash commands and the team bundle carry role logic. The native plugin limits the data layer to eleven tools. The current source record exercises all eleven roles through native leaf sessions.

Open the Proof Ledger