← Back to Hermes
Hermes safety

Security and approval modes

Treat approval mode, authorization, allowlists, and container choices as a layered rollout surface, not one toggle.

Safety ruleStart with non-reckless approval defaults and verify the real risk posture before widening exposure.

Hermes security should not be treated as one toggle. The current source material frames it as a layered operating surface: who is allowed to talk to the agent, which dangerous commands require approval, what happens when YOLO is enabled, how permanent allowlists widen the execution surface, and how backend/container choices change isolation and persistence expectations.

Choose approval mode deliberately

The practical rollout default is to start with manual or smart, not off.

Treat YOLO as a real risk escalation

Do not assume YOLO removes every guardrail

Hermes still documents an unrecoverable blocklist. Some command classes are refused even with YOLO, approvals.mode: off, or headless approval contexts.

Review backend and container isolation on purpose

Practical failure checks

Related pages