01Check requirements
02Choose a supported path
03Test and document rollback
Explanatory diagram. A conceptual reading aid, not benchmark or ROI data. See sources checked for the factual guidance used in this article.

A tool review asks what Hermes can do. A memory review asks what information can influence later work. Both matter before a business pilot expands, because a saved assumption or an overly broad connection can outlive the conversation that introduced it.

This guide helps a Hermes operator create an access-and-persistence inventory, then test it using fictional information. It covers documented behavior reviewed on October 10, 2026. Treat the checklist as an operating review, not a security certification or a promise that every risk is eliminated.

1. Inventory capabilities by consequence

Start with the work the agent is supposed to perform. For each enabled tool or integration, write down the system it reaches, what it can read, what it can change, and who controls the credential. Mark actions that send information, execute commands, remove content, or create continuing access.

Hermes toolsets can be configured by platform, and its terminal tool can use different backends. A local terminal acts on the host; changing the backend changes the execution environment. Review the active configuration for the exact interface used in the pilot. Tools and toolsets.

Remove capabilities that have no job in the current workflow. Do not enable terminal execution merely because a collection of tools includes it. Ask how a reviewer would recognize and stop an unintended action, especially when the same integration supports both reading and writing.

2. Verify the boundary underneath the prompt

Hermes documents dangerous-command approval modes and file-write protections. The optional write-root guard applies to its file-writing tools; the security guide explicitly warns that terminal commands run with the operating-system user's access and are not contained by that file-tool guard. Security boundaries.

That distinction changes the test plan. A denied file-tool write is not enough evidence to call the whole session sandboxed. Review operating-system permissions, mounted folders, credentials, network access, and the chosen terminal backend together. Retain human approval for consequential actions as part of the workflow design.

Use a harmless outside-scope test location containing only invented data. Check that the configured boundary behaves as intended without experimenting on real system files. If the result contradicts the written policy, stop the pilot and narrow access before adding more instructions.

3. Review MCP connections at two levels

For a Model Context Protocol connection, review both the account grant and the tools registered with Hermes. Its MCP configuration supports disabling an entire server and per-server include or exclude lists. The documentation says include takes precedence when both lists are present. MCP filtering.

Prefer a short explicit list for a narrow pilot, then inspect the resulting tool inventory. Do not assume that hiding a tool revokes the underlying account's permissions. A credential with broad rights remains important even if the current tool list is small.

Record who operates each server and whether its requests leave your environment. Treat a new server or a changed tool inventory as a fresh review point. Test that a required read operation works and that an unnecessary write operation is not available through the chosen route.

4. Distinguish the persistence layers

Hermes's built-in memory uses bounded, curated files, separate from searchable conversation history. Memory is loaded into the session's starting context; later changes persist on disk but do not refresh that frozen starting snapshot. The optional memory write-approval gate can prompt in the interactive CLI or stage writes for review on other surfaces. Persistent memory.

Use those distinctions to create three inventory lines: durable notes, session history, and reusable procedures. Then add any external memory provider. Hermes supports memory-provider integrations, so inspect which one is actually configured and its separate data handling before making retention claims. Memory providers.

Choose what is worth retaining. A stable preference about checklist format may help. A customer's private details, a temporary access code, or an unverified assumption should not become a casual durable note. Keep business source documents authoritative when their contents change.

5. Test a correction from end to end

Use an invented fact, save it through the supported memory flow, and inspect that it was actually recorded. Start a new session, verify recall, then correct the fact and repeat. Test rejection of a proposed save if your workflow requires approval. Keep all these examples harmless.

Also distinguish removing a note from deleting its earlier conversation. Hermes documents that deleting an open session does not stop the running chat; a later save can recreate its transcript. Close the relevant chat before evaluating session deletion. Session management.

Treat backups and external providers as additional copies to review. Do not claim that a single deletion control erases information everywhere. Establish the actual retention procedure for each place in your inventory.

Fictional example

Spruce Demo Catalog is a fictional stationery business. Its pilot remembers that internal summaries should use short checklists. A sample document incorrectly claims the team can promise next-day delivery. The operator rejects that as an enduring business rule and corrects the test output. The test succeeds only when the next session uses the approved formatting preference without repeating the unsupported delivery promise.

6. Review reusable skills separately

Hermes skills are on-demand instruction documents and can include supporting material. Inspect the complete content, scripts, and credential requirements before adopting a skill. A familiar title does not establish trustworthy behavior. Skills system.

Finish with this checklist: approved tools, constrained account grants, identified execution environment, reviewed MCP inventory, chosen memory policy, verified correction test, known session-retention procedure, and named review owner. Repeat the review when you add a connector, skill, memory provider, or new class of business information.

Bring this inventory to InstallAI when discussing a Hermes configuration. It helps turn broad privacy and control questions into specific settings and tests that can be checked.

Sources checked