Declare acceptance
Optional artifact_requirements set minimum/maximum bytes and expected SHA-256 values before dispatch. Each isolated attempt carries the same immutable checks.
v0.14.0 released • Local-first • Autopilot default off
Hermes GPT v0.14.0 strengthens Autopilot with declared artifact size and digest checks, a durable delivery grace, and bounded recovery after confirmed deliverable failures. Flight Deck explains the evidence behind completion. Final Mission approval stays with the Owner.
What v0.14.0 adds
Declare acceptance before dispatch. Accept late valid artifacts without duplicate work, recover confirmed failures within the existing allowance, and stop when evidence or authority is unresolved. Autopilot stays default off.
Optional artifact_requirements set minimum/maximum bytes and expected SHA-256 values before dispatch. Each isolated attempt carries the same immutable checks.
Successful execution with confirmed artifact failures receives a durable 30-second delivery grace. If defects remain and all other required checks pass, existing bounded replan recovery can proceed. Unreadable evidence, pending review, denied authority, and ambiguous cancellation remain unverified.
Read-only Flight Deck supervision shows check results, fixed artifact failure reasons, delivery grace, and pending validation. Size and integrity checks prove declared requirements; semantic quality still requires review.
hermes_plan_create/get/list/validate/decompose/review/node_transition/set_status: a deterministic, bounded decomposition DAG over a MissionSpec. Plan mutations touch only the isolated plan store and are read-only with respect to the Mission lifecycle.
hermes_capability_manifest folds the Fabric node registry, Fleet authority manifest, profile toolsets/skills, and provider manifests into one queryable index. hermes_mission_ledger is a merged, replayable, cursor-paginated event timeline. No mutation path exists.
hermes_budget_set/get/check/record: a per-mission spend envelope with a read-only budget_check evaluation surface. v0.12 adds the gated D3 enforcement rung: when the flags are armed, a crossing pauses the Mission through the existing transition, spools one fleet-attention interrupt, and records one budget_events break row.
hermes_placement_score/candidates/get/list: deterministic hard filters then soft scores over the derived capability index. Scoring is unchanged and still decision-only; would_assign is true only for a dispatch that actually happened under the v0.12 L2 gates, and real dispatch stays on the existing contract, fleet, and delegation authority surfaces.
An 8-class taxonomy classifies an authoritative observation envelope and proposes the deterministic smallest-first recovery action, recorded on a controller_plan row. That classification surface stays decision-only; executing the proposed action is the separate, default-off v0.12 L2 rung.
A durable, default-off Mission worker schedules ready nodes through existing authority surfaces. v0.14 carries declared minimum/maximum artifact sizes and optional SHA-256 values into immutable Work Contracts. Rework preserves the requirements; final Mission approval remains Owner-only.
System Architecture
Autopilot advances ready MissionPlan nodes through existing authority surfaces, then reconciles against durable observed state. It does not bypass Work Contracts, budgets, or owner approval.
Declared artifact size/digest checks, durable 30-second delivery grace, bounded recovery after confirmed artifact failures, and clear completion evidence in Flight Deck. Requirements survive rework unchanged. No new tools or authority; final Mission approval remains Owner-only.
ChatGPT, Codex, Cursor, Claude Desktop, or another trusted MCP client submits a bounded request to Hermes GPT.
The controller observes authoritative mission, plan, delegation, and runner state through the derived capability manifest and mission ledger.
Ready nodes are dispatched within configured concurrency. Delegation reconciliation reads runner and Fabric records; Work Contract evidence must validate against observed state before a node completes.
Approval and high-impact nodes are never dispatched or advanced. Autopilot waits for the owner, then resumes through existing authority surfaces; only Owner-gated approval can complete the Mission.
Interactive Sandbox
Explore the policy model without touching a real Hermes installation. The simulator mirrors dry-run-first behavior and Owner acknowledgment requirements.
Capabilities
vNext adds the controller layer without weakening the security and evidence invariants shipped in v0.6 through v0.9.
Tiered authority from read_only through owner, with explicit direct mode, confirmation gates, and dry-run-first mutation.
Completion is validated from observed state, including declared artifact sizes and optional expected digests. Changing or unreadable evidence remains unverified. Size and integrity checks do not replace semantic review.
v0.9 adds the first-class durable Mission runtime with Owner-gated final approval, unified delegation lineage, a durable event bus with a WebSocket stream, and runner-neutral job supervision.
v0.8 Fabric: authenticated peers, capability-aware auto routing, hash-verified remote evidence and artifacts, and same-attempt reconciliation — with the coordinator authoritative.
Supported OpenAI products reach loopback Hermes GPT through an outbound-only private tunnel path, and hermes_export_file provides workspace-authorized binary transfer with denied-path enforcement and size caps.
Mission Control, event history, review evidence, diagnostics, recovery tools, and Fabric routing views keep long-running autonomy inspectable. v0.14 adds no tools: 137 with Autopilot disabled, 140 when enabled. Completion checks, fixed artifact failure reasons, delivery grace, and pending validation are visible through read-only supervision.
Install
Install from PyPI or run the current checkout. Keep the HTTP server on loopback unless you deliberately configure an authenticated private boundary.
python -m pip install hermes-gpt==0.14.0v0.14.0 is published on PyPI. Autopilot requires HERMES_GPT_AUTOPILOT=1 and the normal Operator policy gates. Read the setup guides.
git clone https://github.com/asimons81/hermes-gpt.git
cd hermes-gpt
python -m pip install .
hermes-gpthermes-gpt --http --host 127.0.0.1 --port 7677Endpoint: http://127.0.0.1:7677/mcp. For supported OpenAI products, prefer the OpenAI Secure MCP Tunnel path documented in the repository.
Changelog
v0.14.0 is available on GitHub and PyPI. These are independent distribution channels; verify each when updating.
A durable, default-off Mission scheduler with bounded parallel execution, observed-state validation, retries and replans, budget checks, and Owner approval frontiers. Autopilot uses existing authority surfaces and cannot approve or complete a Mission.
vNext slice 2: budget D3 hard-block enforcement (pause through the existing transition, one fleet-attention interrupt for the delivery broker, one budget_events break row) and the controller L2 rung (at most one smallest recovery action per pass, dispatched through the existing authority surfaces, intent recorded before dispatch). Both are default-off behind per-call confirm plus a machine gate, direct-mode Operator policy, and per-mission flags — and byte-identical to v0.11.0 while unarmed. 137 tools; no new mutating surface by default.
Opt-in Gemini Spark custom-app client profile (verified end-to-end), MCP Python SDK 2.x support with SDK 1 retained, profile-aware Bot Chat and session delivery, fleet loopback Agent Cards, and the post-v0.10 security remediation. 137 tools; no new mutating surface by default.
MissionPlan decomposition DAGs, read-only capability-manifest and mission-ledger views, a dry-run budget envelope, placement scoring, an 8-class failure taxonomy with recovery matrix, and a shadow/observe controller with GREEN/YELLOW/RED telemetry. 27 new tools (137 total); none can mutate a Mission, dispatch, or approve.
First-class durable Missions with Owner-gated final approval, unified delegation lineage across runners, a durable live-event bus with WebSocket stream, runner-neutral job supervision, and the bounded Finance bridge.
Authenticated cross-machine Swarm execution, capability-aware routing, remote evidence and artifact admission, restart/timeout/cancel reconciliation, write-ownership safeguards, and Fabric Flight Deck visibility. Passed fresh real two-machine G6 acceptance and independent review.
Production review evidence, structured redacted event history, durable encrypted token storage, and restart-safe Swarm continuity.
Read-only operational views, observed-state completion validation, and bounded DAG orchestration with explicit ownership and human approval.
Codex as MCP client plus policy-gated delegated Codex CLI work and review.