Comparisons

Nimbus vs Hermes: A Personal Agent That Learns You, or a System That Remembers the Business?

Hermes Agent is a self-hosted personal agent that learns how you work; Nimbus remembers how the company works when that person is away.

Hermes Agent is built to get better at you. It remembers your projects, writes little how-to notes for itself after a hard task, and can schedule briefings while you are away. Nimbus is built so the business still knows what happened when that person is on a plane: official playbooks, a named signer on writes, and a record that does not live on one laptop.

Both are “an agent that remembers.” They are not the same memory. Personal memory is preferences, procedures, the way you like a report. Company memory is playbooks, signers, and a graph the next person can query. Hermes is honest about the bargain: remembering you is the product. Nimbus is honest about a different bargain: the company still knows after you leave.

Hermes is a real step beyond a chat window that forgets you every morning. It is an open-source personal agent from Nous Research. You install it on a Mac, Windows, or Linux machine. It can also live in Telegram, Discord, Slack, WhatsApp, Signal, email, or a terminal. It talks to many model providers, so you are not locked to one lab. It can spin up helper agents with their own conversations. The code is public. If you are a founder, a researcher, or a power user who will actually look after the install, Hermes is doing the job it was designed for.

Words you’ll hear

  • Hermes Agent. An open-source personal agent from Nous Research. You install it on a Mac, Windows, or Linux machine. It can also live in Telegram, Discord, Slack, WhatsApp, Signal, email, or a terminal.
  • Self-hosted. You run the software. You pay the model bill. You keep the secrets. You are the operator.
  • Personal memory. Preferences, procedures, the way you like a report. Powerful for one operator. Risky if that operator also has mailbox and company-file access.
  • Workstream. In Nimbus, a shared workspace for one job — not a private conversation on a machine.
  • Wiki. Official playbooks: how we book a journal, who may sign, what “done” means. Agents read that, not a private note on a desktop.
  • Write-back. Changing a live system. Reads are on by default. Writes stay off until you name a person who must approve.
  • Lifecycle Graph. The company record of what ran, who approved, and what changed. When the operator leaves, the record does not leave with their laptop.
  • Secure by Design. CISA’s programme about who owns security outcomes. When you run software yourself, you are the operator.

Why the difference matters

You also own the upkeep. A laptop agent with mailbox and company files is a privileged identity you operate. CISA’s Secure by Design framing is blunt: if you chose to run the agent yourself, you own the outcome. Logging, least privilege, and a named signer are yours to provide. Hermes will not invent them because it learned your email voice.

On Hermes, the trail of a finance journal is a conversation on a machine, a how-to note the agent wrote for itself, maybe an email it sent. That may be enough for one person. It is not enough for an auditor who asks, “Show me the approved version.” Self-hosting means you keep the secrets and pay the model bill. It does not mean the company has a release process. Hosting choice is not company governance.

On Nimbus, finance opens a workstream. The wiki states the journal policy. The ledger connector is read-only until a human releases the write. The Lifecycle Graph keeps the brief, the draft, the signer, and the change. When the operator leaves, the record does not leave with their laptop. Nimbus is not trying to learn your email voice. It is trying to make sure finance cannot post a journal without a named signer, and that the analysis still exists in two years.

If three people each run Hermes, you have three memories and no shared playbook. One of them will eventually put a production password in a local file “just for this week.” That is not a Hermes flaw. It is what happens when a personal agent becomes the unofficial company system — shadow AI with a better memory. Auto-promoting a note from one user’s Hermes into company-wide write access is how a friendly shortcut spreads.

A laptop is convenient and easy to lose. A server you run yourself is always on and a bigger target if it is reachable from the internet. Neither gives you a named signer on a journal. Hermes can live in many chat apps; reach is not a control system. The more surfaces the agent sits on, the more ways a privileged identity can be messaged.

Role by role: a founder or researcher who will patch the install gets a personal agent that improves at their workflows — that is the fit. IT should not be asked to standardise the company on a fleet of laptops and a spreadsheet of who is supposed to update them. Finance cannot treat a how-to note on a desktop as the journal policy. Security inherits CISA’s point: you ran it, you own the outcome. A COO who needs an org chart for those personal agents is already in a different product — see Nimbus vs Paperclip. Operators who need the business to remember should not wait for each person’s Hermes to become unofficial infrastructure.

The job split is clean if you keep it clean. Hermes (or something like OpenClaw) as a personal assistant with no production passwords. Nimbus as the place that work is submitted, approved, and remembered. Feed drafts into a workstream the way you would feed a human’s first pass. Do not let Hermes hold the write password.

When Hermes is a better fit

Choose Hermes when you are the user, you want an agent that improves at your workflows, and the blast radius is your own files. Choose it to feel what a persistent agent is like before you operationalise anything. Choose it in a lab that will never touch customer systems.

Do not standardise the company on Hermes and call it an AI programme. You will recreate a pile of personal agents and a spreadsheet of who is supposed to patch them. If you need an org chart for those agents, that is a different product again — see Nimbus vs Paperclip.

You can use both. Hermes as a personal assistant with no production passwords. Nimbus as the place that work is submitted, approved, and remembered. That coexistence only works if credentials stay out of the personal agent. A brilliant personal memory with a production login is still a privileged identity on a laptop.

How this shows up in Nimbus

Nimbus is a company system, not a program you install on one person’s machine. You log in the way you log into any other business app. You do not hope they remember to patch it.

Connectors link to the tools you already run — the ledger, the CRM, the shared drive. Governance is the release path: agents draft, humans release, the graph keeps the decision. The wiki is where “how we do this” lives after a human has reviewed it — not a private note the agent wrote for itself. You still review the vendor. You do not become the platform team for every laptop.

Start at the overview.

Questions people actually ask

Is Nimbus built on Hermes?

No. They sit on different layers. Nimbus may call some of the same models Hermes uses. That is the model market, not a fork.

Can Hermes be our company AI platform?

Only if you are willing to staff the upkeep: identity, secrets, updates, and a release process for anything that touches production. At that point you are building a company system by hand. Most operators should not.

Where should the “how we do this” notes live?

On a personal agent, or as playbooks in the Nimbus wiki after a human has reviewed them. Auto-promoting a note from one user’s Hermes into company-wide write access is how a friendly shortcut spreads.

Can we run Hermes beside Nimbus?

Yes — as a personal assistant with no production credentials. Feed drafts into a Nimbus workstream the way you would feed a human’s first pass. Do not let Hermes hold the write password.

Does it matter if Hermes runs on a laptop or a server?

A laptop is convenient and easy to lose. A server you run yourself is always on and a bigger target if it is reachable from the internet. Neither gives you a named signer on a journal. Hosting choice is not company governance.

How is Hermes different from OpenClaw?

Same layer — a personal assistant you look after — different emphasis. OpenClaw maximises channels. Hermes maximises skills and personal memory. Neither is a company OS. See Nimbus vs OpenClaw.

Who owns security if we allow Hermes?

You do. CISA’s Secure by Design framing is about who owns security outcomes. When you run the software yourself, you are the operator. Logging, least privilege, and a named signer are yours to provide. Nimbus does not remove the need to review a vendor; it does mean you are not the platform team for every laptop.

What happens when the person who ran Hermes leaves?

Their personal memory leaves with them, unless you copied it somewhere else. That is the product working as designed. If the business needed the journal policy, the signer, and the change, those should already have lived in a workstream and a graph — not on a machine that is about to be wiped.

What is institutional memory in enterprise AI, What is write-back governance, and Nimbus vs OpenClaw.

Sources

See what governed AI looks like on your stack.

Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.