Hermes: The Messenger Agent
A dedicated, isolated agent whose only job is to deliver signals between your AI workforce, your humans, and the outside world. Every notification, every webhook, every translation, every retry: logged and signed.
OpenClawPro ships Hermes as a standard add-on on Managed Pro+ and Self-Hosted Advanced+ plans. It runs in its own container: no shared memory, no shared secrets, no cross-contamination.
What Hermes Does
Six capabilities that turn a chaotic multi-agent setup into a clean, observable messaging layer.
Multi-Channel Delivery
Dispatches signals to WhatsApp, Telegram, Discord, Slack, email, and any webhook endpoint. One agent, every channel.
Smart Routing
Routes notifications by priority and recipient with rules you define: critical alerts to the on-call channel, digests to the team room.
Isolated by Design
Runs in its own Docker container on a dedicated network. No access to your other agents' memory, code, or secrets, unless you grant it.
Audit-Logged
Every message, every delivery attempt, every retry: timestamped and kept, so you can reconstruct exactly what was sent, where and when.
Inbound Webhooks Too
Accepts incoming webhooks and turns them into channel messages: point any service that can POST at it, and the event lands where your team reads.
Human Approval Requests
Carries an approve-or-deny question to your channel and returns the answer to the requesting agent. The decision stays with a person, and it is logged.
Real Use Cases
How Hermes is deployed in the wild: patterns we install for every Managed Pro+ and Self-Hosted Advanced+ customer.
Daily Standups
Your agents post status updates; Hermes delivers them to your team channel on the schedule you set. One place to read what ran overnight.
Customer Notifications
When your support agent resolves a ticket, Hermes sends the confirmation email (with the customer's preferred language) and updates the CRM.
Approval Gates
Before any spend or production change, Hermes sends an approval request to the human on call. Nothing moves until a person answers.
Incident Routing
A monitoring alert reaches the on-call human in the channel they actually read, with the context attached. No pager theatre, just delivery.
Why a Separate Agent?
A messaging layer that lives inside the same process as your business agents is a liability: one prompt-injection in a customer email can pivot into your CRM, your code, your spending. Hermes is built to prevent that.
- Runs in its own Docker container, on a dedicated Docker network.
- No read access to other agents' memory, code, or secrets: explicit allow-list only.
- Outbound calls go through a small, audited set of HTTP libraries: no exec, no eval, no file system.
- Every inbound payload is parsed, validated, and re-emitted as a typed event: no raw forwarding.
- Token budget and rate limits are enforced at the container boundary, not at the LLM layer.
Included in Pro+ and Advanced+ Plans
Hermes Messaging Agent
Standard add-on at no extra cost with any Managed plan or Self-Hosted install. Standalone install also available for existing OpenClaw deployments.
Hermes in the OpenClaw Family
Each OpenClaw component has a clear role. Hermes is the messenger.
OpenClaw →
The brain. Persistent memory, tool use, channel integrations. Wire them together and Hermes delivers what OpenClaw decides.
NemoClaw →
The compliance-hardened on-prem variant of the OpenClaw assistant, for regulated data. A separate install; Hermes can deliver its alerts like any agent’s.
Paperclip →
A separate open-source project that runs a company of AI agents. We install it too; pair it with Hermes if you want its alerts in your channels.
Ship Signals, Not Surprises.
Stop juggling webhooks, retries, channel formats, and translations across half a dozen agents. Hermes does it once, in one container, with one audit log.
Paperclip, NeMo, Nemotron and other product names are trademarks of their respective owners. OpenClawPro provides independent setup, hosting and support and is not affiliated with or endorsed by them.