{
  "schemaVersion": "1.0",
  "title": "Hermes Agent isolated-live qualification on 11 July 2026",
  "description": "Historical reported result: PASS. The retained narrative gives the execution date as 11 July 2026 but does not retain an exact UTC start or end.",
  "canonical": "https://getaip.org/docs/testing/hermes-agent-isolated-live",
  "route": "/docs/testing/hermes-agent-isolated-live",
  "source": "docs/testing/hermes-agent-isolated-live.md",
  "protocol": "Agent Interoperability Protocol",
  "protocolVersion": "1.0",
  "section": "Qualification and Evidence",
  "documentType": "Qualification evidence",
  "language": "en",
  "revision": {
    "lastReviewedRevision": "97be86e9efedf07ecf1783b03800f683f107fb04",
    "documentationSourceRevision": "9192fef3695ad294994f2712f6d156241e5e92fb",
    "basis": "frontmatter"
  },
  "downloads": {
    "md": "/docs/download/testing/hermes-agent-isolated-live.md",
    "txt": "/docs/download/testing/hermes-agent-isolated-live.txt",
    "json": "/docs/download/testing/hermes-agent-isolated-live.json",
    "pdf": "/docs/download/testing/hermes-agent-isolated-live.pdf"
  },
  "content": {
    "format": "text/markdown",
    "markdown": "---\ntitle: Hermes Agent isolated-live qualification on 11 July 2026\ndescription: Evaluate the reported historical Hermes Agent result and the evidence gaps that limit its use\nkind: qualification\naudience: evaluator\nappliesTo: \"1.x\"\nwritingStandard: \"aip-docs/1.0\"\nlastReviewedRevision: \"97be86e9efedf07ecf1783b03800f683f107fb04\"\n---\n\n# Hermes Agent isolated-live qualification on 11 July 2026\n\n**Historical reported result: `PASS`.** The retained narrative gives the\nexecution date as 11 July 2026 but does not retain an exact UTC start or end.\n\nThis result applies only to the recorded AIP image, Hermes Agent image,\nupstream revision, two-endpoint topology, model route, and seven assertion\ngroups. It does not qualify the current documentation review revision\n`97be86e9efedf07ecf1783b03800f683f107fb04`, a different model provider, or a\nproduction deployment.\n\n> Historical implementation naming: this record documents a pre-v2.0.0\n> implementation. Executable, crate, configuration, image, and identity names\n> below are retained as evidence; use current reference documentation for\n> present names.\n\n## Understand the evidence level\n\nThe only retained result is a narrative report. No machine-readable result,\nraw driver output, command log, signature, full checksum manifest, or cleanup\nrecord accompanies it. The report contains exact image digests, execution\nidentifiers, counts, and outcomes, but those observations cannot be\nindependently recomputed from the public record.\n\n| Evidence | What it supports | Limitation |\n| --- | --- | --- |\n| Historical narrative | Reported date, status, identities, topology, security controls, assertions, exact execution identifiers, and results | It is a human-readable claim record rather than a signed or machine-generated result |\n| Historical source | The driver and AIP base commit used to frame the campaign | The image included uncommitted qualification work with no retained worktree digest |\n| Current pinned source | The same operator-driver file remains present and byte-identical | Other runtime, deployment, and connector components changed; file equality does not renew the result |\n| Official Hermes source | The recorded upstream commit and exact Git tree | A source commit does not identify the retained Hermes image contents by itself |\n\nThe historical narrative retained outside this v2 page has SHA-256 digest\n`0956b7fe3f1c96ee6696d8316d5f2de4f589a72a874f0920ceb055f1a0d19a71`.\n\n## Identify the recorded artifacts\n\n| Artifact | Recorded identity |\n| --- | --- |\n| AIP source base commit | `c51e149ce1df762cb62bc736edfb81a674f56852` |\n| AIP base Git tree | `e36378e93846cdf6730fd69a80462f9ebc471061` |\n| Qualification record and driver commit | `f14af77e464625b92bd6c1b86774d1449acd8f3f` |\n| AIP qualification image | `aipd:local@sha256:00e468c3603941a091e5f9c473b121ef57c9d0f7eaf10f4e07ebfcaf58579786` |\n| Hermes Agent upstream commit | `7426c09beee73bdff94d916015bac71384f6bc92` |\n| Hermes Agent Git tree | `583423a976e761d3f076d2cf7f7859c13e40cc29` |\n| Hermes Agent image | `hermes-agent:aip-lite@sha256:15912eaf6211f3b953ad6ed2268545a521cb0c440604231cc61dabfd9666f32c` |\n| Architecture | `linux/arm64` |\n| Reported model route | `cohere/north-mini-code:free` through an OpenRouter-compatible provider |\n\nThe official Hermes Agent checkout confirms the upstream commit and tree. A\nhistorical AIP checkout confirms the AIP base commit and tree.\n\nThe report says\nthe AIP image also contained then-current connector qualification work, but it\nrecords no source digest for that worktree. The direct child commit identified\nabove retains the report and driver, but no recorded digest binds its complete\ntree to the image. The image digest identifies what ran without making its\ncomplete source independently reconstructable.\n\n## Review the isolated topology\n\nThe historical report describes:\n\n- two isolated Hermes Agent containers;\n- one AIP daemon with MCP Streamable HTTP and native AIP access;\n- an OAuth 2.0 token-introspection boundary;\n- NATS and a deterministic PostgreSQL-backed system of record;\n- an external orchestrator and a separately authenticated human approver;\n- a configured external model route.\n\nThis topology tested governed operator and delegation behavior. The controlled\nsystem of record was part of the test boundary, not one of the six maintained\npublic connectors and not a production provider.\n\n## Review the reported security boundary\n\nThe narrative reports that both Hermes endpoints, the external orchestrator,\nand the human approver used distinct principals and credentials. An\nunauthenticated MCP `initialize` request returned HTTP `401` through the token\nintrospection boundary.\n\nIt also reports these controls:\n\n- each Hermes endpoint exposed only its selected AIP tools;\n- recursive delegation was absent from the model-facing allowlist;\n- Hermes received no credentials for the controlled system of record;\n- business facts entered the run only through authenticated AIP tool use;\n- native lifecycle state, rather than final model prose, supplied the\n  authoritative delegated result;\n- action contract, transport principal, scope, identity, tenant, and result\n  integrity were checked before accepting that result;\n- the report retained no access token, provider key, or introspection secret.\n\nNo raw authentication exchange or redaction log is retained with the report,\nso these are reported controls rather than independently replayable evidence.\n\n## Reconstruct the reported procedure\n\nThe campaign reportedly followed this sequence:\n\n1. Start the isolated AIP implementation stack, authorization boundary, NATS,\n   controlled record service, and two Hermes Agent endpoints.\n2. Verify that unauthenticated MCP initialization fails and that each embedded\n   authenticated Hermes MCP client discovers the expected tool surface.\n3. Submit one governed operator action to each endpoint and observe native\n   pending approval.\n4. Approve each immutable request through the separately authenticated native\n   principal.\n5. Observe structured Hermes runs, incremental stream chunks, and AIP tool\n   start and completion events.\n6. Verify exactly one downstream business action and compare its structured\n   result with an independently read expected record.\n7. Reject one delegated request outside the allowed scope.\n8. Execute one allowed first-class delegation and compare the protocol-assigned\n   child action with the actual downstream action.\n9. Repeat the operator and delegation path independently for the second Hermes\n   endpoint.\n\nThe report also states that a standalone Hermes MCP check authenticated and\ndiscovered 89 tools for each endpoint. This count is historical and\ntopology-specific.\n\n## Inspect the required assertions\n\nThe driver failed unless every endpoint satisfied all seven boundaries.\n\n| Assertion | Required result |\n| --- | --- |\n| Independent approval | The operator action enters pending approval and resumes only after a separately authenticated decision |\n| Structured execution | Hermes starts a structured run and retains incremental stream chunks |\n| AIP tool lifecycle | The stream contains successful AIP tool start and completion events |\n| Trusted data path | Expected business facts arrive through the AIP tool rather than direct database access or model memory |\n| Scope enforcement | A delegated request outside the endpoint allowlist is rejected |\n| Delegation identity | One child action is assigned and the executed downstream action has exactly the same identifier |\n| Independent endpoints | Both isolated Hermes endpoints complete the full operator and delegation path |\n\nThe equality between the assigned child action and the executed downstream\naction is the decisive delegation invariant. Model-generated prose or a\nreplacement identifier cannot satisfy it.\n\n## Inspect the reported observations\n\nThe public v2 record omits controlled-system capability names, disposable\nbusiness records, and execution identifiers. The retained historical source\nremains the audit input for authorized reviewers.\n\n| Observation | Endpoint A | Endpoint B |\n| --- | --- | --- |\n| Stream chunks | `74` | `76` |\n| Pending and authenticated approval | `PASS` | `PASS` |\n| AIP tool start and completion | `PASS` | `PASS` |\n| Exactly one direct downstream action | `PASS` | `PASS` |\n| Out-of-scope delegation rejected | `PASS` | `PASS` |\n| Child action equals delegated downstream action | `PASS` | `PASS` |\n| Structured business output matches expected record | `PASS` | `PASS` |\n\nThese values are transcribed from the narrative report. No separately retained\ndriver JSON is available to verify them.\n\n## Account for missing and excluded evidence\n\nThe result does not establish:\n\n- qualification of any connector other than Hermes Agent;\n- current behavior of revision\n  `97be86e9efedf07ecf1783b03800f683f107fb04`;\n- exact reconstruction of the uncommitted AIP qualification worktree;\n- independent proof of the model-provider response, raw streams, native state,\n  database reads, or authorization exchange;\n- model quality, provider availability, latency, capacity, or cost;\n- production TLS, workload isolation, secret management, egress policy,\n  storage, tenancy, or disaster recovery;\n- execution of the historically listed deterministic tests and static checks;\n- teardown of the isolated stack or cleanup of every disposable effect.\n\nThe current qualification standard makes independently verified cleanup part\nof `PASS`. The historical report has no cleanup record. Its status remains a\nreported historical `PASS` under the scope used on 11 July 2026, but it cannot\nbe accepted as a new campaign result under the current standard.\n\n## Understand the current source relationship\n\nThe operator-driver source has the same SHA-256 digest at the historical\nqualification commit and at the pinned review revision:\n\n```text\n2464b1af2d40ab37280bf184377ceb79991823bac44d660c8247c5a54f19b15d\n```\n\nThis equality confirms that the seven driver checks did not change in that\nfile. It says nothing about changes in the daemon, runtime, gateway, MCP\nserver, deployment, images, credentials, Hermes configuration, or provider.\n\n## Run only a new campaign\n\nUse the current [live-product procedure](live-product-e2e.md) and the retained\noperator entry point to create a new result. Record protected credentials\noutside the command history and supply two endpoint identifiers from the\nisolated deployment.\n\n```sh\ncargo run -p aip-connector-hermes-agent \\\n  --bin aipd-hermes-operator-smoke -- \\\n  --endpoint-id \"hermes-qualification-a\" \\\n  --endpoint-id \"hermes-qualification-b\"\n```\n\nThe command requires the MCP and native approver tokens described by the\nprocedure. A successful new exit does not repair the missing historical\nevidence; retain the new driver output, identities, cleanup result, and checksum\nmanifest as a separate campaign.\n\n## Related documentation\n\n- [Testing and qualification](README.md)\n- [Live-product qualification procedure](live-product-e2e.md)\n- [Connector upstream baselines](../connectors/upstream-baselines.md)\n- [Implementation status](../reference/implementation-status.md)\n- [Hermes Agent connector](../connectors/hermes-agent.md)\n",
    "text": "Hermes Agent isolated-live qualification on 11 July 2026\n\nHistorical reported result: PASS. The retained narrative gives the\nexecution date as 11 July 2026 but does not retain an exact UTC start or end.\n\nThis result applies only to the recorded AIP image, Hermes Agent image,\nupstream revision, two-endpoint topology, model route, and seven assertion\ngroups. It does not qualify the current documentation review revision\n97be86e9efedf07ecf1783b03800f683f107fb04, a different model provider, or a\nproduction deployment.\n\nHistorical implementation naming: this record documents a pre-v2.0.0\nimplementation. Executable, crate, configuration, image, and identity names\nbelow are retained as evidence; use current reference documentation for\npresent names.\n\nUnderstand the evidence level\n\nThe only retained result is a narrative report. No machine-readable result,\nraw driver output, command log, signature, full checksum manifest, or cleanup\nrecord accompanies it. The report contains exact image digests, execution\nidentifiers, counts, and outcomes, but those observations cannot be\nindependently recomputed from the public record.\n\n| Evidence | What it supports | Limitation |\n\n| Historical narrative | Reported date, status, identities, topology, security controls, assertions, exact execution identifiers, and results | It is a human-readable claim record rather than a signed or machine-generated result |\n| Historical source | The driver and AIP base commit used to frame the campaign | The image included uncommitted qualification work with no retained worktree digest |\n| Current pinned source | The same operator-driver file remains present and byte-identical | Other runtime, deployment, and connector components changed; file equality does not renew the result |\n| Official Hermes source | The recorded upstream commit and exact Git tree | A source commit does not identify the retained Hermes image contents by itself |\n\nThe historical narrative retained outside this v2 page has SHA-256 digest\n0956b7fe3f1c96ee6696d8316d5f2de4f589a72a874f0920ceb055f1a0d19a71.\n\nIdentify the recorded artifacts\n\n| Artifact | Recorded identity |\n\n| AIP source base commit | c51e149ce1df762cb62bc736edfb81a674f56852 |\n| AIP base Git tree | e36378e93846cdf6730fd69a80462f9ebc471061 |\n| Qualification record and driver commit | f14af77e464625b92bd6c1b86774d1449acd8f3f |\n| AIP qualification image | aipd:local@sha256:00e468c3603941a091e5f9c473b121ef57c9d0f7eaf10f4e07ebfcaf58579786 |\n| Hermes Agent upstream commit | 7426c09beee73bdff94d916015bac71384f6bc92 |\n| Hermes Agent Git tree | 583423a976e761d3f076d2cf7f7859c13e40cc29 |\n| Hermes Agent image | hermes-agent:aip-lite@sha256:15912eaf6211f3b953ad6ed2268545a521cb0c440604231cc61dabfd9666f32c |\n| Architecture | linux/arm64 |\n| Reported model route | cohere/north-mini-code:free through an OpenRouter-compatible provider |\n\nThe official Hermes Agent checkout confirms the upstream commit and tree. A\nhistorical AIP checkout confirms the AIP base commit and tree.\n\nThe report says\nthe AIP image also contained then-current connector qualification work, but it\nrecords no source digest for that worktree. The direct child commit identified\nabove retains the report and driver, but no recorded digest binds its complete\ntree to the image. The image digest identifies what ran without making its\ncomplete source independently reconstructable.\n\nReview the isolated topology\n\nThe historical report describes:\n• two isolated Hermes Agent containers;\n• one AIP daemon with MCP Streamable HTTP and native AIP access;\n• an OAuth 2.0 token-introspection boundary;\n• NATS and a deterministic PostgreSQL-backed system of record;\n• an external orchestrator and a separately authenticated human approver;\n• a configured external model route.\n\nThis topology tested governed operator and delegation behavior. The controlled\nsystem of record was part of the test boundary, not one of the six maintained\npublic connectors and not a production provider.\n\nReview the reported security boundary\n\nThe narrative reports that both Hermes endpoints, the external orchestrator,\nand the human approver used distinct principals and credentials. An\nunauthenticated MCP initialize request returned HTTP 401 through the token\nintrospection boundary.\n\nIt also reports these controls:\n• each Hermes endpoint exposed only its selected AIP tools;\n• recursive delegation was absent from the model-facing allowlist;\n• Hermes received no credentials for the controlled system of record;\n• business facts entered the run only through authenticated AIP tool use;\n• native lifecycle state, rather than final model prose, supplied the\n  authoritative delegated result;\n• action contract, transport principal, scope, identity, tenant, and result\n  integrity were checked before accepting that result;\n• the report retained no access token, provider key, or introspection secret.\n\nNo raw authentication exchange or redaction log is retained with the report,\nso these are reported controls rather than independently replayable evidence.\n\nReconstruct the reported procedure\n\nThe campaign reportedly followed this sequence:\n1. Start the isolated AIP implementation stack, authorization boundary, NATS,\n   controlled record service, and two Hermes Agent endpoints.\n2. Verify that unauthenticated MCP initialization fails and that each embedded\n   authenticated Hermes MCP client discovers the expected tool surface.\n3. Submit one governed operator action to each endpoint and observe native\n   pending approval.\n4. Approve each immutable request through the separately authenticated native\n   principal.\n5. Observe structured Hermes runs, incremental stream chunks, and AIP tool\n   start and completion events.\n6. Verify exactly one downstream business action and compare its structured\n   result with an independently read expected record.\n7. Reject one delegated request outside the allowed scope.\n8. Execute one allowed first-class delegation and compare the protocol-assigned\n   child action with the actual downstream action.\n9. Repeat the operator and delegation path independently for the second Hermes\n   endpoint.\n\nThe report also states that a standalone Hermes MCP check authenticated and\ndiscovered 89 tools for each endpoint. This count is historical and\ntopology-specific.\n\nInspect the required assertions\n\nThe driver failed unless every endpoint satisfied all seven boundaries.\n\n| Assertion | Required result |\n\n| Independent approval | The operator action enters pending approval and resumes only after a separately authenticated decision |\n| Structured execution | Hermes starts a structured run and retains incremental stream chunks |\n| AIP tool lifecycle | The stream contains successful AIP tool start and completion events |\n| Trusted data path | Expected business facts arrive through the AIP tool rather than direct database access or model memory |\n| Scope enforcement | A delegated request outside the endpoint allowlist is rejected |\n| Delegation identity | One child action is assigned and the executed downstream action has exactly the same identifier |\n| Independent endpoints | Both isolated Hermes endpoints complete the full operator and delegation path |\n\nThe equality between the assigned child action and the executed downstream\naction is the decisive delegation invariant. Model-generated prose or a\nreplacement identifier cannot satisfy it.\n\nInspect the reported observations\n\nThe public v2 record omits controlled-system capability names, disposable\nbusiness records, and execution identifiers. The retained historical source\nremains the audit input for authorized reviewers.\n\n| Observation | Endpoint A | Endpoint B |\n\n| Stream chunks | 74 | 76 |\n| Pending and authenticated approval | PASS | PASS |\n| AIP tool start and completion | PASS | PASS |\n| Exactly one direct downstream action | PASS | PASS |\n| Out-of-scope delegation rejected | PASS | PASS |\n| Child action equals delegated downstream action | PASS | PASS |\n| Structured business output matches expected record | PASS | PASS |\n\nThese values are transcribed from the narrative report. No separately retained\ndriver JSON is available to verify them.\n\nAccount for missing and excluded evidence\n\nThe result does not establish:\n• qualification of any connector other than Hermes Agent;\n• current behavior of revision\n  97be86e9efedf07ecf1783b03800f683f107fb04;\n• exact reconstruction of the uncommitted AIP qualification worktree;\n• independent proof of the model-provider response, raw streams, native state,\n  database reads, or authorization exchange;\n• model quality, provider availability, latency, capacity, or cost;\n• production TLS, workload isolation, secret management, egress policy,\n  storage, tenancy, or disaster recovery;\n• execution of the historically listed deterministic tests and static checks;\n• teardown of the isolated stack or cleanup of every disposable effect.\n\nThe current qualification standard makes independently verified cleanup part\nof PASS. The historical report has no cleanup record. Its status remains a\nreported historical PASS under the scope used on 11 July 2026, but it cannot\nbe accepted as a new campaign result under the current standard.\n\nUnderstand the current source relationship\n\nThe operator-driver source has the same SHA-256 digest at the historical\nqualification commit and at the pinned review revision:\n\n2464b1af2d40ab37280bf184377ceb79991823bac44d660c8247c5a54f19b15d\n\nThis equality confirms that the seven driver checks did not change in that\nfile. It says nothing about changes in the daemon, runtime, gateway, MCP\nserver, deployment, images, credentials, Hermes configuration, or provider.\n\nRun only a new campaign\n\nUse the current live-product procedure (live-product-e2e.md) and the retained\noperator entry point to create a new result. Record protected credentials\noutside the command history and supply two endpoint identifiers from the\nisolated deployment.\n\ncargo run -p aip-connector-hermes-agent \\\n  --bin aipd-hermes-operator-smoke -- \\\n  --endpoint-id \"hermes-qualification-a\" \\\n  --endpoint-id \"hermes-qualification-b\"\n\nThe command requires the MCP and native approver tokens described by the\nprocedure. A successful new exit does not repair the missing historical\nevidence; retain the new driver output, identities, cleanup result, and checksum\nmanifest as a separate campaign.\n\nRelated documentation\n• Testing and qualification (README.md)\n• Live-product qualification procedure (live-product-e2e.md)\n• Connector upstream baselines (../connectors/upstream-baselines.md)\n• Implementation status (../reference/implementation-status.md)\n• Hermes Agent connector (../connectors/hermes-agent.md)\n"
  },
  "integrity": {
    "algorithm": "sha256",
    "sourceDigest": "0175b7a994701d972e903d1959c92ae378983647d35ff9763456dade4cef7e3f"
  }
}
