PTENES
MODULE 3.1

🛡️ Security · Principle of least access

An agent doesn’t just talk — it actsIt sends email, modifies files, spends money. That’s why the first operating rule isn’t a feature: it’s an attitude. Grant the least access possible, never expose secrets, and enable capabilities gradually.

6
Topics
~25
Minutes
Advanced
Level
Practice
Type
1

⚖️ With great power comes great responsibility

In Tracks 1 and 2, you saw Hermes gain capabilities: computer actions, integrations, MCPs, memory. Each of these is a door to the real world. A chatbot that makes a mistake gives you a bad answer; an agent that makes a mistake can send the wrong email to the wrong client or delete a file. The difference isn’t one of degree — it’s one of kind.

🧭 The right mindset

Think of the agent as a very fast, very literal intern. You wouldn't give a first-day intern the company's bank password. You give them small tasks, observe them, and only expand their access when you trust them.

  • •Enable capabilities one at a time, not all of them during setup.
  • •Observe its behavior before giving it access to irreversible actions.
  • •Treat each new capability as a conscious decision, not a default.
Acts, doesn’t talk

Errors have real-world consequences.

Little by little

One capability at a time.

Observe

Trust it after you see it in action.

Conscious

Every capability is a decision.

2

🔐 The principle of least access

In security, this has a name: least privilege (least privilege). The rule is simple: each part of a system should have the minimum access necessary to do its job — and nothing more. This applies to Hermes, your phone, and your bank account. It’s the most universal security principle there is.

Read safe Write / edit Send / delete — requires more trust more access → ← less risk

Illustrative diagram · each ring outward means more power and more risk

📐 The three access levels

  • Read — the agent only observes (check email, read a file). Low risk, reversible.
  • Write / edit — creates or modifies (draft an email, save a file). Medium risk.
  • Send / delete — irreversible actions in the world. High risk; save for last.
3

📧 The Email-Sending Case

The classic example, and where most people got burned: you connect Gmail and, excited, grant everything — including sending. In an automatic morning briefing, the agent misinterprets an instruction and sends an email to the wrong list. You can’t “unsend” an email.

✓ Start here

  • ✓Connect read-only of email (summarize inbox).
  • ✓Let the agent draft answers for you to review.
  • ✓Observe for days to see if the readings are correct.

✗ Avoid at the start

  • ✗Allow automatic sending without human review.
  • ✗Grant send access within an unsupervised 24/7 cron job.
  • ✗Trusting "it understood" without testing it in read-only mode.

💡 Practical tip

Golden rule: irreversible actions last. Email, transfer, deletion — only after the agent has proven, in read/draft mode, that it understands what you want.

4

🔑 Never paste API keys into chat

Remember memory (Trail 2)? Every message from every session is indexed and savedIf you paste an API key into chat, it becomes a permanent part of memory — even worse if you enabled the daily backup on GitHub: now the secret is versioned. A secret belongs in a environment variable, not the chat.

The right way to add a key (illustrative)

# 1. ask Hermes for a terminal command with a placeholder
export OPENROUTER_API_KEY="COLE_SUA_CHAVE_AQUI"
# 2. replace the placeholder with the real key IN THE TERMINAL
# 3. paste it into the terminal — never back into the chat

🚨 Caution

If you've already pasted a key into the chat, consider it compromised: rotate it immediately. When you rotate it, the old key stops working forever — exactly what you want.

5

🚦 Allow once / session / never

When the agent needs a new permission, it asks. You choose between three levels — and each trades convenience for control. Think of them as a gate with three openings.

1

Allow once — allow one time

For something unfamiliar or one-off

The agent performs the action this time and asks again next time. Maximum control, minimum convenience. Use it for things you don't trust it with yet.

2

Allow session — allow for the session

For repetitive tasks in the same job

It lasts for the session; after a reset, it asks again. A good balance for a task that repeats the same action several times.

3

Never — block it completely

For what's dangerous or unwanted

The agent never asks or executes again. Use this for actions you've decided it should never take.

6

✅ Responsible use applies to all AI

The best thing about security is that it’s transferableThe habits you build with Hermes — least access, secrets kept out of chat, irreversible actions saved for last — protect you with any agent, plugin, or AI system you use from now on.

🧠 Practical tip

Before enabling any new capability, ask three questions: (1) is it reversible? (2) what’s the worst-case scenario? (3) Have I tested it in read-only mode? If anything gets stuck, it’s not ready yet.

Minimum access

Only what’s necessary.

Secrets kept out

Env, never chat.

Leave irreversible actions for last

Send first, delete later.

Transferable

Applies to all AI.

📌 Module Summary

✓
Acts, doesn’t talk - agent errors have real consequences, so security comes first.
✓
Least access - give only the minimum: read ≠ write ≠ send.
✓
Email last - read and draft first; send only once you trust it.
✓
Secrets in env - never paste API keys into chat; if one leaks, rotate it.
✓
Once / session / never - balance convenience against control.

Next Module:

3.2 - ⭐ Northstar (Goals): give the agent a direction to pursue until it reaches the goal.