Skip to main content
Back to Read
AI Agents13 April 2026Updated 6 September 20268 min read

How to Deploy Hermes Agent: A UK Business Complete Guide (2026)

Deploy Hermes Agent for a UK business using the current Linux setup, gateway service, scoped tools, monitoring, security controls and recovery testing.

Sajad Saleem

Co-founder of Ampliflow. Builds AI automation, websites, SEO/AEO, and growth systems for UK SMEs.

A compact computer and network cable being prepared on a painted shelf.
Illustrative scene.
  1. 011. Choose the host
  2. 022. Prepare the server
  3. 033. Install Hermes Agent
  4. 046. Scope the tools
  5. 058. Monitor the things that fail

Deploying Hermes Agent for a business is not just running the installer. A useful deployment has a Linux host, a configured model route, a managed gateway service, scoped tools, backups, monitoring, and a written recovery path. The install can take minutes. The operating boundary is the work that decides whether the agent is useful or reckless.

Use this guide to plan the end-to-end deployment, then follow the linked specialist guides for Oracle Cloud, security, monitoring and backup/migration details.

Last updated: 6 September 2026. Checked against the official Hermes installation, messaging and updating documentation on 6 September 2026.

TL;DR:

  • Install Hermes from the official installer, then run hermes setup, hermes doctor and hermes gateway status.
  • On a VPS, run the gateway as a managed service using the Hermes gateway commands, not a copied service file from an old tutorial.
  • Choose Oracle Free Tier only when capacity risk is acceptable; a small paid VPS is often simpler once a workflow matters.
  • Disable broad tools until the workflow needs them. Shell, file write, browser automation and external sending all need explicit scope.
  • Add backups, update receipts, monitoring and a restore drill before real work depends on the agent.

If you are weighing up whether to build this yourself, use the guide as a due-diligence checklist. For a managed system, start with AI automation, Apps & MVPs, or get unstuck.

The production shape

A working Hermes deployment brings together these parts:

textLinux host
  -> Hermes install
  -> configured model provider
  -> messaging gateway service
  -> scoped tools and skills
  -> logs, backups and update receipts
  -> monitoring and recovery runbook
  -> human approval for risky actions

Do not skip the last three. They are what turn an interesting agent into an operated business system.

1. Choose the host

Hermes does not need a GPU. It needs uptime, memory headroom, predictable access and a recovery owner.

HostGood fitWatch out for
Oracle Cloud Free TierNarrow proof-of-concept where free-eligible capacity is availableCapacity errors, idle reclamation, account limits
Small paid VPSFounder/team pilot that needs predictable uptimeCurrent price, backups, support and region
AWS/GCP/AzureTeams already operating in that cloudCost estimate, IAM complexity, region/model routing
On-premise Linux hostLocal-data requirement with an ownerPower, network, patching and remote recovery

The Oracle Cloud guide covers the current Always Free limits and the capacity caveats. Use it if Oracle is your preferred first host.

2. Prepare the server

Use a supported Linux environment. For production, create a dedicated unprivileged service user rather than running the agent from a general admin account.

Minimum preparation:

bashsudo apt update
sudo apt upgrade -y
sudo npx playwright install-deps chromium

The Playwright dependency step is only needed if your workflows use browser automation or computer-use features. If your Hermes deployment is headless and does not need browser automation, skip that path and keep the server smaller.

Keep credentials out of repositories and screenshots. Before setup, collect only the credentials the first workflow actually needs:

  • model provider key or local model route;
  • messaging-channel credential/pairing plan;
  • API keys for approved business systems;
  • backup destination;
  • monitoring alert destination.

3. Install Hermes Agent

  1. 01Provision and patch the host
  2. 02Install with least privilege
  3. 03Add secrets outside source control
  4. 04Configure restart and monitoring
  5. 05Test recovery before real work

The current official command for Linux, macOS, WSL2 and Termux is:

bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash

For a headless deployment that does not need browser automation:

bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser

Then configure:

bashhermes setup
hermes doctor
hermes --version

hermes setup runs the configuration wizard. hermes doctor is the quick health check. Do not pin this article to a specific Hermes version; check the installed version on the server you are operating.

4. Install the gateway service

For a headless VPS, the current Hermes messaging docs recommend the system-service route:

bashsudo hermes gateway install --system
sudo hermes gateway start --system
sudo hermes gateway status --system
journalctl -u hermes-gateway -f

For a user service:

bashhermes gateway install
hermes gateway start
hermes gateway status
journalctl --user -u hermes-gateway -f

For a headless VM where the service should survive logout:

bashsudo loginctl enable-linger $USER

The current updating docs also note that user services can be restarted by hermes update without root prompts. Pick one service model and document it.

Do not keep both installed unless you have a reason. Hermes warns about ambiguous service behaviour when both user and system gateway units exist.

5. Connect the messaging channel

For WhatsApp:

bashhermes whatsapp link

Use a dedicated business number where possible. It gives the agent a cleaner audit trail and avoids linking a founder's primary WhatsApp to a server nobody wants to debug during a family weekend.

Before production use, test:

  1. message in;
  2. message out;
  3. restart gateway;
  4. message after restart;
  5. host reboot;
  6. message after reboot.

That catches the difference between "the QR code scanned" and "the channel survives operations".

6. Scope the tools

A business agent should not start life with every capability enabled.

Start with the smallest practical permission set for the first workflow. Write down the sources it may read, the outputs it may create, the commands or scripts it may call, the external services it may contact, and the actions that need human approval.

If the workflow needs write access, enforce that boundary with operating-system permissions, containers, fixed scripts or the controls available in your installed Hermes version. If the workflow needs a command, wrap the command in a narrow script with validation. If the workflow sends an external message, require human approval until the risk is well understood.

The security detail is in Hermes Agent Security & GDPR.

7. Add backups and update discipline

Current Hermes has better native update tooling than older guides described:

bashhermes update --check
hermes update --plan
hermes update --backup

The official update docs describe default snapshots, optional full HERMES_HOME backups, update receipts, post-pull validation, gateway restart checks and version checks.

For host migration or full state recovery, use:

bashhermes backup
hermes import <backup-file>

The dedicated Hermes backup and restore guide covers the move-server sequence. Treat that guide as required reading before a free-tier Oracle pilot becomes a business dependency.

8. Monitor the things that fail

For a single deployment, monitor:

LayerCheck
Hostinstance state, SSH, disk space
Gateway`hermes gateway status`, systemd state
Messagingchannel pairing and send/receive test
Model providerauth, quota, rate limit, provider status
Updates`~/.hermes/logs/update_receipts/latest.json`
Backupslast successful restore drill

The monitoring and recovery guide gives the five-minute down-agent sequence and one-page runbook.

9. Define the first business workflow

Do not begin with "give the agent access to the business". Begin with one narrow workflow:

Every weekday at 08:00, read yesterday's website enquiries, group them by urgency, draft next actions, send the owner a WhatsApp summary, and do not contact the lead.

That contains the schedule, sources, output, action boundary and approval rule. It is boring enough to test.

Good first workflows:

  • daily lead summary;
  • weekly reporting summary;
  • read-only CRM review queue;
  • supplier or competitor digest;
  • internal knowledge-base answer draft.

Poor first workflows:

  • customer-facing decisions;
  • finance actions;
  • deletion;
  • anything nobody has written down;
  • anything the owner will not review.

10. Decide who owns it

Every Hermes deployment needs a named operator. The operator owns:

  • server access;
  • credentials;
  • enabled workflows;
  • update cadence;
  • backup restore tests;
  • incident notes;
  • tool permission reviews;
  • escalation when the agent should stop.

If nobody owns that list, the deployment is still an experiment.

Frequently asked questions

Can I deploy Hermes Agent on Oracle Cloud Free Tier?

Yes, for a narrow pilot when capacity is available and the workflow can tolerate migration. Read the Oracle guide before assuming the free tier is a production guarantee.

Can Hermes Agent run on Windows?

The official installer supports native Windows and WSL2, but a production server workflow is cleaner on Linux because the gateway service, systemd logs, server patching and recovery paths are easier to operate.

Is Hermes Agent free?

Hermes is open-source software. You still own hosting, model-provider usage, credentials, monitoring, backup storage, support time and maintenance.

What command tells me whether Hermes is healthy?

Start with:

bashhermes doctor
hermes gateway status

Then check logs with journalctl --user -u hermes-gateway -f for a user service or journalctl -u hermes-gateway -f for a system service.

Should I auto-update Hermes?

Only after backups and rollback are tested. Use the native update path first: hermes update --check, hermes update --plan, hermes update --backup, then inspect update receipts.

Can Ampliflow deploy this?

Yes, when the workflow is clear enough to operate responsibly. We start with the smallest useful deployment boundary, then add skills and channels only when the first loop is reliable.

What should you do next?

If Hermes is still an experiment, install it and prove one workflow. If it will touch real business operations, finish the runbook, monitoring, backup and approval path first.

Hermes setup help

Deployment, skills and day-two reliability

Get help setting up your Hermes agent

We deploy, harden and maintain Hermes Agent for UK businesses — cloud hosting, gateways, skills, approvals, monitoring and recovery included.

Cloud deployment & hardening
WhatsApp, Slack & email
Safe, repeatable skills
Monitoring & recovery
Scope my Hermes setup

Bring the use case or the setup you already have. We will tell you the smallest sensible next step.