How to Deploy Hermes Agent: A UK Business Complete Guide (2026)
Deploy Hermes Agent for a UK business using the current Linux setup, gateway service, scoped tools, monitoring, security controls and recovery testing.
Co-founder of Ampliflow. Builds AI automation, websites, SEO/AEO, and growth systems for UK SMEs.

- 011. Choose the host
- 022. Prepare the server
- 033. Install Hermes Agent
- 046. Scope the tools
- 058. Monitor the things that fail
Deploying Hermes Agent for a business is not just running the installer. A useful deployment has a Linux host, a configured model route, a managed gateway service, scoped tools, backups, monitoring, and a written recovery path. The install can take minutes. The operating boundary is the work that decides whether the agent is useful or reckless.
Use this guide to plan the end-to-end deployment, then follow the linked specialist guides for Oracle Cloud, security, monitoring and backup/migration details.
Last updated: 6 September 2026. Checked against the official Hermes installation, messaging and updating documentation on 6 September 2026.
TL;DR:
- Install Hermes from the official installer, then run
hermes setup,hermes doctorandhermes gateway status. - On a VPS, run the gateway as a managed service using the Hermes gateway commands, not a copied service file from an old tutorial.
- Choose Oracle Free Tier only when capacity risk is acceptable; a small paid VPS is often simpler once a workflow matters.
- Disable broad tools until the workflow needs them. Shell, file write, browser automation and external sending all need explicit scope.
- Add backups, update receipts, monitoring and a restore drill before real work depends on the agent.
If you are weighing up whether to build this yourself, use the guide as a due-diligence checklist. For a managed system, start with AI automation, Apps & MVPs, or get unstuck.
The production shape
A working Hermes deployment brings together these parts:
textLinux host
-> Hermes install
-> configured model provider
-> messaging gateway service
-> scoped tools and skills
-> logs, backups and update receipts
-> monitoring and recovery runbook
-> human approval for risky actionsDo not skip the last three. They are what turn an interesting agent into an operated business system.
1. Choose the host
Hermes does not need a GPU. It needs uptime, memory headroom, predictable access and a recovery owner.
| Host | Good fit | Watch out for |
|---|---|---|
| Oracle Cloud Free Tier | Narrow proof-of-concept where free-eligible capacity is available | Capacity errors, idle reclamation, account limits |
| Small paid VPS | Founder/team pilot that needs predictable uptime | Current price, backups, support and region |
| AWS/GCP/Azure | Teams already operating in that cloud | Cost estimate, IAM complexity, region/model routing |
| On-premise Linux host | Local-data requirement with an owner | Power, network, patching and remote recovery |
The Oracle Cloud guide covers the current Always Free limits and the capacity caveats. Use it if Oracle is your preferred first host.
2. Prepare the server
Use a supported Linux environment. For production, create a dedicated unprivileged service user rather than running the agent from a general admin account.
Minimum preparation:
bashsudo apt update
sudo apt upgrade -y
sudo npx playwright install-deps chromiumThe Playwright dependency step is only needed if your workflows use browser automation or computer-use features. If your Hermes deployment is headless and does not need browser automation, skip that path and keep the server smaller.
Keep credentials out of repositories and screenshots. Before setup, collect only the credentials the first workflow actually needs:
- model provider key or local model route;
- messaging-channel credential/pairing plan;
- API keys for approved business systems;
- backup destination;
- monitoring alert destination.
3. Install Hermes Agent
- 01Provision and patch the host
- 02Install with least privilege
- 03Add secrets outside source control
- 04Configure restart and monitoring
- 05Test recovery before real work
The current official command for Linux, macOS, WSL2 and Termux is:
bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bashFor a headless deployment that does not need browser automation:
bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browserThen configure:
bashhermes setup
hermes doctor
hermes --versionhermes setup runs the configuration wizard. hermes doctor is the quick health check. Do not pin this article to a specific Hermes version; check the installed version on the server you are operating.
4. Install the gateway service
For a headless VPS, the current Hermes messaging docs recommend the system-service route:
bashsudo hermes gateway install --system
sudo hermes gateway start --system
sudo hermes gateway status --system
journalctl -u hermes-gateway -fFor a user service:
bashhermes gateway install
hermes gateway start
hermes gateway status
journalctl --user -u hermes-gateway -fFor a headless VM where the service should survive logout:
bashsudo loginctl enable-linger $USERThe current updating docs also note that user services can be restarted by hermes update without root prompts. Pick one service model and document it.
Do not keep both installed unless you have a reason. Hermes warns about ambiguous service behaviour when both user and system gateway units exist.
5. Connect the messaging channel
For WhatsApp:
bashhermes whatsapp linkUse a dedicated business number where possible. It gives the agent a cleaner audit trail and avoids linking a founder's primary WhatsApp to a server nobody wants to debug during a family weekend.
Before production use, test:
- message in;
- message out;
- restart gateway;
- message after restart;
- host reboot;
- message after reboot.
That catches the difference between "the QR code scanned" and "the channel survives operations".
6. Scope the tools
A business agent should not start life with every capability enabled.
Start with the smallest practical permission set for the first workflow. Write down the sources it may read, the outputs it may create, the commands or scripts it may call, the external services it may contact, and the actions that need human approval.
If the workflow needs write access, enforce that boundary with operating-system permissions, containers, fixed scripts or the controls available in your installed Hermes version. If the workflow needs a command, wrap the command in a narrow script with validation. If the workflow sends an external message, require human approval until the risk is well understood.
The security detail is in Hermes Agent Security & GDPR.
7. Add backups and update discipline
Current Hermes has better native update tooling than older guides described:
bashhermes update --check
hermes update --plan
hermes update --backupThe official update docs describe default snapshots, optional full HERMES_HOME backups, update receipts, post-pull validation, gateway restart checks and version checks.
For host migration or full state recovery, use:
bashhermes backup
hermes import <backup-file>The dedicated Hermes backup and restore guide covers the move-server sequence. Treat that guide as required reading before a free-tier Oracle pilot becomes a business dependency.
8. Monitor the things that fail
For a single deployment, monitor:
| Layer | Check |
|---|---|
| Host | instance state, SSH, disk space |
| Gateway | `hermes gateway status`, systemd state |
| Messaging | channel pairing and send/receive test |
| Model provider | auth, quota, rate limit, provider status |
| Updates | `~/.hermes/logs/update_receipts/latest.json` |
| Backups | last successful restore drill |
The monitoring and recovery guide gives the five-minute down-agent sequence and one-page runbook.
9. Define the first business workflow
Do not begin with "give the agent access to the business". Begin with one narrow workflow:
Every weekday at 08:00, read yesterday's website enquiries, group them by urgency, draft next actions, send the owner a WhatsApp summary, and do not contact the lead.
That contains the schedule, sources, output, action boundary and approval rule. It is boring enough to test.
Good first workflows:
- daily lead summary;
- weekly reporting summary;
- read-only CRM review queue;
- supplier or competitor digest;
- internal knowledge-base answer draft.
Poor first workflows:
- customer-facing decisions;
- finance actions;
- deletion;
- anything nobody has written down;
- anything the owner will not review.
10. Decide who owns it
Every Hermes deployment needs a named operator. The operator owns:
- server access;
- credentials;
- enabled workflows;
- update cadence;
- backup restore tests;
- incident notes;
- tool permission reviews;
- escalation when the agent should stop.
If nobody owns that list, the deployment is still an experiment.
Frequently asked questions
Can I deploy Hermes Agent on Oracle Cloud Free Tier?
Yes, for a narrow pilot when capacity is available and the workflow can tolerate migration. Read the Oracle guide before assuming the free tier is a production guarantee.
Can Hermes Agent run on Windows?
The official installer supports native Windows and WSL2, but a production server workflow is cleaner on Linux because the gateway service, systemd logs, server patching and recovery paths are easier to operate.
Is Hermes Agent free?
Hermes is open-source software. You still own hosting, model-provider usage, credentials, monitoring, backup storage, support time and maintenance.
What command tells me whether Hermes is healthy?
Start with:
bashhermes doctor
hermes gateway statusThen check logs with journalctl --user -u hermes-gateway -f for a user service or journalctl -u hermes-gateway -f for a system service.
Should I auto-update Hermes?
Only after backups and rollback are tested. Use the native update path first: hermes update --check, hermes update --plan, hermes update --backup, then inspect update receipts.
Can Ampliflow deploy this?
Yes, when the workflow is clear enough to operate responsibly. We start with the smallest useful deployment boundary, then add skills and channels only when the first loop is reliable.
Related reading
- Hermes Agent on Oracle Cloud Free Tier
- Hermes Agent Down? Monitoring, Logs, systemd & Production Recovery
- Hermes Agent Security & GDPR
- Hermes Agent Backup & Restore: Move Server Without Losing Memory
- Hermes Agent Production Cost Teardown
- External: Hermes installation docs, Hermes messaging gateway docs, Hermes updating docs.
What should you do next?
If Hermes is still an experiment, install it and prove one workflow. If it will touch real business operations, finish the runbook, monitoring, backup and approval path first.