Processing...

 AI Agents: OpenClaw, Hermes Agent and NemoClaw, Deployed Safely

Self-hosted AI agents with the permissions, sandboxing and oversight a business needs

Self-hosted AI agents such as OpenClaw and Hermes Agent can read and send email, manage calendars, browse the web, query databases and run commands on their own. That is what makes them useful, and it is what makes them dangerous on a business network. GEN deploy them the way a business needs: sandboxed, on local models, with only the tools and data each agent needs, and every action logged.

Many of our conversations start the other way round, with an agent someone has already installed on a work machine. We find out what it can reach, contain it, and either replace it with a controlled deployment or remove it.

  • "Someone installed OpenClaw on their laptop"
  • "Could an agent handle our routine admin?"
  • "We want agents, but not in the cloud"
  • "Which is safer, OpenClaw or Hermes?"
LocalModels run by GEN or on your hardware, not a cloud AI service
SandboxedEach agent contained, with its network access set by policy
Least accessOnly the tools and data the job needs
LoggedEvery action recorded and open to review

Why Agents Need Care

An agent acts with whatever access it has been given, and it cannot reliably tell an instruction from its user apart from an instruction hidden in an email, a document or a web page it has been asked to read. Installed on a work machine with a member of staff's own access, it can reach their mailbox, their files, their saved passwords and every system they are signed into, and it will act on that access quickly and confidently, including when it is wrong.

OpenClaw's early releases shipped with permissive defaults and were followed by a long run of published vulnerabilities, and some of the community skills that extend it have been found to be malicious. The project has hardened a great deal since, and Hermes Agent was designed with security in mind from the start, but no agent is safe simply because of the software it runs. Safety comes from what it is allowed to reach, and that is a matter of design.

What goes wrong

  • Instructions hidden in an email or web page are obeyed
  • An unreviewed skill does more than it claims
  • Broad file, terminal or mailbox access turns one mistake into many
  • Credentials and documents leave through a connected tool
  • The agent misreads the task and acts on it anyway
  • Nobody in IT knows the agent is there

OpenClaw, Hermes Agent and NemoClaw

OpenClaw

The best known self-hosted agent, now run by the OpenClaw Foundation and developing quickly. It has the largest ecosystem of skills and integrations, which gives it the most capability and the largest attack surface, so every skill we deploy is reviewed first.

Hermes Agent

Nous Research's open source agent, now as widely used as OpenClaw. It works with any model, keeps a memory that improves with use, and was built with a layered security model from the start, which makes it a natural fit where the data is sensitive.

NemoClaw

NVIDIA's open source stack that runs OpenClaw or Hermes Agent inside its OpenShell sandbox, with network policy, privacy and inference controls around the agent. Still in early releases, so we use it as one layer of protection among several.

How We Deploy an Agent

A defined job

Each agent does one job, agreed in advance, such as triaging service desk tickets or drafting replies to enquiries. An agent with a vague remit needs broad access, and broad access is the risk.

Sandboxed

The agent runs in its own contained environment, under NemoClaw's OpenShell or a dedicated container, with its network access limited to the services the job needs.

Local models

Reasoning runs on GAIN, our own AI platform, or on models on your own hardware, so prompts and documents are not sent to a cloud AI service.

Least access

Only vetted skills, read-only access wherever writing is not needed, and credentials of the agent's own rather than a member of staff's, so they can be limited and withdrawn.

A person approves

Anything that sends, pays, deletes or commits the business waits for a person to approve it. The agent prepares the work; someone accountable releases it.

Logged and reviewed

Every request, plan, tool call and result is recorded, so you can see what the agent did and why, and we review the logs as part of supporting it.

What Agents Connect To

We set agents up around the systems your teams already use, each connection built with the least access the job needs. Typical deployments include web search for research, controlled database queries and updates, corporate calendars and address books over CalDAV and CardDAV, and email that the agent can read and send within defined limits.

We also connect agents to n8n, so an agent can start a workflow and a workflow can hand a task to an agent. That combines judgement where it is needed with predictable, auditable steps for approvals, notifications and back-office processing. Beyond these, we build skills for your own APIs, file stores, reporting tools and line of business systems, using the same integration frameworks as the rest of our development work.

Where it runs

  • Hosted by GEN on our own infrastructure in the UK
  • Or on your own servers, deployed and supported by us
  • Models on GAIN, or on your own hardware
  • Supported through the HelpDesk under a service level agreement

Agents Already on Your Network

Installing OpenClaw or Hermes Agent takes a single command, and staff who have read about them are doing exactly that, on work laptops, signed into work accounts. Most do it with good intentions, to get through routine work faster, and without realising that the agent now holds the same access they do.

We review what has been installed and what it can reach, contain it, and then either bring it under control as a proper deployment or remove it cleanly. The aim is not to stop people using agents, but to make sure the business decides what they can touch.

The review

  • Where agents are installed, and by whom
  • Which accounts, files and systems each one can reach
  • Which skills and connections each one has
  • Contain, then replace with a controlled deployment or remove

AI Agent Questions

Is OpenClaw safe to use in a business?

Not as it is usually installed, on a work machine with the user's own access to everything. With a sandbox, a narrow job, vetted skills, the least access that job needs and a person approving anything consequential, it can be. The risk comes from what the agent can reach, so that is what we control.

Should we use OpenClaw or Hermes Agent?

It depends on the job. Hermes Agent was designed with a layered security model from the start. OpenClaw has the larger ecosystem of skills and integrations, and has hardened considerably since its first few months. Both can run inside NemoClaw's sandbox, and we recommend one or the other per deployment rather than as a rule.

Do our data and prompts go to a cloud AI service?

Not in a deployment run by GEN. Agents use local models on GAIN, our own AI platform, or models on your own hardware, so your documents, email and prompts stay within systems you or we control.

What is NemoClaw?

NVIDIA's open source stack for running OpenClaw and Hermes Agent inside its OpenShell sandbox, which adds network policy, privacy and inference controls around the agent. It is still in early releases, so we treat it as one layer of protection rather than the only one.

Someone has already installed an agent. What should we do?

Find out what it can reach before anything else: which accounts it is signed into, which files and systems it can touch, and which skills it has installed. Then contain it. We can carry out that review, and either replace it with a controlled deployment or remove it cleanly.

When is n8n a better choice than an agent?

Whenever the steps are known in advance. n8n runs the same workflow the same way every time and is easy to audit. An agent is for work that needs judgement, such as reading an enquiry and deciding what it is about. Many deployments use both, with the agent handing the predictable steps to n8n.

Start With One Job

The agents that work in business are the ones given one clear job and no more access than it needs. Tell us which piece of routine work you would like taken off your team, and what systems it touches, and we will tell you whether an agent, a workflow or both is the right answer.

If an agent is already running somewhere it should not be, tell us that too. It is quicker to contain now than to explain later.

Contact Us