Subscribe to GEN
Login to GEN
Self-hosted AI agents such as OpenClaw and Hermes Agent can read and send email, manage calendars, browse the web, query databases and run commands on their own. That is what makes them useful, and it is what makes them dangerous on a business network. GEN deploy them the way a business needs: sandboxed, on local models, with only the tools and data each agent needs, and every action logged.
Many of our conversations start the other way round, with an agent someone has already installed on a work machine. We find out what it can reach, contain it, and either replace it with a controlled deployment or remove it.
An agent acts with whatever access it has been given, and it cannot reliably tell an instruction from its user apart from an instruction hidden in an email, a document or a web page it has been asked to read. Installed on a work machine with a member of staff's own access, it can reach their mailbox, their files, their saved passwords and every system they are signed into, and it will act on that access quickly and confidently, including when it is wrong.
OpenClaw's early releases shipped with permissive defaults and were followed by a long run of published vulnerabilities, and some of the community skills that extend it have been found to be malicious. The project has hardened a great deal since, and Hermes Agent was designed with security in mind from the start, but no agent is safe simply because of the software it runs. Safety comes from what it is allowed to reach, and that is a matter of design.
The best known self-hosted agent, now run by the OpenClaw Foundation and developing quickly. It has the largest ecosystem of skills and integrations, which gives it the most capability and the largest attack surface, so every skill we deploy is reviewed first.
Nous Research's open source agent, now as widely used as OpenClaw. It works with any model, keeps a memory that improves with use, and was built with a layered security model from the start, which makes it a natural fit where the data is sensitive.
NVIDIA's open source stack that runs OpenClaw or Hermes Agent inside its OpenShell sandbox, with network policy, privacy and inference controls around the agent. Still in early releases, so we use it as one layer of protection among several.
Each agent does one job, agreed in advance, such as triaging service desk tickets or drafting replies to enquiries. An agent with a vague remit needs broad access, and broad access is the risk.
The agent runs in its own contained environment, under NemoClaw's OpenShell or a dedicated container, with its network access limited to the services the job needs.
Reasoning runs on GAIN, our own AI platform, or on models on your own hardware, so prompts and documents are not sent to a cloud AI service.
Only vetted skills, read-only access wherever writing is not needed, and credentials of the agent's own rather than a member of staff's, so they can be limited and withdrawn.
Anything that sends, pays, deletes or commits the business waits for a person to approve it. The agent prepares the work; someone accountable releases it.
Every request, plan, tool call and result is recorded, so you can see what the agent did and why, and we review the logs as part of supporting it.
We set agents up around the systems your teams already use, each connection built with the least access the job needs. Typical deployments include web search for research, controlled database queries and updates, corporate calendars and address books over CalDAV and CardDAV, and email that the agent can read and send within defined limits.
We also connect agents to n8n, so an agent can start a workflow and a workflow can hand a task to an agent. That combines judgement where it is needed with predictable, auditable steps for approvals, notifications and back-office processing. Beyond these, we build skills for your own APIs, file stores, reporting tools and line of business systems, using the same integration frameworks as the rest of our development work.
Installing OpenClaw or Hermes Agent takes a single command, and staff who have read about them are doing exactly that, on work laptops, signed into work accounts. Most do it with good intentions, to get through routine work faster, and without realising that the agent now holds the same access they do.
We review what has been installed and what it can reach, contain it, and then either bring it under control as a proper deployment or remove it cleanly. The aim is not to stop people using agents, but to make sure the business decides what they can touch.
Not as it is usually installed, on a work machine with the user's own access to everything. With a sandbox, a narrow job, vetted skills, the least access that job needs and a person approving anything consequential, it can be. The risk comes from what the agent can reach, so that is what we control.
It depends on the job. Hermes Agent was designed with a layered security model from the start. OpenClaw has the larger ecosystem of skills and integrations, and has hardened considerably since its first few months. Both can run inside NemoClaw's sandbox, and we recommend one or the other per deployment rather than as a rule.
Not in a deployment run by GEN. Agents use local models on GAIN, our own AI platform, or models on your own hardware, so your documents, email and prompts stay within systems you or we control.
NVIDIA's open source stack for running OpenClaw and Hermes Agent inside its OpenShell sandbox, which adds network policy, privacy and inference controls around the agent. It is still in early releases, so we treat it as one layer of protection rather than the only one.
Find out what it can reach before anything else: which accounts it is signed into, which files and systems it can touch, and which skills it has installed. Then contain it. We can carry out that review, and either replace it with a controlled deployment or remove it cleanly.
Whenever the steps are known in advance. n8n runs the same workflow the same way every time and is easy to audit. An agent is for work that needs judgement, such as reading an enquiry and deciding what it is about. Many deployments use both, with the agent handing the predictable steps to n8n.
The agents that work in business are the ones given one clear job and no more access than it needs. Tell us which piece of routine work you would like taken off your team, and what systems it touches, and we will tell you whether an agent, a workflow or both is the right answer.
If an agent is already running somewhere it should not be, tell us that too. It is quicker to contain now than to explain later.