Hermes adds a root-owned, user-immutable /etc/hermes managed scope
What this changes for operators
- PR #49098 (in v0.17.0 / v2026.6.19) adds a managed
/etc/hermesscope: a root-owned, user-immutable layer of config and secrets that wins per-key over a user's own files. It is Hermes's first centralized, OS-backed policy pin, for a tool whose posture had been governs-through-allowlists, not identity services. - Operators wanting an OS-enforced policy floor can now pin config and secrets a user cannot override; audit which keys the managed scope wins so credential flow stays legible.
Primary sources
Signal metadata
Source findings
- 2026-06-23-hermes-managed-scope-etc-hermes 2026-06-23-hermes-managed-scope-etc-hermes
Run: 2026-06-23-weekly-digest-2026-06-16_2026-06-23-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-06-23-hermes-managed-scope-etc-hermes
Research evidence and publication history are open in the repository.