Hermes moved the approval decision from a human to a model, and shipped it without the guardrails built for it
v2026.7.20 sets approvals.mode to smart for default configurations, so a classifier decides what would previously have reached a person. The policy override, the consecutive-denial circuit breaker, the approvals suggest command, and the docker-daemon-redirect and recursive-rm detectors that were written for that change are all merged to main and in no tag. The release that flipped the default is the one without the safety net.
What this changes for operators
- Anyone upgrading to the current tag hands a decision to a classifier and does not receive the controls intended to bound it. Pin to v2026.7.7 if you need the human default, or upgrade deliberately and set approvals.mode explicitly rather than inheriting it.
Featured in
- Assume the Rule Does Not Bind / 2026-07-27
Run: 2026-07-27-weekly-digest-2026-07-02_2026-07-27-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-07-27-hermes-approvals-default-flipped-without-guardrails
Research evidence and publication history are open in the repository.