What stays paused
Decision 1. Nothing writes until Boyd uses the approval wording below. Opening this page does nothing.
Decision 1 is still paused. No settings, protected instructions, providers or gateway processes have changed. This page shows the corrected design and the exact approvals Boyd can copy when ready.
The plan is no longer a broad rewrite. It is a narrow repair of how the three active default instruction files are changed, plus a separately approved fallback test.
Decision 1. Nothing writes until Boyd uses the approval wording below. Opening this page does nothing.
Only the active default SOUL, USER and MEMORY files. Profile files and every file merely sharing a basename are outside this narrow gate.
First approve the write-protection redesign. Separately log in to OpenCode Go. Approve a fallback smoke only after login is confirmed.
These are settled requirements, not questions being reopened.
Hermes model and provider routing should follow official Hermes guidance, not a hand-written guess.
The protected instruction scope is the default SOUL.md, USER.md and active memories/MEMORY.md.
Run five compression and intent-preservation passes before native memory staging. Staging is not approval.
The v3 hook remains for the root default SOUL.md, but loses basename-wide and profile-wide reach.
Dropbox is not an always-loaded runtime fact. Its disabled or future state belongs in configuration and evidence, not permanent memory.
The human name is Web Vault. The local technical root remains ~/.hermes/vault.
It has recent, completed use. There is no evidence-based reason to remove it.
Boyd wants a fallback, but only through a verified logged-in route and only after a bounded smoke test.
A protected change must be made smaller and checked for lost intent before Hermes can even stage it for Boyd.
/memory pending| Exact target | Protection route | Allowed result | Explicitly outside scope |
|---|---|---|---|
~/.hermes/SOUL.md | Five-pass draft, then narrowed memory-gate v3 approval | One exact root SOUL edit after approval | Profile SOUL files and same-basename files |
~/.hermes/memories/USER.md | Five-pass draft, native stage, /memory pending | Approve or reject the staged USER change | USER files in profiles, projects or backups |
~/.hermes/memories/MEMORY.md | Five-pass draft, native stage, /memory pending | Approve or reject the staged MEMORY change | Other MEMORY files, archives and snapshots |
AGENTS.md and all other files | Not covered by this Decision 1 gate | Existing owner, config and safety rules still apply | No basename-wide protection and no hidden expansion |
The failure has two causes. Trusted Telegram instructions arrive with a system-added [BB] prefix that the current parser does not recognise as Boyd's approval. The file matcher also treats AGENTS.md by basename, so unrelated AGENTS files fall into the protected scope.
Repair: recognise only the trusted Telegram [BB] prefix, match exact default-file paths, preserve backups, and prove the result with harmless live tests. Do not weaken the gate for arbitrary message text.
A model name existing in a catalogue does not mean Hermes can use it now.
DeepSeek V4 Flash and MiniMax M3 exist on OpenCode Go. The current route returns CreditsError 401 and reports logged out, so neither is a working fallback yet.
This is paid extra usage and may rotate to an Anthropic API key. It is not a subscription-safe automatic fallback and should not be added to the chain.
The existing local Claude Code Sonnet route remains a manual lane for suitable work. It is separate from Hermes' automatic global fallback chain.
hermes auth reports logged in should Boyd use the fallback approval wording.Context7 retrieves current library and product documentation. Its recent activity is completed usage, not dead configuration.
One name for Boyd, one technical root for Hermes, and one stable public address when a page is approved for publishing.
~/.hermes/vaulthttps://hermes-vault.pages.devbriefs/, research/, holidays/, plus deliberately added categoriesnoindex is not an access gate.https://hermes-vault.pages.dev/briefs/hermes-operating-map/decision-1-current-plan/ only after an approved Web Vault publish.There are two decisions and one authentication prerequisite. Use them in this order.
This does not approve a gateway restart, provider change, model fallback or Web Vault deployment.
Do not paste an API key, token or login secret into chat. Complete authentication in the local flow. Stop if it asks you to expose a credential here.
Do not use this approval while OpenCode Go is logged out. One DeepSeek smoke comes first. MiniMax is added second only if the smoke passes.
Each phase has a stop point. A green check in one phase does not silently authorise the next.
Back up exact targets, preserve the 29-record v3 baseline, record hashes, and make no live behaviour change yet.
Add exact default-file matching, trusted Telegram [BB] prefix handling, and native USER/MEMORY pending approval. Keep root SOUL on narrowed v3.
Test approve and reject paths against harmless temporary wording, verify backups and rollback, then restore the intended content. No gateway restart.
Boyd runs hermes auth add opencode-go locally. Continue only when the route reports logged in. Do not transmit credentials in chat.
After separate approval, run one DeepSeek V4 Flash smoke. If it passes, add DeepSeek V4 Flash first and MiniMax M3 second, then verify the reported chain.
Expanded paths and links are kept here so the decision surface stays readable.
~/.hermes/SOUL.md~/.hermes/memories/USER.md~/.hermes/memories/MEMORY.md~/.hermes/config.yaml~/.hermes/hooks/memory-gate/~/.hermes/sessions/~/.hermes/vault/~/.hermes/vault/briefs/hermes-operating-map/decision-1-approval.html~/.hermes/vault/briefs/hermes-operating-map/decision-1-current-plan/index.htmlCreditsError 401.