2.14am a change enters
↓
01
Control Plane · the tower itself
the shell that wraps everything below
What changes · leaders can say yes without watching every
step. Trust becomes a decision, not a gamble.
tap
Identity & RBAC
Humans and agents get roles, both kept to least-privilege on
data and actions.
Policy engine
Policy as code. It decides which tools, which model, which
data class, and whether sign-off is needed.
Approval / HITL
High-risk actions stop and wait on role-based approval. A
checker, then an approver.
Audit log & compliance
Every action logged to a principal, tamper-evident, ready for
SOX-style review.
02Agent Runtime · the workers (Hermes)agentic fleet composition
A pool of Hermes agents, each scoped to one role or domain.
The control plane decides what tools they get; an agent
doesn't grant itself anything.
What changes · one senior planner's playbook runs in
twenty copies, 24/7, and coverage never depends on one person's calendar.
Role-scoped agent pool
Planning-health, exception-handling, forecasting. Each
owns one bounded domain.
Per-agent: orchestrator + skills + memory
Skills are codified, versioned SOPs. Memory is scoped to
the role, and the orchestrator runs the loop.
Sandboxed execution
Workspaces are isolated and tool access comes from policy,
so one bad agent can't reach far.
Forecast & what-if simulation
Detection is only half of it. The forecasting agent runs
the what-if: leave this alone and it becomes a stockout in
about [FILL] weeks, worth [FILL] in excess.
tap
governs · constrains · enforces
03Knowledge & Memorycontext layer
Where the tower keeps what it knows, locked down so no agent
can reach past its role.
What changes · the playbook outlives any one person's
head: versioned, reviewed, never lost because someone's on leave.
Per-agent persistent memory
Long-term, Honcho-style context, isolated per tenant and
locked to one role.
Shared org skill / knowledge library
Shared SOPs as versioned, reviewed skills pushed out to
the whole fleet.
Data-classification tags
Labels that tell policy and routing who can see the data,
down to which model.
tap
04Inference Routingmodel-agnostic
No single vendor lock. Policy routes each task by data
sensitivity: sensitive work stays on Applied Materials' own hardware,
everything else may reach a frontier model that keeps nothing.
Which brain sees what is a permission, not a choice.
What changes · each task goes to the model that fits its complexity and its data: nothing simple overspends, nothing sensitive leaves, and policy decides which is which.
Frontier via ZDR
Claude or GPT with zero data retention, for complex
reasoning that isn't sensitive.
Self-hosted open weights
Kimi K3 and deepseek-v4-flash on Applied Materials hardware, for work
that can't leave the building.
Eval gates
No model gets to touch anything consequential until it
passes the eval harness.
tap
05Integration Layerenterprise connectors
Where read and write rights are actually enforced, not inside
the agent.
What changes · data only gets modified when an authorized human approves.
SAP · Databricks · ServiceNow · internal APIs
Planning tables, analytics, ITSM, and internal systems
behind one surface with enforced entitlements.
tap
06Observability & Ops
What changes · anyone can replay the story of what happened
and answer "what just happened?" in 30 seconds.
The dashboard. What makes a VP willing to bet on this: a trail of
evidence, not a black box.
Tracing · logging · cost metering
Centralized per agent and per team, with cost attribution and
full action traces.
Eval harness · SLOs · incident response
Reliability targets that gate what gets promoted and drive how
incidents get handled.
The morning brief
The interface that matters: one ranked queue of exceptions for
today, each with evidence, severity in supply-chain terms, and
a recommended action. A planner decides in seconds, from one
card.
watches every layer