NexusThe conversational layer
Chooses a bounded identity and adds deterministic privacy, risk and capability signals to the current turn. Two stock hooks; no tool grants. Labels advise the active model—they do not enforce policy.
Governed intelligence around Hermes Agent
A consistent voice. Context that matters. Clear limits on what an assistant can do.
Nexus adds a considered layer to Hermes—not another source of authority.
Advisory by design. The human stays in control.
One conversation.
Distinct responsibilities.
Nexus shapes how a turn is presented and labels request signals. It does not select providers, grant tools or approve actions.
Conceptual map, not a product screenshot.Read the layers ↓
01 / The architecture
A personality, a reasoning model and an execution system are not interchangeable. Nexus keeps those responsibilities legible.
Chooses a bounded identity and adds deterministic privacy, risk and capability signals to the current turn. Two stock hooks; no tool grants. Labels advise the active model—they do not enforce policy.
Owns authentication, model and provider selection, tools, approvals, streaming and session storage. Nexus cannot promote a suggestion into permission or replace the host’s controls.
Houses collectors, bounded proactive routines, answer critique and the overlay guardian. These are separate components of an installation—not hidden abilities granted by selecting an identity.
A voice is not a model. A model is not an authorization.The distinction is the design.
02 / A consistent presence
Automatic selection adapts the identity to each request, with Nyx as the fallback. A conversation can also pin a particular identity. Either way, its role and style are presentation—not a separate agent, a model switch or a security exception.
An identity is a way of working
More deliberate when the stakes are high.
More concise when the answer is simple.
/identitySee the available identities./identity hexPin Hex’s presentation in this conversation./identity autoReturn to automatic per-turn selection.Commands are for a Hermes installation with Nexus enabled. Selecting Hex here is not the separate private /hex lane.
03 / The next intelligence layer
The v3.1.1 candidate explores a fuller loop: maintain the goal, bind a plan to current evidence, prepare the next step, and use explicit feedback to correct course.
This is a separate intelligence candidate, not the version of the running Nexus plugin. A historical 63-test pass covers candidate behavior; it does not prove end-to-end production execution or certify later edits.
Maintain durable task state, rather than relying on a chat summary.
Bind decisions to scoped sources and their current revisions.
Compile an advisory plan and recheck which steps are ready.
Preparation is useful progress. It is not a completed goal.
Real executors and authenticated approval paths remain separate work.
Require trusted completion evidence—not a model’s assertion of success.
Persist explicit feedback; reopen work or cancel stale preparation when sources change.
04 / Boundaries that mean something
Local-first is an architectural preference, not a blanket guarantee. The actual destination, fallback behavior and data handling have to be enforced and verified by the host.
/hex troubleshooting lane and /pii route are designed for local processing with no cloud fallback. They are not identity selections. A main conversation using a cloud model does not acquire that protection simply because sensitive content is mentioned.The separate guardian supports evidence-led recovery and hash-pinned promotion under explicit operator controls. Approved maintenance may be automated; uncertain attribution is not permission to improvise a repair.
05 / The evidence, and its limits
Installation evidence checked .
A static snapshot of the inspected installation—not a live status feed.
Advisory request context and identity selection through two stock Hermes hooks.
The runtime receipt matches the inspected gateway generation. This establishes the observed plugin load, not a certification of every host security control.
Owned by the separate nyx-critique component, not by Nexus’s two hooks.
Out-of-band review is not a quarantine for a streamed answer. Its presence should not be read as a guarantee that every answer is checked or blocked before delivery.
Historical verification, recorded 5 September: 63 tests, zero failures, errors or skips; 34 bound files in that record. The recorded file bindings still match, but the wider package manifest has changed or missing entries and needs re-verification. This refresh did not rerun the suite.
Not activated in production. The unit suite did not exercise model inference. The historical feedback-fix review recorded no verdict; first-hand checks are not an independent sign-off for later changes.
4 advisor profiles and 2 chair configurations support bounded, multi-model review. The board returns findings and a decision for the requester—not permission to act.
Convened only by explicit request: no schedule, no gateway hook, and advisors return text that only the requester acts on. The hardened-runner installation is unverified in this snapshot; saved review receipts alone do not establish which implementation is installed.
/dj on [vibe] approves one listening session, up to two hours. /dj off stops new picks; /dj shows status. Select any, chill, dinner, driving, focus, party or workout.
Song programming follows dj-craft/v1, a brief derived from published DJ teaching: choose the song first and bridge on a shared groove, timbre or mood rather than a shared decade; move energy by holding, lifting or easing rather than escalating; give each vibe different work. It forbids inventing tempo, key or crowd reactions, and treats queued songs as queued, not as songs heard or liked.
The controller validates ranked song choices, avoids repeats and reads the queue back after adding. It does not start playback, transfer devices or renew approval silently. Observed pause ends the session; API-restricted playback cannot be controlled. Automatic vibe detection and a dedicated vibe-check command are not shipped. It performs no audio mixing and measures no listening quality: contract files check that instructions reach the model, not that the music sounds better.
Separate automation components use explicit controls, shadow observation and bounded approvals. A prepared change is not a running feature.
Completion-gated activation requires its recorded prerequisites and prior authorization. Decision-gated work still needs a human decision. Updating documentation changes neither control files nor runtime authority.
Versions describe different components. Plugin 2.3.3 and intelligence candidate v3.1.1 are not successive deployments of the same running module. These records are not a general reliability, security or privacy certification.
Neither. Nexus is an advisory plugin around Hermes Agent. Identities shape presentation; Hermes supplies the active model and execution environment. The wider system includes separate automation components with their own controls.
The candidate demonstrates planning and state-management behavior. A separate synthetic model probe exercised an advisory planning lifecycle, not a completed real-world goal. Production executors, authenticated recipients, approvals and outcome verification are still integration work.
A public architecture page should not expose private operational data or present aging counters as current health. This page uses a dated, reduced evidence snapshot and makes no requests to private backends.
No. It is a review instrument: separate profiles scoped down by configuration, with no tools, schedule or gateway presence. They can disagree with a proposal, but none can speak first or act on its own. Their receipts are review material for the human.
Yes. The design, diagram and interactions are contained in this HTML file. There are no remote fonts, analytics or runtime dependencies. External documentation links only connect when you choose to follow them.