Kortix vs Hermes: an open-source agent that grows with you, or one your team reviews
Hermes is a self-hosted personal agent with persistent memory; open-source Kortix is the platform a team runs from one git repo it owns.
Hermes is a strong self-hosted agent built for one person, and Kortix is the open-source platform a team runs from a repo it owns. Both are free to self-host and both are open source, so the choice is not about values. It comes down to what the agent owns, who reviews what it changes, and where its configuration lives.
What Hermes does well
Hermes Agent is an open-source, self-hosted personal agent from Nous Research that remembers across sessions and writes its own skills. It earns its following, and the things it gets right are the ones you notice when you leave.
- Skills it writes itself. Hermes writes a new skill after a complex task, improves that skill the next time it runs, and keeps memory across sessions, so it compounds on your work instead of starting cold every time (Hermes repository).
- Any model you want. Nous Portal, OpenRouter, OpenAI, a local endpoint, or your own vLLM; you switch models with one command and leave your code untouched.
- Runs on your box. Seven terminal backends, from local to Docker, SSH and serverless options, so a $5 VPS works as well as a GPU cluster, and idle environments hibernate.
- Reachable where you already chat. One gateway serves 20 chat platforms, from Telegram and Slack to WhatsApp and email, with the same memory behind each (Hermes docs).
- Guardrails for one operator. Dangerous commands run through smart, manual or off approval modes, inside container isolation, with per-platform allowlists (Hermes security).
Where it stops: nothing reviews a change
For the work of one person, none of this bites. For a group, four things do.
- One owner by design. Authorization is allowlists and direct-message pairing, so the question of who on the team may run it has no team-level answer: no roles, no groups, and no audit trail across people.
- No repo the whole team clones. Memory and skills are files on the host. A teammate does not get the same agents, memory and connectors by cloning a project, because there is nothing to clone.
- Coarse tool control. Approval guards a dangerous shell command as a whole. It does not set Allow, Ask or Block on a connector call, down to the arguments, so scoping a tool to one customer record or one repo is manual work.
- No reviewed path to done. Work happens and stays. Nothing is proposed as a change request that a person reads, approves and merges, so there is no diff to review and no record of who let a change in.
Those are not defects. Hermes is a personal agent, and at that job it is excellent.
Your agents, memory and connectors in one repo
Kortix is the open-source AI Operating System. Your agents, their skills, your company memory, every connector and every trigger are files in one git repo you own, so the same configuration runs for one person or a thousand. That repo is the company: versioned, diffable and shared (Kortix on GitHub). A teammate clones the project and gets the same agents, the same memory and the same connector grants, and every change to any of them is a commit a reviewer can open.
# kortix.yaml
agents:
support-triage:
file: agents/support-triage.md
connectors: all
triggers:
- slug: daily-digest
type: cron
cron: '0 0 9 * * 1-5'
prompt: Summarize yesterday's tickets and open a change request.
An agent can edit its own configuration on its session branch and propose the change; a person approves it. Nothing about the setup lives in a vendor's database.
A sandbox and a change request per task
Every session gets its own isolated sandbox on its own branch. The agent can install, run and break anything; only what it commits survives. Work reaches main through a change request you review, and merge is default-deny for agents, so a change lands only after a person has read the diff.
Connectors reach 3,000+ apps through one scoped token, plus MCP, OpenAPI, GraphQL and raw HTTP, and connector credentials are brokered server-side, never entering the machine (Kortix on GitHub). Agents answer in Slack and Microsoft Teams, or run on a cron schedule or a signed webhook with nobody watching. Self-host is free; the managed cloud is $40 per seat per month with 2,500 pooled credits, in your VPC or on-prem if you need it (Kortix pricing).
What the switch actually changes
- Config moves into a repo. The agents, skills, memory and connectors you built on one host become files a whole team clones and reviews.
- A review step appears. Work stops landing silently; it arrives as a change request with a diff.
- Your model choice does not change. Kortix runs any provider with your own keys, or the ChatGPT plan you already pay for, so this is not a model migration.
Where Kortix is not the answer
If you want one always-on assistant that learns your habits and answers you in Telegram, Hermes is the better tool. Kortix carries a team's worth of machinery: a repo, roles, sandboxes and change requests. For a single operator with no review step, that is more system than the job needs, and the review step itself is overhead if your work never needs a second pair of eyes.
Side by side
Both columns describe each project the way its own documentation does, checked October 2026: Hermes on GitHub and the Hermes docs, against Kortix on GitHub and Kortix pricing.
When to pick which
You want one self-improving assistant on your own machine, reached from the chat apps you already use.
You want the agents, memory and connectors in one repo a team reviews, each task on its own sandbox.
Next reads: Personal AI agents vs a company OS and Kortix vs AnythingLLM.
Start with Kortix: free to start, free to self-host.
More from the blog
Kortix vs AnythingLLM: document chat, or an open-source system a team owns?
AnythingLLM is a local-first app for chatting with your documents; Kortix is the open-source system a team owns, with shared memory and reviewed agent work.
Kortix vs n8n: an open-source agent platform or a workflow engine
Kortix is the open-source agent platform for open-ended work; n8n runs fixed workflows and bills by execution, so the unit of work decides.