Research · Where humans enter

Glass & HITL

Last updated: 2026-08-12

Users meet a glass, not a stack

What does a human actually see, and which HITL primitives are enforced rather than hoped?

A looking glass is the surface for goals, step visibility, gates, and outputs. Behind it: a harness.

Grok’s glass

Why does Grok Bot feel like iMessage with a coworker?

There is no Linux glass. The computer is Linux; you watch it from Mac/Windows/iOS.[5]

Identity gravity: Cursor SSO. Legacy Privacy Mode blocks the product entirely.[4][5]

Hermes’ glasses

If Bot Mode is optional UI, where do Hermes bots live when Desktop is off?

Glass Role
CLI / TUI Harness-native. hermes -p name chat is the Bot.[21]
Desktop Sessions Chat list, classic agent.
Desktop Bot Mode Roster, forever-chat, routines pane, groups, @mentions.[21]
Gateway Telegram, Discord, Slack, WhatsApp, Teams, … 20+.[8] Pairing/auth for DMs.
Hermes Cloud Preview: same agent, many channels, memory not tied to device.[11]

Bot Mode specifics that Grok also has, almost phrase-for-phrase: New Agent (name/title/description), Advanced clone, hide without deleting, routines beside the Bot, group rooms, @mention handoff, “needs you” escalation.[21]

Hermes-only glass details:

HITL primitives

Which of the five gates exist as product, not as a sentence in a system prompt?

House primitives: (1) gate on action class (2) pause / durable blocked state (3) context packet (4) recorded decision (5) resume or cancel.

Primitive Grok Bot Hermes
Gate on class Auto Review rules + local-computer Never/Ask/Always; team ceiling “coming soon.”[5][19] approvals.mode; toolset disable; YOLO as explicit bypass
Pause / durable Routines pause after long absence; computer recover/reset; takeover blocks.[18][3] Kanban blocked; approval prompts; cron
Context packet Approval card shows operation + inputs.[19] Approval UI / gateway /approve /deny
Recorded decision Desktop/iPhone allow/deny; org audit view coming.[5] Session transcripts you own; Kanban comments
Resume Return control; “Always allow” matching rule.[19] Continue loop after approval

HITL ≠ “humans use the chat.” Grok’s best HITL is takeover of the VM for 2FA — a genuine primitive. Hermes’ best HITL is you own the log plus Kanban block. Both still lean on prose boundaries (“never send without approval”) for a lot of the blast radius.

Roles

Who builds the bot, who writes the skill, who reviews tools?

Role Grok Hermes
End user Creates Bots, teaches tasks, approves Same, plus CLI
Citizen builder Teammate roster, no workflow canvas (by design)[1] Bot Mode + SOUL.md
Platform Cursor admins: MCP policy, Cloud Agents toggle, privacy mode[5] You / your IT: backends, toolsets, Portal
Domain expert Bot description + skills SKILL.md authors
Vendor SpaceXAI/Cursor loop and models Nous optional Portal/Cloud; MIT core

Building a Bot ≠ training a foundation model. Grok will not let you pick the model anyway.[5]

Looking-glass lock-in

If the critical path is single-homed on one glass, what fails at 2 a.m.?

Grok: if Cursor identity or the desktop/iOS app has an incident, you have no second glass except waiting. The VM may still run routines.

Hermes: if Desktop dies, CLI and gateway remain. If Portal dies, BYOK remains. If your laptop dies and you only ran local, work dies — unless you already operated SSH/Cloud.

That is the operate-vs-rent split again, now at the glass.

← Tools & skillsNous Portal →