Research · What the diagram missed

Stack gaps

Last updated: 2026-08-12

Did the house stack miss a box?

Which layers must we add or split after laying both products on the map?

The overlay does not throw away the house stack. It fails a stress test in four places.

1. Runtime host / persistent computer (high)

Miss: Tools has one box, execution environment / safe sandbox. Harness has a “where it runs” banner. Grok Bot’s product is a durable Linux VM with identity, disk, screens, recover/reset, egress IPs.[3][5]

That is the LTC the graph already names Agent Runtime Host — not a sandbox doodle, not the model.

Proposal (research take, not a silent diagram edit): either

House color language can stay: operate vs rent (violet solid), not on-prem vs cloud.

2. Identity / subscription plane (medium)

Cursor SSO, Legacy Privacy Mode hard-block, MCP allowlists, combined invoices.[5] Nous Portal OAuth, credit ledger, Tool Gateway partners.[9]

Not a MECE peer to Skills. It is why Grok Bot cannot be “just an agent.” Draw it as a cross-cut like governance.

3. Shared-vs-isolated computer (medium)

A design choice, not a layer. It should appear as a mark on Host: shared cookie jar vs per-profile tenant. Grok documents the blast radius; Hermes defaults to isolation.[19][21]

4. Teach-by-demonstration (low as layer, high as skill path)

Demonstration → draft skill is a skill-authoring method, not a new band. The stack’s Skills gold band (“cannot buy”) still holds: Grok can sell the recorder; your workflow still has to be added as rules.[18]

What we should not add

Contrarian scan

Who disagrees that these two products are the pair to watch, and where do they fail?

1. OpenClaw / Claude Code / Codex are the real peers.
Fair for coding loops. Unfair for named digital employees on a cloud PC. Grok Bot’s buyer is not shopping ACP. Strongest form of this critique: if you only write software, Grok Build + Claude Code matter more than Grok Bot.

2. Shared VM is a security foot-gun sold as a feature.
Grok’s own security page says Bots are not a boundary.[19] Prompt injection on a logged-in Gmail tab is worse than on a hermetic sandbox. Strongest form: regulated shops should forbid shared-browser agents until per-bot tenants exist.

3. Hermes YOLO on a personal machine is worse than Grok’s VM.
True if backend stays local and approvals off. False if Docker/SSH + approvals. The contrarian is really “defaults matter more than architecture slides.”

4. Multi-bot group chat without a board is theater.
Grok group chats and Hermes Bot rooms (3 rounds, 10 messages) are collaboration UX. Crash-durable work still wants Kanban (Hermes) or an external ticket SoR. Bonus-level test: both products do useful single-agent work without orchestration. Grok’s launch even brags you skip workflow setup.[1]

5. “Always-on computer” is an ephemeral container with good copy.
Partly testable: Grok documents recover/reset and replaceable temp state.[3] If /workspace and cookies routinely vanish, the claim fails. Unresolved without operator telemetry.

6. Protocol theater / MCP.
Grok’s best line is anti-theater: click the legacy site. The risk is unlogged side effects. Hermes’ MCP/CLI split is healthier for audit if you use it.

7. Unreviewed self-improving skills.
Hermes curator + pin is the grown-up version. Grok teach-a-task drafts can encode one lucky demo, including secrets if you were sloppy.[18] Both can poison procedural memory.

8. Global problems.
Relevant bounded link: Automation/UBI and Rogue SuperIntelligence from the problems list — only as “unattended write access to real apps.” Grok meeting-stand-in and refunds-manager examples are exactly that class of side effect.[24] Neither product is a superintelligence. Both can send money and mail if you approve the wrong card.

Field conclusions

What should a builder or buyer actually do with this overlay?

  1. Compare packaging, then host, then glass. Model benchmarks are the least interesting part of this pair.
  2. Grok Bot if the job is “stay logged into the messy SaaS and finish the clickpath overnight” and Cursor gravity is acceptable.
  3. Hermes Bots if the job is “own the loop, swap models, isolate specialists, live in Telegram/CLI/Linux.”
  4. Portal if you want Hermes without five tool vendors — not if you wanted Grok’s office VM.
  5. Do not treat Bot Mode and Grok Bot as the same LTC. One is a UI over profiles. The other is a SKU over a VM.
  6. Update the stack drawing so Host is visible. The graph node Agent Runtime Host already exists; the poster lagged the products.
  7. Keep grey SoR grey. Neither /workspace nor ~/.hermes/ is the general ledger.

Outlook (take)

Looking-glass teammate UX will keep copying in days. Persistent tenant-safe computers will copy in quarters. The winner of “bots” is whoever combines:

Hermes is closer on exit, skills, and board. Grok is closer on furnished always-on desktop. The next obvious product — from either side — is per-bot tenants on a persistent host, which would close the last honest gap between them.

Assumptions that would flip this: Grok ships per-bot isolation + log export; Hermes Cloud ships a real persistent desktop with computer-use and account-wide plugins. Until then, they are cousins exchanging clothes, not twins.

Why this is a good explanation

Hard to vary: If you drop the host distinction, Grok Bot becomes “ChatGPT with plugins” and you cannot explain laptop-closed work or shared cookies. If you drop the packaging distinction, Bot Mode becomes a hosted SKU and you cannot explain hermes -p on a VPS.

Refutability: Public per-bot VMs, or Hermes defaulting to a shared browser profile, would force a rewrite of chapters 03 and 08.

Reach: The same fork will show up in every “digital employee” launch in 2026–27.

← Copying weekResearch references →