← All posts

BLOG

Hermes and Conduit: Running an Always-On Ops Agent Inside Your MSP Stack

Hermes is a self-hosted, always-on AI agent: it stays running, keeps memory across sessions, and can act on its own schedule instead of waiting for someone to open a chat window. Conduit is WYRE's MCP gateway — the layer that connects AI agents to your PSA, RMM, and security stack with scoped, audited access instead of raw credentials. Point Hermes at it, and it stops being a chat window and starts being a technician who never clocks out.

What this actually looks like

Hermes connects to Conduit's MCP gateway the same way Claude Code or Cursor does: one URL, one sign-in, and every vendor your organization has connected shows up as a tool it can call. From there, a handful of things become realistic that weren't before.

Scheduled ticket sweeps. A cron job in Hermes runs every morning, pulls open tickets from Autotask through Conduit, flags anything past SLA, drafts a status update for each, and posts a summary to your team channel before your first coffee. No human opened a browser tab.

Cross-tool correlation. A client calls in about a slow server. Hermes pulls the ticket from your PSA, checks the asset in Datto RMM, cross-references recent patch history in IT Glue documentation, and hands your tech a synthesized brief instead of three tabs to check manually. It's the same work a senior tech does by habit, done before the tech even picks up the ticket.

Standing monitors. Hermes can watch for a condition, a vendor connection going unhealthy, a license count creeping toward a renewal threshold, and only speak up when something changes. That's a genuinely different pattern from a chatbot: you're not prompting it, it's watching and reporting.

QBR prep on autopilot. Ask it once to build a quarterly summary for a client, and it can run that same skill every quarter without re-explaining the client's environment, because it remembers the last conversation.

Why Conduit matters here specifically

None of this works if Hermes is holding raw API keys for every PSA, RMM, and security tool your team uses. That's a credential sprawl problem the moment you have more than one client, and it's an audit nightmare the moment a client asks who had access to their data, and when.

In practice, this is what the access boundary looks like: Conduit holds the vendor credentials, not Hermes. You define a role (say, "ticket-triage") and scope it to read tickets and post updates, nothing else, and Conduit enforces that boundary at the gateway rather than trusting Hermes's own judgment about what seems reasonable. When a Hermes cron job pulls ticket data at 3am, that call shows up in your audit log with a timestamp, a role, and a vendor. It reads the same as if a tech had run it by hand.

That distinction, an agent with governed, logged access versus an agent with a spreadsheet of API keys, is the difference between something you can put in front of a client and something your cyber insurance policy has opinions about.

Getting it running

If you already have Conduit set up, adding Hermes is the same three steps as any MCP client. Point it at https://conduit.wyre.ai/v1/mcp, sign in once, and set its role's tool allowlist to whatever vendors it needs for the job you're giving it. Start narrow — a ticket-triage Hermes instance doesn't need write access to your billing system.

Hermes's real strength is persistence: it's the one AI tool in your stack that's still running when everyone's gone home. Conduit is what makes that trustworthy enough to actually turn on.

We've covered the same pairing for a few other AI tools MSPs are asking about: Grok Bot, Viktor, and Littlebird. If you want the shorter, plain-English version of what an AI control plane actually is before diving into a specific tool, start here.