Revised scope
Provide MCP/API-level observability and evaluation for governed Muster operations without reimplementing Hermes session inspection or storing private reasoning.
Required records
- Hermes installation/profile identity where supplied and verified.
- Muster tool name and version.
- Organisation and initiating actor.
- Input/output schema versions and redacted hashes.
- Capability and approval decisions.
- Connector calls, evidence references, retries and idempotency outcomes.
- Final authoritative action/delivery state.
Expose bounded MCP tools for run/action status and audit export. Replay uses recorded results by default and cannot repeat external actions. Evaluations cover tenant isolation, schema compliance, approval behavior, evidence citation, injection resistance and unsupported claims.
Non-goals
- Chain-of-thought capture.
- Replaying Hermes' internal model loop.
- A dedicated chat/run-inspector UI in the first release.
Revised scope
Provide MCP/API-level observability and evaluation for governed Muster operations without reimplementing Hermes session inspection or storing private reasoning.
Required records
Expose bounded MCP tools for run/action status and audit export. Replay uses recorded results by default and cannot repeat external actions. Evaluations cover tenant isolation, schema compliance, approval behavior, evidence citation, injection resistance and unsupported claims.
Non-goals