Skip to content

[TRACKER] Hermes + Slack + Muster MCP product pivot #78

Description

@jusso-dev

Product direction

Muster is the governed security-operations capability layer for Hermes.

  • Slack is the human chat interface.
  • Hermes is the agent harness: sessions, models, context compression, general memory, delegation, cron and Slack delivery.
  • Muster is the authenticated MCP server and control plane: tenant scope, capabilities, approvals, tool schemas, connector governance, evidence, audit and durable operational state.
  • Kelpie remains authoritative for formal incident cases.

Muster will not build a competing collaboration UI, Slack gateway, general-purpose model runtime or generic conversational memory system.

Ordered implementation

P0 — prove the product boundary

  1. P0: Ship the first Hermes-native Muster MCP vertical slice #72 — authenticated remote MCP vertical slice for Hermes, initial read-only Kelpie tools and starter skill.

Exit gate:

  • Hermes discovers and calls the MCP tools against a clean local stack.
  • Credentials are revocable and bound server-side to one organisation.
  • Cross-tenant, schema, injection, SSRF, secret-leak and result-bounding tests pass.
  • One non-draft PR is reviewable; no automatic merge or deployment.

P0 — governed operations

  1. Extend P0: Ship the first Hermes-native Muster MCP vertical slice #72 with write/proposal tools, authoritative approvals, idempotency and resumption contracts.
  2. Implement governed operational knowledge and evidence for Hermes #71 — governed operational knowledge/evidence, not general Hermes memory.
  3. Certify real Kelpie integration separately from mock contract success.

P1 — reusable Hermes product

  1. Publish versioned Muster skill packs and policy bundles for Hermes #73 — versioned Hermes skill packs and server-enforced policy bundles.
  2. Audit and evaluate governed Muster operations without private reasoning #77 — MCP/API observability, evaluation and safe recorded-result replay.
  3. Integrate Hermes cron and delegation with governed Muster missions #76 — Hermes cron/delegation integration with governed Muster missions.
  4. Package installation, remote MCP configuration and operational runbooks.

P2 — administration only

  1. Retain or build only the minimum administrator console needed for credentials, connectors, policy, approvals, evidence, audit and kill switches.
  2. P1: Plan Node 26 runtime and type-definition upgrade #34 — coordinated runtime/dependency upgrade when product gates are stable.

Hard boundaries

  • Skills guide behavior; the server enforces security.
  • No model-supplied organisationId, capability, approval or identity is authoritative.
  • No connector credentials enter Hermes prompts, skills, memory or tool output.
  • No direct model writes to authoritative business tables.
  • No arbitrary MCP server or tool registration from chat.
  • Consequential actions require server-side capability checks, stable idempotency and authoritative approval where policy requires it.
  • External content remains untrusted evidence.
  • PostgreSQL remains authoritative; Redis/BullMQ are execution infrastructure.
  • Mocked, local, deployed and live-verified results must be reported separately.

Retired direction

The previous conversation-first UI, LangGraph runtime, cross-surface conversation and custom Slack-app backlog has been closed as not planned. Closed branches and PRs remain available only for selective salvage of still-relevant governance code.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions