Permission policies
Set each tool to allow, ask, or deny.
terminal
files
secrets
Security and access control
Herm lets teams set tool permissions, approval rules, agent roles, and scoped vault access so production agents only reach the systems they are allowed to use.
Vault access
resolved only after policy passes
01 / ACCESS CONTROLS
Set each tool to allow, ask, or deny.
terminal
files
secrets
Start sessions with the right access level.
Pause sensitive actions before they run.
Attach vault access only where it belongs.
02 / EXAMPLES
Set the role, tools, approval policy, and credentials for the situation the agent is serving.
Let the agent read tickets and account notes automatically, but require approval before refunds, plan changes, or outbound messages.
Give teammates a role that can inspect dashboards, search files, and draft fixes without handing it production shell access.
Expose a limited agent to customers or partners with scoped MCP tools and vault credentials for only their workspace.