The landscape of artificial intelligence engineering is undergoing a structural shift where the fundamental unit of reuse has moved from individual prompts to named profiles with persistent identities. Recent developments in Hermes, Grok Bot, and Claude Tag demonstrate that AI systems are evolving into durable workers capable of maintaining state across weeks of accumulated work. For practitioners building or securing these environments, this transition requires re-evaluating how we model identity architecture within our platforms.
The Shift from Session to Identity
Historically, the reusable object in AI interactions was the conversation itself—a transient state that vanished upon session closure. The current trajectory sees agents adopting job titles and descriptions that function like routing tables for work handoffs. In Hermes v0.20.4, profiles are bundled with avatars, schedules, and pinned models within a sidebar of named bots. Similarly, xAI's Grok Bot allows up to 50 routines per account, while Claude Tag provisions organization-level service identities in Slack channels.
This architectural change means that the "bot" is no longer just an interface over primitives; it represents a distinct entity with its own home directory holding configuration keys and memory. In Hermes specifically, these profiles are not sandboxes but rather separate directories containing state and credentials scoped to specific hosts or shared machines.
Implications for Identity Architecture
The persistence of agent identity introduces significant operational complexity that differs from traditional software development. While the roster of bots is trivially copied, the underlying identity model dictates how an organization manages access over time. Three distinct deployment models are emerging:
- Host-scoped profiles: Hermes keeps credentials scoped to whichever host runs the agent, whether a laptop or remote server.
- Shared machine accounts: Grok Bot shares one account-scoped computer across all bots, including files and browser sessions that survive bot deletion.
- Service identities: Claude Tag provisions organization service identities with channel-specific access to tools rather than relying on feature lists alone.
A critical consideration for security engineers is the separation of concerns. In Hermes documentation, profiles separate state and configuration explicitly noting they are not sandboxes. This distinction implies that isolation relies heavily on how these directories or shared machines are managed at an infrastructure level rather than within the agent runtime itself.
Operational Risks in Persistent Agents
The durability of these agents creates a new surface area for operational risk. If credentials stored in a profile directory remain valid across weeks, and if files or browser sessions persist after bot deletion as xAI suggests, the attack vector expands beyond simple prompt injection to include unauthorized access through compromised agent identities.
Furthermore, because nothing inherently keeps an agent coherent without explicit configuration support from vendors like Hermes, Grok, or Anthropic, teams must assume that persistence is a manual operational burden. The lack of published evidence regarding how these agents maintain coherence across extended periods suggests that reliability depends on external orchestration rather than internal guarantees.
Related CloudNinjas coverage: AI engineering.
What This Means For Practitioners
Evaluating any AI agent platform requires starting with the identity architecture before considering feature sets. Teams should treat named bots as colleagues in a literal sense, where their job descriptions encode durable responsibilities and boundaries similar to human employees or service accounts.
When designing platforms that integrate these agents, engineers must ensure that authentication mechanisms for shared machines are distinct from those used by individual user sessions. Security controls cannot rely on the ephemeral nature of chat interfaces; instead, they must account for persistent storage locations and long-lived credentials associated with each agent profile.
As organizations adopt multi-bot rosters capable of handoffs between agents via CLI invocations or tool calls in Slack threads, the routing logic becomes part of the security perimeter. Practitioners should audit how descriptions carry weight in defining bot behavior and whether those definitions can be tampered with to alter access patterns.
The transition from chatbot to agent demands a shift in mindset: these are not toys but infrastructure components requiring rigorous identity governance, lifecycle management, and separation of duties across hosts or service accounts. Ignoring this evolution risks exposing persistent credentials and sensitive data stored within shared environments that were previously considered transient byproducts of user interaction.


