Build1 distinct publisher3 min readUpdated
Grok Bot puts the whole roster on one account-wide machine, Hermes gives each bot its own directory, and two other projects push the boundary into a sandbox or a container. Operators inherit the gap.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Shared state under Grok Bot is deliberate. SpaceXAI's documentation, according to The New Stack, describes one persistent cloud computer assigned to the user account rather than to any bot, with browser cookies and signed-in sessions shared, files visible to every bot, and command-line credentials shared [5][6]. Connectors are installed account-wide, one bot can resume work another saved, and the `/workspace` directory is built to survive machine updates and recovery, so the durable state belongs to the roster [9]. That arrangement is what makes a handoff cost nothing, and cheap handoffs are the product [20]. The documentation then says the honest thing: if another bot on the account cannot use a credential or a file, keep it off the machine entirely [8].
Read that as an operating rule and it sets a ceiling. On a single account there is no per-bot least privilege available, only two states for any secret: reachable by every bot in the roster, or absent [19]. A bot named Expense Manager is therefore as capable as the credentials you were willing to hand the entire office.
Hermes takes the other position, and the operator work does not disappear, it moves. Each bot is a profile with its own directory for configuration, memory, skills, credentials and chat history, and handoffs run as real invocations against the named profile rather than a context blob passed inside one process [10][12]. But a separate credential store is not a different credential [13]. Two profiles pointed at the same API token have two directories and one blast radius, and nothing in the roster interface tells you which situation you are in.
The packaging matters as much as the design. Nous shipped the teammate protocol inside v0.20.3 alongside an MCP 2.x SDK migration and runtime hardening changes, then archived the standalone plugin repository once the merge landed [16]. A change to what one agent can reach arrived in the same version bump as dependency maintenance.
Then the arithmetic. Only one of the four products makes the roster itself the boundary [14], which leaves three where the named agent is not the unit of isolation [15]. The units in play are an account, a profile directory, an opt-in container and the deployment topology, and they are not interchangeable [21]. Two of those are not properties of the software at all: an opt-in sandbox is off until someone turns it on, and a topological boundary exists only if whoever deploys it draws one. The New Stack's reading is that the documentation shows an industry converging on the persistent coworker interface faster than on what counts as an identity or a security boundary for it [17]. The convergence is the part that is finished. The boundary is homework, and it has been handed to the platform team without being labelled as such.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
On August 17, Nous Research announced that its Bot Mode would ship bundled and enabled by default in Hermes Agent v0.20.3, turning agent profiles into a roster of named bots that hand off work to one another.
About a week before the Hermes announcement, SpaceXAI launched Grok Bot with almost the same interface: a sidebar of named teammates who sign in to the user's tools and keep working long after the laptop is closed. The interface converged within a week.
Four projects have reached four different answers on containment: Grok Bot draws the line around the user account, Hermes around the profile, OpenClaw around an optional runtime sandbox, and ClawFleet around a container.
SpaceXAI's Grok Bot launch post leads with the promise that bots have their own computer.
Grok Bot documentation, last updated the same day as the launch post, describes a single persistent cloud computer assigned to the user account rather than to any individual bot.
In Grok Bot, browser cookies and signed-in sessions are shared across the roster, files are visible to every bot, and command-line credentials are shared; signing in for one bot makes that session available to the others.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documentation-grounded but single-publisher
Nearly every factual claim is traced to primary vendor material -- launch posts, product documentation with update dates, and release contents -- including a direct quotation ('separate work surfaces, not separate security boundaries') and specific artifacts such as /workspace and agent-scoped auth profiles. That is strong for architectural claims. It is capped by having one publisher, no independent verification of the documentation readings, no vendor comment, and by ClawFleet's container boundary being asserted without accompanying documentation in the supplied text.
Shipped and default-on, but no usage data
Adoption evidence is limited to availability: two products shipped within roughly a week of each other, one of them enabling the roster by default on update, plus documented default configuration for a third. There are no install counts, deployment figures, customer names, or telemetry in the supplied source, so real-world uptake of these agent rosters -- and therefore the population actually exposed to the boundary mismatch -- cannot be sized.
Slightly ahead of demonstrated harm
The reporting is deflationary rather than promotional -- it documents the gap between SpaceXAI's 'bots have their own computer' launch framing and same-day documentation describing one account-wide machine, which is a case of vendor overstatement the article corrects. The small positive score reflects the cluster's own framing risk: 'four blast radii' and the inherited-gap thesis rest entirely on documented configuration, with no incident, exploit, or measured loss showing the risk materializing, and with one of the four projects' boundaries asserted rather than sourced.
Vendor framing incentives visible and named
The cluster surfaces concrete incentive structure: SpaceXAI's launch page benefits from an isolation-implying 'own computer' promise while its documentation describes shared account-wide state, and the report explains that the sharing exists because cheap handoffs are the product. Nous benefits from shipping the roster default-on, which maximizes footprint. On the publishing side, a developer-focused trade outlet gains attention from a vendor-versus-vendor security framing. What is missing is any disclosure of commercial relationships, sponsorship, or analyst ties, so incentive mapping stops at what the text itself reveals.
Solid on specifics, thin on breadth
Confidence is moderate: the per-product documentation facts are quoted with enough specificity to be checkable and are internally consistent, and the release timeline is dated. It is held down by a single publisher with no corroboration or vendor response, the absence of any adoption or incident measurement, a truncated source that cuts off mid-sentence in the OpenClaw section, and one approximate date (the Grok Bot launch is given only as about a week before August 17).
build
Nous wants you to own the harness, which means you own the patching too1 distinct publisher
build
Before you spend quota on an agent skill, make it pass an eval harness1 distinct publisher
build
Wiring, not headcount: same agent task swung from 70% worse to 81% better on topology alone1 distinct publisher
product
Docker puts Verified Publisher behind a signup form, and pull data behind a plan1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026