Command-X
Private KernelX command desk for planning, discovery, safe execution, and project memory.
Ask Command-X
Plan, inspect, execute safely, and keep KernelX context in one guided workspace.
Advanced tools are available for inspection, Workspace Admin, Super Admin, finalization, and memory operations.
Implementation planning
Write what you want to build or fix, then generate a safe planning-only implementation plan. Hermes will not execute commands or change files.
No instruction sent yet.
Approved VPS inspection
Run approved read-only VPS inspections through Hermes. Nothing is patched, committed, pushed, deployed, deleted, or externally executed.
Safety boundary:
approval required, read-only only, allowlisted commands only, no shell, no patch, no commit, no push, no Docker mutation.
No VPS inspection run yet.
Workspace Admin Mode
Approved repo-scoped execution inside /docker/openclaw-ops-work. No git commit or push here. Use structured JSON actions only.
Safety boundary:
approved only, workspace scoped, protected paths blocked, protected values redacted, no arbitrary shell, no git commit, no git push.
No Workspace Admin run yet.
Super Admin Mode
Break-glass runtime/server/container-level execution. Use only when Workspace Admin is not enough.
Red warning:
Super Admin can inspect Docker, Traefik, containers, networks, volumes, and approved runtime targets.
Mutation commands require stronger approval. Protected old containers remain blocked unless explicitly allowed.
No Super Admin run yet.
Final approval: commit / push / checkpoint
Use only after Workspace Admin verification passes. This can commit and push selected changed paths to origin/github.
Finalization boundary:
separate approval required, selected paths only, safe commit message only, push origin/github main, verify remote alignment, then save Hermes memory.
No finalization run yet.
Save / query memory
No memory loaded yet.