Skip to content
Workflows Resources Case Studies Pricing About
Playbooks

Self-Hosted AI Agents: A Security Checklist for Business

Running OpenClaw or Hermes yourself? This security checklist covers isolation, permissions, approvals, logging, and updates to keep business data safe.

By Ahmad TawfikPublished 8 min read

A self-hosted AI agent is the most capable assistant you can get for the least money, and the one whose failures are entirely your problem. OpenClaw and Hermes Agent can read your files, run shell commands, browse the web, message your team, and act on schedules. That power is the point. It is also why running one for business without a security routine is asking for an incident you will discover too late.

This checklist gives you that routine. It assumes you are a non-technical owner working with someone technical, or a technical owner setting this up yourself. Each item is small on its own; together they are the difference between an agent you trust and one you hope about.

Key takeaways

  • Self-hosted agents like OpenClaw and Hermes run shell commands and read files by design, so sandboxing and scoped credentials are mandatory, not optional.
  • Give the agent its own accounts with minimum permissions, require human approval for money, customers, and deletions, and log every consequential action.
  • Treat everything the agent reads from the web or inbox as untrusted input that could carry injected instructions.
  • Update on a schedule, review logs weekly, and name one person who owns the agent's security.
  • If nobody will own updates and reviews, do not self-host; use a managed agent with defined scope instead.

Start from the threat model

Before any settings, get clear on what can go wrong. A self-hosted agent holds credentials to your accounts, can execute commands on a machine you own, reads untrusted content from the web and your inbox, and acts in chat platforms where your team trusts inside messages. The realistic incident list is short: stolen credentials, a destructive or expensive action it took alone, a hijacked instruction from something it read, and silent data exposure.

Everything below maps to those four. Work through the checklist in order the first time, then keep the weekly and quarterly habits at the end. For the general principles behind these rules, our small-business agent security guide covers the same ground for managed agents.

Isolate what the agent can touch

Isolation limits how far any single mistake or compromise can travel.

  • Run the agent as its own user, not as you. The gateway process gets a dedicated operating-system account with access only to its own directories. On OpenClaw, choose sandboxed shell execution over full access unless a specific task needs more. On Hermes, pick the most constrained terminal backend that still does the job: a Docker container, Modal, or Daytona sandbox beats running directly on your laptop.
  • Separate business data from personal data. The machine that runs the agent should not hold your personal password vault, family photos, or unrelated client files. If the agent only needs one shared folder and one mailbox, that is all the account can see.
  • Segment the network. A cheap virtual server, such as DigitalOcean's hardened one-click OpenClaw deploy from $24 per month, keeps agent activity off your office network and your laptop.
  • Keep secrets out of chat and files the agent reads. API keys and passwords live in a secret store or environment file with tight permissions, never pasted into prompts, memory files, or channel messages.

Apply least privilege to every credential

An agent with your admin login is you on your worst day, acting at machine speed. Our least-privilege setup guide goes into depth; the essentials for self-hosting are:

  • One identity per agent. The agent gets its own logins and API keys, never your personal credentials. When something breaks or someone leaves, you revoke the agent's keys without touching anyone's access.
  • Minimum scopes. Read-only where reading is the job. No delete, no admin, no billing access unless a named workflow requires it, and then only for that workflow.
  • Separate keys per integration. The key that reads the calendar is not the key that sends email. A compromise then costs you one capability, not all of them.
  • Expiry and review. Set credentials to expire, and review what the agent can access every quarter. Access that was needed for a March project is a liability in September.

One OpenClaw gateway can serve a whole shared team across its 29 channels, which means one credential set guards everyone's data. Split gateways or scoped identities per function when the data differs.

Gate consequential actions with approvals

Approvals are the cheapest incident prevention you have. Define three tiers and enforce them:

TierExamplesHandling
AutomaticReading files, searching the web, drafting text, summarizingAllowed, logged
NotifySending routine messages, creating calendar events, filing reportsAllowed, you get a notice you actually read
Approve firstSpending money, contacting customers, deleting or publishing anything, changing accessBlocked until a named human approves

Write down which actions sit in which tier, tell the team, and review the list whenever the agent gains a new capability. Anything that touches money, customers, or credentials starts in the approve-first tier and only moves down with evidence.

Treat everything the agent reads as untrusted

Prompt injection is the attack where hostile instructions hide in content the agent processes: a web page, an email, a pasted document, a calendar invite. Because self-hosted agents can act on what they read, browsing plus acting equals exposure. Defenses, in order of value:

  1. Read-only defaults for research. Web reads and inbox scans summarize; they do not trigger follow-on actions without approval.
  2. Allowlisted triggers. Decide which senders, channels, and sites can cause the agent to act. Everything else is information only.
  3. No credential use on untrusted pages. The agent never logs in anywhere it arrived at by following a link in content it was reading.
  4. Outbound gates. Messages the agent sends, especially to customers or public channels, pass approval or a strict template until the workflow has a clean history.
  5. Logging you can reconstruct from. Every tool call, approval, and external message gets a timestamped record. When something looks wrong, you should be able to answer what the agent did, what it read beforehand, and who approved it.

Microsoft's Agent 365 control plane, generally available since May 1, 2026, packages this kind of discipline for enterprises with agent registries, lifecycle rules, and threat protection at $15 per user per month. You do not need the enterprise product to copy the habits: inventory your agents, expire what is idle, and audit what acted.

Update, back up, and review on a schedule

Self-hosted means you are the operations team. Both projects move quickly: OpenClaw sat at release v2026.9.4 in September 2026, and Hermes shipped voice, agent-to-agent protocol support, and grounded citations in its August v0.20.0 Herald release with more in the September v0.21 line. Fast-moving software has fast-moving fixes, including security ones.

  • Updates: apply agent, model-gateway, and operating-system updates on a fixed cadence, not when something breaks. Read release notes for breaking changes before upgrading a production gateway.
  • Backups: back up memory files, skill definitions, configuration, and credential inventories (not the secrets themselves) so a failed machine is an afternoon, not a rebuild.
  • Weekly review, 30 minutes: scan the approval queue, skim logs for anomalies, confirm scheduled jobs did what they claim, and check that no new permissions appeared.
  • Quarterly review: re-scope credentials, prune unused skills and integrations, confirm the owner is still the owner, and test restoring from backup.

Name one person who owns this. Shared ownership of a security routine means nobody does it.

Know when not to self-host

Self-hosting is the wrong choice more often than enthusiasts admit. Do not self-host if nobody will apply updates, if logs will never be read, if the agent needs access to regulated data you cannot properly isolate, or if the business cannot tolerate the agent being down while someone debugs it. OpenClaw has no paid tier and no hosted service, and Hermes leaves every operational decision to you, so there is no vendor safety net behind either one.

The alternative is not giving up on agents. A managed internal assistant with a defined scope, or a narrow workflow like review requests or onboarding, gets you most of the value with the operations included. Self-host for the jobs where control is worth the upkeep; buy for everything else.

FAQ

Is it safe to run OpenClaw or Hermes Agent for business work?

It can be, if you treat the agent like a privileged employee. Both run shell commands and read your files by design: OpenClaw offers full access or sandboxed execution, and Hermes runs across 7 terminal backends. Safety comes from sandboxing, scoped credentials, approval gates, logging, and updates, not from the software alone.

What is the single most important security setting?

Least privilege on credentials and tools. Give the agent its own accounts with the minimum permissions the job needs, run file and shell access sandboxed where possible, and require human approval before anything that spends money, contacts customers, or deletes data. Most incidents trace back to over-broad access.

How do I protect against prompt injection with a self-hosted agent?

Assume any web page, email, or message the agent reads could carry hostile instructions. Default web reads and research to read-only, restrict which sites and senders can trigger actions, keep an allowlist of permitted tools, and require approval for outbound messages, payments, and system changes. Log everything so you can reconstruct what happened.

When should a small business NOT self-host an AI agent?

Do not self-host if nobody will apply updates, review logs weekly, and own incidents. OpenClaw has no paid tier or hosted service, and Hermes leaves operations entirely to you. If that ownership has no name attached, use a managed service or an agency-built agent with defined scope instead.

Next step

Run the checklist against your setup this week, starting with isolation and credentials, and put a name next to the weekly review. If the ownership question has no good answer, that is your answer. The free six-step AI automation plan on our homepage shows which jobs fit managed automation: start your AI automation plan. To talk through the decision, book a call.

Frequently asked questions

Is it safe to run OpenClaw or Hermes Agent for business work?
It can be, if you treat the agent like a privileged employee. Both run shell commands and read your files by design: OpenClaw offers full access or sandboxed execution, and Hermes runs across 7 terminal backends. Safety comes from sandboxing, scoped credentials, approval gates, logging, and updates, not from the software alone.
What is the single most important security setting?
Least privilege on credentials and tools. Give the agent its own accounts with the minimum permissions the job needs, run file and shell access sandboxed where possible, and require human approval before anything that spends money, contacts customers, or deletes data. Most incidents trace back to over-broad access.
How do I protect against prompt injection with a self-hosted agent?
Assume any web page, email, or message the agent reads could carry hostile instructions. Default web reads and research to read-only, restrict which sites and senders can trigger actions, keep an allowlist of permitted tools, and require approval for outbound messages, payments, and system changes. Log everything so you can reconstruct what happened.
When should a small business NOT self-host an AI agent?
Do not self-host if nobody will apply updates, review logs weekly, and own incidents. OpenClaw has no paid tier or hosted service, and Hermes leaves operations entirely to you. If that ownership has no name attached, use a managed service or an agency-built agent with defined scope instead.
Keep reading

Related articles

Get Your AI Automation Plan