The Agent That Never Sleeps Also Never Stops Having Access
OpenClaw and Hermes show what changes when an assistant remembers, schedules work and acts between prompts. The useful product is not maximal autonomy. It is carefully delegated authority.
Chatbots wait.
You open a tab, remember what you wanted, explain it, wait for the answer, then carry that answer into the rest of your life.
An always-on agent flips the relationship.
It can wake up at 7am, check what changed, remember what mattered yesterday and send you the result in the place you already talk. It can notice that a renewal is coming, that a customer is still waiting, that a price moved or that a document was never signed. Then, if allowed, it can do something about it.
That is a much bigger product leap than another 10% on a reasoning benchmark.
It is also where the risk gets real.
The agent that never sleeps also never stops having access.
“Always on” is four product decisions
Projects like OpenClaw and Hermes Agent are interesting because they make the architecture visible.
OpenClaw is designed for one operator. A Gateway connects models, tools, sessions, events and messaging channels like WhatsApp, Telegram, Slack, Discord, Signal and iMessage. The agent can run on your device, reach device-local capabilities and stay available through the chats you already use.
Hermes combines a similar messaging gateway with persistent memory, cross-session search, a cron scheduler and a learning loop that can turn experience into reusable skills. It can run locally, on a cheap VPS or in an environment that hibernates until there is work. It can switch model providers without rebuilding the agent around one model.
Ignore the horse race between the two for a moment. Look at the primitives:
- Presence: the agent is reachable where events and people already arrive.
- Memory: it can carry useful state across sessions.
- Schedule: it can initiate work without a fresh prompt.
- Tools: it can change something outside the conversation.
Remove any one and you have a weaker product.
Presence without tools is a chatbot in WhatsApp. Tools without memory produce repeated setup. Memory without a schedule waits for you to remember. A schedule without judgement is normal automation.
Put the four together and the agent gains continuity.
The common framing is that continuity makes the AI more human. I don't think that is the useful way to look at it.
Continuity makes the agent more like infrastructure.
The consumer product is personal operations
I do not need an AI best friend.
I do need something that remembers which refund never arrived, watches three subscriptions I keep forgetting to cancel, checks whether an expensive flight falls below my limit, keeps track of family paperwork and turns “we should do this sometime” into a real calendar plan.
These jobs are boring partly because each one is small. No single task justifies sitting down, opening five products and rebuilding the context. An always-on agent can amortise that setup over months.
That is the consumer advantage: temporal arbitrage.
The agent can work when the human is not paying attention. It can watch a slow-moving situation and act only when a threshold is crossed.
Examples:
- Track a price for 40 days, then prepare the purchase when it drops below ₹X.
- Watch email for a refund confirmation and escalate after seven days.
- Compare insurance renewal terms against last year's policy before the deadline.
- Keep a running list of household maintenance, cluster jobs by location and schedule the right person.
- Notice that a passport expires before the next planned trip, then assemble the renewal checklist.
- Reorder a predictable product, but pause if the price or quantity changes materially.
None of these need a genius. They need memory, patience, context and a little authority.
That last word matters.
In June 2026, Accenture surveyed 25,590 people across 16 countries. Seventy-four percent said they would delegate routine tasks such as negotiating a deal, resolving a complaint or renewing a subscription when the agent follows strict instructions. Thirty-two percent would let the agent choose what to buy inside boundaries while the human pays. Only 9% were open to fully autonomous purchases.
That gradient is the market.
People are not deciding whether they “trust AI.” They are setting different autonomy levels for different objects.
Reorder detergent under ₹1,000? Fine.
Choose a wedding gift, book an unfamiliar medical procedure or move ₹5 lakh? Different conversation.
The best consumer agent will not have one autonomy toggle. It will have an authority model that feels obvious without requiring users to become security engineers.
Memory is a product and a liability
An assistant becomes useful when it knows I prefer an aisle seat, my company bills in dollars, my parents need direct flights and I never want a subscription with an annual auto-renewal.
After a year, that memory may be more valuable than the model.
It is also more dangerous.
A persistent agent can accumulate an unusually intimate behavioural record: purchases, health logistics, family relationships, work anxieties, daily patterns, credentials and the exceptions we rarely write in a profile.
Normal software stores data we deliberately enter. An always-on agent also stores interpretations.
“Pushpak prefers morning flights” is harmless until it is wrong. “This customer is likely to churn” may shape treatment. “This employee can approve the invoice” can create a security incident.
So memory needs product affordances we do not treat seriously enough yet:
- Source: why does the agent believe this?
- Confidence: is it a fact, preference or guess?
- Scope: which agent and workflow may use it?
- Expiry: when should it be reconfirmed?
- Correction: can the user fix it without hunting through chat history?
- Rollback: can a bad memory or skill update be reversed?
- Portability: can the useful state leave with the user?
Hermes already supports importing memories, skills and settings from OpenClaw. That is a small implementation feature with a large implication: agent state is becoming a user-owned asset.
I expect memory portability to become the agent equivalent of exporting contacts from a phone. Vendors will resist because it is the retention moat. Users will eventually demand it because starting from zero feels like training a new chief of staff every time they change products.
One agent for everything is probably the wrong end state
There is a seductive demo where one assistant sees every message, file, purchase, calendar event and device.
Maximum context. Maximum convenience. Maximum blast radius.
I think most people will end up with a small portfolio of persistent agents instead:
- a personal operations agent
- a money agent with read-heavy, spend-light access
- a family or home agent shared with other people
- a work agent governed by the employer
- specialist agents for travel, health or education when needed
They may share a common interface. They should not automatically share every memory or permission.
This looks less magical in a keynote. It is much more believable as a product.
The separation gives users a mental model. My work agent can read the company drive but not my medical email. My travel agent can spend within a trip budget but cannot move money between bank accounts. A family agent can update a shared calendar but cannot read private work messages.
Autonomy is not one number from zero to 100.
It is: who can act, on which object, for how long, with what budget, under which conditions?
Consumer commerce will arrive through thresholds, not blank cheques
McKinsey estimates that by 2030, agents could orchestrate $900 billion to $1 trillion of US B2C retail revenue and $3 trillion to $5 trillion globally. This is a scenario based on adoption assumptions, not a fact waiting to happen.
Still, the direction makes sense.
Shopping is full of machine-friendly work: compare specifications, monitor prices, apply loyalty rules, assemble a basket, find delivery windows and manage returns. Agents can travel over existing web rails while merchants expose cleaner protocols and APIs.
The mistake is imagining the first trillion dollars as autonomous agents wandering the internet with our credit cards.
It will be much more constrained.
“Buy this exact item below this price.”
“Choose any hotel with these six constraints, then ask before payment.”
“Renew unless the price rises more than 8%.”
“Replenish from an approved list with a ₹5,000 monthly cap.”
The important product surface is the mandate. The user expresses intent once; the mandate makes it executable over time.
This also changes what brands compete on. An agent does not care that a checkout button is orange. It cares whether inventory is accurate, terms are legible, delivery performance is reliable and the price can be verified. Brands will still matter to humans, but machine-readable reliability becomes a new kind of brand equity.
SEO became AEO. E-commerce will become agent-ready operations.
At work, the agent will be hired for a process
The consumer story is broad because a person's life is broad.
The enterprise story starts narrow because mistakes have owners.
Customer support is one clear entry point. Sierra raised $350 million at a $10 billion valuation in 2025 after reaching hundreds of customers, including large and heavily regulated companies. Its agents handle concrete jobs: dispute a charge, explain a deductible, arrange roadside assistance, fix an internet connection.
In July 2026, Sierra described agents that can coordinate outbound and inbound interactions over days or weeks. That is the enterprise version of always on. The agent is not having one clever conversation. It owns a customer issue until the issue closes.
Legal is another. Harvey raised $200 million at an $11 billion valuation in March 2026. The company said customers were running more than 25,000 custom legal agents and that it was expanding the legal engineers who implement and tune them inside firms.
That human implementation layer is a signal. The model is horizontal. The trustworthy workflow is not.
Then there is enterprise context. Glean raised $150 million at a $7.2 billion valuation in 2025 and reported more than 100 million annual agent actions soon after launching Glean Agents. Its product sits across company knowledge, permissions and connectors.
These three capital flows point to where investors believe value will stay:
- Sierra owns a measurable customer outcome.
- Harvey owns a high-value professional workflow.
- Glean owns the permission-aware context and action layer across systems.
Very little of the durable value is “we call the smartest model.” Most enterprise agent platforms are already model-agnostic. The 2025 AI Agent Index found that most prominent agents depend on GPT, Claude or Gemini families, while enterprise products were more likely to support multiple providers.
Model quality matters. Model loyalty will be weak.
The business moat will come from implementation, proprietary outcome data, workflow depth, trust and the ability to improve after each completed case.
Agents will eat software interfaces unevenly
Traditional SaaS assumes a person navigates the interface.
An agent can call an API when one exists and use the browser when it does not. a16z's 2025 computer-use map separates the stack into models, browser-control layers, execution environments and full-stack agents. Their thesis is that computer use opens the long tail of legacy software, while specialised business functions will work before general autonomous coworkers.
I agree with the sequence, but I think the UI disappears more slowly than people expect.
Agents are good at high-volume paths. Humans still need a place to inspect exceptions, understand why an action happened, change policy and recover from failure.
The interface does not vanish. It becomes the control room.
For software builders, this means every product will need two surfaces:
- A human surface for intent, policy, exceptions and trust.
- An agent surface for structured context, actions and verification.
Products that only optimise the human click path will lose agent traffic. Products that only expose machine actions without a good control room will be impossible to govern.
Security cannot be a permissions page added later
OpenClaw's own documentation is unusually direct: inbound messages should be treated as untrusted, and tools in the main session run on the host unless sandboxing is configured.
The dangerous input may not even come from a stranger messaging the bot. It can arrive inside a website, email, document, attachment or pasted log the agent was asked to read. If the same agent can read the instruction and use credentials, prompt injection becomes an authority problem.
Persistence makes it worse in two ways.
First, the attack can wait. A malicious instruction can influence a scheduled job later, when nobody is watching.
Second, a poisoned memory or skill can survive the conversation that introduced it.
This is why “the user approved access once” is not enough.
NIST's 2026 review found broad agreement that agents introduce security threats requiring existing cyber practices to be adapted. Its identity work focuses on identification, authorisation, audit, non-repudiation and prompt-injection controls. The 2025 AI Agent Index found a large transparency gap: 135 of 240 safety-related fields across 30 widely deployed agents had no public information, and only four published agent-specific safety evaluations.
The enterprise agent needs to be treated as a non-human identity with:
- its own name and owner
- scoped, short-lived credentials
- explicit allowed actions
- per-action and per-period budgets
- separation between reading and changing
- a full audit trail
- revocation and a kill switch
- sandboxed handling of untrusted content
- a way to prove which human mandate authorised the action
“It used the employee's OAuth token” is going to age badly.
The product loop should be delegated authority
Most agent diagrams show a model surrounded by tools.
I would draw the product differently:
Observe → Propose → Approve → Act → Verify → Learn
Not every workflow needs every step on every run.
A low-risk, reversible job can move from observe straight to act. A high-risk payment should pause for approval. Verification should be automatic wherever possible. Learning should update a bounded preference or skill, not silently rewrite the agent's personality because one email was unusual.
The authority can expand with evidence.
The first time, draft the refund email.
After five correct drafts, send to approved merchants.
After twenty successful cases, follow up automatically under a fixed amount.
If the merchant disputes the claim, escalate to the human.
This is how trust works in normal organisations. We do not hire someone on Monday and give them signing authority over every account. Software should stop treating autonomy like an onboarding checkbox.
Five bets through 2030
1. People will use a portfolio of agents, even if one interface hides it
Confidence: medium-high.
Personal, work, family and financial context have different owners and risk. The front end may look unified, but permissions and memories will separate underneath.
What would prove me wrong: one general consumer agent safely becomes the dominant home for both personal and employer-controlled work.
2. Permissioning will become part of the core experience
Confidence: high.
The winning products will make time limits, budgets, object scopes, previews and revocation understandable. “Allow access to Gmail” is too blunt for an agent that can act all night.
What would prove me wrong: successful always-on agents continue using broad, static permissions without repeated consumer or enterprise failures.
3. Enterprise agents will win process by process
Confidence: high.
Customer disputes, contract review, compliance evidence, invoice reconciliation and IT resolution have bounded inputs and verifiable outcomes. General digital employees will remain the demo; vertical process ownership will remain the deployment.
What would prove me wrong: general autonomous-employee products outgrow specialised agents across regulated enterprises.
4. Agent state will become portable
Confidence: medium.
Users will not want years of preferences, corrections and skills trapped in one vendor. Export formats and migration tools will emerge before perfect standards do.
What would prove me wrong: memory remains locked to vendors through 2030 with little user or regulatory pressure.
5. Agent commerce will be mandate-driven before it is autonomous
Confidence: medium-high.
Most serious volume will come from bounded replenishment, travel, procurement and renewal rules. The agent will act freely inside a small box, not roam freely with a card.
What would prove me wrong: consumers broadly allow agents to initiate high-value purchases without category, merchant or budget constraints.
The agent should earn a longer leash
Always-on agents will be more useful than chatbots for the same reason a good colleague is more useful than a search box.
They retain context. They notice time passing. They follow through.
But a colleague has a role, a manager, a budget, an audit trail and boundaries. An agent needs the same.
OpenClaw and Hermes show the raw shape of the product: a persistent gateway, memory, schedules, tools and presence across channels. The enterprise funding tells us where commercial value is forming: outcomes, vertical expertise, context and control. The security research tells us what is missing: clear identity, scoped authority and evidence of what happened.
The winner will not be the agent that can do the most.
It will be the one we can trust to keep working after we close the tab.
Research note: product capabilities were checked against official OpenClaw and Hermes documentation on August 10, 2026. Sierra, Harvey and Glean figures are company-reported. McKinsey's commerce figures are modeled scenarios, and Accenture's figures reflect stated survey intent rather than observed purchasing behaviour.