# Hermes Profile contract

Copy this file once per profile. Do not record API keys, OAuth tokens, bot tokens, or `.env` values.

## Identity

- Canonical profile ID:
- Display name:
- Owner and backup owner:
- Purpose:
- Created / review / retirement date:
- Actual HERMES_HOME:
- Distribution origin and version, if any:

## Runtime boundary

- Terminal backend:
- Absolute `terminal.cwd`:
- `terminal.home_mode`:
- Allowed filesystem roots:
- Cross-root negative test and evidence:
- Provider / model / reasoning owner:

## State contract

- Memory allowed facts and approval policy:
- Session retention:
- Installed Skills and regression evidence:
- Plugins:
- Cron jobs and exact IDs:
- Gateway platforms and service name:
- API host / port / key owner; never write the key:

## Clone and recovery

- Created blank / `--clone` / `--clone-all` / import:
- Source profile ID:
- Assets expected to copy:
- Assets required to remain fresh:
- Export archive path:
- Export SHA-256:
- Restore drill result:

## Stop and delete

- Stop Gateway/API owner:
- Pause/remove Cron evidence:
- Credential revoke/rotation evidence:
- `hermes profile delete` evidence:
- Final `hermes profile list` evidence:
