What each engine allows is enforced by the platform, not only hidden in the interface: a channel or integration outside an engine’s profile is refused.
Hermes — general-purpose agent
Hermes is the default engine. A Hermes agent gets the full product: every channel, integrations with granular permissions, and scheduled tasks. Pick it for anything that isn’t primarily writing code in a repository.opencode — coding agent
An opencode agent works on your code, in GitHub repositories you choose. Each piece of work runs in its own session and ends in a draft pull request.Requirements
- At least one repository, in
owner/repoform. The agent only works in the repositories on its list; each session picks one. You can edit the list at any time from the agent’s settings, but it can never be empty. - An active GitHub connection for your company. A coding agent can’t be created without one. See Integrations overview.
How it reaches GitHub
The agent never holds a GitHub credential of its own. When it needs to access one of its repositories, it asks Atako for your company’s GitHub access token for that repository only. Atako checks that the repository is on the agent’s list, hands the token over the agent’s authenticated channel, and the agent passes it straight to git — it’s never stored on the agent’s side, nor written to logs. Each request, granted or denied, is recorded in the integration audit trail with the repository name, never the token itself. GitHub is a repository perimeter for this engine, not a set of integration actions: an opencode agent doesn’t get connector tools, and no other integration can be granted to it.Channels
Related
Agents
What an agent is made of and how it behaves over time.
Channels overview
Every way to reach an agent.
Atako inference
Choosing the model behind an agent.
Glossary
Quick definitions of the terms used here.