---
title: "NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It. | Anomity Blog"
description: "OpenShell sandboxes agents with policy outside their reach, and Sentry watches from the DPU. Both cover the agents you enroll. The rest need a list first."
url: "https://anomity.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry/"
source: html
---

On this page

- OpenShell: the runtime
- Sentry: the watchdog on the DPU
- NVIDIA's framing: an engineering problem
- The question a sandbox cannot answer
- A practical sequence
- How Anomity covers the agents outside the sandbox
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It.

![Anomity robot illustrating NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It.]

Insights

# NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It.

Anomity Research
Anomity Research
·
Oct 2, 2026
·
6 min read

Share: Copied

TL;DR

- On September 28, 2026 , NVIDIA announced the Open Agent Safety Platform : OpenShell , an open-source agent runtime, plus Sentry , an optional hardware enforcement layer on BlueField-4 DPUs. More than 100 organizations are working with it, including Anthropic, Salesforce, SAP, Red Hat, SUSE and Canonical.
- OpenShell (Apache 2.0, written in Rust) runs each agent in a sandbox with kernel-level filesystem and process controls , and a supervisor outside the workload that checks every outbound request against policy, down to HTTP method and path, GraphQL and MCP traffic.
- Credentials never enter the sandbox : the real secret is substituted outside the workload, and only for an authorized endpoint. Policy decisions are logged in OCSF format, and when an agent asks for more access, it cannot approve its own request .
- Sentry runs on the DPU, isolated from the host, verifies agent identity and enforces policy at line speed. It targets Vera CPU and BlueField-based data center systems such as the Vera Rubin POD, not laptops.
- NVIDIA's framing is the right one: AI security is an engineering problem with defined requirements, enforceable controls, named owners and evidence. And protected logs should capture the attempted tool call, the authorization decision and the outcome.
- The limit is structural. A sandbox governs the agents someone deliberately put in it. The coding agent a developer installed natively last month is not in OpenShell, and no DPU is watching it. Containment starts with a count.

NVIDIA's **Open Agent Safety Platform**, announced on **September 28, 2026**, is built on one idea that deserves to become standard: **the controls that contain an agent should not live inside the agent**. OpenShell enforces policy from outside the agent's process. Sentry enforces it from outside the host entirely, on the network card. An agent that goes wrong cannot simply turn its own guardrails off.

That is the right design. This post covers what NVIDIA shipped, and then the question every containment architecture eventually has to answer: how many of your agents are actually inside it?

## OpenShell: the runtime

OpenShell is open source under Apache 2.0, written in Rust, and in NVIDIA's words is **an open-source runtime for defining and enforcing which systems and data an agent can access**. It has three parts:

- Gateway: manages the lifecycles and policies of many sandboxes.
- Supervisor: runs outside the agent workload and checks outbound requests against policy.
- Sandbox: runs the workload with kernel-level controls over its filesystem and processes.

The enforcement detail is good. Network policy inspects **HTTP and REST down to method and path**, plus GraphQL and **MCP traffic**, so a policy can allow a read through an API while blocking a write through the same API. **Real credentials never enter the sandbox**: they are substituted outside the workload, and only for an authorized endpoint. Policies are written in YAML and compiled to OPA Rego. Network rules are hot-reloadable; filesystem and process rules are fixed when the sandbox is created.

Two design choices stand out. When an agent hits a boundary and proposes a narrower policy change, a human reviews it, and **the agent cannot approve its own request**. And every policy decision is recorded in an **OCSF audit trail**, a standard format that security tooling already ingests. NVIDIA lists Claude Code, Codex, Pi and Hermes among supported agents, with Docker, Podman, MicroVM and Kubernetes as compute drivers. For a hands-on walkthrough of the policy model and the defaults to change before production, see [our OpenShell security guide](https://anomity.ai/blog/nvidia-openshell-agent-sandbox-security-guide/).

## Sentry: the watchdog on the DPU

Sentry is the optional second layer. It runs on **BlueField-4 DPUs** using NVIDIA DOCA, isolated from the host, so a compromised runtime cannot disable it. NVIDIA says it correlates agent interactions, policy decisions, and tool and data access into a contextual record, continuously verifies each agent's identity, and enforces policy at line speed. Launch coverage reports it can quarantine an agent that leaves its boundary within milliseconds. It is aimed at Vera CPU and BlueField-based **data center** systems such as the Vera Rubin POD.

The partner list signals real adoption intent. Anthropic integrated Claude Managed Agents with OpenShell and BlueField. Salesforce connected OpenShell to Slack for approving agent permission requests. SAP is embedding OpenShell in the Joule Studio runtime. Red Hat, SUSE and Canonical are integrating it into their operating systems.

## NVIDIA's framing: an engineering problem

A week earlier, NVIDIA's Saša Zdjelar laid out the thinking behind the platform. Models provide capabilities, harnesses organize context, tools and workflows, and runtime environments provide the infrastructure where actions execute. Security has to be solved at each layer. Two passages are worth adopting verbatim as requirements:

> AI security is an engineering problem. That means defined security requirements, enforceable controls, named owners and evidence that protections work. Saša Zdjelar, NVIDIA

> Protected logs should capture the attempted tool call, authorization decision and outcome so the security team can identify the tool used and the destination it attempted to reach. Saša Zdjelar, NVIDIA

The same post adds that consequential actions and permission changes should still require human approval, and that permission to update a record should not automatically extend to exporting it. That is least privilege applied to tool calls, the argument of [least privilege for AI agents](https://anomity.ai/blog/least-privilege-for-ai-agents/).

## The question a sandbox cannot answer

OpenShell governs the agents someone deliberately starts inside it. Sentry watches the agents running on data center hardware it sits beside. Neither can see the coding agent a developer installed natively on a laptop last month, the desktop assistant a sales team adopted on its own, or the MCP server started from a README. On most fleets today, those are not edge cases. They are the majority of agents.

This is the same gap that survey data keeps finding. In [the containment gap](https://anomity.ai/blog/ai-agent-containment-gap-identity-without-isolation/), 46 of 57 enterprises that had solved agent identity had never built isolation. A free, well-designed sandbox lowers the cost of isolation dramatically. It does not tell you which agents still need it.

> A containment program is a numerator and a denominator. OpenShell improves the numerator. Most organizations have never measured the denominator.

## A practical sequence

- Count. Inventory every agent, CLI, MCP server and local model runtime across endpoints and servers. This is the denominator.
- Classify. Mark which agents run with production credentials, customer data or broad repository access. These are the first candidates for a sandbox.
- Contain the highest-risk agents in OpenShell or an equivalent runtime, with credentials substituted outside the workload.
- Govern the rest where they run. Agents that stay native on endpoints still need tool-call policy and an audit trail.
- Log the same way everywhere. Attempted tool call, decision, outcome, for sandboxed and native agents alike, so the record is complete.

## How Anomity covers the agents outside the sandbox

Anomity supplies the denominator. The Endpoint Sensor inventories agents, CLIs, MCP servers, plugins, skills, hooks and local LLM runtimes on every managed endpoint, across 144 tracked AI tools, so the list of agents a containment program needs to reach is built from what is installed, not from what was approved.

For agents that run natively, Anomity governs at the agent's own hook. On Claude Code, it decides **allow, deny or log at PreToolUse** before a tool call runs, across 180 enforcement rules and nine guards. Each attempted call, its decision and its outcome are recorded in a **90-day audit trail** that routes to SIEM, Slack, email or Jira, which is the logging requirement NVIDIA describes, applied to the agents no sandbox is watching. A hook in the harness is not the same isolation as a kernel boundary, and we do not claim it is. It is the control available for an agent that was never sandboxed, and it complements runtimes like OpenShell rather than competing with them.

NVIDIA has made strong agent containment cheaper and more standard, and the industry support behind it suggests it will spread. The work that remains is knowing which agents to put inside it. For more on Anomity and NVIDIA, see [Anomity joins the NVIDIA Inception program](https://anomity.ai/blog/anomity-nvidia-inception-program/). For a step-by-step inventory method, see [how to build an AI agent inventory](https://anomity.ai/blog/how-to-build-an-ai-agent-inventory/). To count the agents across your own fleet, [book a 30-minute demo](https://anomity.ai/#early-access).

Share: Copied

## Frequently asked questions

What is the NVIDIA Open Agent Safety Platform?
It is a layered safety architecture NVIDIA announced on September 28, 2026, combining the OpenShell agent runtime with NVIDIA Sentry for continuous in-silicon monitoring. NVIDIA describes three layers: an application layer of models, tools, data and scripts; a runtime layer where OpenShell runs each agent in a sandbox with kernel-level isolation; and an infrastructure layer of NVIDIA Vera CPUs and BlueField-4 DPUs. The core idea is that safety controls should not live inside the agent they are meant to control.

What does OpenShell enforce?
OpenShell has three components. A gateway manages the lifecycle and policies of many sandboxes. A supervisor runs outside the agent workload and checks outbound requests against policy. The sandbox runs the workload with kernel-level controls over its filesystem and processes. Network policy can inspect HTTP and REST at the method level, as well as GraphQL and Model Context Protocol traffic, so it can allow a data query while blocking a write through the same API. Real credentials are substituted outside the workload and only for an authorized endpoint. Policies are written in YAML and compiled to OPA Rego.

Which agents and platforms does OpenShell support?
NVIDIA's developer documentation names Claude Code, Codex, Pi and Hermes among supported agents, and lists Docker, Podman, MicroVM and Kubernetes as compute drivers. Coverage of the launch reports support for Linux, macOS on Apple Silicon and Windows through WSL 2. OpenShell does not require NVIDIA hardware; it is optimized for NVIDIA Vera CPUs and can be extended to Arm and Intel platforms.

What is NVIDIA Sentry?
Sentry is an optional, independent enforcement layer that runs on BlueField-4 data processing units using NVIDIA DOCA. NVIDIA says it correlates agent interactions, policy decisions, and tool and data access into a contextual record of agent activity, continuously verifies each agent's identity, and enforces policy at line speed. Because it runs on the DPU, isolated from the host, a compromised runtime cannot disable it. Coverage of the launch reports it can quarantine an agent that leaves its boundary within milliseconds. It targets data center systems, such as the Vera Rubin POD.

Does OpenShell replace endpoint visibility or hook-level controls?
No, they solve different problems. OpenShell provides strong isolation for agents that run inside it, with kernel and network enforcement outside the agent's reach. It does nothing for agents that were never put in a sandbox, which on most fleets is the majority: coding agents, CLIs and desktop assistants installed natively on developer and employee machines. Those still need to be found, and governed where they run. The two approaches are complementary.

What should a security team take from the launch?
Three things. Adopt the design principle that enforcement should sit outside the agent, wherever you can. Adopt NVIDIA's logging requirement that every attempted tool call, its authorization decision and its outcome are recorded in protected logs. And treat sandbox adoption as a coverage problem: measure what fraction of the agents in your organization actually run inside a controlled runtime, because the remainder is where the risk concentrates.

How does Anomity help with this?
Anomity supplies the count and covers the agents outside the sandbox. The Endpoint Sensor inventories agents, CLIs, MCP servers, plugins, skills, hooks and local LLM runtimes on every managed endpoint, which is the denominator any containment program needs. For agents running natively, Anomity decides allow, deny or log at hooks such as Claude Code's PreToolUse before a tool call runs, and records each attempted call, decision and outcome in a 90-day audit trail that routes to SIEM, Slack, email or Jira. That matches the logging NVIDIA recommends, for the agents no sandbox is watching.

## Related

[Insights ### Claude Fable 5.1 and Mythos 5.1: One Model, Two Safeguard Tiers, and a Fallback Your Security Team Will Hit Fable 5.1 and Mythos 5.1 are one model with two safeguard tiers. Flagged cyber requests in Claude Code fall back to Opus 4.8. What it means for you. Anomity Research · Oct 2, 2026 · 5 min](https://anomity.ai/blog/claude-fable-5-1-mythos-5-1-model-fallback-governance/)

[Insights ### OpenAI Astra Crossed the Critical Cyber Threshold. Its Safeguards Stop at the Model. Astra is OpenAI's first model rated Critical for cyber. OpenAI built safeguards for the model. The agents running it on your endpoints are still yours. Anomity Research · Oct 2, 2026 · 5 min](https://anomity.ai/blog/openai-astra-critical-cyber-capability-enterprise/)

[Insights ### MCP HTTP Fallback Auth Keeps Shipping as Critical MCP HTTP servers keep shipping Critical flaws where missing auth falls through to globally configured credentials. CVE-2026-77254/77244 in mcp-atlassian are the latest clean examples of the class. Anomity Research · Sep 28, 2026 · 3 min](https://anomity.ai/blog/mcp-http-fallback-auth-global-credentials-class-2026/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "BlogPosting",
  "headline": "NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It.",
  "description": "OpenShell sandboxes agents with policy outside their reach, and Sentry watches from the DPU. Both cover the agents you enroll. The rest need a list first.",
  "datePublished": "2026-10-02",
  "dateModified": "2026-10-02",
  "author": {
    "@type": "Person",
    "name": "Anomity Research",
    "jobTitle": "Anomity Research"
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/audit-compliance.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "Insights",
  "url": "https://anomity.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry/"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What is the NVIDIA Open Agent Safety Platform?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is a layered safety architecture NVIDIA announced on September 28, 2026, combining the OpenShell agent runtime with NVIDIA Sentry for continuous in-silicon monitoring. NVIDIA describes three layers: an application layer of models, tools, data and scripts; a runtime layer where OpenShell runs each agent in a sandbox with kernel-level isolation; and an infrastructure layer of NVIDIA Vera CPUs and BlueField-4 DPUs. The core idea is that safety controls should not live inside the agent they are meant to control."
      }
    },
    {
      "@type": "Question",
      "name": "What does OpenShell enforce?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "OpenShell has three components. A gateway manages the lifecycle and policies of many sandboxes. A supervisor runs outside the agent workload and checks outbound requests against policy. The sandbox runs the workload with kernel-level controls over its filesystem and processes. Network policy can inspect HTTP and REST at the method level, as well as GraphQL and Model Context Protocol traffic, so it can allow a data query while blocking a write through the same API. Real credentials are substituted outside the workload and only for an authorized endpoint. Policies are written in YAML and compiled to OPA Rego."
      }
    },
    {
      "@type": "Question",
      "name": "Which agents and platforms does OpenShell support?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "NVIDIA's developer documentation names Claude Code, Codex, Pi and Hermes among supported agents, and lists Docker, Podman, MicroVM and Kubernetes as compute drivers. Coverage of the launch reports support for Linux, macOS on Apple Silicon and Windows through WSL 2. OpenShell does not require NVIDIA hardware; it is optimized for NVIDIA Vera CPUs and can be extended to Arm and Intel platforms."
      }
    },
    {
      "@type": "Question",
      "name": "What is NVIDIA Sentry?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Sentry is an optional, independent enforcement layer that runs on BlueField-4 data processing units using NVIDIA DOCA. NVIDIA says it correlates agent interactions, policy decisions, and tool and data access into a contextual record of agent activity, continuously verifies each agent's identity, and enforces policy at line speed. Because it runs on the DPU, isolated from the host, a compromised runtime cannot disable it. Coverage of the launch reports it can quarantine an agent that leaves its boundary within milliseconds. It targets data center systems, such as the Vera Rubin POD."
      }
    },
    {
      "@type": "Question",
      "name": "Does OpenShell replace endpoint visibility or hook-level controls?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No, they solve different problems. OpenShell provides strong isolation for agents that run inside it, with kernel and network enforcement outside the agent's reach. It does nothing for agents that were never put in a sandbox, which on most fleets is the majority: coding agents, CLIs and desktop assistants installed natively on developer and employee machines. Those still need to be found, and governed where they run. The two approaches are complementary."
      }
    },
    {
      "@type": "Question",
      "name": "What should a security team take from the launch?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Three things. Adopt the design principle that enforcement should sit outside the agent, wherever you can. Adopt NVIDIA's logging requirement that every attempted tool call, its authorization decision and its outcome are recorded in protected logs. And treat sandbox adoption as a coverage problem: measure what fraction of the agents in your organization actually run inside a controlled runtime, because the remainder is where the risk concentrates."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help with this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity supplies the count and covers the agents outside the sandbox. The Endpoint Sensor inventories agents, CLIs, MCP servers, plugins, skills, hooks and local LLM runtimes on every managed endpoint, which is the denominator any containment program needs. For agents running natively, Anomity decides allow, deny or log at hooks such as Claude Code's PreToolUse before a tool call runs, and records each attempted call, decision and outcome in a 90-day audit trail that routes to SIEM, Slack, email or Jira. That matches the logging NVIDIA recommends, for the agents no sandbox is watching."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It.",
      "item": "https://anomity.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry/"
    }
  ]
}
```
