NVIDIA announced its Open Agent Safety Platform on 28 September 2026, combining OpenShell software with a reference design for monitoring agent workloads. For teams deploying agents that read files, call services and use credentials, the useful distinction is between controlling those permissions and observing activity through a separate hardware layer.
NVIDIA describes OpenShell as broadly available. Sentry is an additional reference system design, rather than a requirement for using the software runtime. The announcement also cautions that features are at different stages of availability, so platform-level claims should not be read as a delivery guarantee for every component.
OpenShell applies the operator’s access policy
The OpenShell documentation, inspected at version 0.1.2, describes a sandboxed runtime with kernel-level isolation and declarative YAML policies. Operators specify what an agent may access instead of relying solely on instructions in its prompt.
Its controls cover filesystem access, outbound connections, process behaviour and provider credentials. Filesystem and process restrictions are fixed when a sandbox is created. Network policies can change while it runs. Provider credentials resolve through placeholders at authorised endpoints, keeping credential handling tied to the permitted destination.
NVIDIA’s OpenShell repository also describes formal verification of proposed policy changes to flag newly granted sensitive access for human review. This checks changes to permissions; it should not be mistaken for proof that an agent’s reasoning or resulting work is correct. OpenShell is licensed under Apache 2.0.
Sentry adds a separate monitoring boundary
NVIDIA’s technical explanation of the platform describes Sentry as an optional layer extending monitoring and enforcement into BlueField hardware. The reference design places BlueField-4 on the node’s path to model inference, isolated from the host running the agent.
That separation is the architectural distinction: runtime policy governs permitted activity, while an independent hardware layer can monitor it. NVIDIA says the platform is optimised for Vera CPU and BlueField DPU systems while supporting other hardware. This does not establish identical capabilities across configurations or independently demonstrate protection against every failure.
For operators, configuration remains central. OpenShell’s security guidance distinguishes destination controls from request-level enforcement. When application-layer inspection is enabled, its documented default audit mode records rule violations but forwards traffic. Enforce mode blocks requests that do not match the rules.
A deployment review therefore needs to establish which controls are active, what each policy permits and whether a setting observes or blocks activity. Teams should test their intended workload and denied actions against the effective policy. A reference design provides a starting point for that evaluation, not a substitute for it.



