ACKUITY BLOG

Ackuity and NVIDIA OpenShell: Context-Aware Control for Sandboxed Agents

How Ackuity adds context-aware checks to NVIDIA OpenShell through supervisor middleware: context, anomaly and threat pattern checks on each agent action.

Ackuity is building an integration with NVIDIA OpenShell that adds context-aware decisions on top of OpenShell's sandbox policy. OpenShell policy sets what an agent may touch. Ackuity checks whether a specific action makes sense right now, using live context, behavioral baselines and threat patterns.

Ackuity is a member of NVIDIA Inception. The integration described here is our own engineering work, and it is still in development.

What did NVIDIA launch?

On September 28, 2026, NVIDIA announced the Open Agent Safety Platform. It has two parts and a reference system design that combines them. OpenShell is open source software, released on GitHub under the Apache 2.0 license, that runs each agent in a sandbox with kernel-level isolation. Sentry is an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs and, according to NVIDIA, can quarantine an agent that tries to move outside its boundaries in milliseconds.

Inside OpenShell, a supervisor sits on the trusted side of the sandbox boundary. NVIDIA's architecture documentation describes it as the workload's only allowed egress path. The supervisor is the agent's only way out, inspecting outbound HTTP, GraphQL and MCP traffic against policy before it leaves, and it supplies credentials only where policy allows. Operators define in policy which files, networks, tools, processes and credentials an agent can access. NVIDIA says the platform's products are in various stages of availability; OpenShell is available now. Our explainer on what NVIDIA OpenShell is and how it works covers the platform in more depth.

Why does control belong outside the agent?

We built Ackuity, the Agent Execution Control Switch for AI agents, on the same principle OpenShell uses. You cannot write rules inside an agent and expect the agent to follow them. An agent that can reason can also reason around its own instructions, so the control has to be independent of the agent and sit outside its scope.

Placement matters too. We call the right spot the Goldilocks zone: not inside the agent, not at the gateway. Inside the agent, the controlled party is also the control. At a gateway, the control sees the call without its context, and most agent actions never cross a gateway at all. That zone is beside the agent, in the execution path: close enough to see intent, plan and history, and out of the agent's reach. OpenShell's supervisor occupies that kind of position, which makes it a natural place to attach an Ackuity decision.

What does OpenShell policy decide, and what does Ackuity add?

OpenShell policy answers a scope question. May this agent read this path, reach this destination, send this kind of request? Every deployment needs that answer. Scope alone cannot say whether a permitted action is a good idea at this moment. A finance agent may be allowed to call the payments API, and the question of whether this payment, for this user, after these earlier steps, should go through still remains.

Ackuity answers that question with three checks on each action.

Does the action fit the enterprise security context?

Ackuity keeps a live picture of the users, agents and their entitlements, target systems and intent behind each action. We call it the Agent Security Context Graph. It gathers 29 signals across six dimensions, outside the agent and before the action runs, so the agent cannot edit it:

  • User: identity, permissions, attributes and risk status.
  • Agent: identity and credentials, permissions and scope, tools, business rules and risk status.
  • Intent: the user's request, the agent's goal and any delegations.
  • Reasoning: planning steps, chain of thought, and the integrity of memory and context data.
  • Systems: system and data policies, regulations, owner and provenance, state change impact, tool integrity and vulnerabilities.
  • History: earlier actions in the session, prior alerts, user and agent action history, and baseline drift.
One agent action, an update to a patient record, sits at the center. Six dimensions surround it: User (Identity, Permissions, Attributes, Risk status); Agent (Identity and credentials, Permissions and scope, Tools and capabilities, Business rules, Risk status); Intent and goal (User request, Agent goal, Planning steps, Chain of thought, Delegations); Target system and data (System policies, Data policies, Regulations, Owner and provenance, State change impact); Tools and supply chain (Vulnerabilities and reputation, Tool description integrity, Memory integrity, Context data integrity, Tool policies); History (Prior actions this session, Prior security alerts, User action history, Agent action history, Baseline drifts). Together they hold 29 signals, assembled outside the agent before the action runs.IdentityPermissionsAttributesRisk statusUserSTABLE · 4Identity and credentialsPermissions and scopeTools and capabilitiesBusiness rulesRisk statusAgentSTABLE · 5User requestAgent goalPlanning stepsChain of thoughtDelegationsIntentand goalPER ACTION · 5System policiesData policiesRegulationsOwner and provenanceState change impactTarget systemand dataSTABLE · 5Vulnerabilities and reputationTool description integrityMemory integrityContext data integrityTool policiesTools andsupply chainPER ACTION · 5Prior actions this sessionPrior security alertsUser action historyAgent action historyBaseline driftsHistoryACCUMULATED · 5AGENT ACTIONUpdate patient record BDB.WRITE · EHR.PATIENTSSTABLE CONTEXTCHECKED PER ACTIONACCUMULATES OVER TIME6 DIMENSIONS · 29 SIGNALS · ASSEMBLED OUTSIDE THE AGENT
The Agent Security Context Graph is a security context graph for AI agents: everything relevant to a single agent action, across six dimensions and 29 signals, assembled outside the agent before the action runs, so the agent cannot edit it.

Is the action anomalous?

Ackuity compares each action with historical baselines for the agent, the user, the tool and the target system. A large export can be routine for one reporting agent and far outside the norm for another, or for the same agent acting for a different user.

Do the cumulative actions form a threat pattern?

Steps that look harmless one at a time can add up to an attack. Reading a config file, searching for credentials and opening a new outbound connection may each pass policy. Together they look like credential theft followed by exfiltration. Ackuity checks sequences against 60+ threat models in 14 categories, mapped to MITRE ATLAS, OWASP and NIST. The engine combines rules, behavioral baselines and small language models and correlates them across steps, an approach we call neurosymbolic verification. A decision takes 40 to 100 ms. That figure is decision time, not end-to-end latency.

How does the OpenShell integration work?

OpenShell has an extension point called supervisor middleware. It is a set of gRPC services that the supervisor calls after policy evaluation and before it injects provider credentials. Middleware lets an external service allow, deny or modify agent traffic. NVIDIA's documentation says the middleware API is still evolving.

We are connecting Ackuity's threat and context engine to that hook. When OpenShell policy permits a request, the supervisor hands it to Ackuity, which runs the three checks and returns a verdict. The verdicts map onto part of Ackuity's response ladder:

  • Allow: the request goes through as sent, and Ackuity logs the decision.
  • Constrain: Ackuity modifies the request, for example by masking a field or narrowing a query, and the scoped version goes through.
  • Block: Ackuity denies the request before it reaches the target.

Human in the loop and Terminate are also on Ackuity's ladder. We have not yet settled how they will map onto OpenShell's interfaces, and we will document that once the design is stable.

The agent runs inside an OpenShell sandbox that denies all outbound traffic except to the OpenShell supervisor. The supervisor inspects outbound HTTP, GraphQL and MCP traffic against policy, resolves credentials and proxies traffic to tools, APIs and MCP servers. Through the supervisor middleware hook, it sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. NVIDIA Sentry is shown as a future integration.OPENSHELL SANDBOXkernel-isolated container or VMAgentuntrusted workloadDeny all egress exceptto the supervisorNVIDIA OPENSHELLSupervisorbeside each sandboxHTTP · GraphQL · MCP policyCredential resolutionDNS and proxyingAgent session handlingMEDIATEDCHANNELTARGETSTools and APIsMCP serversData and servicesALLOWEDTRAFFICACKUITYContext · Anomaly · PatternAgent Security Context Graph60+ threat models · 40 to 100 msSUPERVISOR MIDDLEWARE (gRPC)each outbound actionVERDICTallow · deny · modifyINTEGRATION STATUSIn developmentNVIDIA Sentryout-of-band watchdogFUTURE INTEGRATIONNOT ON OPENSHELL? THE SAME DECISION LAYER RUNS AS THE ACKUITY SIDECAR ON ANY KUBERNETES CLUSTER.
How Ackuity works with NVIDIA OpenShell, integration in development. The supervisor sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. Sentry integration is a future direction.

What is the integration status?

The integration is in development. The middleware contract is still changing, and we will follow it as NVIDIA updates it. Sentry integration is a future direction that depends on NVIDIA's partner interfaces. Quarantine is a sound last resort, and we explain where it fits beside per-action decisions in kill switch or control switch. Current status and answers to common questions live on our NVIDIA OpenShell integration page.

What if you do not run OpenShell?

The same decision layer runs with Ackuity's own sidecar in the agent's pod, on any Kubernetes cluster, including NVIDIA-based infrastructure. The sidecar is software only and needs no changes to agent code. It sits in the same place as the supervisor hook, beside the agent and outside its scope. How the Ackuity platform works covers the sidecar and the other ways to deploy.

NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.

Frequently asked questions

Is Ackuity an NVIDIA Open Agent Safety Platform partner?

No. Ackuity is a member of NVIDIA Inception and is building an OpenShell integration as its own engineering work. It is not an Open Agent Safety Platform launch partner, and NVIDIA has not endorsed or certified Ackuity. The integration is in development.

How does Ackuity connect to NVIDIA OpenShell?

Ackuity connects through OpenShell's supervisor middleware, a gRPC hook the supervisor calls after policy evaluation. The hook lets an external service allow, deny or modify agent traffic. NVIDIA describes the middleware API as still evolving, so the integration will track changes to it.

Does Ackuity replace OpenShell policy?

No. OpenShell policy defines what an agent may touch, and Ackuity runs after that policy permits a request. Ackuity then checks whether the specific action fits the security context, matches behavioral baselines and stays clear of known threat patterns.

Can I use Ackuity without OpenShell?

Yes. Ackuity runs as its own sidecar in the agent's pod on any Kubernetes cluster, including NVIDIA-based infrastructure. It needs no agent code changes and makes the same per-action decisions, from outside the agent's scope.

KEEP READING

Keep exploring.

NEXT STEP

What does this mean for your agents?

Connect the ideas to your own tools, data and execution environment.

Request access