ACKUITY BLOG

What Is NVIDIA OpenShell? Sandbox, Supervisor and Sentry Explained

NVIDIA OpenShell runs each AI agent in a sandbox and checks its traffic against policy. Learn how the supervisor, policies and BlueField-4 Sentry fit together.

NVIDIA OpenShell is an open source runtime that runs each AI agent in an isolated sandbox and sends every outbound connection through a supervisor that checks it against policy. It is part of the NVIDIA Open Agent Safety Platform, alongside Sentry, which watches agent activity from NVIDIA BlueField-4 hardware and can quarantine an agent in milliseconds.

What did NVIDIA announce?

On September 28, 2026, NVIDIA launched the Open Agent Safety Platform. It has three parts: OpenShell, Sentry, and a reference system design that puts the two together. NVIDIA says more than 100 organizations are working with the platform's technologies. The release also notes that many of the products and features remain "in various stages" and will be offered when and if available.

OpenShell itself is already public. The code sits in the NVIDIA/OpenShell repository on GitHub under the Apache 2.0 license, and NVIDIA's OpenShell product page lists agents it supports today, including Claude Code, Codex, GitHub Copilot CLI and LangChain Deep Agents.

How does OpenShell work?

NVIDIA's product page describes OpenShell as "an open, secure runtime for agents." Its design starts from default deny: nothing is permitted until a policy grants it, and enforcement happens outside the agent's process. The architecture documentation splits the system into three pieces.

Anatomy of NVIDIA OpenShell, in NVIDIA's terms. The sandbox is a kernel-isolated container or VM. The agent runs inside it and has no direct network access. The supervisor sits beside each sandbox and is the agent's only way out: it inspects outbound HTTP, GraphQL and MCP traffic against policy before it leaves, and resolves credentials. Allowed traffic reaches tools, APIs and MCP servers. The policy sets which files, networks, tools, processes and credentials an agent may access. NVIDIA Sentry is an out-of-band watchdog on BlueField-4 that can quarantine an agent in milliseconds. NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.ANATOMY OF NVIDIA OPENSHELLSandboxKernel-isolated container or VMAgentruns insideNo direct network accessONLYWAY OUTSupervisorBeside each sandboxInspects outboundHTTP, GraphQL and MCPChecks traffic againstpolicy before it leavesResolvescredentialsALLOWEDOUTSIDEToolsAPIsMCP serversPolicyWhich of these an agent may accessFilesNetworksToolsProcessesCredentialsNVIDIA SentryOut-of-band watchdogon BlueField-4. Can quarantinean agent in milliseconds.OUT OF BANDNVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.
NVIDIA OpenShell runs the agent in a sandbox with no direct network access, and the supervisor beside it is the only way out, checking outbound traffic against policy. NVIDIA Sentry watches out of band and can quarantine an agent in milliseconds.

The sandbox

Each agent runs in its own sandbox with no direct network access. Kernel controls limit which files the agent can open and which system calls it can make. Unsafe system calls are filtered and blocked in the kernel.

The supervisor

A separate supervisor process sits beside each sandbox. According to NVIDIA's documentation, the channel to the supervisor is the workload's only allowed egress path, so the agent cannot reach a service, DNS or another private address on its own. The supervisor inspects outbound HTTP, GraphQL and MCP traffic against policy before it leaves, resolves DNS, opens approved connections and adds credentials. Agents never see real credentials; OpenShell attaches them only to requests bound for approved endpoints.

The gateway

The gateway is OpenShell's control plane. It handles user authentication and the lifecycle of sandboxes, and it can be deployed on Kubernetes with Helm. It is a management component and should not be confused with an AI or API gateway that traffic flows through.

The agent runs inside an OpenShell sandbox that denies all outbound traffic except to the OpenShell supervisor. The supervisor inspects outbound HTTP, GraphQL and MCP traffic against policy, resolves credentials and proxies traffic to tools, APIs and MCP servers. Through the supervisor middleware hook, it sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. NVIDIA Sentry is shown as a future integration.OPENSHELL SANDBOXkernel-isolated container or VMAgentuntrusted workloadDeny all egress exceptto the supervisorNVIDIA OPENSHELLSupervisorbeside each sandboxHTTP · GraphQL · MCP policyCredential resolutionDNS and proxyingAgent session handlingMEDIATEDCHANNELTARGETSTools and APIsMCP serversData and servicesALLOWEDTRAFFICACKUITYContext · Anomaly · PatternAgent Security Context Graph60+ threat models · 40 to 100 msSUPERVISOR MIDDLEWARE (gRPC)each outbound actionVERDICTallow · deny · modifyINTEGRATION STATUSIn developmentNVIDIA Sentryout-of-band watchdogFUTURE INTEGRATIONNOT ON OPENSHELL? THE SAME DECISION LAYER RUNS AS THE ACKUITY SIDECAR ON ANY KUBERNETES CLUSTER.
How Ackuity works with NVIDIA OpenShell, integration in development. The supervisor sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. Sentry integration is a future direction.

What does an OpenShell policy control?

Operators write policies that cover the files, networks, tools, processes and credentials an agent may use. For network traffic, a rule names the destinations an agent may reach and the binaries allowed to reach them, and it can restrict the requests themselves. The network rules reference lists the protocols the supervisor can inspect:

  • REST: HTTP method, path and query parameters
  • GraphQL: operation type, operation name and top-level fields, so a rule can allow a query and refuse a mutation on the same endpoint
  • MCP: the method and tool name
  • WebSocket and JSON-RPC, plus plain TCP for databases and other non-HTTP clients

Two tools help keep policies tight. The policy advisor lets an agent propose narrow new rules for a person to review, and the policy prover uses formal verification to confirm a policy grants no more access than a boundary you define. Every allow and deny is logged for audit.

OpenShell also exposes supervisor middleware: an external gRPC service that the supervisor calls after the policy check and before it forwards traffic. Middleware lets an external service allow, deny or modify agent traffic. If the middleware service fails, OpenShell blocks the affected traffic by default.

What is NVIDIA Sentry and where does it run?

Sentry is an out-of-band watchdog. It runs on NVIDIA BlueField-4 data processing units (DPUs) and is built on NVIDIA DOCA software. NVIDIA's developer blog notes that the DPU sits on the node's only path to the model, which gives Sentry a view of agent traffic that does not depend on the host. It monitors agent activity, enforces policy in silicon, and correlates agent interactions, policy decisions and tool and data access into a record of what each agent did. NVIDIA states that Sentry "can quarantine agents that attempt to move outside their boundaries in milliseconds."

How do OpenShell and Sentry fit together?

They work at different layers. OpenShell enforces policy in software on the host, request by request. Sentry adds an independent check in hardware and acts as the last resort when an agent tries to leave its boundary. NVIDIA's reference design pairs OpenShell on NVIDIA Vera CPUs with Sentry on BlueField-4 DPUs in Vera Rubin POD systems.

What does this design get right?

Enforcement sits outside the agent. An agent cannot be prompted into rewriting a supervisor it cannot reach, and a control in the execution path sees actions that a distant gateway never would. We call that placement the Goldilocks zone: not inside the agent, not at the gateway. Ackuity was built on the same principle, because rules written inside an agent depend on the agent choosing to follow them.

What can a sandbox policy not judge on its own?

A policy says what an agent may do or touch. It cannot say whether a specific, allowed action makes sense right now. An MCP tool call can match an allow rule and still be wrong for the person who asked or the task at hand. Answering that takes three more checks:

  • Context: does the action fit who asked, what the agent is entitled to, the target system and the stated intent?
  • Anomaly: does it depart from the usual behavior of this agent, user, tool or system?
  • Sequence: do several harmless steps add up to a known attack pattern, such as those in MITRE ATLAS and OWASP guidance?

Ackuity answers those questions with the Agent Security Context Graph, a live view of each action across six dimensions and 29 signals, and returns one of five decisions on the response ladder, from Allow to Terminate. We are working on an integration with the OpenShell supervisor through its middleware hook; it is in development. How Ackuity adds context checks to OpenShell explains the approach, and the NVIDIA OpenShell integration page tracks its status.

Not running OpenShell? The same decision layer runs in Ackuity's own sidecar on any Kubernetes cluster, including NVIDIA-based infrastructure, outside the agent's scope. See how the Ackuity platform works.

NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.

Frequently asked questions

Is NVIDIA OpenShell open source?

Yes. OpenShell is published on GitHub at github.com/NVIDIA/OpenShell under the Apache 2.0 license. NVIDIA's announcement describes it as open source software that can be extended to third-party compute platforms, including those from Arm and Intel.

Does OpenShell need NVIDIA hardware?

No, OpenShell itself does not. Its documentation lists Linux, macOS on Apple Silicon and Windows with WSL 2 (experimental), with Docker, Podman or host virtualization, and it can run on Kubernetes. NVIDIA says it runs with minimal overhead on NVIDIA Vera CPUs. Sentry is different: it runs on NVIDIA BlueField-4 DPUs.

What is the difference between OpenShell and Sentry?

OpenShell is software that sandboxes each agent and checks its outbound requests against policy through a supervisor on the host. Sentry is an out-of-band watchdog on BlueField-4 DPUs that monitors agent activity independently of the host and can quarantine an agent that tries to move outside its boundaries.

Can OpenShell work with other security tools?

Yes. OpenShell offers supervisor middleware, a gRPC service the supervisor calls after its policy check, which can allow, deny or modify agent traffic. It also offers gateway interceptors for control-plane operations. External tools, including Ackuity's integration now in development, can plug in through these hooks.

KEEP READING

Keep exploring.

NEXT STEP

What does this mean for your agents?

Connect the ideas to your own tools, data and execution environment.

Request access