In development
Built on OpenShell’s supervisor middleware, a gRPC hook that NVIDIA describes as still evolving.
INTEGRATION · IN DEVELOPMENT
OpenShell decides what an agent may touch. Ackuity decides whether this action, right now, should run. We are building an integration through the OpenShell supervisor, so every outbound action can get a context-aware verdict before it leaves the sandbox.
STATUS
Built on OpenShell’s supervisor middleware, a gRPC hook that NVIDIA describes as still evolving.
Depends on NVIDIA’s partner interfaces for Sentry, which runs on BlueField-4 hardware.
The same decision layer runs on any Kubernetes cluster, including NVIDIA-based infrastructure.
HOW IT WORKS
OpenShell runs each agent in a sandbox whose only way out is the supervisor, which inspects outbound HTTP, GraphQL and MCP traffic against policy. After its own policy check, the supervisor sends the action to Ackuity through the middleware hook. Ackuity returns allow, deny or modify, and the supervisor enforces it.
WHAT ACKUITY ADDS
Ackuity checks the action against the security context graph for AI agents: the user, the agent, the intent and goal, the target system and data, the tools and supply chain, and the history.
See the context graphThe action is compared with historical baselines for the agent, the user, the tool and the target system.
How detection worksIndividually harmless steps can add up. Ackuity checks sequences against 60+ threat models mapped to NIST, OWASP and MITRE ATLAS.
Browse the threat modelsWHO DECIDES WHAT
The two layers answer different questions.
| Decision | NVIDIA OpenShell | Ackuity |
|---|---|---|
| Isolating the agent process and its system calls | Yes | |
| Policy on files, networks, tools, processes and credentials | Yes | |
| Injecting credentials only where policy allows | Yes | |
| Whether an allowed action fits the user, the intent and the data policy | Yes | |
| Whether the action is normal for this agent, user, tool and system | Yes | |
| Whether a run of harmless-looking steps adds up to an attack | Yes |
Verdict mapping: the middleware’s allow, deny and modify map to Ackuity’s Allow, Block and Constrain. How Human in the loop and Terminate map onto OpenShell is still being designed. See the full response ladder.
YOUR QUESTIONS, ANSWERED
Not yet. Ackuity is building it on OpenShell’s supervisor middleware, which NVIDIA describes as still evolving. Teams can run the same Ackuity decision layer today with the Ackuity sidecar on any Kubernetes cluster.
No. Ackuity is a member of NVIDIA Inception. The OpenShell integration is built by Ackuity on OpenShell’s published extension point and is not an NVIDIA product.
No. It connects to the OpenShell supervisor, and NVIDIA’s OpenShell repository states that no NVIDIA GPU is required. Sentry runs on BlueField-4 hardware, and integrating with it is a future direction that depends on NVIDIA’s partner interfaces.
By default, OpenShell blocks traffic when a supervisor middleware service fails, according to NVIDIA’s documentation. Ackuity also lets you choose fail-open or fail-closed per policy.
No. OpenShell already routes the agent’s traffic through the supervisor, and Ackuity attaches to the supervisor, not to the agent.
READ MORE
EXPLAINER
INTEGRATION
POINT OF VIEW
Sources: NVIDIA Open Agent Safety Platform announcement · NVIDIA OpenShell product page · OpenShell supervisor middleware documentation · NVIDIA OpenShell on GitHub. NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.
NEXT STEP
Tell us about your setup. We’ll share integration progress and show you the sidecar in the meantime.