INTEGRATION · IN DEVELOPMENT

Ackuity for NVIDIA OpenShell

OpenShell decides what an agent may touch. Ackuity decides whether this action, right now, should run. We are building an integration through the OpenShell supervisor, so every outbound action can get a context-aware verdict before it leaves the sandbox.

STATUS

Where the integration stands today.

STATUS

In development

Built on OpenShell’s supervisor middleware, a gRPC hook that NVIDIA describes as still evolving.

NVIDIA SENTRY

Future direction

Depends on NVIDIA’s partner interfaces for Sentry, which runs on BlueField-4 hardware.

AVAILABLE NOW

Ackuity sidecar

The same decision layer runs on any Kubernetes cluster, including NVIDIA-based infrastructure.

HOW IT WORKS

The supervisor asks. Ackuity answers.

OpenShell runs each agent in a sandbox whose only way out is the supervisor, which inspects outbound HTTP, GraphQL and MCP traffic against policy. After its own policy check, the supervisor sends the action to Ackuity through the middleware hook. Ackuity returns allow, deny or modify, and the supervisor enforces it.

The agent runs inside an OpenShell sandbox that denies all outbound traffic except to the OpenShell supervisor. The supervisor inspects outbound HTTP, GraphQL and MCP traffic against policy, resolves credentials and proxies traffic to tools, APIs and MCP servers. Through the supervisor middleware hook, it sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. NVIDIA Sentry is shown as a future integration.OPENSHELL SANDBOXkernel-isolated container or VMAgentuntrusted workloadDeny all egress exceptto the supervisorNVIDIA OPENSHELLSupervisorbeside each sandboxHTTP · GraphQL · MCP policyCredential resolutionDNS and proxyingAgent session handlingMEDIATEDCHANNELTARGETSTools and APIsMCP serversData and servicesALLOWEDTRAFFICACKUITYContext · Anomaly · PatternAgent Security Context Graph60+ threat models · 40 to 100 msSUPERVISOR MIDDLEWARE (gRPC)each outbound actionVERDICTallow · deny · modifyINTEGRATION STATUSIn developmentNVIDIA Sentryout-of-band watchdogFUTURE INTEGRATIONNOT ON OPENSHELL? THE SAME DECISION LAYER RUNS AS THE ACKUITY SIDECAR ON ANY KUBERNETES CLUSTER.
How Ackuity works with NVIDIA OpenShell, integration in development. The supervisor sends each outbound action to Ackuity, which checks context, anomalies and threat patterns and returns allow, deny or modify. Sentry integration is a future direction.

WHAT ACKUITY ADDS

Three questions a sandbox policy cannot answer alone.

Two layers working together. The bottom layer is NVIDIA OpenShell policy, which decides what the agent may touch: files, networks, tools, processes and credentials. The top layer is Ackuity context, which decides whether this action makes sense right now, with three checks: context, using the Agent Security Context Graph; anomaly, against baselines; and pattern, for multi-step threats across 60+ threat models. Status: the Ackuity sidecar is available now, the OpenShell integration is in development, and NVIDIA Sentry is a future direction. NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.ACKUITY CONTEXTWhether this action makes sense right nowContextAgent SecurityContext GraphAnomalyDeviation frombaselinesPatternMulti-step threats,60+ threat modelsALLOWED BY POLICY, THEN CHECKED IN CONTEXTNVIDIA OPENSHELL POLICYWhat the agent may touchFilesNetworksToolsProcessesCredentialsSTATUSAckuity sidecarAvailable nowOpenShell integrationIn developmentNVIDIA SentryFuture directionNVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.
OpenShell policy decides what an agent may touch, and Ackuity decides whether a specific action makes sense right now by checking context, anomalies and multi-step threat patterns. The Ackuity sidecar is available now and the OpenShell integration is in development.
02

Is it anomalous?

The action is compared with historical baselines for the agent, the user, the tool and the target system.

How detection works
03

Does the sequence form an attack?

Individually harmless steps can add up. Ackuity checks sequences against 60+ threat models mapped to NIST, OWASP and MITRE ATLAS.

Browse the threat models

WHO DECIDES WHAT

OpenShell and Ackuity, side by side.

The two layers answer different questions.

DecisionNVIDIA OpenShellAckuity
Isolating the agent process and its system callsYes
Policy on files, networks, tools, processes and credentialsYes
Injecting credentials only where policy allowsYes
Whether an allowed action fits the user, the intent and the data policyYes
Whether the action is normal for this agent, user, tool and systemYes
Whether a run of harmless-looking steps adds up to an attackYes

Verdict mapping: the middleware’s allow, deny and modify map to Ackuity’s Allow, Block and Constrain. How Human in the loop and Terminate map onto OpenShell is still being designed. See the full response ladder.

YOUR QUESTIONS, ANSWERED

Before you take the next step.

Is the Ackuity integration with NVIDIA OpenShell available today?

Not yet. Ackuity is building it on OpenShell’s supervisor middleware, which NVIDIA describes as still evolving. Teams can run the same Ackuity decision layer today with the Ackuity sidecar on any Kubernetes cluster.

Is Ackuity an NVIDIA partner for the Open Agent Safety Platform?

No. Ackuity is a member of NVIDIA Inception. The OpenShell integration is built by Ackuity on OpenShell’s published extension point and is not an NVIDIA product.

Does the integration need NVIDIA Sentry or NVIDIA hardware?

No. It connects to the OpenShell supervisor, and NVIDIA’s OpenShell repository states that no NVIDIA GPU is required. Sentry runs on BlueField-4 hardware, and integrating with it is a future direction that depends on NVIDIA’s partner interfaces.

What happens if Ackuity cannot be reached?

By default, OpenShell blocks traffic when a supervisor middleware service fails, according to NVIDIA’s documentation. Ackuity also lets you choose fail-open or fail-closed per policy.

Do we need to change agent code?

No. OpenShell already routes the agent’s traffic through the supervisor, and Ackuity attaches to the supervisor, not to the agent.

READ MORE

Our take on NVIDIA’s agent safety launch.

Sources: NVIDIA Open Agent Safety Platform announcement · NVIDIA OpenShell product page · OpenShell supervisor middleware documentation · NVIDIA OpenShell on GitHub. NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.

NEXT STEP

Running agents in OpenShell?

Tell us about your setup. We’ll share integration progress and show you the sidecar in the meantime.

Request access