- Agent Controls: Nvidia made OpenShell broadly available for organizations to limit AI-agent access; Sentry remains a hardware monitoring reference design.
- Runtime Rules: OpenShell confines agents to operator-set file, process and network permissions, enforced outside the agent’s own code.
- Partner Use: Cisco’s DefenseClaw security tool already integrates OpenShell’s agent limits; broader Hypershield network controls remain under development.
Nvidia has made OpenShell, software that limits what autonomous AI agents can reach on a computer or network, broadly available and unveiled a separate hardware monitoring design called Sentry. Organizations deploying agents can use OpenShell’s software boundary as of the September 28 launch; the extra chip-based layer remains a reference design. An operator could, for example, permit an agent to read from a service while blocking a write to that same service.
OpenShell Moves Beyond Preview
Nvidia’s Open Agent Safety Platform takes an existing runtime beyond preview. The March NemoClaw launch included OpenShell, which Nvidia later described as an early preview. Developers can now get its code and installation resources from a public repository.
An enterprise agent can run code, read files and call outside services to complete a task. OpenShell puts each agent in a sandbox governed by permissions set by its operator. The software’s gateway manages those sandboxes and their policies; a supervisor outside the agent’s workload checks outgoing requests, while operating-system controls restrict file access and processes inside the sandbox. A model instruction alone cannot change those enforced permissions.
Nvidia’s documented policy example shows a rule that permits a read request to the GitHub API but blocks a write request to the same service. The walkthrough uses a simple command rather than a model to make those requests; an agent in that sandbox would face the same policy check.
Network permissions can be changed while an agent is running after an approval. File and process restrictions are set when its sandbox starts, so changing those requires a new sandbox. For an organization running long-lived agents, that difference determines which access can be adjusted during a task and which calls for a fresh environment.
What the BlueField Layer Would Add
Sentry, the hardware monitoring design, would add a control point on a BlueField-4 chip isolated from the agent’s host processor. In Nvidia’s technical description, DOCA software records agent interactions and policy decisions, checks identity and applies access rules. Nvidia says the separate chip could quarantine an agent that crosses its boundary within milliseconds; no independent field measurement accompanies that claim.
The two layers also have different hardware needs. OpenShell runs as software on CPUs beyond Nvidia’s Vera processors, so organizations can use it without BlueField-4. Sentry’s chip-isolated monitoring depends on that hardware in Nvidia’s design.
Cisco says its DefenseClaw security tool already integrates OpenShell to limit an agent’s file, process, network and inference access. Cisco is still extending Hypershield, its wider network security system, to the Nvidia platform. A sandbox controls one agent’s environment, while an enterprise may also need controls where that agent’s requests reach other systems.


