Tool profile · Checked September 30, 2026
NVIDIA Open Agent Safety Platform: OpenShell vs Sentry
NVIDIA Open Agent Safety Platform is a software and reference-system approach to governing agent actions. OpenShell supplies runtime controls; Sentry adds a separate hardware watchdog. It is infrastructure, not an end-user assistant.
Source-based editorial profile. No account, model inference or paid workflow was tested.
Two layers with different jobs
OpenShell: runtime software
NVIDIA describes policy enforcement and action tracing for agents running on Vera CPUs, with open-source extensibility to third-party compute such as Arm and Intel. The OpenShell repository documents isolated sandboxes, kernel checks on file access and system calls, network policy checks, and credential injection for approved endpoints.
Sources: Nvidia · Openshell. Checked September 30, 2026.
Sentry: reference system design
The reference architecture uses BlueField-4 DPUs as an out-of-band watchdog. NVIDIA says Sentry can quarantine and stop a boundary-crossing agent in milliseconds. That is a vendor claim, not a response time measured by AI Tool Finder.
What is available now?
The September 28 announcement calls OpenShell broadly available and links software and skills through developer resources and GitHub. Treat Sentry as a reference-system design tied to the stated hardware route; the announcement does not establish immediate availability, pricing or an SLA for every complete deployment.
Sources: Nvidia. Checked September 30, 2026.
Inspect the OpenShell repository before choosing a supported environment. Third-party extensibility does not mean every processor and platform is already validated.
What to evaluate before adoption
Source-verified; not independently security-tested.
Start by writing the allowed files, destinations and actions for a single workload. In an isolated test, check permitted actions, blocked actions and the audit record. Then assess what happens if the agent process, policy service or monitoring path fails.
Runtime containment is only one part of an agent system. It does not establish that a model’s decisions are correct or that the configured permissions match your intent. We have not tested escape resistance, false positives, performance overhead or quarantine reliability.