In this briefing
- 01Policy enforcement leaves the model and prompt
- 02Out-of-band hardware creates an optional second trust domain
- 03Cloud sandboxes adopt the same structure, while preview status still governs usability
- 04A credential broker keeps secrets out of the Agent environment
- →What to watch next
- ↗Sources and verification
- NVIDIA's new platform separates the OpenShell runtime from the optional Sentry/BlueField-4 out-of-band control layer. OpenShell can be deployed without BlueField-4, while Sentry is positioned as a reference system design outside the host. The vendor's millisecond quarantine claim has not been independently tested, and Sentry pricing, availability and a formal procurement date have not been disclosed.
- Baseten announced that Blaxel Carbon can host OpenShell, but Carbon remains in private preview and is rolling out progressively by region and workspace. Its snapshot and fork capabilities are also labelled private preview, and the official documentation explicitly says that they are not recommended for production.
- DigitalOcean keeps standing credentials outside the model and sandbox, with Action Gateway brokering them at execution time. Its policies are described as designed to fit the OpenShell schema. This shows a similar control structure entering cloud services, but does not establish mutual certification or a common standard.
Policy enforcement leaves the model and prompt
On 28 September, NVIDIA announced the Open Agent Safety Platform, describing an Agent safety architecture composed of the OpenShell open-source software and the Sentry reference system design. The official product page distinguishes model safeguards from runtime controls: prompts, model safeguards and Agent frameworks influence what a system attempts to do, whereas OpenShell enforces allow and deny rules outside the Agent process. OpenShell can run in supported local, on-premises, cloud and Kubernetes environments without BlueField-4, and supports open models, proprietary models and several Agent workflows. The repository nevertheless labels the Kubernetes deployment path experimental, with rough edges and breaking changes still possible.
The OpenShell repository uses the Apache-2.0 licence. The project says that kernel mechanisms constrain every file access, system call and network connection, while formal verification checks newly granted access before a policy change is applied. Real credentials are not exposed to the Agent and are added only to requests bound for approved endpoints. The stated support scope covers Linux, Apple Silicon macOS and Windows WSL2, which remains experimental; container or virtualisation paths include Docker, Podman and host virtualisation. Version v0.1.2, released the same day, also fixes the network supervisor, improves sandbox orphan-reaper performance and updates documentation.
For enterprise adoption, the security acceptance boundary expands from prompt rules to enforceable controls over files, processes, networks, tools and credentials. Whether a policy takes effect can therefore be recorded and inspected outside the model. These remain the project's published design and implementation claims: the public material provides no independent security audit, complete runtime-overhead data, false-positive rate or cross-sector production validation. Out-of-process enforcement cannot by itself be treated as proof that controls are impossible to bypass or that risk has been removed.
Out-of-band hardware creates an optional second trust domain
NVIDIA defines Sentry as a real-time watchdog running on a BlueField-4 DPU: it sits outside the Agent and host software, observes activity and enforces policy. NVIDIA says that an anomalous Agent can be quarantined within milliseconds, a vendor claim rather than an independently tested result. The product page also confirms that OpenShell can run without BlueField-4, so the software runtime and the out-of-band hardware control layer are distinct deployment states and should not be combined into one mandatory capability.
Arm's same-day account separates the compute required to run an Agent from the compute required to protect one. It says that BlueField-4 is powered by NVIDIA Grace with 64 Arm Neoverse V2 cores and provides an independent infrastructure environment beyond the host. Today's material does not specify the Sentry reference system's form factor, power consumption, memory capacity or bandwidth, price, supply, enterprise support level or formal procurement date. Nor does it provide time-to-first-token latency, throughput or concurrency figures; those model-serving metrics cannot be inferred from the core count or a control-plane description.
For enterprise adoption, an independent control plane offers an architectural route that may preserve monitoring and isolation even if a host or workload is compromised. It also extends safety assessment to the DPU, firmware, telemetry, attestation chain and incident handling. The present evidence establishes only the reference design and its layered relationship. Sentry cannot be described as newly available production hardware, and a partner's architectural account is not a third-party security benchmark. Software-only and hardware-enhanced deployments need separate availability and validation records.
Cloud sandboxes adopt the same structure, while preview status still governs usability
On the same day, Baseten announced as a launch partner that the latest generation of Blaxel sandbox can host OpenShell. Its Carbon infrastructure uses a microVM foundation and dedicated IPv6, while providing a wider kernel surface and runtime enforcement. Manual snapshot and fork operations preserve environment state and derive new runtime instances. Baseten says that there is a direct path from a snapshot to production within milliseconds, but this is a vendor statement; the public material does not disclose reproducible hardware, workload, concurrency or sample conditions.
Blaxel's documentation sets a stricter status boundary. Carbon remains in private preview, is rolling out progressively by region and workspace, and is not the default in every environment. It also does not yet offer Agent Drive, firewalling and dedicated egress IP together. Snapshot and fork are likewise labelled private preview, and the documentation explicitly says that they are not recommended for production. Feature existence, access to a preview and production suitability are three different conclusions.
For enterprise adoption, combining a policy runtime, an isolated sandbox and snapshot-based recovery can make task state and incident handling properties of the runtime foundation, rather than leaving recovery entirely to the Agent. Preview coverage, missing network and storage controls, snapshot consistency and recovery time will still determine whether the service can enter production acceptance. A vendor's millisecond path cannot replace stability and data-integrity evidence from the actual workload.
A credential broker keeps secrets out of the Agent environment
DigitalOcean published the credential architecture for Managed Agents on the same day. Each Agent runs in an isolated harness session, while the model, filesystem and sandbox hold no standing API key or token. When a task needs access to a controlled document, database or other system, Action Gateway brokers the request and uses the credential only at execution time. The gateway also handles renewed authorisation instead of passing a refresh token to the Agent. Each tool connection can additionally be bound to the particular actor on whose behalf the Agent is acting.
The same material describes zero-egress microVM firewall rules at the VPC level, a process identity fixed as non-root, default-deny rules for files and tools, and an audit record of allow/deny decisions. DigitalOcean's precise wording is that these permissions and network controls are designed to fit the open OpenShell policy schema; it does not claim OpenShell compatibility certification. Similar structures across platforms do not yet demonstrate that policy semantics, audit fields, credential lifecycles and revocation behaviour can move between providers without loss.
For enterprise adoption, credential brokering separates model-inference permissions, Agent identity and business-system authorisation into layers that can be constrained independently. It can reduce the opportunity for long-lived secrets to be exposed directly through prompts, memory or the working directory. The design still depends on the broker's identity mapping, scopes, refresh and revocation behaviour, log integrity and network path. An Agent being unable to see a secret also does not mean that an authorised tool call cannot create a business side effect or leak data. Interoperability and failure boundaries still need public evidence before cross-platform adoption can be inferred.
What to watch next
- Whether Sentry will disclose a formal procurement date, pricing and availability, together with independent attack testing and the complete conditions for policy-enforcement overhead, false-positive rates and quarantine latency.
- When Carbon will move from private preview to general availability and add Agent Drive, firewalling, dedicated egress IP and production-suitable guarantees for snapshot/fork.
- Whether OpenShell, cloud sandboxes and credential brokers can form portable specifications for policy, audit and credential lifecycles, rather than merely using similar architectural language.
Sources and verification
Golden Data has edited this briefing from the public materials listed above. The original sources govern facts and figures. The enterprise relevance sections are Golden Data editorial analysis and do not constitute an endorsement of any third-party product.
← Back to AI Daily Briefing