
Meet the Authors
NVIDIA's Open Agent Safety Platform pairs the broadly available OpenShell runtime with Sentry, a reference design for hardware-isolated monitoring of AI agents.
SAP is embedding NVIDIA OpenShell in Joule Studio runtime, which decides whether an agent action should run before OpenShell governs how it executes.
Connections between OpenShell and SAP's authorization, IAM, and audit layers, along with FedRAMP and FIPS enablement, remain on the road map.
NVIDIA has launched a new security platform designed to put enforceable boundaries around AI agents as they take on more work across enterprise systems.
The Open Agent Safety Platform combines OpenShell, an open-source runtime that controls how agents execute tasks, with NVIDIA Sentry, a reference system design for independently monitoring and enforcing agent behavior. NVIDIA said OpenShell is now broadly available and that more than 100 organizations are working with technologies from the wider platform.
SAP is among them. The company is embedding OpenShell within Joule Studio runtime, part of SAP Business AI Platform, and contributing engineering work to the project as it develops controls for agents operating across business processes. SAP and NVIDIA are also working to connect OpenShell’s technical boundaries with enterprise authorization, identity and access management, and audit controls.
As companies give agents more authority to act, business permissions address only part of the security problem. An agent may be authorized to perform a task while still requiring limits on the actions, systems, and resources it can use to complete that work.
NVIDIA Moves Agent Security Outside the Agent
NVIDIA’s approach assumes that controls inside an AI model or agent application may not always be enough. The company pointed to recent security incidents in which agents circumvented application-level controls while pursuing assigned tasks. OpenShell instead creates a runtime boundary outside the model and agent harness, where policies can restrict how an agent interacts with systems and resources.
NVIDIA is proposing another layer through Sentry. The reference system design runs on BlueField-4 data processing units, creating an isolated environment for monitoring agent activity. NVIDIA says the design can quarantine an agent in milliseconds when it moves beyond permitted boundaries, verify agent identities, and enforce access policies covering data, tools, APIs, and services.
The architecture applies a familiar security principle to autonomous AI: enforcement should remain separate from the system being controlled.
OpenShell does not depend on the Sentry hardware architecture. The open-source software is available separately and provides a runtime boundary for constraining agent execution. NVIDIA says OpenShell is optimized for its Vera CPUs but can be extended to third-party compute platforms, including Arm and Intel.
SAP Is Building Business Controls Above OpenShell
SAP places OpenShell underneath a separate layer of business governance. Joule Studio runtime, SAP says, determines whether an action should execute using business authorization, role-based policies, and process context. OpenShell governs how execution occurs, including what an agent can see and do and where inference takes place.
That creates two control points: one for whether an action should happen, and one for how it is carried out.
SAP engineers are contributing code directly to OpenShell. Their work includes separating supervisory and agent-execution components so they can scale independently, along with Kubernetes deployment, private container registry support, storage configuration, health monitoring, and structured logging.
The companies are now working on the connection between those runtime controls and existing enterprise governance. SAP says that work includes enterprise authorization models, IAM frameworks, and audit trails, with FedRAMP, FIPS, and regulated-industry enablement also on the road map.
OpenShell is broadly available, and SAP is contributing to the project. The fuller integration between runtime isolation and SAP’s authorization, identity, and audit layers remains under development.
What This Means for SAPinsiders
- Treat agents as identities with execution boundaries. Review the roles and segregation of duties agents will inherit before runtime policies are layered on top. Cleaner authorizations give both control points a sound foundation.
- Assign ownership of agent policy limits. OpenShell adds controls over tools, systems, data, and execution that sit alongside business authorization. Naming owners now keeps those boundaries accountable as agent deployments grow.
- Plan audit evidence across both layers. SAP and NVIDIA are still connecting runtime isolation to enterprise IAM and audit trails. Deciding what evidence each layer must produce helps teams judge readiness when those integrations arrive.



