NVIDIA launches the Open Agent Safety Platform, pairing Anthropic's Claude Managed Agents with OpenShell for credential isolation and runtime policy enforcement
Synopsis
NVIDIA announced the Open Agent Safety Platform, an open software platform and reference system design, and collaborated with Anthropic to combine Claude Managed Agents with the open source NVIDIA OpenShell runtime: Managed Agents keeps the passwords and access keys an agent needs in a separate vault so the agent never sees them and adds audit trails plus integration with existing access controls, while OpenShell enforces policies outside the agent for every tool, file, network connection and data access, blocking everything unless a rule allows it and logging every decision it allows or blocks, so teams can start with narrow permissions, review the log, tighten rules toward least access with Claude, and use the policy prover to confirm by mathematical proof what the agent can reach under
Interpretation
Separating an agent's credentials from the agent itself: Managed Agents holds passwords and access keys in a separate vault, and the agent loop runs on a separate server from the sandbox, so the agent never sees the credentials. Previously, enterprise agent deployments often had to hand credentials to the agent to use; here credential custody and agent execution are split into two places, so an agent cannot directly read keys even if misused. The text describes this separation architecturally ("the agent loop runs on a separate server from the sandbox", "Credentials ... are held in a separate vault, so the agent never sees them"); it is a product design description without independent evaluation data.
Adding an independent runtime policy layer outside the model: the open source NVIDIA OpenShell blocks everything unless a rule allows it, checks each tool an agent tries to use, applies rules to the files, network connections and data the agent accesses, enforces rules outside the agent, and logs every decision it allows or blocks. Beyond safeguards inside the model, there is now an external constraint that does not depend on the model's own judgment, and each layer is designed to enforce its limits independently so protection does not depend on any single layer. The text describes OpenShell's rule behavior and logging, and states it is open source under the Apache 2.0 license on GitHub and NVIDIA's developer resources page; no third-party evaluation or attack testing is provided.
Making permission tightening an iterative process with verifiability: teams can start with narrow permissions, review the log, use Claude to tighten rules toward the least access a task needs, and then have OpenShell's policy prover use mathematical proof to confirm what the agent can reach under the rules the team wrote. Least privilege moves from a one-time configuration to a start-review-tighten-prove loop, and mathematical proof is introduced to confirm the rules' actual reachable scope. The text describes the process and the policy prover's purpose as a capability statement; it gives no data on proof scale, coverage, or false-positive behavior.
Describing enterprise usage shapes: Managed Agents provides secure sandboxing, authentication and tool execution, long-running sessions that operate autonomously for hours with progress and outputs persisting through disconnections, multi-agent orchestration where agents spin up and direct other agents to parallelize complex work, and governance with scoped permissions, identity management and execution tracing; Notion, Rakuten and Asana are named as users, with Rakuten's specialist agents across engineering, product, sales, marketing and finance each deployed within a week. It maps agent security and governance capabilities onto concrete enterprise workflows (shipping code, producing websites and presentations, cross-functional specialist agents, AI Teammates inside projects) rather than leaving them as an abstract capability list. The text presents these as customer cases without quantitative outcome metrics or comparison data; the deployment period "within a week" is the only time figure given.
Perspective
This offering targets enterprise teams connecting agents to real business systems: organizations whose agents use proprietary data, take actions on behalf of users and run across business units can deploy Managed Agents in a sandbox on their own infrastructure or with a managed provider, and adopt the modular layers that fit their setup. It suits teams that want to start with narrow permissions, review logs and tighten toward the least access a task needs, and confirm reachable scope with a policy prover; it also suits scenarios needing long-running sessions, multi-agent orchestration and execution tracing. The Notion, Rakuten and Asana cases in the text show such capabilities being used for shipping code, producing websites and presentations, cross-functional specialist agents and AI Teammates inside projects.
The text provides no independent evaluation, attack testing or quantitative comparison, so how effective each layer is under real adversarial conditions remains to be seen; the scale of rules the policy prover covers and how completely it confirms reachable scope, the auditability of logs under long-running sessions and multi-agent orchestration, and how quickly the least-access tightening loop converges in complex businesses are all open questions a reader can keep watching. In addition, the customer cases are largely qualitative, and apart from Rakuten's specialist agents being deployed "within a week" there are no other time or outcome figures, making it hard to judge performance in larger organizations.
