Guide · agent safety
Governing agents that run in OpenShell
NVIDIA OpenShell is an open-source sandbox runtime for AI agents: it limits which files an agent can touch, which binaries can reach which hosts, and which HTTP or MCP requests pass, and it logs what happened in OCSF. That is the runtime boundary. Governance is the layer around it: who owns the agent, which policy applies, who approves the actions a sandbox cannot decide, and what an auditor can sample afterwards.
What OpenShell enforces
An OpenShell sandbox policy is a YAML file (`version: 1`) with filesystem, process, network policy and network middleware sections. Network rules are deny-by-default: an endpoint is reachable only if a rule allows it, deny rules win over allow rules, and REST, GraphQL, WebSocket, MCP and JSON-RPC requests can be inspected and matched by method, path or tool name. Events are written as OCSF, and a full OCSF JSON export can be switched on for SIEM use.
What a sandbox does not decide
A sandbox answers “can this process reach that host with that request”. It does not hold an action until a named person approves it, keep a monthly spend cap, know which business owner answers for the agent, or produce the per-action decision record an auditor samples. Those are governance controls, and they sit outside any single runtime.
- Human approval before consequential actions
- Spend caps, merchant allow-lists and owner attestation
- An owner and an inventory across every runtime, not only sandboxed ones
- A decision record with its inputs and the rule that decided
One policy, two enforcement points
Agent Trust Cloud exports an agent’s egress policy as an OpenShell policy file using only the documented schema. Allow rules become OpenShell allow rules; deny rules become deny rules. Actions that need a person, or data that must be redacted, are written as OpenShell deny rules and the export report says so: those actions go through the Agent Trust Cloud gateway, where a person approves them or the data is redacted. The export is never weaker than the policy it came from.
Evidence from the sandbox
OpenShell’s OCSF JSONL export can be imported into the Agent Trust Cloud evidence ledger. Network and HTTP activity becomes allowed or denied action records, detection findings become behaviour anomalies, and configuration changes are kept as policy events — each with the sandbox, the process, the destination and the OpenShell rule that matched. Importing the same file twice records each event once.
Where this fits
Agent Trust Cloud is independent of NVIDIA and is not a partner, certified integration or endorsed product. The bridge reads and writes the file formats OpenShell documents, checked against its repository on 28 September 2026.