Compatibility · export and import · documented formats only
OpenShell policy bridge
NVIDIA OpenShell is an open-source sandbox runtime for AI agents. Agent Trust Cloud reads and writes two of its documented formats, so one policy governs agents in an OpenShell sandbox and at the Agent Trust Cloud gateway, and the sandbox’s logs become audit evidence.
What is supported
| Direction | Format | What happens |
|---|---|---|
| Export | OpenShell sandbox policy YAML, version: 1 | An agent’s filesystem paths, run-as user and network egress rules become an OpenShell policy file. Allow rules become allow rules, deny rules become deny rules, MCP tools become tools/call rules. The file is validated against the documented constraints before you get it. |
| Import | OpenShell OCSF JSON export (JSONL) | Network, HTTP, SSH and process events become allowed or denied action records; detection findings become behaviour anomalies; configuration changes become policy events. Each keeps its sandbox, process, destination and matched OpenShell rule, and importing the same file twice records each event once. |
Where the models differ
OpenShell has no “hold for a person” and documents no redaction settings for this case, so actions that need approval and data that must be redacted are exported as OpenShell deny rules, and the export says so. Those actions go through the Agent Trust Cloud gateway instead. The export is never weaker than the policy it came from.
Export a policy
Edit the example or paste your own. Converted in your browser.
Preview an OCSF import
Paste lines from an openshell-ocsf.YYYY-MM-DD.log file. In a workspace the same parser writes them to the evidence ledger; here it only shows what would be recorded.
Sources and status
Formats checked against the OpenShell repository on 2026-09-28. Agent Trust Cloud is independent of NVIDIA and is not a partner, certified integration or endorsed product; OpenShell and NVIDIA are named only to describe file compatibility.
Read more: governing agents that run in OpenShell.