DEV Community

Mikhail Savchenko
Mikhail Savchenko

Posted on Originally published at inite.ai

Anthropic Pairs Claude Agents With NVIDIA's OpenShell to Lock Down Credentials and Permissions

Anthropic has worked with NVIDIA on the newly announced Open Agent Safety Platform, adding security and control layers to Claude's agent stack as companies move from AI that answers questions to agents that act across business units with proprietary data.

Two pieces are involved. Claude Managed Agents, Anthropic's suite of composable APIs for building production-grade agents, now runs the agent loop on a server separate from the sandbox where work happens, and holds credentials — passwords and access keys — in a separate vault the agent never sees. It also logs audit trails of what each agent did and integrates with a company's existing access controls.

NVIDIA's OpenShell, open-source secure runtime software released under Apache 2.0, governs what an agent can reach while it works. It blocks every action unless a rule allows it, checking each tool call against rules on files, network connections and data, with every decision logged. A policy prover built into OpenShell uses mathematical proof to confirm what an agent can actually reach under the rules a team has written.

Anthropic frames the two systems as independent layers: each is designed to enforce its limits on its own, so protection doesn't rely on any single layer holding, and companies can adopt the pieces that fit their existing sandbox setup.

Managed Agents is available today and can run in a sandbox on a company's own infrastructure or with a managed provider. OpenShell is available now on GitHub and NVIDIA's developer resources page. Anthropic cites Notion, Rakuten and Asana as companies already running specialist and multi-agent workflows on Managed Agents, though details of OpenShell adoption by name are not given.

Top comments (0)