
OpenShell has also matured since its March debut. “When we launched in March, it was essentially single player,” Golshan said in a follow-up analyst Q&A. “With this release, it is fully multi-tenant.” He described the new release as a stable foundation with no breaking changes, adding, “It is ready for prime time.”
The second piece, Sentry, is the more strategically interesting one. It runs on BlueField-4 DPUs as an independent, out-of-band security domain. Because the DPU sits between the agent harness on the CPU and the model it calls, Sentry can monitor requests, responses, and chain-of-thought reasoning, and cut the agent off in milliseconds. Boitano compared it to the safety island in a self-driving car, an independent system that ensures the primary system fails safely. If a security testing agent starts reasoning about going beyond its approved target, he said, “Sentry can then detect this and intervene instantly.” Importantly, Sentry on BlueField adds an optional security layer for added protection. Boitano said OpenShell on CPUs is “honestly good enough” for most enterprise access control, with Sentry aimed at frontier work such as red teaming and evaluating models before they’ve been aligned.
The partner list is what gives this weight. According to Nvidia, Anthropic is integrating Claude Managed Agents with OpenShell and BlueField; Salesforce has connected OpenShell to Slack so teams can approve or reject agent permission requests; SAP is embedding it in Joule Studio; and SpaceXAI is using the platform for Cursor coding agents and Grok models. Citi and JPMorganChase are collaborating on the technology, and more than 100 organizations are working with it. “Safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, president of SpaceXAI, in the release. That sentence sums up the whole architecture.





















