Open Agent Safety Platform: the power of defense in depth and how Ory fits in
Learn how NVIDIA Sentry, OpenShell, and Ory Agent Security enforce least-privilege security for AI agents across hardware, network, and harness layers.

Learn how NVIDIA Sentry, OpenShell, and Ory Agent Security enforce least-privilege security for AI agents across hardware, network, and harness layers.

The RSA Conference 2002 took place in San Jose in February 2002 and the Cryptographers’ Panel that year consisted of Whitfield Diffie, Ron Rivest, Adi Shamir, and Dan Geer, and was moderated by Bruce Schneier. I was in attendance.
Schneier asked each panelist to identify the most significant crypto/security event of the previous year. Whit Diffie chose 9/11. Diffie said that, in his view, the only responses that had actually improved airline safety were: “1) putting locks on the cockpit doors and 2) telling the passengers it was ok to fight.”
Moments later Shamir discussed 9/11 and argued that aviation security should learn from computer security; particularly regarding multiple lines of defense and “zone separation.” His example was specifically that passengers aren’t allowed in the cockpit, comparing that separation to isolating an operating system from its users.
It is from that day that I borrow the analogy…
Nobody at the airport thinks a locked cockpit door means we can skip the boarding pass.
Think about how many layers stand between you and the gate. Someone checks your ID and your boarding pass. Your bag goes through a scanner. Air traffic control watches every plane in the sky. And the cockpit door locks from the inside, where no passenger can reach it. None of those layers is perfect on its own. Together, they're why flying is so reliably, wonderfully boring.
This morning NVIDIA announced its Open Agent Safety Platform, and I read it with a big grin. It's the most visible argument yet for something I've believed my whole career: security works in layers. Agents don't change that. They just make it urgent.
It's been a year of agents coloring outside the lines. In April, a coding agent fixing a staging bug found an infrastructure token in an unrelated file and deleted a production database and its backups in a single API call. Over the summer, researchers at Pillar Security escaped the sandboxes of several major coding agents without ever attacking the sandbox itself. And OpenAI has been refreshingly open about its own test agents slipping out of research sandboxes to finish their tasks.
Here's the part that gets lost in the headlines: none of those agents were malicious. Each one chased its goal with more access than the job needed. And each one was caught, disclosed and fixed. That isn't a crisis, it's an engineering problem with known answers.
NVIDIA's answer has two parts. OpenShell is an open source runtime that sandboxes agents, traces what they do and enforces policy. Sentry runs on BlueField-4 DPUs, out of band, where it inspects agent traffic, verifies agent identity, enforces access policy and can quarantine an agent that breaks its boundary. The agent can't see Sentry, can't reach it and can't talk its way around it.
That's the cockpit door. And it's backed by more than 100 organizations and a new Open Secure AI Alliance under the Linux Foundation. That's not a product launch, it's a category growing up.
NVIDIA's VP of enterprise AI described the goal as giving an agent "enough authority to do its job and no more." I couldn't have said it better. That's the principle of least privilege, and it's the same principle Ory Agent Security is built on.
NVIDIA also makes a point I agree with completely: some control has to live where the agent can't touch it. A harness runs right next to the agent. When an agent can execute its own code, the harness sees the command it runs, not every step the script takes afterward. Silicon closes that gap.
So does that make the harness less important? Just the opposite.
Every layer has a vantage point, and every vantage point has a blind spot. Sentry sees requests and responses on the wire. What it doesn't see is the task the agent was handed, which user delegated it, or whether this particular call makes sense for this particular job.
The harness does. Ory Agent Security sits where the agent decides what to do next. Before a shell command runs, a file gets written or an MCP server gets called, we check that action against Ory Keto, the same permission system that already governs human access for our customers. The harness sees the task, the user, the delegation and the exact tool call… before any of it happens.
In airport terms, the harness is the gate agent checking your boarding pass. Silicon is the cockpit door. Nobody would pick one and skip the other.
Here's how I think about the full stack for agents:

Notice what every one of those layers needs: an answer to who this agent is and what it's allowed to do. At the airport, that's your boarding pass, and every checkpoint reads the same one. If each layer invents its own answer, you end up with four policies that disagree, and that's exactly where things slip through the cracks.
That shared answer is what Ory provides. Agent identities that are separate from the human's, scoped to the task, delegated on purpose and revocable the moment the job is done.
NVIDIA just helped lock the cockpit door. We make sure every boarding pass is real.
Lock the door. Check the pass. Then let the agents fly.