All posts

OpenShell keeps the agent inside the fence. ArtzAIn decides, and proves.

NVIDIA just published the Open Agent Safety Platform around OpenShell and optional Sentry.

That is a serious step on containment. Agents need a fence: clear limits on what they can reach, change, and use.

Containment is necessary. It is not the whole program.

When an agent is already inside the fence, Legal, Compliance, and the General Counsel still ask: was this move authorized as a decision under our rules, and can we prove it later?

ArtzAIn is built for that layer.

We are integrating OpenShell into ArtzAIn

CogNEXUS Labs is integrating NVIDIA OpenShell into ArtzAIn, the model-agnostic agent control plane. With artzain 0.6.32, that path is available to enable alongside OpenShell v0.1.2.

The fit is complementary, not competitive. OpenShell is the secure runtime. ArtzAIn sits beside it as Policy before / Proof after: team-specific rules checked before consequential actions run, then sealed into a record you can reconstruct later.

OpenShell keeps the agent inside the fence. ArtzAIn decides, and proves, which moves inside the fence were authorized as decisions.

You encode those rules once (SLAs, SOWs, customer contracts, discount empowerment, or the equivalent in your function). They travel with your agents, whichever model they use.

Evidence supports a governance program. It is not a certificate.

How the stack fits together

Think of three questions:

  1. What is the agent trying to do? That is the model and the harness.
  2. What is it allowed to reach? That is OpenShell: the sandbox and the runtime fence.
  3. Should this move proceed as a company decision, and can we prove it? That is ArtzAIn.

Before an OpenShell gateway commits a policy change, it asks ArtzAIn. Allow commits. Deny, review, or no answer leaves the sandbox unchanged. Fail-closed by design.

ArtzAIn holds the signed policy bundle (governance). OpenShell holds the runtime rules that enforce the fence. Neither replaces the other. ArtzAIn does not claim to prevent sandbox escapes, replace OpenShell or NeMo Guardrails, or depend on BlueField.

Today the OpenShell path covers sandbox create, policy update, draft approval, and provider attach. Agents never see the ArtzAIn key; OpenShell injects it only on the request path. You can run OpenClaw agents inside an OpenShell sandbox, governed end to end.

Deploy and use

On artzain 0.6.32 (or later), enable the OpenShell path as documented on the ArtzAIn product page. At a high level:

  1. Install or upgrade to artzain 0.6.32.
  2. Confirm OpenShell v0.1.2 is healthy for the reach you intend.
  3. Register ArtzAIn on the OpenShell gateway.
  4. Load team policy once.
  5. Test allow and deny or review, then export the sealed receipt.

Air-gapped and sovereign layouts are operator guidance for how you place the control plane and the runtime inside the same boundary, with telemetry off when you choose, not a separate GA product claim. Exact commands live in the product manuals, not here.

Where to learn more

Footnote: OpenShell v0.1.2 · artzain 0.6.32 · sandbox create, policy update, draft approval, provider attach.

Give your agents the authority to act

If you are evaluating OpenShell for containment, add decision proof to the same conversation. Fence and decide-and-prove are different controls. Enterprises need both.

Start at cognexuslabs.ai/artzain or app.cognexuslabs.ai.
Optional: hello@cognexuslabs.ai