Skip to content

Anthropic Pairs Claude Agents With NVIDIA's OpenShell to Lock Down Credentials and Permissions

Short answer

Anthropic worked with NVIDIA to add security layers to Claude's agent stack. Claude Managed Agents now holds credentials in a separate vault the agent never sees, while NVIDIA's open-source OpenShell blocks every agent action unless explicitly allowed. Together they let companies log, restrict and verify what deployed agents can reach.

What this means for operators

For a 10-200 person company running Claude agents against CRM, support tickets or finance systems, this closes a real gap: until now, giving an agent broad tool access meant trusting the model itself not to misuse credentials. With Managed Agents separating the agent loop from the sandbox and vaulting credentials, and OpenShell enforcing a default-deny policy on every file, network call and data access, an operations lead can start an agent on narrow permissions, review the audit log, and widen access only where the log shows it's needed — turning agent rollout from a one-time trust decision into an auditable, reversible control process.

Anthropic has worked with NVIDIA on the newly announced Open Agent Safety Platform, adding security and control layers to Claude's agent stack as companies move from AI that answers questions to agents that act across business units with proprietary data.

Two pieces are involved. Claude Managed Agents, Anthropic's suite of composable APIs for building production-grade agents, now runs the agent loop on a server separate from the sandbox where work happens, and holds credentials — passwords and access keys — in a separate vault the agent never sees. It also logs audit trails of what each agent did and integrates with a company's existing access controls.

NVIDIA's OpenShell, open-source secure runtime software released under Apache 2.0, governs what an agent can reach while it works. It blocks every action unless a rule allows it, checking each tool call against rules on files, network connections and data, with every decision logged. A policy prover built into OpenShell uses mathematical proof to confirm what an agent can actually reach under the rules a team has written.

Anthropic frames the two systems as independent layers: each is designed to enforce its limits on its own, so protection doesn't rely on any single layer holding, and companies can adopt the pieces that fit their existing sandbox setup.

Managed Agents is available today and can run in a sandbox on a company's own infrastructure or with a managed provider. OpenShell is available now on GitHub and NVIDIA's developer resources page. Anthropic cites Notion, Rakuten and Asana as companies already running specialist and multi-agent workflows on Managed Agents, though details of OpenShell adoption by name are not given.

Source: Claude Blog · In the Atlas: Claude →

Next step

Discovery Sprint

If that argument holds for your operation, the next step is measuring it. Thirty minutes on one process, and we say whether the arithmetic is likely to close.

Put a time in the calendar

Thirty minutes, free. The sprint is what the call is about.

Fee
$2,500
Length
1-2 weeks

Ends in one of two answers: build this, or do not. The process map, the numbers and the ranked backlog are yours either way.