NVIDIA’s New Agent Watchdog Can Quarantine an Agent. It Can’t Revoke Its Credentials.

NVIDIA Open Agent Safety Platform portnox

Schedule a Portnox Cloud demo today.

Contents

On Monday, NVIDIA announced its Open Agent Safety Platform, which pairs OpenShell (an open source sandboxed runtime) with Sentry, an out-of-band watchdog that runs on BlueField-4 DPUs and can quarantine an agent within milliseconds. If you haven’t run into DPUs before, think of one as a separate computer living on the network card that the host can’t tamper with. Given the number of agent-escape stories the frontier labs have published over the last few months, it’s easy to see why they built it, and putting enforcement somewhere the agent can’t reach is a sound idea.

My concern is more with how it’s going to be used. Containment is being positioned as the answer to agent risk, and the security industry has a habit of taking a reasonable control, leaning on it far harder than it was designed for, and calling it a day.

We’ve Over-Trusted Good Controls Before

Password rotation is the example everyone remembers. For the better part of two decades we forced 90-day changes and complexity rules on users, and what we got in return was a workforce that learned to go from Summer2023! to Fall2023!. NIST eventually walked it back in 800-63B, but plenty of organizations still enforce it because an auditor somewhere expects to see it. SMS MFA got a lot of organizations a checkmark on their cyber insurance questionnaire until SIM swapping and phishing proxies like Evilginx made it mostly decorative, and MAC filtering still shows up in wireless audits even though you can spoof a MAC address with one command.

Malware sandboxes went through the same cycle. Detonating suspicious samples in an isolated VM worked great until malware authors started checking for VM artifacts, sleeping past the analysis window, and generally behaving themselves whenever they suspected someone was watching. The labs have already published research on models that appear to recognize when they’re being evaluated, and in NVIDIA’s own testing, agents spent up to two hours trying to talk an AI reviewer into granting them write access to a protected repo (I’ve worked sales cycles with less persistence than that). Something that determined will probably figure out where the watchdog’s thresholds sit eventually.

An Agent With Valid Credentials Doesn’t Need to Escape

That said, evasion isn’t what worries me most. Containment watches behavior, and an agent holding valid credentials doesn’t need to behave badly to do damage. Agents operate through delegated access: an OAuth grant from whoever launched them, a service account, an API key someone pasted into an MCP server config. If a prompt-injected agent pulls your customer list through an approved Salesforce API call using a valid grant, what exactly is the watchdog supposed to flag? It’s an authorized identity doing something it’s authorized to do. The confused deputy problem has been around for decades, and watching the deputy more closely doesn’t do much good when the deputy is using real credentials. Quarantine doesn’t fix that either, because killing an agent’s runtime doesn’t revoke the OAuth grant it was using. The refresh token is still sitting in whatever platform issued it, and if someone lifted it, it still works. Unless your containment is wired into your IdP and kills the credential along with the process, you’ve stopped the agent and left the keys in the door.

Salesloft Drift is the obvious recent example. Attackers used OAuth tokens stolen from a chatbot integration to pull Salesforce data out of hundreds of companies last year, and nothing about it involved escaping a sandbox. Midnight Blizzard got into Microsoft’s corporate email via an old test OAuth app that had far more access than it ever needed. Agents are about to create a lot more identities like those, a lot faster than any access review process I’m aware of can keep up with.

Most Agents Won’t Live Anywhere Near a DPU

Sentry also needs specific hardware in your own data center, and most agents today live somewhere else: SaaS apps, developer laptops, browser extensions, some automation workflow marketing stood up with their own OAuth grant. I’ve seen what that kind of sprawl looks like when leadership blesses it. At my last operational job, we had an army of developers who’d basically been told to do whatever it took to get the job done (not far off from the “spend tokens at all costs” mandates a lot of companies have now). The result was shadow IT on a level I still haven’t seen matched: unsanctioned apps everywhere, production systems reachable from the outside (sometimes even with authentication), and entire racks of equipment we only found out about after they were already running.

My favorite was a company we’d recently acquired that had been breached, didn’t report it, and then “deleted” (yes, really) the entire environment where it happened. VMs, cloud compute, storage, containers, all of it, gone, along with any chance of a forensic investigation, and we never got to confirm the incident was actually over. Agents create a quieter version of that same problem. When one runs on a human’s OAuth grant, the logs say the human did it, and good luck separating the two in the middle of an incident once legal is involved.

Leadership said it was fine and security found out last, which is roughly how agent adoption is going at a lot of companies right now, except agents create access in minutes and don’t leave network cables behind for anyone to trip over.

Govern Agents Like the Identities They Are

Coming from the identity and access control side of the house, I’d posit the answer is less exciting than new technology. Agents are identities, and we already know how to govern identities; we just haven’t been great at actually doing it. That means an inventory and a named human owner for every agent, agents authenticating as themselves instead of borrowing their creator’s identity so the logs mean something, and access scoped to the task with an expiration attached so a stolen grant has a shelf life. Put them in access reviews with enough context that the reviewer isn’t guessing, and when the project wraps or the owner leaves, offboard the agent and revoke its grants at the source. Containment on top of all that is a perfectly good backstop.

If anyone has gotten agent ownership and revocation working at real scale, I’d like to hear how you pulled it off.

Share

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

Related Reading

Security TrendsZero Trust

Microsoft Just Proved the Passwordless Argument

September 28, 2026
Network Access ControlNetwork SecuritySecurity Trends

Visibility Isn’t Control

September 28, 2026
Network Access ControlNetwork SecurityPortnox Product Release

Your Firewall Doesn’t Know Who 10.1.45.112 Is

September 24, 2026

Portnox Closes the Gap on Shadow AI

X