Every hosted agent runs in its own sandbox. Its workspace and available capabilities define where the work can happen.
NVIDIA OpenShell provides the hosted runtime boundary. Your agent uses the tools and connections configured for that environment.
Dedicated agent workspace
Runtime isolation
Explicit tool access
02 / Credential protection
Connect Accounts. Keep Secrets Out of Chat.
Use dedicated connection and credential controls to authorize your tools, instead of pasting passwords or API keys into a conversation.
Managed app connections use provider authorization. Custom credential slots use the platform’s encrypted storage and scoped access. How a secret is consumed depends on the integration.
Provider authorization
Encrypted credential storage
Scoped connections
03 / Human control
Give It Autonomy. Keep Your Say.
Configure which actions require a review. When approval is required, the agent pauses so you can inspect the request before it proceeds.
An app connection gives an agent access to available capabilities. It does not replace your approval policy or the permissions on the connected account.
Review before execution
Approve or reject
Permissions still apply
A FOUNDATION FOR ORGANIZATIONS
Control at Every Connection.
Connect Deliberately.
Authorize the accounts your agent needs. Granted scopes and provider permissions define the available access.
Make Review Part of the Work.
Use explicit workflow steps and approval policies where an action needs human judgment.
Build on a Hosted Foundation.
Microsoft Azure provides the cloud foundation. NVIDIA OpenShell provides the hosted agent runtime boundary.
A practical look at the controls around your agents.
Hosted agents run in dedicated sandbox environments using NVIDIA OpenShell. Workspace, installed capabilities, and connected accounts establish the agent’s working context.
No. Use app authorization and the credential settings for the relevant integration. Credentials belong in dedicated connection controls, not prompts, files, or conversation history.
Approval depends on the configured policy and action. You can review actions that require approval before they proceed. Provider permissions and account access continue to apply.
You authorize an account through the provider’s connection flow. Available actions depend on the integration, granted scopes, account permissions, and your organization’s configuration.
The hosted platform uses Microsoft Azure. NVIDIA OpenShell provides the agent runtime isolation layer. Ask our team about the requirements of your specific deployment.
Yes. Book a security walkthrough to discuss isolation, credential handling, app permissions, approval policies, and your organization’s requirements. Ask for current evidence for any compliance or contractual requirement.