AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

Runtime boundaries for agents — NVIDIA OpenShell in Joule Studio

Runtime boundaries for agents — NVIDIA OpenShell in Joule Studio — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-04

What is Runtime boundaries for agents?

NVIDIA OpenShell is an open-source runtime that sandboxes agents with kernel-level isolation and declarative policy across filesystem, process, network and credentials; SAP is embedding it in Joule Studio below the business-authorisation layer. The links to SAP authorisation, IAM and audit trails were still under development on 28 September 2026, so reviewers must treat the audit story as incomplete.

The problem a runtime boundary solves

Content filters and prompts govern what an agent says. They do not govern what the agent process can touch. An agent that can write files, open network connections, install packages or call inference endpoints has a blast radius defined by its host, not by its instructions, and OWASP's 2026 ranking of LLM application risks moved Excessive Agency from sixth to third place on that realisation. The Five Eyes agencies' May 2026 guidance on careful adoption of agentic AI reaches the same conclusion from the defender's side: limit agents to what each task needs, use temporary credentials for sensitive actions, isolate where possible, and monitor internal processes rather than only inputs and outputs. A runtime boundary is the layer that makes those statements enforceable by something other than the model's good behaviour.

Why it matters

  • Content filters decide what an agent says; a runtime boundary decides what its process can reach, and OWASP's 2026 ranking moved Excessive Agency from sixth to third because that second question went unanswered in practice.
  • SAP's stack has three layers (content, business authorisation, execution) that fail differently, and a review that checks only one will miss the others.
  • The link between a blocked system call and the SAP business user and authorisation decision is still under development, so audit evidence has to be planned by the customer today.

Key points

  • OpenShell: open-source (Apache 2.0) runtime sandboxing autonomous agents with kernel-level isolation and a declarative YAML policy; upstream docs at the 0.1.x line.
  • Four enforcement domains upstream: filesystem (Landlock), process (seccomp, privilege drop), network (deny-by-default egress proxy), credentials/inference (placeholders, no provider by default).
  • Filesystem and process rules are fixed at sandbox creation; network and credential rules can be hot-reloaded.
  • Joule Studio's runtime asks 'should this action happen?'; OpenShell asks 'can it safely execute?' (SAP News, 28 Sep 2026).
  • Under development per SAP and SAPinsider: links to SAP authorisation, IAM and audit trails; FedRAMP, FIPS and regulated-industry enablement are on the committed roadmap.
  • Joule Studio runtime free for SAP customers and partners through October 2026; pricing afterwards not found as of 4 October 2026.
  • Complementary to Joule guardrails and orchestration filtering: those govern text in and out of a model, not what a process can reach.

Terms used on this page

OpenShell
NVIDIA's open-source secure runtime that sandboxes autonomous agents under declarative policy.
Landlock
Linux security module restricting filesystem access to declared paths.
seccomp
Linux mechanism that filters which system calls a process may make.
Egress deny-by-default
All outbound traffic is blocked except endpoints explicitly listed in policy.
Joule Studio runtime
SAP's enterprise harness for agents adding roles, skills, lifecycle and process context on top of OpenShell.
Excessive Agency
OWASP risk of an agent holding more capability or permission than its task needs; #3 in the 2026 ranking.
Open Agent Safety Platform
NVIDIA initiative announced with OpenShell's broad availability on 28 Sep 2026.

Sources

  1. SAP News — SAP and NVIDIA OpenShell: Working Toward Governance and Security for Auditable AI Agents (28 Sep 2026)
  2. SAP News — Shaping the Future of Secure AI Agents: How SAP and NVIDIA Are Co-Defining Enterprise-Grade Agent Execution (May 2026)
  3. SAPinsider — NVIDIA AI agent security: OpenShell and SAP Joule Studio (28 Sep 2026)
  4. NVIDIA Blog — NVIDIA and SAP Bring Trust to Specialized Agents
  5. IT Brief Australia — SAP, NVIDIA expand OpenShell for AI agent governance
  6. IT Brief UK — SAP, NVIDIA expand OpenShell for AI agent governance
  7. NVIDIA OpenShell documentation — Overview
  8. NVIDIA OpenShell documentation — Security best practices
  9. GitHub — NVIDIA/OpenShell (Apache 2.0, 0.1.x, requirements)
  10. SAPinsider — SAP Sapphire 2026: OpenShell embedded in Joule Studio, IAM and audit links under development
  11. Constellation Research — SAP Sapphire 2026: SAP makes its case
  12. MIT AI Agent Index — Joule Agents (built-in guardrails described only at high level)
  13. Mayer Brown — Multi-agency guidance on securing agentic AI systems (Five Eyes, 1 May 2026)
  14. Cloud Security Alliance — Five Eyes issue first joint agentic AI security guidance
  15. Cloud Security Alliance — OWASP 2026 LLM Top 10 and new Agent Control Standard
  16. SAP Architecture Center — Third-Party MCP Access to SAP Solutions (authentication, token exchange, governance)
  17. SAPinsider — SAP Business AI Platform: Build, Contextualize & Reason, Govern

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →