OpenShift is becoming the meeting point for four agent-security control planes
IBM and NVIDIA split agent governance across identity, credentials, runtime policy and infrastructure enforcement, leaving platform teams to assemble the operating model.
IBM’s support for NVIDIA’s Open Agent Safety Platform is not one new security control plane. It is a proposed stack of distinct control planes that meet around agents running on Red Hat OpenShift.
That distinction matters for platform teams. The announcement assigns identity, credentials, runtime policy, infrastructure enforcement and workload placement to different components. The useful question is therefore not whether the stack is “secure,” but which system owns each decision and which integrations are available now.
Four planes, four jobs
Delegated identity and credentials. IBM says Agent Identity and HashiCorp Vault now integrate with NVIDIA OpenShell. Agent Identity, currently in public preview, is meant to establish who an agent is, what authority a human delegated to it and what it may access. Vault supplies the credential and secret-management layer. This is the authorization context that should follow an agent into execution; it is not the runtime that enforces every action.
Inventory and monitoring. IBM Identity Protection is the discovery plane. IBM positions it as the place for security teams to find and monitor agents, including unregistered or “shadow” agents. That makes it an oversight system rather than the component that grants workload credentials.
Runtime policy. NVIDIA OpenShell provides the software boundary around execution. NVIDIA says the open-source runtime traces actions and enforces policy outside the model and agent harness. It is the first enforcement point when an agent reaches for data, tools, APIs or services.
Infrastructure enforcement. NVIDIA Sentry moves a second enforcement point below the host. The reference design runs an out-of-band watchdog on BlueField-4 DPUs, using DOCA to verify identity, apply granular access policies and produce attested telemetry. NVIDIA says Sentry can quarantine an agent that crosses its boundary in milliseconds, independently of the host workload.
OpenShift supplies the placement and operations layer across hybrid environments. NVIDIA says Red Hat runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA; IBM describes OpenShift as the platform for governed agents and says Red Hat is working with NVIDIA on BlueField and OpenShell integration. IBM Fusion adds a separate data-infrastructure track: IBM says it is integrating BlueField-4 at the hardware level to protect data agents access.
What changes for OpenShift teams
The immediate change is architectural, not a single product switch. Platform teams now have a named division of responsibility: identity and delegation in IBM Agent Identity, secrets in Vault, execution policy in OpenShell, host-independent enforcement in Sentry and workload operations in OpenShift.
That division also exposes the unfinished work. IBM Agent Identity is still in public preview, while IBM describes the Fusion and Red Hat integrations as work in progress. The announcements do not provide one policy model, one audit schema or one generally available OpenShift installation path spanning all four planes.
Teams evaluating the stack should therefore demand concrete answers before treating it as a unified control plane: how an agent identity maps to an OpenShift workload identity; which system is authoritative when Vault, OpenShell and Sentry policies disagree; where attested telemetry is retained; and how emergency revocation propagates across layers.
The direction is clear: agent governance is moving outside prompts and into infrastructure. The operational contract between these products is less clear—and that contract is the part OpenShift platform teams will eventually have to run.
sources
- IBM: Building Trust Into the Next Generation of AI Agentsnewsroom.ibm.com
- NVIDIA launches Open Agent Safety Platformnvidianews.nvidia.com
comments · 0