Better, Faster, More Cost-Effective – TENEX Leverages AI and Automation to Transform Security Operations

contact us

8586 Potter Park Dr.
Sarasota, FL 34238

Who Watches the Agents? NVIDIA OpenShell and the SOC

By Venkata Koppaka, Co-Founder and CTO, TENEX.ai

NVIDIA invited TENEX.ai to participate in the launch of the NVIDIA Open Agent Safety Platform. The part I’m particularly interested in is NVIDIA OpenShell, and how we might use it to put runtime boundaries around our own agents.

Setting boundaries for our own agents

Think about what a security agent actually does. It reads phishing emails, investigates suspicious URLs, and examines scripts someone may have written to compromise a system. It’s going to encounter malicious instructions. In some cases, understanding those instructions is the whole point of the investigation.

We need the agent to work with that material without letting the material change what the agent is allowed to do. Content screening helps, but we also need controls around the files it can access, the credentials it can use, and the destinations it can reach.

NVIDIA designed OpenShell to enforce those controls outside the agent, including controls over execution and inference. NVIDIA’s stated design is that the agent can’t override them even if it has been compromised. That’s what we want to evaluate for future TENEX.ai agents.

We already make a related distinction in our agentic Security Operations platform. A playbook can guide an investigation, and a model can conclude that an endpoint should be isolated. Whether the system is allowed to isolate that endpoint is a separate decision. Our response architecture checks policy when the action is about to execute, against the customer, target, operation, and applicable approval.

OpenShell could extend that approach into the runtime. That’s how I think about Fully-Agentic, Human-Led Security Operations: people shouldn’t have to approve every routine lookup, but they do need to decide what authority they’re delegating, when approval is required, and when the system should stop and ask for help.

Bringing agent activity into the SOC

There’s another part of this that matters for agentic Security Operations: the record of what the runtime allowed or denied.

Take an agent that’s supposed to summarize an internal document. It tries to send data to an unexpected destination, and the runtime blocks it. Good, the boundary held. But I’d still want to know why it tried.

Maybe the document contained an instruction that redirected the agent. Maybe a legitimate integration was configured incorrectly. Maybe the task itself wasn’t authorized. We’d need the task, the content it encountered, the identity it used, and the surrounding activity to work that out. Those explanations lead to different responses, from correcting a configuration to pausing the agent and investigating further.

I’d also want to look at allowed actions. An agent can have permission to use a credential and still use it for something unrelated to the job it was given.

That’s where I see the opportunity for TENEX.ai. We want to evaluate the boundaries around our own agents and understand how OpenShell’s allow/deny data could become useful evidence for the SOC. The runtime can prevent an action. The security team still has to understand what happened, whether anything else was affected, and what to do next.

Read NVIDIA’s announcement

Resources:

Keep Up with TENEX.AI

Press Releases and Company News

Who Watches the Agents? NVIDIA OpenShell and the SOC

By Venkata Koppaka, Co-Founder and CTO, TENEX.ai NVIDIA invited TENEX.ai to participate in the...

The Problem Was Never Network Detection: What TENEX and ExtraHop RevealX Deliver Together

The problem was never network detection. It was the distance between a good detection and a...

Eight Agentic Capabilities. One Continuous Security Operation.

Security teams have never had more tools or more distance between them. Alerts arrive in one...

Reviews

Perspectives from Those Who Know Us Best

Eric Foster
★★★★★
CEO of TENEX
"TENEX was founded to help enterprises overcome persistent security challenges by leveraging the scale and efficiency of modern cloud provider security stacks combined with AI-driven services. We aim to deliver exceptional outcomes with agility and cost-effectiveness."
Zane Lackey
★★★★★
General Partner, Andreessen Horowitz
"TENEX is tackling one of the most critical challenges in cybersecurity: the inefficiency of managing comprehensive security programs”
Iman Ghanizada
★★★★★
Godfather of Autonomic Security
"In an era where modern threat actors can bypass years of security controls in minutes, the industry needed a fundamentally different approach to security operations. Tenex represents the first true implementation of what autonomic defenses must look like in an AI-first world."
Elias "Lou" Manousos
★★★★★
Shield Cap
"At TENEX, we’re not just delivering another cybersecurity service—we’re redefining how security operates in an AI-driven world."
Zane Lackey
★★★★★
General Partner, Andreessen Horowitz
With their AI-driven, cloud-native platform and deep security expertise, TENEX is strongly positioned to deliver automated, scalable solutions that modern enterprise customers need. We are proud to support Eric Foster and the TENEX team as they redefine the way cybersecurity is delivered.
Chad Kreimendahl
★★★★★
CEO, Onspring
Imagine a cybersecurity partner that redefines industry standards. An AI-first approach that integrates seamlessly with your infrastructure, automating routine tasks and enabling your team to focus on strategic priorities. With advanced technology and expertise, we envision a future that sustains and enhances our operational excellence. That's what the team at Tenex has done for us, and what they can do for you.
#side-panel.side-panel .side-panel_sidebar {background-color: #070C1F;}