We Gave Our Agents Autonomy. Here's How We Kept Control.
SUSE, Monday, September 28th, 2026
SUSE explains how infrastructure controls, NVIDIA OpenShell sandboxing and egress proxies kept its autonomous SecOps agents in check.
SUSE argues that prompt and model safeguards only guide agent behavior, while infrastructure controls limit what agents can actually access and do.
Using SUSE AI Factory with NVIDIA and the NVIDIA Open Agent Safety Platform, NVIDIA OpenShell isolates agent execution in sandboxes, where SecOps agents investigate container vulnerabilities, prepare fixes and submit pull requests while humans keep approval authority.
SUSE reports that all agent egress went through out-of-process proxies, with zero direct git merges or Kubernetes API calls.