DigiCert Adds Verifiable AI Agent Identity to NVIDIA’s Safety Platform
The support starts with OpenShell, which limits what agents can do. DigiCert’s plans for signed audit records remain future work.
Loading page…
The support starts with OpenShell, which limits what agents can do. DigiCert’s plans for signed audit records remain future work.
Listen to this story
DigiCert’s support for NVIDIA’s Open Agent Safety Platform starts with OpenShell, linking an agent’s verified identity and accountable owner to rules enforced outside the agent’s process. The approach could help organizations verify credentials across company boundaries, but a passport does not grant access: each receiving organization must still apply its own policies. DigiCert describes signed action records and broader agent, model, and MCP-server scanning as future work; it provides no deployment results or timeline for those capabilities.
OpenShell runs agents in isolated environments, limits access to files, networks, tools, processes, and credentials, and records allowed or denied actions.
DigiCert’s AI Passport is a portable, cryptographically signed identity record; policy-based visas can specify permitted access and how long authority lasts.
DigiCert says prohibited actions can be blocked and may trigger authority revocation or quarantine under policies set by an owner or passport issuer.
An AI agent could carry proof of who owns it and what it is allowed to do, while a separate system checks its actions. DigiCert announced support for NVIDIA’s Open Agent Safety Platform on September 29, beginning with the OpenShell runtime. The aim is to connect an agent’s verifiable identity to rules enforced outside the agent itself.
OpenShell runs AI agents in isolated environments. An operator can set limits on the files, networks, tools, processes and credentials an agent may reach. OpenShell checks those limits as the agent works, with enforcement outside the agent’s process. It also records decisions to allow or deny actions.
DigiCert’s AI Trust Manager addresses a different question: which agent is making the request? DigiCert says the product helps organizations identify the agents they operate, connect each to an owner, define its authority and revoke that authority. In an OpenShell environment, the company says, a rule can use a verified agent identity instead of relying on a name in a configuration file. DigiCert says its support starts with OpenShell now.
“NVIDIA helps create the boundary around the agent. DigiCert helps establish who that agent is and what authority it has.”
Amit Sinha, DigiCert CEO, in the company’s announcement
DigiCert calls its agent credential an AI Passport. It is designed as a portable, cryptographically signed record of an agent’s identity and accountable owner. DigiCert also describes policy-based “visas” that specify which systems, data and actions the agent may access, and how long that authority lasts. An identity tells a receiving system who the agent claims to be; OpenShell’s operating rules still determine what the agent may do inside its boundary.
The cross-company use is central to DigiCert’s pitch. It says the passport and its permissions can travel with an agent, allowing another organization to verify them without using the same identity provider. That could help a receiving organization identify an outside agent, but a valid credential would not, by itself, grant that agent access. The receiving organization still has to apply its own rules.
DigiCert also describes an automated response when an agent attempts a prohibited action. It says the system can block the action and, under policies set by the agent’s owner or passport issuer, revoke the agent’s authority and quarantine it. That describes the company’s intended control; the announcement provides no customer deployment result showing how the response performs.
DigiCert lays out work beyond assigning passports. It describes signing and scanning agents, models and Model Context Protocol servers, which connect agents to tools or data. An AI Bill of Materials would identify what is being deployed before it runs. The company also says it will sign OpenShell’s record of allowed and denied actions and anchor that record to its cryptographic trust system. OpenShell already records those decisions; DigiCert presents its signed record as work still to come.
NVIDIA’s wider platform includes an optional Sentry layer, designed to monitor agents and enforce policy from separate BlueField hardware. That is distinct from DigiCert’s stated starting point, OpenShell. DigiCert says more capabilities are planned, but gives no schedule. The test for the partnership will be whether its portable credentials and future signed records can give organizations a useful account of an agent’s authority and actions across company boundaries.
Loading discussion...
Join the conversation
What would help you decide whether to grant it access?
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.