OpenShell explained: where an AI agent is allowed to act
An OpenShell adoption pilot with evidence and rollback
Turn the documented controls into a small reviewable operational report
What you will learn
- Freeze the artifact set
- Exercise a narrow agent
- Review and either expand or stop
Before you start
- One disposable workload and a supported compute runtime
- Authority to inspect policy and provider configuration
Turn the documented controls into a small reviewable operational report
Key takeaways
- Reproducible identity includes runtime and policy revisions.
- One passing denial is not a security certification.
- Credential revocation belongs in the rollback.
Freeze the artifact set
Record the source commit, stable release, gateway image, sandbox runtime, CLI and policy revision. Keep install and deployment manifests without secrets.
Use the support matrix for your platform. A pinned source commit is a research reference, not proof that a package manager installed the same code; record installed versions separately.
Exercise a narrow agent
Create one disposable sandbox, confirm the effective policy, then run a bounded task with no private inputs. Test one allowed and one denied destination and stop the supervisor connection in a controlled environment.
Store process logs, policy decisions, observable application state and teardown result. Treat a blocked request as evidence of that case only, not a universal security guarantee.
Review and either expand or stop
Ask a reviewer to sign off on each additional file path, network destination and provider. Keep a rollback that revokes credentials and removes the test sandbox.
The report template below is an EasyAI exercise, not a generated OpenShell artifact. Future releases may alter interfaces; repeat the boundary check after a runtime or policy-engine upgrade.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Pin and record both source and installed release artifacts.
- 2
Run one allowed and one denied task with retained evidence.
- 3
Review expansion and rehearse rollback before broader use.
Copy-ready example
{"source_commit":"71c3cd957abef062eb7f37010056717cd49f2ed3","installed_release":"record","driver":"record","policy_revision":"record","denied_egress":"not-run","credential_revocation":"not-run"}Frequently asked questions
Does OpenShell generate this full report automatically?
No. It is a suggested reader exercise combining records from the pilot.
When should I repeat the test?
After material runtime, provider or policy changes, and before broader deployment.
Sources
- OpenShell / README.mdSource checked 2026-10-04
- OpenShell / docs/about/architecture.mdxSource checked 2026-10-04
- OpenShell / docs/how-it-works/policies/default-policy.mdxSource checked 2026-10-04
- OpenShell / docs/about/support-matrix.mdxSource checked 2026-10-04