Noma Extends Agent Security and Governance to the Employee Endpoint

noma-extends-agent-security-and-governance-to-the-employee-endpoint
Noma Extends Agent Security and Governance to the Employee Endpoint

New Capability Brings Discovery, Access Control, and Runtime Protection to Agents, MCP Servers, and Skills Running on Employee Machines

, /PRNewswire/ — Noma, the market-leading enterprise AI and agent security platform, today announced expanded endpoint agent security capabilities across the Noma Platform. The endpoint has become one of the largest blind spots in enterprise AI security; with agents, MCP servers, and skills already running on employee laptops carrying the same permissions and credentials as the people who installed them. Noma’s new capabilities discover the agents, MCP servers, and skills running on employee machines, enforce access control over what each is allowed to do, and use AI Detection and Response (AI-DR) to block dangerous behavior at runtime. Policy and context now follow each agent between SaaS, homegrown, and endpoint environments, giving security teams one control plane across the entire agent estate.

Developers use coding agents such as Claude Code, Cursor, Codex, and Windsurf to work with source code and production infrastructure. Business users rely on productivity agents such as Claude Cowork to work with documents, browsers, SaaS applications, and internal data. MCP servers and skills extend that reach into databases, repositories, and other systems. Agents can chain those actions together across a session without human approval at every step, and that access already exists before any attacker is ever involved.

The risk does not require an exploit. A security researcher recently found that xAI’s Grok Build coding assistant was uploading entire tracked repositories and their full Git history to the provider’s cloud, even after being explicitly instructed not to open any files. Approving an agent is not enough. Security teams need a way to find new agents as they arrive and enforce policy while those agents act. Noma’s shared Runtime Context Engine ties identity, permissions, policy, and behavior together into one signal.

Discovery and Governance
Endpoint activity leaves local evidence in configuration files, skills directories, connector history, and running processes. Noma connects through the EDR or MDM already in place to turn that evidence into a live inventory of agents, MCP servers, skills and connected accounts across managed devices.  Noma continuously assesses those assets for risks such as secrets in agent instructions, unsandboxed execution and excessive agency.

That inventory feeds directly into Noma Access Control, turning agents and tools already present on employee machines into governed assets. Access Control brings together three capabilities:

  • Governed Registry – Every agent, MCP server, and skill receives a clear status: approved, needs review, or blocked, with newly discovered assets entering the registry automatically.
  • Identity-Aware Policy – Noma attributes each agent to the human behind it and connects that identity to IdP users and groups, so policy can be enforced by user, group, tool, or organization-wide.
  • Tool- and Action-Level Control – Policies can govern the agent, MCP server, skill, individual tool, and action, so read access can stay broadly available while create, update, or delete operations remain limited to a smaller group.

Runtime Protection with AI-DR
AI-DR is Noma’s runtime threat protection layer. It monitors the skills, MCP servers, and tools agents actually use, establishes a baseline for agent behavior, and detects prompt injection, sensitive data leakage, malicious intent, tool poisoning, scope violations, and agents drifting from their intent or established behavior. Noma’s Contextual Policies extend that protection across full sessions, correlating prompts, tool calls, tool responses, data access, identity and behavior over time. This allows Noma to identify threats that develop across a sequence of otherwise permitted actions. Every detector is independently tunable to monitor, alert, steer, block, mask sensitive data inline, or route an action to a human. Coverage must follow the agent past the laptop, since an approved database or API tool can turn a routine task into mass deletion.

“Agents on the endpoint carry some of the most privileged identities in the company, often unnoticed by security until something goes wrong,” said Niv Braun, CEO and Co-Founder of Noma Security. “Extending our access control and AI-DR model to the endpoint means security teams get the same visibility and enforcement they already have across SaaS and homegrown agents, in the place agents are proliferating fastest.”

Noma Open Enforcement applies these policies across the architecture organizations already run, including agent hooks, AI and MCP gateways, SDKs, and EDR and MDM, with coverage spanning agents including Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, and OpenClaw. Organizations start with hundreds of AI-DR policies and protection profiles tuned by industry and agent type, reflecting work with dozens of Fortune 500 security teams. Noma also plans to bring Agent Boundaries, which enforce business-defined limits on agent actions, to the endpoint.

To learn more about how Noma secures agents at the endpoint, visit https://noma.security/platform/endpoint-agents.

About Noma
Noma is the AI and agent security platform purpose-built for the enterprise. Noma detects behavioral threats, governs what agents are allowed to do, and protects AI across every environment where agents run: homegrown applications built on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS agent platforms like Microsoft Copilot Studio and Salesforce AgentForce; and prebuilt agents like Claude Code, Cursor, and GitHub Copilot running on developer machines. Backed by Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures, and SVCI, Noma is widely adopted by Fortune 500 customers and has been recognized by Gartner as a leader in AI trust, risk, and security management (AI TRiSM). Learn more at https://noma.security and follow us on LinkedIn.

Media Contact 
ICR for Noma
[email protected]

SOURCE Noma Security