Noma Brings Agent Security to Every Employee Endpoint
Noma provides a unified agent control plane across endpoint, SaaS and homegrown agents, giving security teams one place to discover what is running, govern what agents can access and do, and stop dangerous behavior at runtime. Today, Noma secures more than 2.6 million agents across enterprise customers, including deployments at some of the world’s largest companies.
We’re extending that coverage deeper into the employee endpoint, where coding and productivity agents are quickly becoming part of everyday work. Noma discovers the agents, MCP servers, and skills running on employee machines and brings them under the same Access Control, business boundaries, and AI-DR protections already used across the rest of the agent estate.
An agent may be running on an employee’s laptop, but much of what it does happens elsewhere. A coding agent can move between source code, databases, cloud infrastructure and SaaS applications using the identity and permission of the person behind it. That makes the endpoint one part of a much broader agent security problem.
Agents are already running across the business
Developers use Claude Code, Cursor, Codex, Windsurf, and other coding agents to work with source code and production infrastructure. Business users use tools such as Claude Cowork and other productivity agents to work with documents, browsers, SaaS applications, and internal data.
These agents inherit the permissions, credentials, browser sessions, and connected accounts of the people running them. MCP servers and skills extend that reach into databases, repositories, customer records, cloud services, and external systems. Agents can chain those actions together across a session without human approval at every step.

The risk does not require an exploit. With xAI’s Grok Build coding assistant, a security researcher found that Grok Build was uploading entire tracked repositories and their complete Git history to the provider’s cloud, even when the agent was explicitly instructed not to open any files. The tool had access to the repository before anyone had evaluated what it would do with that access. The Grok Build incident illustrates why approving an agent is not enough. Security teams need visibility into what an agent can access, what its connected tools and services can reach, where data can leave the environment, and how those capabilities are being used.
New agents and tools appear continuously. Security needs a way to find them as they arrive, define what they are allowed to do, and enforce those decisions while they act.
Bring endpoint agents into the same control plane
Noma extends its existing agent inventory to the endpoint, using the EDR or MDM already deployed across the organization to discover agents, MCP servers, skills, connectors and active processes. That endpoint telemetry becomes another source of context within Noma, alongside the SaaS and homegrown agents the platform already secures.
Endpoint activity leaves local evidence in configuration files, skills directories, connector history, and running processes. Noma turns that local state into a live inventory of agents, IDEs, MCP servers, skills, hooks, and connected accounts across managed devices.
That endpoint visibility becomes part of the same inventory Noma already uses across large enterprise agent estates. Noma continuously maps what each agent has access to and provides a risk assessment of AI assets: agents, MCP servers, skills, models, and tools. Security teams can see linked personal and enterprise accounts, along with posture risks such as secrets in agent instructions, unsandboxed execution, and excessive agency.
Permissions, Boundaries, and threat protection
That inventory becomes the foundation for enforcement. Noma connects identity, permissions, business policy, and behavior through three complementary controls: Access Control governs who can use which tools; Agent Boundaries keep authorized activity within business-defined limits; and AI-DR stops threats and dangerous behavior as they unfold. Each decision draws on the Runtime Context Engine and is applied through Open Enforcement wherever agents run.
One control plane, enforcement wherever agents run
A unified control plane only works if policy can follow agents across the different environments where they operate. Noma’s Open Enforcement architecture separates security policy from any single enforcement point.
The same Access Control, Boundaries, and AI-DR policies can be enforced through agent hooks, AI and MCP gateways, SDKs, direct APIs, and the endpoint infrastructure enterprises already use. Security teams do not need to force every agent through one architecture or deploy another endpoint sensor to maintain consistent control.
The Runtime Context Engine connects those enforcement points, carrying identity, session, tool, data and behavioral context across the agent’s activity.
Access Control governs permissions
Endpoint discovery feeds directly into Noma Access Control, turning the agents and tools already present on employee machines into governed assets. Security teams define the rules once and enforce them when an agent connects or acts.
- One governed registry. Every agent, MCP server, and skill receives a clear status: approved, needs review, or blocked. Newly discovered assets enter the registry automatically, giving security one place to review what employees are adopting and decide what belongs in the organization.
- Identity-aware policy. Noma attributes each agent to the human behind it and connects that identity to IdP users and groups. Policies can be enforced based on the user, group, or tool, or applied across the organization.
- Tool- and action-level control. Policies can govern the agent, MCP server, skill, individual tool, and action. Read access to one capability can be broadly available while create, update, or delete operations remain limited to a smaller group.
Noma Access Control gives security precise control over what every agent can do. Those policies are enforced at the moment of connection or action, using identity, group membership, tool sensitivity, and runtime context.

AI-DR stops dangerous behavior
AI-DR is Noma's runtime threat protection layer. It monitors the skills, MCP servers, and tools agents actually use, then establishes a baseline for agent behavior over time.
Agent threats often emerge through a sequence of legitimate-looking actions. AI-DR detects prompt injection, including encoded, obfuscated, and indirect injection through tool responses; sensitive data leakage involving PII, PCI data, and secrets; malicious intent; tool poisoning; scope violations; and agents drifting from their intent or established behavior. It also catches risky behavior caused by rogue agents, misinterpreted intent, and mistakes. These protections have been developed and tuned against activity in real enterprise environments, where agents interact with different identities, tools, data and systems across a session.
Contextual Policies extend that protection across full sessions. They correlate prompts, tool calls, tool responses, and reasoning with the data touched, tools used, source of tool responses, user identity, agent configuration, and behavior over time. This makes multi-step attacks visible, including indirect prompt injection followed later by secret exfiltration or sensitive data staged in a file before leaving the organization. This allows Noma to detect and stop threats that develop gradually over time, even when there isn’t a single obvious indicator of compromise. Noma’s Adaptive Context Retrieval learns an application’s traffic patterns to distinguish reusable context, such as system prompts, session history, and RAG context, from user-controlled input. This gives Noma’s detectors a clearer signal, improving detection while reducing false positives. Combined with session-level analysis, Noma can identify when individually legitimate actions build into dangerous behavior and intervene before they become an incident.
The Runtime Context Engine connects each action to the full session, the identity behind the agent, the data in reach, the potential blast radius, and the agent's baseline behavior. AI-DR uses that context to identify dangerous behavior as it develops. AI-DR uses that context to identify real risk with fewer false positives. Every detector is independently tunable to monitor, alert, steer, block, mask sensitive data inline, or route an action to a human.

Coming soon: Business boundaries to enforce organizational policy
Agent Boundaries enforce business-defined limits on how agents can act. They evaluate the content and context of an action at runtime, including the operation, data, target system, session, and identity behind the agent.
When an action crosses a Boundary, Noma can block it, mask sensitive data, route it for human approval, or update the agent’s access state. Boundaries use the same Runtime Context Engine and Open Enforcement architecture as Access Control and AI-DR.
Endpoint agent activity extends beyond the device
Endpoint agents can quickly extend their activity beyond the device. A coding agent asked to clean up outdated database tables used an approved Postgres MCP server to inspect the schema and begin removing tables, but the activity escalated into mass schema deletion. Noma maintains visibility, policy, and protection across the agent, MCP server, and systems it interacts with, so security coverage follows the agent wherever it operates.
Security teams shouldn’t have to standardize on a specific architecture just to enforce policy. Noma Open Enforcement works with agent hooks, AI and MCP gateways, SDKs, direct APIs, EDR and MDM. This lets teams enforce policy across the infrastructure they already use, while still being able to adopt new agents and frameworks as their environment changes.

Built for enterprise deployment
- Broad agent coverage. Cover coding and productivity agents including Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, and OpenClaw.
- Policies ready to use. Start with hundreds of AI-DR policies, benchmarks, and protection profiles tuned by industry, agent function, and agent type.
- Built from enterprise deployments. Protection profiles reflect work with dozens of Fortune 500 security teams.
Start at the endpoint. Secure the entire agent estate.
Endpoint agents are often one of the fastest ways to uncover how agentic AI is already spreading through the enterprise. But discovery on the endpoint is only the beginning.
Bring those agents into a unified inventory, govern what they can access, apply business boundaries, and protect their behavior with AI-DR. As agents move between the endpoints, SaaS applications, cloud infrastructure, and enterprise systems, the same policy and context follow them.
Secure the agents already running with Noma
Read how Noma covers the Claude Ecosystem.
Getting Started
Want to see it in action? Reach out for a demo.


.png)
