Noma Extends Agent Security and Governance to the Employee Endpoint
New Capability Brings Discovery, Access Control, and Runtime Protection to Agents, MCP Servers, and Skills Running on Employee Machines
Developers use coding agents such as
The risk does not require an exploit. A security researcher recently found that xAI's Grok Build coding assistant was uploading entire tracked repositories and their full Git history to the provider's cloud, even after being explicitly instructed not to open any files. Approving an agent is not enough. Security teams need a way to find new agents as they arrive and enforce policy while those agents act. Noma's shared Runtime Context Engine ties identity, permissions, policy, and behavior together into one signal.
Discovery and Governance
Endpoint activity leaves local evidence in configuration files, skills directories, connector history, and running processes. Noma connects through the EDR or MDM already in place to turn that evidence into a live inventory of agents, MCP servers, skills and connected accounts across managed devices. Noma continuously assesses those assets for risks such as secrets in agent instructions, unsandboxed execution and excessive agency.
That inventory feeds directly into Noma Access Control, turning agents and tools already present on employee machines into governed assets. Access Control brings together three capabilities:
- Governed Registry - Every agent, MCP server, and skill receives a clear status: approved, needs review, or blocked, with newly discovered assets entering the registry automatically.
- Identity-Aware Policy - Noma attributes each agent to the human behind it and connects that identity to IdP users and groups, so policy can be enforced by user, group, tool, or organization-wide.
- Tool- and Action-Level Control - Policies can govern the agent, MCP server, skill, individual tool, and action, so read access can stay broadly available while create, update, or delete operations remain limited to a smaller group.
Runtime Protection with AI-DR
AI-DR is Noma's runtime threat protection layer. It monitors the skills, MCP servers, and tools agents actually use, establishes a baseline for agent behavior, and detects prompt injection, sensitive data leakage, malicious intent, tool poisoning, scope violations, and agents drifting from their intent or established behavior. Noma's Contextual Policies extend that protection across full sessions, correlating prompts, tool calls, tool responses, data access, identity and behavior over time. This allows Noma to identify threats that develop across a sequence of otherwise permitted actions. Every detector is independently tunable to monitor, alert, steer, block, mask sensitive data inline, or route an action to a human. Coverage must follow the agent past the laptop, since an approved database or API tool can turn a routine task into mass deletion.
"Agents on the endpoint carry some of the most privileged identities in the company, often unnoticed by security until something goes wrong," said
Noma Open Enforcement applies these policies across the architecture organizations already run, including agent hooks, AI and MCP gateways, SDKs, and EDR and MDM, with coverage spanning agents including
To learn more about how Noma secures agents at the endpoint, visit https://noma.security/platform/endpoint-agents.
About Noma
Noma is the AI and agent security platform purpose-built for the enterprise. Noma detects behavioral threats, governs what agents are allowed to do, and protects AI across every environment where agents run: homegrown applications built on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS agent platforms like Microsoft Copilot Studio and Salesforce AgentForce; and prebuilt agents like Claude Code, Cursor, and GitHub Copilot running on developer machines. Backed by Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures, and SVCI, Noma is widely adopted by Fortune 500 customers and has been recognized by Gartner as a leader in AI trust, risk, and security management (AI TRiSM). Learn more at https://noma.security and follow us on LinkedIn.
Media Contact
ICR for Noma
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/noma-extends-agent-security-and-governance-to-the-employee-endpoint-302890925.html
SOURCE Noma Security
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Pulse PEMF Celebrates 20 Years of Innovation and Wellness Leadership with Milestone Promotion
- Lakewood-Amedex Biotherapeutics Announces Positive Data Against Recent Clinical Isolates from Infected Diabetic Foot Ulcers
- Project HEAL Announces 9 Virtual Events with 20+ Partners for HEAL Week
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share