New capabilities bring discovery, access control, and runtime protection to agents, MCP servers, and skills running on employee devices.
New York, September 28, 2026 /PRNewswire/ — Noma, an enterprise AI and agent security platform, today announced the expansion of endpoint agent security capabilities on its platform. Endpoints have become one of the largest blind spots in enterprise AI security; agents, MCP servers, and skills are already running on employees’ laptops, carrying the same permissions and credentials as the employees who installed them. Noma’s new capabilities discover agents, MCP servers, and skills running on employee devices, enforce access controls on their permitted actions, and leverage AI Detection and Response (AI-DR) to block dangerous behaviors at runtime. Now, policies and context can follow each agent as it moves across SaaS, custom-built, and endpoint environments, enabling security teams to manage their entire agent portfolio through a single control plane.
Developers use coding agents such as Claude Code, Cursor, Codex, and Windsurf to handle source code and production infrastructure. Business users rely on productivity agents like Claude Cowork to manage documents, browsers, SaaS applications, and internal data. MCP servers and skills extend this capability to databases, code repositories, and other systems. Agents can chain these operations together within a single session without requiring manual approval at each step—and this access already exists before any attacker could intervene.
This risk does not require exploiting a vulnerability. Noma said that a recent security researcher discovered that xAI’s Grok Build coding assistant uploads the entire tracked code repository along with its full Git history to the provider’s cloud, even when explicitly instructed not to open any files. Simply approving an agent is not enough. Security teams need a way to detect new agents as they emerge and enforce policies as these agents perform actions. Noma stated that its shared Runtime Context Engine unifies identity, permissions, policies, and behavior into a single signal.
Discovery and Governance
Terminal activities leave local traces in configuration files, skill directories, connector histories, and running processes. Noma integrates with existing EDR or MDM systems to transform these traces into a real-time inventory of agents, MCP servers, skills, and associated accounts on managed devices. Noma continuously assesses the risk of these assets, including the presence of keys in agent commands, unsandboxed execution, and excessive proxy capabilities.
This list integrates directly with Noma Access Control, transforming existing agents and tools on employee devices into governable assets. Access Control combines three capabilities:
- Governed Registry—Each agent, MCP server, and skill receives a defined status: Approved, Under Review, or Blocked; newly discovered assets are automatically added to the registry.
- Identity-Aware Policy — Noma assigns each agent to its underlying human user and links that identity with users and groups from an Identity Provider (IdP), enabling policies to be enforced at the user, group, tool, or organization-wide level.
- Tool- and Action-Level Control—Strategies can cover agents, MCP servers, skills, individual tools, and specific actions, allowing read permissions to remain broadly open while create, update, or delete operations are restricted to a smaller group.
Run-time protection via AI-DR
AI-DR is Noma’s runtime threat protection layer. It monitors the skills, MCP servers, and tools actually used by agents to establish a baseline of agent behavior and detects prompt injection, sensitive data leakage, malicious intent, tool poisoning, scope escalation, and deviations from an agent’s intended or defined behavior. Noma states that its Contextual Policies extend this protection across entire sessions, correlating prompts, tool calls, tool responses, data access, identity, and behavior over time. This enables Noma to identify threats that emerge gradually through a sequence of individually permitted actions. Each detector can be independently tuned to monitor, alert, guide, block, inline mask sensitive data, or escalate an action for human review. Protection must follow the agent beyond the laptop, as an approved database or API tool could turn a routine task into a large-scale deletion operation.
“The agents on endpoints carry some of the highest-privilege identities within the company, and security teams often don’t notice them until problems arise,” said Niv Braun, CEO and co-founder of Noma Security. “Extending our access control and AI-DR model to endpoints means security teams can gain the same level of visibility and enforcement on agents where they’re growing fastest—matching the capabilities they already have in SaaS and custom agent environments.”
Noma stated that Noma Open Enforcement can apply these policies to existing enterprise architectures, including agent hooks, AI and MCP gateways, SDKs, as well as EDR and MDM solutions, covering agents such as Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, and OpenClaw. The company says enterprises can begin deployment with hundreds of AI-DR policies and hardened configurations tuned by industry and agent type, reflecting its collaboration experience with security teams from dozens of Fortune 500 companies. Noma also plans to introduce Agent Boundaries to endpoints to enforce enterprise-defined business boundaries on agent behavior.
To learn more about how Noma protects endpoint agents, visit: https://noma.security/platform/endpoint-agents.
About Noma
Noma says the company is an AI and agent security platform built for enterprises. Noma detects behavioral threats, governs what actions agents are permitted to perform, and protects AI across the various environments in which agents operate—including custom applications built on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS agent platforms such as Microsoft Copilot Studio and Salesforce AgentForce; and pre-built agents like Claude Code, Cursor, and GitHub Copilot running on developers’ devices. Noma states that it has received backing from Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures, and SVCI, is widely adopted by Fortune 500 customers, and has been recognized by Gartner as a leader in the AI Trust, Risk, and Security Management (AI TRiSM) space.
Media contact
ICR for Noma
[email protected]
