Noma Extends Agent Security and Governance to Employee Endpoints
Noma has announced new capabilities to secure enterprise AI agents on employee computers. The expansion covers agent discovery, access control, and runtime protection.

NEW YORK – Noma, an enterprise AI and agent security platform, today announced expanded endpoint agent security capabilities.
The new features bring discovery, access control, and runtime protection to agents, MCP servers, and skills running on employee machines. Noma states that endpoints have become one of the largest blind spots in enterprise AI security, as agents and their associated servers and skills utilize the same permissions and credentials on employee computers as the users themselves.
Noma's new functionalities discover agents, servers, and skills operating on employee machines. They monitor and control their actions, and block malicious behavior in real-time using AI Detection and Response (AI-DR). Policies and context now follow agents across SaaS, homegrown, and endpoint environments, providing security teams with a single control plane for the entire agent estate.
The press release highlights risks that do not require exploitation. A security researcher recently found that a coding assistant uploaded entire repositories and their Git history to the provider's cloud, despite explicit instructions not to open files. Noma CEO Niv Braun stated that agents on the endpoint often hold the company's most privileged identities, frequently unnoticed by security until issues arise.
Noma's solution ties together identity, permissions, policy, and behavior into a single signal via the Runtime Context Engine. It creates a live inventory of agents, servers, and skills on managed devices by connecting to EDR or MDM solutions. The system continuously identifies and assesses risks such as secrets in instructions, unsanctioned execution, and excessive agency.