What happened
On Sept 28, 2026 Noma announced expanded endpoint agent security: it discovers agents, MCP servers and skills running on employee machines via the EDR/MDM already in place, feeds them into a governed registry with identity-aware, tool/action-level access control, and applies AI Detection and Response (AI-DR) to block prompt injection, data leakage, tool poisoning, scope violations and intent drift at runtime, with policy following agents across SaaS, homegrown and endpoint environments.
Why it matters
Endpoints are the biggest unmanaged blind spot for agent security — coding/productivity agents carry the employee's credentials and can chain actions without approval. Noma extends its existing SaaS+homegrown agent governance to laptops, giving security teams one runtime control plane across the whole agent estate instead of only governed platforms.
Applicability
Enterprise security teams adopting developer agents (Claude Code, Cursor, Codex) should evaluate Noma's endpoint module to close the shadow-agent gap on employee machines; plan pilot concurrently with MCP gateway/governance rollouts.