
Today we’re launching a new way to secure your AI workforce that interacts with employees - by putting a human owner behind every agent. Agent Intent & Posture Management (AIPM) connects discovered agents to employee owners, documents each agent’s stated purpose, and guides risk remediation.
Amplifier was founded on one belief: employees should be part of the defense, not just the source of risk.
Until now we applied that belief to endpoint devices. Every laptop mapped to an employee. Every endpoint security finding routed to the person accountable for it. Every fix verified and proven. That is Endpoint Security Posture Management (ESPM): EDR detects and responds, ESPM identifies and protects, and neither substitutes for the other. The architecture underneath ESPM is asset attribution plus engagement: find the object, find the human owner, orchestrate the issue resolution through them. For endpoint devices, that architecture made security better.
For the AI agents employees build and use, attribution and engagement are not a better approach. They are the only approach that finishes the job. That is what we shipped into private preview today.
Employees stopped carrying risk. They started creating infrastructure.
Every AI agent an employee spins up is something that employee personally authored. IT never provisioned it. Security never approved it. No record explains why it exists. The agent holds credentials, permissions, and access, and the reason it holds them lives in exactly one place: the employee’s head.
This breaks the remediation model the industry spent twenty years perfecting. Malware has one right answer, and automation knows it. A missing patch has one right answer, and a machine can apply it. Off-the-shelf software behaves the same way on every device, so policy gets written once and enforced everywhere.
Employee-built agents are different in kind. Every finding is a question before it is a fix. Does this OAuth grant still serve a purpose? Is this dormant token attached to a live agent? Is this MCP server sanctioned, or one typo away from a supply chain attack? No scanner reads intent. No admin knows the answer. Guessing wrong breaks real work, and tools that break real work get turned off.
The risk mix inverts accordingly. Endpoint risk was mostly attack with a hygiene tail, and machines won the attack side decisively. Agent risk runs the other way: mostly hygiene, with an attack tail. That tail is a speed problem, and it belongs to inline runtime vendors and the platforms. The body is an intent problem, and intent is reachable only through the person who built the agent. The market is crowding into the tail.
The center of gravity moved to the endpoint
For the last two years, enterprise AI governance was built on a data-center mental model: agents running in Bedrock, Vertex, Azure AI Foundry, or a company’s own cloud, with security teams watching model endpoints and API traffic.
What security leaders have told us over the past couple of quarters is something else. The agents keeping them up at night run in browsers, IDEs, and desktop apps that employees installed themselves. They live on the endpoint, largely invisible to tools built to watch cloud-hosted AI. Agentic AI moved quietly from managed cloud infrastructure to unmanaged endpoints.
That is why endpoint posture is the foundation for this work rather than a neighboring product. If agents run on employee desktops, the security posture of those desktops is the ground everything else stands on. Agent Intent & Posture Management (AIPM) is the next layer up, on the same graph, reaching the same person.
A human stays in the loop, and there is no better human than the one who created the agent.
Detection has arrived. Disposition has not.
Over the past three quarters, nearly every major security platform began firing AI agent events: CrowdStrike Falcon AIDR, Jamf AI Governance, Okta ISPM and agent discovery, Microsoft Purview and Entra Agent ID, with more arriving each month.
This is good news, and we are glad to see it. Each of these vendors sees a real slice. Jamf sees agents on managed Macs, Okta sees OAuth grants, Microsoft sees the Copilot ecosystem, CrowdStrike sees its sensor fleet. No enterprise runs only one of them, and no single console was built to hold a competitor’s telemetry.
So we do both. We ingest those feeds from the tools you already run, and we discover agents ourselves on the endpoint, because no single source sees the whole footprint. Building that took real engineering. Getting to a usable agent inventory is hard work, but it is tractable work, and a machine can finish it.
What no event firehose can finish, including ours, is the question of what the agent was created to accomplish. None of them close a finding through the person who created it.
What we shipped
Security leaders ask us four questions about agents.
Who is accountable for an agent, and what is its intent?
This is access reviews, but for agents. Device attribution answered one question: whose is this? Agent attribution has to answer two: whose is this, and why does it exist? Discovery finds the agent. Behavioral monitoring shows what it touched. Risk modeling scores the exposure. Not one of them can tell you whether the agent should exist at all, because that fact was never written down anywhere a machine can read. Answering this question is only possible through human interaction with the agent's owner.
What agents do we have?
Most organizations have a partial picture of their agentic footprint at best. Amplifier discovers AI agents from existing agentic AI platforms and on the endpoint, where most employee-built agents run. Discovery requires no reconfiguration or instrumentation of your existing agents. No manual inputs. No stale snapshots. Every agent we find, first-party on the endpoint or ingested from a connected tool, resolves to a single record in the Workforce Security Graph, correlated across identity grants, endpoint telemetry, and provider inventories, and joined to a human owner.
What are the agents actually doing?
Amplifier monitors agent activity and ingests behavioral signals from your connected tools. Baselining and anomaly detection build a profile of how each agent normally operates and flag when something falls outside it. One boundary matters here, and we state it the same way on a blog as we do in a security questionnaire: we monitor that activity to catch drift from what the owner declared, and we do not store it for retrieval later. We keep the decisions, not the activity log.
What risk does this create?
Amplifier’s risk modeling, enriched with third-party threat intelligence, gives you a view of both operational and compliance risk. Findings map to the security and AI standards you report against, including NIST AI RMF and ISO/IEC 42001 lifecycle controls. That is alignment, not certification, and it is what turns a pile of findings into a queue you can work in order.
The process loop remains unchanged, it's simply pointed at a new entity.
Engage.
Ampy, the AI Security Engineer, reaches the owner in Slack or Teams with one question and one tap: keep, scope down, investigate, remediate, or retire. Consent where intent is required, automation where it is not, escalation clocks on silence. Conversations run in parallel across hundreds of agents, not one owner at a time.
Act.
Execute through levers that already exist. Revoke or rescope grants through Google Workspace, Microsoft Graph, and Okta APIs. Retire credentials through provider admin APIs. Retire agents through Claude, OpenAI, Copilot, and platform registries. Sweep local debris through existing MDM script delivery. No new endpoint software required. Your security team decides. We orchestrate the decision.
Prove.
Hand the CISO what a detection feed cannot produce: a validated agent inventory. Not “347 agents detected,” but a report shaped like this: 289 validated with a stated business purpose, 41 scoped down, 17 retired, each one owner-attested and timestamped. The record survives the credential, which is what an auditor asks for a year later.
An owner’s attested answer compounds into something a feed cannot replicate: attestation history, exception log, recertification dates, and behavioral trends per employee.
What we don't do
We monitor what agent behavior. We do not sit in the path of what they do.
Prompt injection defense, inline blocking, and DLP on agent traffic are machine-speed problems in the request path, and they belong to the platforms and the inline vendors. We observe, baseline, and flag. We do not intercept.
Say that plainly, and the gap it leaves is easy to see. Credentials expire. Inline blocks stop an attack in progress. Neither one answers what the agent was supposed to be doing, who said so, or which controls its actual use requires.
That answer is the part we built.
What it looks like to the employee
Why ask before you control? Because the only reliable source of intent is the person who wrote the agent. So we ask. We do not propose a purpose and invite a nod. In practice, that is a short exchange:
“Is this an AI agent you created, and can we attribute you as its owner?”
“You created this agent. What is it for?”
“This agent can still read your entire Google Drive but only uses one folder. Scope it down, revoke it, or keep it?”
“This agent uses a component linked to a known threat. Restrict, investigate, or retire it?”
“Three agents you set up aren’t running anymore but still hold live credentials. Retire all three?”
Here is an over-scoped grant getting closed. Only the owner could have made that call, because only the owner knew what still mattered. Note which option got taken: scope down, not revoke. The alternative stack offers one verb, and using it trades a security finding for a broken weekly report.

The same loop cleans up what agents leave behind on the endpoint: unapproved binaries, malicious hashes in skill files, and the supply chain debris that scanners flag and nobody dispositions.
One thing we are not doing: tracking your employees’ activities. We monitor the agent’s scope and observed behavior against its declared purpose. The employee’s experience of AIPM is a question in Slack about something they built.
What changes after
There is a second-order effect we did not fully expect, and it may end up mattering more than the findings themselves.
When employees learn their agents are visible, and that someone will ask them about each one, sprawl behavior changes before findings ever fire. Silent cleanup mows a lawn that regrows every week. Asking the person who planted it is the only mechanism we have found that slows the growth.
Today’s workforce is no longer just people and their laptops. It is people and the agents they build, connect, and forget. Securing that workforce starts the same way securing the last one did: find the person accountable, ask them a question worth answering, and keep the answer.
See it on your own agents
AIPM is in private preview as part of the Agentic Workforce Security Platform [STUB: replace with live link]. If employee-built agents are outpacing your governance, request an evaluation [STUB: replace with live link]. Bring one named security stakeholder and a scoped set of agent environments, and we will show you what we find, who owns it, and what they decide.
Related: [STUB: replace before publish] Amplifier Extends Workforce Security to the AI Agents Employees Build
Frequently asked questions
Does Amplifier read or store what our employees’ agents do?
No. Amplifier monitors agent activity to catch drift from what the owner declared as the agent’s purpose. It does not store prompts, responses, or tool calls for retrieval later. What persists is the governance record: ownership, purpose, reviews, decisions, remediation, and retirement. In short, we keep the decisions, not the activity log.
Does AIPM replace our identity, endpoint, or GRC tools?
No. Identity and NHI tools still handle credentials and revocation. Cloud and endpoint tools still observe runtime activity and can block inline. GRC and audit tools still capture point-in-time attestations. AIPM connects what those tools already surface to a confirmed owner, a declared purpose, and one lifecycle record, and orchestrates the action your security team chooses. Amplifier ingests and acts; it does not detect, scan, or enforce inline.
Is AIPM generally available today?
AIPM is in private preview as part of the Agentic Workforce Security Platform. Organizations that want to see it against their own environment can request an evaluation, bringing one named security stakeholder and a scoped set of agent environments.
Latest Blogs
Related Blogs & News
Watch



