Amplifier Extends Workforce Security to the AI Agents Employees Build and Use

Amplifier Extends Workforce Security to the AI Agents Employees Build and Use

Agent Intent & Posture Management connects discovered agents to employee owners, documents each agent’s stated purpose, and guides risk remediation.

Sep. 17, 2026

Amplifier Extends Workforce Security to the AI Agents Employees Build and Use

Agent Intent & Posture Management connects discovered agents to employee owners, documents each agent’s stated purpose, and guides risk remediation.

Sep. 17, 2026

ATLANTA, GA: Amplifier Security today announced Agent Intent & Posture Management (AIPM), extending the Amplifier Workforce Security Platform to the AI agents employees create for themselves. AIPM asks employees to confirm what their agents are for and records their answers, giving IT and security teams business context to decide which agents to keep, restrict, or retire, and to act on those decisions.

Cloud Security Alliance research found that 82% of organizations surveyed discovered agents or workflows previously unknown to their security or IT teams within the preceding year. Employees are creating agents through copilots, low-code studios, and SaaS-native builders faster than security teams can establish what exists, why it exists, and who owns it. Each can hold credentials, permissions, and a path to company data without a provisioning request, security review, or record of purpose.

Identity and endpoint tools such as Okta, CrowdStrike, and Jamf reveal what an agent can access and how it behaves. Restricting or retiring it takes something those tools can't supply: its owner-declared purpose, the work that depends on it, and the access that work requires.

Unlike malware or a missing patch, agent findings require business context that lives with the employee who built the agent. Gathering it one employee at a time does not scale. The blunt alternative is bulk revocation. It closes the finding but disrupts the work behind it, such as weekly finance reports or support replies.

“Finding an agent is the start. Security teams need to reduce risk while preserving the productivity employees gain from agents,” said Shreyas Sadalgi, co-founder and CEO of Amplifier Security. “We ask employees for business context only they can provide. Security teams decide what access is appropriate, we orchestrate the action they choose, and we record both to support AI governance.”

AIPM guides teams through six steps:

  1. Discover and confirm ownership. AIPM discovers agents directly on endpoints and ingests agent discoveries from other integrated security tools. It then connects these findings to employee owners for confirmation.

  2. Validate intent. AIPM asks each owner what the agent is for and records the answer rather than inferring purpose from metadata or behavior.

  3. Enrich risk. External threat intelligence adds known risk indicators to agent findings, helping security teams prioritize further review.

  4. Assess access and behavior. AIPM compares permissions and connected behavioral signals with owner-declared intent to surface excessive access, drift, and conditions that need review.

  5. Engage and act. AIPM gathers owner input through Slack or Microsoft Teams. Security teams decide whether to keep, scope down, investigate, remediate, or retire an agent, and AIPM orchestrates the resulting actions. Owner conversations run in parallel to reduce manual follow-up.

  6. Record decisions and actions. AIPM records ownership, purpose, reviews, decisions, remediation, and retirement actions, giving security teams a lifecycle record for each agent.

When an agent’s permissions exceed its stated purpose, AIPM asks the owner what access the work requires, helping security teams determine which permissions to remove. AIPM records the security team’s decision and orchestrates the corresponding actions.

“Discovering agents on employee endpoints helps security teams understand how employees use them. Connecting those discoveries to their owners adds purpose and accountability. That is the strength of workforce security: connecting the employee, endpoint, and agent to inform decisions about access and risk,” said Bradley J. Schaufenbuel, CISO at a leading provider of integrated human capital management solutions.

“Knowing an agent exists doesn’t tell me whether the person who built it still needs it. Getting that answer from the owner, in writing, is the difference between a list and a program I can report on,” said Ravi Nori, CISO at Gopuff.

AIPM complements existing identity, endpoint, cloud, runtime, GRC, and audit tools by connecting their findings to owner-declared purpose, a human decision, and a defensible record. 

AIPM is now available in private preview. To request an evaluation, visit amplifiersecurity.com/demo.


ATLANTA, GA: Amplifier Security today announced Agent Intent & Posture Management (AIPM), extending the Amplifier Workforce Security Platform to the AI agents employees create for themselves. AIPM asks employees to confirm what their agents are for and records their answers, giving IT and security teams business context to decide which agents to keep, restrict, or retire, and to act on those decisions.

Cloud Security Alliance research found that 82% of organizations surveyed discovered agents or workflows previously unknown to their security or IT teams within the preceding year. Employees are creating agents through copilots, low-code studios, and SaaS-native builders faster than security teams can establish what exists, why it exists, and who owns it. Each can hold credentials, permissions, and a path to company data without a provisioning request, security review, or record of purpose.

Identity and endpoint tools such as Okta, CrowdStrike, and Jamf reveal what an agent can access and how it behaves. Restricting or retiring it takes something those tools can't supply: its owner-declared purpose, the work that depends on it, and the access that work requires.

Unlike malware or a missing patch, agent findings require business context that lives with the employee who built the agent. Gathering it one employee at a time does not scale. The blunt alternative is bulk revocation. It closes the finding but disrupts the work behind it, such as weekly finance reports or support replies.

“Finding an agent is the start. Security teams need to reduce risk while preserving the productivity employees gain from agents,” said Shreyas Sadalgi, co-founder and CEO of Amplifier Security. “We ask employees for business context only they can provide. Security teams decide what access is appropriate, we orchestrate the action they choose, and we record both to support AI governance.”

AIPM guides teams through six steps:

  1. Discover and confirm ownership. AIPM discovers agents directly on endpoints and ingests agent discoveries from other integrated security tools. It then connects these findings to employee owners for confirmation.

  2. Validate intent. AIPM asks each owner what the agent is for and records the answer rather than inferring purpose from metadata or behavior.

  3. Enrich risk. External threat intelligence adds known risk indicators to agent findings, helping security teams prioritize further review.

  4. Assess access and behavior. AIPM compares permissions and connected behavioral signals with owner-declared intent to surface excessive access, drift, and conditions that need review.

  5. Engage and act. AIPM gathers owner input through Slack or Microsoft Teams. Security teams decide whether to keep, scope down, investigate, remediate, or retire an agent, and AIPM orchestrates the resulting actions. Owner conversations run in parallel to reduce manual follow-up.

  6. Record decisions and actions. AIPM records ownership, purpose, reviews, decisions, remediation, and retirement actions, giving security teams a lifecycle record for each agent.

When an agent’s permissions exceed its stated purpose, AIPM asks the owner what access the work requires, helping security teams determine which permissions to remove. AIPM records the security team’s decision and orchestrates the corresponding actions.

“Discovering agents on employee endpoints helps security teams understand how employees use them. Connecting those discoveries to their owners adds purpose and accountability. That is the strength of workforce security: connecting the employee, endpoint, and agent to inform decisions about access and risk,” said Bradley J. Schaufenbuel, CISO at a leading provider of integrated human capital management solutions.

“Knowing an agent exists doesn’t tell me whether the person who built it still needs it. Getting that answer from the owner, in writing, is the difference between a list and a program I can report on,” said Ravi Nori, CISO at Gopuff.

AIPM complements existing identity, endpoint, cloud, runtime, GRC, and audit tools by connecting their findings to owner-declared purpose, a human decision, and a defensible record. 

AIPM is now available in private preview. To request an evaluation, visit amplifiersecurity.com/demo.