In summary
- Keeper Security has extended agentic AI governance to Keeper Endpoint Privilege Manager, applying its identity, approval and audit framework to AI agents on managed endpoints.
- The capability works at the operating system level, evaluating every action an agent attempts whether via MCP, a direct API, a local tool or another path.
- It also introduces three new policy types alongside a monitor-first lifecycle and unified audit trail.
Keeper Security has extended agentic AI governance to its Keeper Endpoint Privilege Manager, applying the same identity, approval and audit framework it uses for human users to AI agents running on managed endpoints.
The company said the capability operates at the operating system level, meaning it evaluates every action an AI agent attempts - regardless of whether the agent uses Model Context Protocol (MCP), a direct API, a local tool or another path. Keeper said competing approaches govern only at the MCP layer, leaving non-MCP agent actions outside security policy.
Keeper Endpoint Privilege Manager identifies both known and unknown AI agents on managed endpoints. Known agents - including GitHub Copilot, Cursor, Claude Code and Amazon Q - are recognised through a signed catalogue of agent identities combined with a proprietary AI likelihood score.
Applications outside the known catalogue are assessed by a detection algorithm that assigns each a zero-to-100 score; those crossing a configurable threshold fall under agentic AI policies automatically, with no signature update or manual classification required.
The feature introduces three new policy types: an Agentic AI Policy controlling who can run agents on an endpoint; an Agentic Access Policy controlling what those agents may access, including files, executables and commands; and an Agentic Privilege Elevation Policy controlling how agents request administrative elevation.
A monitor-first lifecycle lets organisations observe agent behaviour before enabling enforcement.
A unified audit trail captures agent actions, policy decisions and approval outcomes. Keeper said the controls are designed to help organisations operationalise National Institute of Standards and Technology (NIST) AI Risk Management Framework requirements at the endpoint.
The release also includes a dashboard with AI agent visibility, a new workload view, dedicated agentic AI groupings and automatic agent updates with version control.
"AI agents are not assistants; they are principals," said Darren Guccione, chief executive and co-founder of Keeper Security.
"Every agent running on an endpoint has an identity, requests access and takes actions on behalf of your organisation. If you are not governing them with the same rigour you apply to your human workforce, you have blind spots that adversaries will find before you do."
Agentic AI governance is available with Keeper Endpoint Privilege Manager as a standalone product or as part of the KeeperPAM platform.




