Skip to content
  1. Home
  2. Blog
  3. Product
01 · product

Introducing endlayer — the control plane for AI

endlayer reads 21 signals from every work device within 60 seconds of install, finds the AI nobody registered, and grades it against nineteen versioned rules.

on this page

Enterprise software used to arrive through procurement. AI arrived through people.

The pattern is the same in every large company now. A developer installs a coding agent on a Tuesday afternoon because it makes the week easier. An analyst signs in to a consumer AI service with a personal account to get through a spreadsheet. A team connects an AI agent straight to a production database, through an MCP server, because the agent needed that context to be useful. None of it is malicious. Most of it is genuinely productive. And almost none of it passed through the process that governance depends on: a request, a review, a record.

None of this is a discipline problem. A company whose people found AI useful before anyone told them to is a company that moves, and slowing that down is the expensive mistake. What is missing is not control. It is the record that makes the speed defensible.

The AI nobody registered#

Ask a governance lead which AI tools the company uses and you get the approved list. Ask which laptops run a coding agent that can act without being asked each time, or hold a provider API key in a file git was told to ignore, and you get a pause.

The pause is structural, not careless. Every established way of looking has the same blind spot. A cloud AI gateway sees the calls someone chose to route through it, not the tool carrying its own key. A network proxy sees traffic it sits in the path of, and a model running locally produces none. Fleet management sees what the operating system registers as an application, which a CLI agent installed through a package manager never does. Questionnaire-based GRC sees what people remember to declare, in the quarter they are asked.

Governing AI at the network layer is a category error. The network was the right place to watch software that had to travel to be useful. A model running on a laptop never leaves it, a coding agent carries its own key, and an MCP server is declared in a settings file rather than a firewall rule. Each of those tools governs AI somewhere convenient to watch. The endpoint is where AI actually runs, and it is the one layer none of them reaches. That layer needs its own control plane, and it did not have one.

The gap has a price. IBM's Cost of a Data Breach study found that breaches involving shadow AI cost $670,000 more than breaches without it, and that 63% of breached organisations had no AI governance policy at all. Meanwhile ISO/IEC 42001, the NIST AI RMF and the EU AI Act, with penalties reaching €35 million or 7% of worldwide turnover, all begin by asking for an inventory of the AI in use. An organisation that cannot produce that list is not partially compliant. It is unable to start.

Holistic AI has spent years helping large enterprises govern the AI they build and buy. The models in a repository, the pipelines in a cloud, the agents shipped inside a product. That work kept running into the same wall. Everything that went through a process was documented and reviewed, and the AI people actually reached for during the working day was not, because nothing in the stack could see it.

That is why we built endlayer.

Introducing endlayer#

endlayer is an AI control plane for work devices. One small agent runs on each laptop or server, reads 21 signals from the files AI tools have already left behind, and reports to a console that grades every device against a versioned policy. It finds the AI applications, coding agents, MCP servers, local models, accounts and API keys that cloud and code integrations cannot reach, on managed and unmanaged machines alike, across macOS, Windows and Linux.

It is built from three modules. Surface builds the inventory of AI on every device. Monitor watches what each tool reaches, whose account it runs on and what it costs. Govern grades all of it against nineteen versioned rules and keeps the record an audit asks for.

Every part of it also runs inside your own infrastructure, console and backend and database and storage, including on networks with no route to the internet. And endlayer is free to use. Not a trial, not a device cap. Free.

endlayerMonitoring › Overview44 devices reporting
213AI tools found
27Not approved
9Rules failing
6Acting alone
Tool installs by sanction
Approved 148
Undecided 38
Disallowed 27
Needs attention now
Agents acting on their own5 failing
Keys in project files3 devices
No report in 9 days1 device
Undecided is not a pass · every failure has an owner
Figure 1The console overview, rendered with the same components the product pages use. One number for what has been found, one for what nobody approved, one for what is failing policy, and one for the agents running without a person in the loop. Example fleet, not live data.

What endlayer does#

What follows is the same fleet in four views, in the order the product produces them: one device reporting, the inventory it joins, the row it becomes, and the rule that grades it.

The first minute#

One small agent goes on the machine, without administrator rights and without changing how anyone works. It reads the files AI tools have already left behind: settings files, saved logins, project files, browser profiles and usage logs. It never launches what it finds, and it routes nothing off the device to a proxy or a gateway.

Inside a minute, the console has its first report.

Figure 2The first report, under a minute after install. The device grades itself against the policy already in force, and what came back is an inventory nobody had to declare. Example device, not live data.

Surface: see the AI running across your devices#

That inventory is Surface, the device layer of the control plane. Across a fleet it is the same list, on macOS, Windows and Linux: every AI application, coding agent, MCP server, local model, account and exposed API key, found without being told any of it exists.

Two of its readings carry most of the weight, because nothing upstream can produce them. MCP servers decide how far an AI agent can reach: the Model Context Protocol is the standard way an agent connects to GitHub, a database or an internal system, and that connection is written in a settings file on the laptop, not in a firewall rule anyone reviews. Credentials are the quiet one. Most key exposure does not begin with a breach. It begins with a .env that was convenient.

Monitor: one row per tool, agent and MCP server#

An inventory says what exists. Monitor says what it is doing: one row per AI app, coding agent, MCP server and skill across every enrolled device, showing who has it, what it reaches, whether it runs on its own, and what it costs.

Figure 3One row per tool. The highlighted row is the one a security team acts on: the same coding agent as the row above it, running unattended, on a personal account, with twelve repositories in scope. The row below has not reported in nine days. Example rows, not live data.

Autonomy is the reading that reframes the risk. The same coding agent is a different exposure in unattended mode with repository write access than it is asking permission at each step. Same tool, same version, same laptop. And a machine that stops reporting gets surfaced rather than assumed healthy, because silence is not evidence of safety.

Govern: publish a rule, and every device is checked#

Govern is where the rules are set: which AI tools and coding agents are approved, what an agent may do on its own, which MCP servers it may reach, and what may leave in a prompt. Nineteen rules ship with the product. Publish, and every device is checked against them.

Figure 4The rule library after a publish. Every rule shows the version in force, how the fleet grades against it and who owns the failures. The rule on agents acting on their own is failing on five devices, one of which is the unattended coding agent from the row above. Example fleet, not live data.

Two things make this hold up in an audit rather than just look good on a dashboard. Every publish is a new version, so a grade is always tied to the policy in force when it was taken. Change a rule today, and last quarter's evidence still says what it said. And every failure gets an owner, a state and a date it closed, instead of a red square on a chart.

When it blocks#

Grading tells you what is wrong. Some risks cannot wait for a person to read a report.

Figure 5A block, recorded. The request never reached the network, the decision was made on the device against a named policy version, and the console holds the fact of the match without holding the secret that matched it.

A request to a consumer AI service can be stopped on the wire before it leaves. An agent-to-agent or MCP call that policy does not allow is refused on the machine. Secrets and personal data are warned on, redacted or blocked on the way out, and the console records that a redaction happened, never what was redacted.

Removing an installed app is the one action that waits for a person: the Blocked apps rule raises a request, and an administrator approves it before anything is uninstalled.

Every one of those decisions leaves the product. Events and requests are visible in the console as they happen, and a nightly export writes the record to storage you own, each verdict citing the policy version behind it. Evidence packs are available on request, one export file a day. Nothing has to stay inside endlayer to be auditable.

How it works underneath#

Everything above is one agent and one console. The agent ships in three tiers, each including everything below it, and you choose the weight per device.

  • Sensor · 3 MB · every device. One binary, no runtime and no model. It lists every AI tool, model and connection on the machine and checks them against fixed rules, with no prompt sent anywhere. Works offline.
  • Decoder · 30 MB · devices sending AI traffic. A local gateway, not a network one. It unscrambles the request on the machine that made it, so a prompt can be checked at the moment it is sent, then re-encrypts before it goes anywhere. That is what makes the block in Figure 4 possible. The readable text never leaves the device.
  • Guardian · 300 MB · devices running agents. It sits where agents meet: one agent calling another, an agent reaching an MCP server, a tool asking for a permission it was never granted.

What every tier reads is the same 21 signals: the tools and agents installed and whether each can act alone, the MCP servers configured and what they reach, the provider keys sitting in files, the account each tool signs in with, what it costs in tokens, the repositories in scope, and the device's own security posture. The signals page lists all of them field by field.

The boundary is as deliberate as the reading. Credential presence is reported; the value is discarded on the device before evidence is built. Repository context is enough, so file contents stay untouched. Prompts and transcripts stay off until an administrator turns them on, and the record says who did. No packet capture off the device, no precise location, no personal account IDs.

Figure 6The whole system. The agent reads 21 signals in seven groups from the device they run on, three modules turn those readings into an inventory, an operating picture and a policy, and what comes out is evidence mapped to a framework. Blocking is the exception to the round trip: it happens on the device, so a refused request never becomes a network event.

Evidence an auditor accepts#

Rules are not a settings page. They are the versioned object the product is organised around, and they ship as packages mapped to the frameworks a review will actually ask about: SOC 2, the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. Turning on a package turns on the rules that framework implies, and the evidence comes out in the shape the auditor expects.

That matters because AI regulation has moved from principles to obligations with dates attached. All of those frameworks assume you can produce the inventory, show the policy that applied on a given day, and name who owned each exception. A dashboard cannot do that. A versioned record can.

endlayer sits inside the information security management system supporting the Holistic AI platform, certified to ISO/IEC 27001:2022, with a SOC 2 Type 2 report published for the platform and an ISO/IEC 42001 audit scheduled. Hosting is AWS, Europe (London) by default and US East (Ohio) for US customers. Data is kept only as long as the purpose requires or your MSA sets out, and on termination or on request it is permanently deleted from storage, databases and backups, with written confirmation available. We do not train models on customer data, and the text a guardrail matches never leaves the device it was found on. The Trust Centre has the detail.

Where we are going next#

Within two years the question will not be which AI tools a company allows. It will be which of its agents are permitted to act alone, on what, and with whose credentials. Every framework now being written assumes someone can answer that, and almost nobody can.

The device layer ships today. Cloud connectors and SDK ingestion are the layers we are building next, so the same rules and the same enforcement reach the AI an enterprise builds and buys as well as the AI its people install. That work sits alongside the Holistic AI platform, which already governs models in repositories, pipelines in clouds and agents inside products through integrations into code, cloud and documentation. Two halves of one footprint, in the same vocabulary.

Available today#

endlayer is free to use, and the agent installs in one command. endlayer enroll prints an enrolment code, someone with authority accepts it, and that acceptance sets the organisation and stores the credential on the device. endlayer doctor then reports the config in force and whether delivery is reachable, which is the check worth running before you go wider than a handful of machines.

If your position is that nothing about your devices should reach a vendor at all, every part of this runs on your own infrastructure: the console, the backend, Postgres and object storage, including on networks with no route to the internet.

Start with your own machine and read what comes back. The first run takes under a minute, and on most machines it returns something the owner had forgotten: an API key in a project file, or an agent still sitting in unattended mode.

When you are ready to go wider, enrolment is the same one command per device, and the console groups what comes back by device, account and rule rather than by whoever installed it first.

Asked about this

What is endlayer?

endlayer is an AI control plane for work devices. One small agent runs on each laptop or server without administrator rights, reads 21 signals from files already on the machine and begins reporting within 60 seconds of install, to a console that grades each device against a versioned policy. It finds AI tools, coding agents, MCP servers, local models, accounts and API keys on work devices, managed or not.

What are the Surface, Monitor and Govern modules?

They are the three modules of the endlayer console, and they run in that order. Surface builds the inventory: every AI application, coding agent, MCP server, local model, account and exposed API key on the machine, found without being told it exists. Monitor watches that inventory in operation: which tools are active, what each can reach, whose account it runs on, what it costs in tokens, and which devices have stopped reporting. Govern applies the policy: nineteen versioned rules grade every device, and every failure gets an owner, a state and a close date.

What are the endlayer agent tiers?

One agent ships in weights, and each includes everything below it. Sensor (3 MB) inventories every AI tool, model and MCP server and applies deterministic policy with no model at all. Decoder (30 MB) is a local TLS gateway that makes a prompt readable on the machine that sent it, so a request can be blocked in real time. Guardian (300 MB) sits where agents meet and blocks an agent-to-agent or MCP call that policy does not allow. The agents page carries each one in full.

How does endlayer find shadow AI?

It reads the disk. AI tools leave configuration files, credential stores, project manifests, browser profiles and usage logs behind. The agent parses those artefacts directly, so it can name a tool that was installed from a website in an afternoon and never went through procurement, a gateway or an app store.

How is endlayer different from an AI gateway or a network proxy?

A network proxy sees traffic it sits in the path of, and a cloud AI gateway sees calls routed through it. Neither sees a model running locally, a tool carrying its own API key, or a coding agent signed in to a personal account. endlayer routes nothing off the device: it reads the machine directly, and where a prompt has to be read in the clear, the Decoder tier terminates TLS on the device itself and re-encrypts before anything leaves.

Which frameworks does endlayer produce evidence for?

Rules ship as packages mapped to the frameworks a review asks about, including SOC 2, the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. Every grade is tied to the policy version in force when it was taken, and the record exports. endlayer itself sits inside the scope of the ISO/IEC 27001:2022 certified information security management system supporting the Holistic AI platform.

What does endlayer enforce automatically, and what needs approval?

Blocking happens on the device, as it happens: Decoder can stop a request to a consumer AI service on the wire before it reaches the network, and Guardian blocks an agent-to-agent or MCP call that policy does not allow. Secrets and personal data are warned on, redacted or blocked on the way out, and the matched text never leaves the machine. Removing an installed app is the one action that waits for a person: the Blocked apps rule raises a request an administrator approves before anything is uninstalled.

Does endlayer need an agent installed on the device?

Yes. Detection needs the agent, and endlayer does not watch a device it is not installed on. That is the trade for reading the machine directly rather than inferring AI use from network traffic.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow