# endlayer — Full Text Index > Every AI tool, agent, and model call across your company: surfaced, monitored, and governed from one plane. Publisher: Holistic AI. Contact: hello@endlayer.com. Canonical root: https://www.endlayer.ai Generated: 2026-09-11 Articles included: 1 Each section below is one article. Cite the URL given in that section's metadata, and attribute to the named author. --- ## Introducing endlayer — the control plane for AI - URL: https://www.endlayer.ai/blog/introducing-endlayer - Author: The endlayer team (Product and research) - Published: 2026-09-09 - Category: Product - Tags: Shadow AI, Control plane, MCP, Coding agents, AI governance, Endpoint - Reading time: 18 min read **Summary:** endlayer is an AI control plane for the devices people actually work on. One small agent, without administrator rights, reads 21 signals from files already on each machine and starts reporting within 60 seconds of install, and three modules turn those readings into a control: Surface builds the AI inventory, Monitor watches what each tool reaches and costs, and Govern grades every device against nineteen versioned rules. Enterprise software used to arrive through procurement. AI arrived through people. The pattern is the same in every large company now. A developer installs a coding agent on a Tuesday afternoon because it makes the week easier. An analyst signs in to a consumer AI service with a personal account to get through a spreadsheet. A team connects an AI agent straight to a production database, through an MCP server, because the agent needed that context to be useful. None of it is malicious. Most of it is genuinely productive. And almost none of it passed through the process that governance depends on: a request, a review, a record. None of this is a discipline problem. A company whose people found AI useful before anyone told them to is a company that moves, and slowing that down is the expensive mistake. What is missing is not control. It is the record that makes the speed defensible. The AI nobody registered Ask a governance lead which AI tools the company uses and you get the approved list. Ask which laptops run a coding agent that can act without being asked each time, or hold a provider API key in a file git was told to ignore, and you get a pause. The pause is structural, not careless. Every established way of looking has the same blind spot. A cloud AI gateway sees the calls someone chose to route through it, not the tool carrying its own key. A network proxy sees traffic it sits in the path of, and a model running locally produces none. Fleet management sees what the operating system registers as an application, which a CLI agent installed through a package manager never does. Questionnaire-based GRC sees what people remember to declare, in the quarter they are asked. Governing AI at the network layer is a category error. The network was the right place to watch software that had to travel to be useful. A model running on a laptop never leaves it, a coding agent carries its own key, and an MCP server is declared in a settings file rather than a firewall rule. Each of those tools governs AI somewhere convenient to watch. The endpoint is where AI actually runs, and it is the one layer none of them reaches. That layer needs its own control plane, and it did not have one. The gap has a price. IBM's Cost of a Data Breach study found that breaches involving shadow AI cost $670,000 more than breaches without it, and that 63% of breached organisations had no AI governance policy at all. Meanwhile ISO/IEC 42001, the NIST AI RMF and the EU AI Act, with penalties reaching €35 million or 7% of worldwide turnover, all begin by asking for an inventory of the AI in use. An organisation that cannot produce that list is not partially compliant. It is unable to start. Holistic AI has spent years helping large enterprises govern the AI they build and buy. The models in a repository, the pipelines in a cloud, the agents shipped inside a product. That work kept running into the same wall. Everything that went through a process was documented and reviewed, and the AI people actually reached for during the working day was not, because nothing in the stack could see it. That is why we built endlayer. Introducing endlayer endlayer is an AI control plane for work devices. One small agent runs on each laptop or server, reads 21 signals from the files AI tools have already left behind, and reports to a console that grades every device against a versioned policy. It finds the AI applications, coding agents, MCP servers, local models, accounts and API keys that cloud and code integrations cannot reach, on managed and unmanaged machines alike, across macOS, Windows and Linux. It is built from three modules. Surface builds the inventory of AI on every device. Monitor watches what each tool reaches, whose account it runs on and what it costs. Govern grades all of it against nineteen versioned rules and keeps the record an audit asks for. Every part of it also runs inside your own infrastructure, console and backend and database and storage, including on networks with no route to the internet. And endlayer is free to use. Not a trial, not a device cap. Free. What endlayer does What follows is the same fleet in four views, in the order the product produces them: one device reporting, the inventory it joins, the row it becomes, and the rule that grades it. The first minute One small agent goes on the machine, without administrator rights and without changing how anyone works. It reads the files AI tools have already left behind: settings files, saved logins, project files, browser profiles and usage logs. It never launches what it finds, and it routes nothing off the device to a proxy or a gateway. Inside a minute, the console has its first report. DEVICES · FIRST REPORT 58 SECONDS AFTER INSTALL MacBook Pro macOS 15.2 · Sensor 3 MB STATUS 17 passing · 3 failing last report: just now FOUND ON THIS DEVICE AI apps 4 Coding agents 2 MCP servers 3 API keys in files 2 Surface: see the AI running across your devices That inventory is Surface, the device layer of the control plane. Across a fleet it is the same list, on macOS, Windows and Linux: every AI application, coding agent, MCP server, local model, account and exposed API key, found without being told any of it exists. Two of its readings carry most of the weight, because nothing upstream can produce them. MCP servers decide how far an AI agent can reach: the Model Context Protocol is the standard way an agent connects to GitHub, a database or an internal system, and that connection is written in a settings file on the laptop, not in a firewall rule anyone reviews. Credentials are the quiet one. Most key exposure does not begin with a breach. It begins with a .env that was convenient. Monitor: one row per tool, agent and MCP server An inventory says what exists. Monitor says what it is doing: one row per AI app, coding agent, MCP server and skill across every enrolled device, showing who has it, what it reaches, whether it runs on its own, and what it costs. MONITOR · ONE ROW PER TOOL, AGENT AND MCP SERVER TOOL ACCOUNT REACHES AUTONOMY SPEND LAST SEEN Coding agent corporate 3 repositories asks each step 41k tokens 2 min ago Coding agent personal 12 repositories unattended 890k tokens 4 min ago MCP server unknown internal database — — 9 days ago Autonomy is the reading that reframes the risk. The same coding agent is a different exposure in unattended mode with repository write access than it is asking permission at each step. Same tool, same version, same laptop. And a machine that stops reporting gets surfaced rather than assumed healthy, because silence is not evidence of safety. Govern: publish a rule, and every device is checked Govern is where the rules are set: which AI tools and coding agents are approved, what an agent may do on its own, which MCP servers it may reach, and what may leave in a prompt. Nineteen rules ship with the product. Publish, and every device is checked against them. GOVERNANCE · LIBRARY POLICY v12 · PUBLISHED 4 MIN AGO RULE IN FORCE PASSING FAILING OWNER Approved AI tools v12 41 3 Security Agents acting on their own v12 39 5 Platform What agents may connect to v12 42 2 Security EVERY GRADE TIED TO THE VERSION THAT WAS IN FORCE Two things make this hold up in an audit rather than just look good on a dashboard. Every publish is a new version, so a grade is always tied to the policy in force when it was taken. Change a rule today, and last quarter's evidence still says what it said. And every failure gets an owner, a state and a date it closed, instead of a red square on a chart. When it blocks Grading tells you what is wrong. Some risks cannot wait for a person to read a report. EVENTS · WHAT NEEDS ATTENTION NOW ON THE DEVICE · 11:04:22 Request blocked before it left the machine A prompt to a consumer AI service carried a provider API key. RULE Approved AI tools · v12 ACTED Decoder, on the device RECORDED that a secret matched never what it was A request to a consumer AI service can be stopped on the wire before it leaves. An agent-to-agent or MCP call that policy does not allow is refused on the machine. Secrets and personal data are warned on, redacted or blocked on the way out, and the console records that a redaction happened, never what was redacted. Removing an installed app is the one action that waits for a person: the Blocked apps rule raises a request, and an administrator approves it before anything is uninstalled. Every one of those decisions leaves the product. Events and requests are visible in the console as they happen, and a nightly export writes the record to storage you own, each verdict citing the policy version behind it. Evidence packs are available on request, one export file a day. Nothing has to stay inside endlayer to be auditable. How it works underneath Everything above is one agent and one console. The agent ships in three tiers, each including everything below it, and you choose the weight per device. Sensor · 3 MB · every device. One binary, no runtime and no model. It lists every AI tool, model and connection on the machine and checks them against fixed rules, with no prompt sent anywhere. Works offline. Decoder · 30 MB · devices sending AI traffic. A local gateway, not a network one. It unscrambles the request on the machine that made it, so a prompt can be checked at the moment it is sent, then re-encrypts before it goes anywhere. That is what makes the block in Figure 4 possible. The readable text never leaves the device. Guardian · 300 MB · devices running agents. It sits where agents meet: one agent calling another, an agent reaching an MCP server, a tool asking for a permission it was never granted. What every tier reads is the same 21 signals: the tools and agents installed and whether each can act alone, the MCP servers configured and what they reach, the provider keys sitting in files, the account each tool signs in with, what it costs in tokens, the repositories in scope, and the device's own security posture. The signals page lists all of them field by field. The boundary is as deliberate as the reading. Credential presence is reported; the value is discarded on the device before evidence is built. Repository context is enough, so file contents stay untouched. Prompts and transcripts stay off until an administrator turns them on, and the record says who did. No packet capture off the device, no precise location, no personal account IDs. 01 · ON THE DEVICE Sensor 3 MB Decoder 30 MB Guardian 300 MB One agent, in tiers. Each includes the one below. It blocks here, in real time. COLLECTING WITHIN 60 SECONDS OF INSTALL 02 · WHAT IT READS Tools & agents Apps & web MCP & access Accounts & spend Projects & data The device Security posture 21 SIGNALS, SENT AS ONE REPORT 03 · IN THE CONSOLE Surface what AI is here tools, agents, keys Monitor what it reaches, runs on and costs Govern the rules, and who owns a failure GRADED, OWNED, KEPT AS EVIDENCE 04 · THE RECORD Rule packages · SOC 2 · EU AI Act · ISO/IEC 42001 · NIST AI RMF Every grade tied to the policy in force · owner, state, close date · exportable Evidence an auditor accepts Rules are not a settings page. They are the versioned object the product is organised around, and they ship as packages mapped to the frameworks a review will actually ask about: SOC 2, the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. Turning on a package turns on the rules that framework implies, and the evidence comes out in the shape the auditor expects. That matters because AI regulation has moved from principles to obligations with dates attached. All of those frameworks assume you can produce the inventory, show the policy that applied on a given day, and name who owned each exception. A dashboard cannot do that. A versioned record can. endlayer sits inside the information security management system supporting the Holistic AI platform, certified to ISO/IEC 27001:2022, with a SOC 2 Type 2 report published for the platform and an ISO/IEC 42001 audit scheduled. Hosting is AWS, Europe (London) by default and US East (Ohio) for US customers. Data is kept only as long as the purpose requires or your MSA sets out, and on termination or on request it is permanently deleted from storage, databases and backups, with written confirmation available. We do not train models on customer data, and the text a guardrail matches never leaves the device it was found on. The Trust Centre has the detail. Detection needs the agent. endlayer does not watch a device it is not installed on. That is the cost of reading the machine directly instead of guessing from traffic. It is a real limit. We would rather you heard it here than found it in week three. Where we are going next Within two years the question will not be which AI tools a company allows. It will be which of its agents are permitted to act alone, on what, and with whose credentials. Every framework now being written assumes someone can answer that, and almost nobody can. The device layer ships today. Cloud connectors and SDK ingestion are the layers we are building next, so the same rules and the same enforcement reach the AI an enterprise builds and buys as well as the AI its people install. That work sits alongside the Holistic AI platform, which already governs models in repositories, pipelines in clouds and agents inside products through integrations into code, cloud and documentation. Two halves of one footprint, in the same vocabulary. Available today endlayer is free to use, and the agent installs in one command. endlayer enroll prints an enrolment code, someone with authority accepts it, and that acceptance sets the organisation and stores the credential on the device. endlayer doctor then reports the config in force and whether delivery is reachable, which is the check worth running before you go wider than a handful of machines. If your position is that nothing about your devices should reach a vendor at all, every part of this runs on your own infrastructure: the console, the backend, Postgres and object storage, including on networks with no route to the internet. Start with your own machine and read what comes back. The first run takes under a minute, and on most machines it returns something the owner had forgotten: an API key in a project file, or an agent still sitting in unattended mode. When you are ready to go wider, enrolment is the same one command per device, and the console groups what comes back by device, account and rule rather than by whoever installed it first. ---