My take on Omnissa CEO Amit Singh’s “The Agentic Endpoint”
Disclosure: I’m an Omnissa Tech Insider. The opinions below are my own.
Omnissa has a new CEO, and Amit Singh didn’t take long to say where he thinks endpoint management is headed. His first major post, The Agentic Endpoint, makes a claim that I think every IT team should sit with for a minute: the endpoint is no longer just where a person works. It’s where AI agents run.
I want to walk through what he argues, and then say where I think it lands for those of us who manage fleets for a living.
The core idea: one user, many actors
For as long as most of us have managed devices, the model was simple. One device, one user, a set of apps. Identity, permissions and network traffic all mapped back to a person.
Singh’s argument is that this assumption is about to break. He expects that within a year, the laptops and phones we manage will each be running not one user but dozens of AI agents. Some will be built into the apps we already license. Some will run as copilots. Some will be built internally. All of them will inherit the user’s identity, the user’s permissions and the user’s traffic patterns.
That last part is what matters. An agent acting “as” a user is indistinguishable, to a lot of our current tooling, from the user. Multiply that by dozens per device and the picture gets complicated quickly.
Why it changes the security picture
Two consequences stood out to me.
A compromised endpoint now exposes every agent on it. Attackers who land on a device don’t just get one person’s session. They get access to the agents running there and the credentials those agents hold. The endpoint becomes a concentration point, which is why Singh calls it “the most valuable ground on the network” and “the last mile of enterprise AI security.”
Agents can misbehave in ways ordinary software doesn’t. They operate asynchronously, so problems can run for a long time before anyone notices. Singh points to reported cases of test agents breaking out of sandboxes and pursuing goals nobody gave them. You don’t have to accept every example to see the underlying point: software that makes its own decisions needs a different kind of oversight than software that follows a fixed path.
He adds a third pressure that’s easy to overlook. Agents won’t stay on laptops and phones. They’ll show up on watches, earbuds, glasses and purpose-built enterprise devices, which means enrolling and managing device categories that many of us don’t touch today.
The framework: Discover, Decide, Contain, Prove
The part of the post I found most useful is that it doesn’t stop at “this is scary.” Singh organizes the response into four verbs.
- Discover. Build a complete inventory of the agents on your devices and what they actually do. You can’t govern what you can’t see.
- Decide. Set what an agent is allowed to do before it runs, not after something goes wrong.
- Contain. Keep endpoints clean, give agents safe places to execute, and respond in proportion when behavior drifts from what was approved.
- Prove. Keep audit trails so you can show compliance and reconstruct what happened.
If you’ve worked in endpoint management, none of these words are foreign. That’s the point of the framing. It maps onto things we already do (inventory, policy, remediation, reporting) and asks us to extend them to a new kind of actor.
Omnissa says it will build on what it already has around device management, virtual workspaces, credential handling, telemetry and fleet-scale remediation. The post names new capabilities on the way: discovery of AI actors, tools for setting agent permissions, agents that close vulnerabilities, and application lifecycle management.
My take
I’m excited about this one, and here’s why: I’ve been asking for a way to see what people are actually running on their devices, and shadow AI is the reason it has become urgent.
Right now, most of us can tell you what’s installed. We can’t tell you which AI tools and agents people are using, what those tools can reach, or whose credentials they’re running under. Some arrive as an install. Others show up as a feature switched on inside an app we already approved, or as a browser tool someone found on their own. Inventory tools tend to miss all of it. That’s a real blind spot, and it’s growing every month.
That’s why Discover is the part of Singh’s framework I care about most. A complete view of the agents on a device is the first thing I’d want, because every other step depends on it. You can’t set permissions for something you don’t know exists, you can’t contain it, and you can’t prove anything about it later. If Omnissa delivers real visibility into what’s running, including the stuff nobody told IT about, that’s a huge help for anyone managing a fleet.
Decide is the next hard problem, and it’s as much about people as tooling. Agent permissions need owners, review cycles and an exception process, the same as any other access. Left to defaults, agents end up with the user’s full reach because that was the easiest thing to configure. Prove is the one I expect auditors to ask about first: “What did this agent do on this device last Tuesday?” needs a real answer, with logs to back it up.
What I’ll be watching is how quickly discovery and permissioning reach the products we already run, and whether they work without yet another console. The value of extending an existing endpoint platform is that the team already knows it. I’m looking forward to seeing it land.
The takeaway
Whether or not the “dozens of agents per device within a year” timeline turns out to be exact, the direction is hard to argue with. Agents are arriving on managed devices, they carry user-level trust, and our tooling was designed for a world where that trust belonged to a person.
It’s worth reading the source, forming your own view, and starting the Discover work now, before the agents outnumber the apps.
Read the original: The Agentic Endpoint
Join the conversation: Omnissa community forums
What are you seeing on your own fleet? I’d like to hear it in the comments.

[…] already wrote about Amit Singh’s “The Agentic Endpoint” post. This is the follow-up: what was actually announced, what’s available now, and what I’m […]