TL;DR: Browser-only discovery misses locally installed SaaS apps, standalone AI desktop tools, and agentic browsers that never generate the cloud or IdP signals standard controls depend on, leaving visibility gaps that affect compliance and risk management, according to JumpCloud. The core problem is that discovery models built for browser activity no longer match software usage that now executes on the endpoint.
At a glance
What this is: JumpCloud argues that device-based discovery closes the gap left by browser-centric SaaS and AI visibility, because locally installed apps and agentic browsers can evade standard cloud controls.
Why it matters: For IAM, SaaS, and endpoint teams, this matters because software inventory, compliance evidence, and AI governance all break when discovery cannot see what is installed and executed on the device.
By the numbers:
- Secure AI adoption is currently stalled for many organisations by limited oversight of permissions 46% and a fundamental lack of visibility into AI activity 45%, according to JumpCloud.
Context
SaaS discovery is no longer just a browser problem. Native desktop clients, local AI tools, and agentic browsers run on the endpoint and can bypass the cloud, IdP, and web signals many discovery programmes depend on.
The governance gap is straightforward: if the software executes locally, browser-only controls cannot see it. That creates a blind spot for shadow IT, rogue AI, compliance evidence, and application inventory across the modern device estate.
Key questions
Q: What breaks when SaaS discovery is incomplete?
A: Incomplete discovery leaves shadow apps, duplicate subscriptions, and employee-purchased tools outside the control model. That means invoices cannot be matched cleanly, renewal decisions are based on partial data, and ownership remains ambiguous. In practice, the organisation pays for services it cannot reliably govern or retire.
Q: Why do locally installed AI tools create governance risk?
A: They move execution outside the browser and can operate without corporate identity signals, which means standard SaaS monitoring, web filters, and SSO logs may never see them. That creates a gap between approved software policy and what is actually installed and used on employee devices.
Q: How should teams build a trustworthy software inventory for endpoint apps?
A: Combine browser, connector, and device-based discovery, then tie each application to a verified user and managed endpoint. That gives security and compliance teams a source of truth that can support audits, shadow IT review, and policy enforcement instead of a partial usage snapshot.
Q: When should organisations treat an agentic browser as an endpoint risk?
A: When the browser can run tasks locally, access sensitive pages, or interact with data outside the normal cloud control path, it should be governed like endpoint software rather than a simple web client. That changes allowlisting, monitoring, and approval decisions.
Technical breakdown
Why browser-only discovery misses local software
Browser discovery works when application activity leaves a cloud trail, such as an IdP login, a web session, or a connector event. Native desktop clients break that assumption because they authenticate locally, store state on the endpoint, or use personal credentials outside corporate identity flows. Local LLM runners and agentic browsers can also execute entirely on the device, which means secure web gateways, browser extensions, and IdP integrations never see the activity. In identity terms, the control plane is watching the wrong layer. Practical visibility must move to where the software actually runs, not only where the session is expected to appear.
Practical implication: build discovery around endpoint execution, not browser telemetry alone.
How device-based discovery changes software inventory
A device agent can scan the local machine and identify installed SaaS clients, standalone AI applications, and agentic browsers without asking users to self-report. That shifts inventory from a partial, activity-based view to a device-derived source of truth that can be reconciled with browser and connector data. The important detail is not simply broader coverage, but attribution: the discovered app must be tied back to a verified user and managed device so inventory can support governance decisions. Without that attribution, the organisation gains noise, not control.
Practical implication: reconcile device-discovered apps with user and device records before using them for governance.
Why local AI creates a new trust boundary
Local AI tools are not just another SaaS category. They can execute tasks, process data, and interact with websites outside the normal browser and cloud control stack, which changes where trust must be enforced. That means the organisation is no longer governing only access to a web application, but software behaviour on unmanaged or partially managed endpoints. For IT and security teams, the technical issue is boundary drift: the work happens on the device, but the controls were designed for the browser and cloud session. Practical implication: discovery must support policy decisions about what software is allowed to exist on the endpoint at all.
Practical implication: treat local AI as an endpoint governance issue, not only an application approval problem.
Threat narrative
Attacker objective: The objective is to operate unvetted software on employee endpoints without leaving the cloud and identity signals needed for governance and detection.
- Entry occurs when an employee downloads a native SaaS client, standalone AI desktop app, or agentic browser onto the endpoint and authenticates with personal or work credentials.
- Privilege and visibility remain outside standard control paths because the software executes locally, bypassing corporate SSO logs, browser monitoring, and secure web gateways.
- Impact is the creation of shadow IT and rogue AI that can handle company data without appearing in the systems teams rely on for oversight.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
- 12,000 secrets in LLM training data: Truffle Security found 11,908 live API keys and passwords hard-coded in web pages captured by Common Crawl, a dataset used to train LLMs.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Endpoint-based software discovery is now a governance requirement, not a convenience feature. Browser-centric inventory models assume the application is visible through web traffic or IdP events. That assumption fails when the software is a native desktop client or a local AI tool that runs on the device itself. The implication is that software inventory, compliance evidence, and AI governance now depend on endpoint telemetry as much as cloud telemetry.
Local AI creates a discovery problem, but the deeper issue is control-plane mismatch. Organisations have spent years tuning visibility around web sessions, federated sign-in, and connector logs. Local execution moves the relevant evidence to the device, where those controls do not naturally observe behaviour. The named concept here is the browser-to-device visibility gap: the distance between where teams expect to see software activity and where it actually occurs.
Agentic browsers collapse the distinction between application inventory and behavioural risk. A browser that can act locally, scrape screens, and execute tasks is not just another installed app. It expands the attack surface because the tool itself becomes a semi-autonomous workflow surface on the endpoint. For practitioners, that means app allowlisting, endpoint management, and AI governance can no longer sit in separate programme silos.
Compliance depends on a complete software bill of materials, not only a cloud-facing one. Audit and evidence processes fail when locally installed applications are invisible to IT. This is especially relevant where regulators or internal controls expect a complete inventory of systems in use. The practical conclusion is that device-discovered software must be treated as part of the official governance record, not an auxiliary report.
Discovery without attribution does not create control. A list of installed apps is useful only if it can be tied to a verified user, managed device, and policy owner. That is why endpoint discovery should feed review and enforcement workflows rather than stop at visibility. Practitioners need a governance model that can distinguish approved local software from unmanaged shadow IT before exposure becomes a policy exception.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Browser-to-device visibility gap: discovery models built around IdP, SWG, and connector logs miss software that executes locally on the endpoint. That gap now covers native SaaS clients, local AI tools, and agentic browsers, so governance teams need device telemetry as part of the control set.
A complete software bill of materials now has to include locally installed applications that never touch the browser. Without that endpoint layer, compliance evidence and shadow IT review remain partial by design, even when the cloud side of the estate looks clean.
For practitioners
- Extend discovery to the endpoint Use device-level telemetry to identify native SaaS clients, local AI desktop tools, and agentic browsers that never appear in cloud-only logs.
- Reconcile inventory across browser, connector, and device data Treat browser, identity, and endpoint discovery as one inventory problem so locally installed software is not counted twice or missed entirely.
- Validate software attribution before governance decisions Tie each discovered application to a verified user and managed device before using it for compliance evidence or removal workflows.
- Review local AI and agentic browser approvals Create explicit approval criteria for standalone AI tools and agentic browsers, including where they may run and what data they may touch.
- Replace browser-only reporting with endpoint-aware audits Build audit evidence from the full software estate, including locally installed applications that do not generate IdP or SWG signals.
Key takeaways
- Browser-centric discovery no longer covers the full software estate when applications execute locally on employee devices.
- The real governance failure is not just missing apps, but missing the identity and inventory signals needed to control them.
- Endpoint-aware discovery gives IT teams a defensible source of truth for compliance, shadow IT review, and local AI oversight.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Employees using local AI tools and SaaS clients creates unmanaged non-human access on endpoints. |
| NHI-03 — Vulnerable Third-Party NHI | Third-party SaaS clients and AI tools introduce unmanaged identity and trust exposure on devices. | |
| Recommendation — Review endpoint-discovered software for human-mediated NHI use and remove unapproved access paths. Inventory third-party applications on endpoints and verify their identity and access dependencies before approval. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Endpoint-discovered software changes how organisations validate permissions and entitlements in practice. |
| Recommendation — Map endpoint-discovered applications to entitlements so access can be reviewed against actual usage. | ||
| CIS Controls v8 | CIS-5 — Account Management | Local SaaS and AI tools often bypass central account visibility and create unmanaged access paths. |
| Recommendation — Maintain authoritative account and application inventories that include locally installed software and unmanaged logins. | ||
Key terms
- Browser-to-Device Visibility Gap: The mismatch between where organisations expect to observe software activity and where the software actually executes. In this pattern, browser, IdP, and gateway telemetry are incomplete because the real control point has shifted to the endpoint, where local applications and AI tools can operate outside traditional discovery.
- Context-Based Discovery: Context-based discovery is the practice of identifying data and attaching meaning to it, such as sensitivity, business use, or access relevance. That context helps security teams make better decisions about classification, policy enforcement, access control, and platform placement.
- Local AI Tooling: AI software that runs on an endpoint rather than through a centrally managed browser or cloud service. These tools can process data, perform tasks, and interact with systems while avoiding the normal log and session trail that identity and network controls expect.
- Software Bill of Materials: A software bill of materials is an inventory of the components and dependencies used in an application. It helps teams identify what they shipped, but it becomes most useful when paired with source verification, signature checks, and policy enforcement for third-party code.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org