TL;DR: Browser-only discovery misses locally installed SaaS apps, standalone AI desktop tools, and agentic browsers that never generate the cloud or IdP signals standard controls depend on, leaving visibility gaps that affect compliance and risk management, according to JumpCloud. The core problem is that discovery models built for browser activity no longer match software usage that now executes on the endpoint.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Device-Based AI & SaaS Discovery with JumpCloud”.
By the numbers:
- Secure AI adoption is currently stalled for many organisations by limited oversight of permissions 46% and a fundamental lack of visibility into AI activity 45%, according to JumpCloud.
Key questions
Q: What breaks when SaaS discovery is incomplete?
A: Incomplete discovery leaves shadow apps, duplicate subscriptions, and employee-purchased tools outside the control model.
Q: Why do locally installed AI tools create governance risk?
A: They move execution outside the browser and can operate without corporate identity signals, which means standard SaaS monitoring, web filters, and SSO logs may never see them.
Q: How should teams build a trustworthy software inventory for endpoint apps?
A: Combine browser, connector, and device-based discovery, then tie each application to a verified user and managed endpoint.
Practitioner guidance
- Extend discovery to the endpoint Use device-level telemetry to identify native SaaS clients, local AI desktop tools, and agentic browsers that never appear in cloud-only logs.
- Reconcile inventory across browser, connector, and device data Treat browser, identity, and endpoint discovery as one inventory problem so locally installed software is not counted twice or missed entirely.
- Validate software attribution before governance decisions Tie each discovered application to a verified user and managed device before using it for compliance evidence or removal workflows.
Bottom line: Browser-centric discovery no longer covers the full software estate when applications execute locally on employee devices.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Device discovery is becoming the missing identity control plane for local software. Browser-centric SaaS management was built for a world where most work happened through the web and every meaningful action left an identity trail. That model breaks when applications move onto the endpoint and can be launched with no browser session, no connector event, and no centralised audit signal. The implication is that software inventory, access governance, and user attribution now need to converge at the device layer.
A few things that frame the scale:
- DeepSeek accidentally embedded over 11,000 secrets in its training data and left a database exposed online, revealing more than one million sensitive records including chat histories, backend credentials, and API keys, according to DeepSeek breach.
- Our research also found that attackers attempt access within an average of 17 minutes when AWS credentials are exposed publicly, and as quickly as 9 minutes in some cases.
A question worth separating out:
Q: How can organisations measure whether local AI is under control?
A: Organisations should measure whether they can link installed local tools to named users, approved device groups, and documented policy decisions. If a local AI app appears in the estate without an owner, a review status, or a recorded business purpose, the programme still has an unmanaged exposure.
👉 Read our full editorial: Device-based AI and SaaS discovery closes local shadow IT gaps
Endpoint-based software discovery is now a governance requirement, not a convenience feature. Browser-centric inventory models assume the application is visible through web traffic or IdP events. That assumption fails when the software is a native desktop client or a local AI tool that runs on the device itself. The implication is that software inventory, compliance evidence, and AI governance now depend on endpoint telemetry as much as cloud telemetry.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
Q: When should organisations treat an agentic browser as an endpoint risk?
A: When the browser can run tasks locally, access sensitive pages, or interact with data outside the normal cloud control path, it should be governed like endpoint software rather than a simple web client. That changes allowlisting, monitoring, and approval decisions.
👉 Read our full editorial: Device-based AI and SaaS discovery closes local shadow IT gaps