LESSON · 15 SEPTEMBER 2026
How to read an endpoint AI control score
The verdict
Each tool gets a 0-10 score on seven criteria from public material, and the total is a weighted average using weights we publish. The total answers one question, how well a tool documents control over AI agents on employee devices, so read the criterion rows against your own priorities and re-weight them in the calculator if they differ.
By Best AI Security editors · 15 September 2026 · 2 min read
What does the total measure?
The endpoint AI control score measures how well a tool documents visibility and control over AI agents, coding assistants and MCP servers on the devices employees use. It is not a measure of overall product quality. A tool built mainly for SaaS or cloud AI apps can be very good at that job and still score lower here, because the rubric weights the endpoint.
What are the seven criteria?
- Endpoint and agent visibility, 22%: Discovery of AI agents, coding assistants, MCP servers, extensions, tools and exposed credentials on devices, fleet-wide.
- MCP and tool-call control, 20%: Ability to evaluate and stop an individual tool call or MCP connection before it runs, not only to list it.
- Policy granularity, 15%: Rules that use context (user, agent, prior actions, data touched) and actions beyond allow/deny, such as ask, warn, mask or simulate.
- Agent vs human identity and audit, 12%: Whether the tool records who triggered an action, whether a person was involved, and the chain from prompt to system action.
- Deployment footprint, 13%: How the tool reaches devices; credit for deploying through existing EDR or MDM without a new resident agent, and for published deployment detail.
- Coverage beyond the endpoint, 8%: SaaS agents, cloud and homegrown AI apps, browser AI, red teaming.
- Maturity and transparency, 10%: Time in market, public documentation, compliance attestations, backing, and whether pricing is published.
How is the total calculated?
Each criterion score is multiplied by its weight, the results are added, and the sum is divided by 100. Totals are shown to one decimal. Tools with the same one-decimal total share a rank, shown as "=3", and are listed alphabetically. The site computes every total from one score table, so a number on a review page, a comparison and the rankings cannot disagree.
Worked example, Bay: 9 x 22 + 9 x 20 + 9 x 15 + 8 x 12 + 9 x 13 + 4 x 8 + 3 x 10 = 788, divided by 100 = 7.88, shown as 7.9.
How should you read a low row?
Read the reason before the number. Many low scores on this site say "Not published" or "not described on the pages we reviewed". That means the public evidence is thin, not that the capability is proven absent. Bay's 3 on maturity, for example, reflects two blog posts, no public documentation portal and no published pricing. Bloom Security's 4 on deployment footprint reflects a deployment method that is not published. Both are questions to ask in a demo; see how to read vendor claims.
What if your priorities differ?
Change the weights. The score calculator lets you set each weight from 0 to 30 and re-ranks all nine tools in your browser. If your agents mostly run in SaaS platforms, raise coverage beyond the endpoint; if procurement weighs vendor history heavily, raise maturity. The side-by-side comparison shows every criterion score and reason for up to five tools, and each tool has an alternatives page, such as Bay alternatives.
Next lesson
Related
Sources
- How we score · Reviewed Sep 2026
- Score calculator · Reviewed Sep 2026