Opens in a new tab
vmblog logo 2024 wht (updated)

Who’s Watching the Agents? Omnissa Answers with Elara, and a New CEO Who Plans to Make Some Noise

Share: 

David Marshall | Published: September 29, 2026
omnissaone 2026 ai agents

At Omnissa ONE 2026 in Orlando, the company introduced a standalone AI governance product, put a new chief executive on stage, and made the case that “end user computing” no longer describes what it does.

ORLANDO, Fla. – Most keynotes open with a sizzle reel. This one opened with a handoff. Before a single product slide appeared, Omnissa told a packed room that its previous CEO had stepped down after taking the company through its first two years as an independent business. Then it walked out his replacement: Amit Singh.

Singh’s résumé reads like a tour of the companies that built the modern enterprise stack. Oracle early on, then Google Cloud (he calls himself one of its founders), then president at Palo Alto Networks. His last two years, though, had nothing to do with any of that. He spent them teaching kids breathwork and meditation through a free app called Bliss.

“I felt this calling to go help young people as they prepared for the world of AI.” — Amit Singh, CEO, Omnissa

I’ll be straight with you. I go to a lot of these events, and most keynotes are a tidy recap of the last six months. This one left me with a notebook full of things I didn’t know were coming, and the biggest of them had nothing to do with desktops.

A CEO with a one-page thesis

Singh’s pitch fits in a single breath: agents are landing on endpoints, and somebody has to make that manageable and secure. He pointed to a Qualcomm chip announced the day before that can run a 30-billion-parameter small language model on a phone as a sign that AI is moving onto the device itself. Some of those agents will be baked into software you already run. Others will be tools like Claude Code, and others still will be consumer agents logged into a personal account on a company laptop.

He also told a Hugging Face story, describing a swarm of agents that took over servers and formed something like its own society before OpenAI shut it down. I can’t vouch for the details, and he told it as a story, not a briefing. The point landed anyway: attackers now have agents too, and patching is no longer a boring maintenance chore.

So why Omnissa? Singh’s answer came down to geography.

“What is the one place that is fully in your control as companies that are running these endpoints? The endpoint itself. That is the last mile.”

From that he built a simple framework, and Chief Product Officer Bharath Rangarajan repeated it almost word for word when I sat down with him later. Agents need a safe place to run. Attacks at machine speed need remediation at machine speed. And someone has to provide a governance layer that says what’s allowed. This story is about that third piece.

The accountability gap

Here’s the tension Omnissa is trying to solve. Employees want to use AI everywhere, and IT wants them to be productive. Yet nobody in IT can say with a straight face what those tools are doing.

Omnissa’s own State of the Digital Workspace report found AI assistant usage across enterprise endpoints grew nearly 1,000% year over year, with about three-quarters of it coming from unsanctioned tools. A second Omnissa finding, released alongside the Elara news, put unsanctioned AI tools on 75% of enterprise-managed devices. Different cuts of the data, same uncomfortable shape.

Jeff McGrath, vice president of product marketing at Omnissa, has a name for the problem. He described it to me in this way:

“There’s this gap we call the accountability gap, between the demand for increased autonomy for your employees to use agents and AI to the fullest, but also balancing that with managed risk.”

Then there’s the money side, which anyone who lived through early cloud adoption will recognize. McGrath compared it to a company opening that first Azure bill and nearly passing out. Now it’s the same feeling, only with AI tokens: someone burns through the month’s Claude budget in the first week, and nobody can say whether it was business work, personal errands, or a runaway script. Honestly, I hear this complaint from nearly every company I talk to about AI. They love what their people are getting out of it. They have no idea what it costs or who’s spending.

Meet Elara

Omnissa’s answer is Elara, a new product family introduced on stage by Brian Link, who leads the product. The company calls it a unified authority layer for AI governance and high-impact actions. Link’s shorter version was better.

“I want to give you control before consequence.”

Elara launches in beta with four capabilities:

  1. Shadow AI detection: discover AI apps, models, agents and tools across the enterprise, including anything outside approved inventories.
  2. Usage guardrails: the Omnissa AI Gateway authorizes model access, applies guardrails and meters token consumption across providers.
  3. Change control: high-impact changes get checked for conflicts, freezes and dependencies before they run.
  4. Audit-ready evidence: a replayable record of what happened, who approved it and what it touched.

The demo on stage was where it got real.

Catching the AI nobody approved

In the Shadow AI view, Link showed a list of discovered AI applications, marked as reviewed or not. OpenClaw was running in his demo environment, unapproved. One click marked it unsanctioned, and another turned that decision into policy: block it, allow it on a few devices, or just monitor. The same page surfaced device signals, including a flag on a possible attempt to override an agent’s instructions, and Link could open the whole session, from the first prompt through every tool call.

An agent registry sits alongside this. It lists what each agent can reach: hooks, extensions, plugins, MCP servers. If someone builds a useful skill, an admin can promote it into the registry for evaluation. If not, restrict it. Link was careful about the tone here.

“I’m not trying to tell you what AI you should or shouldn’t use. What I want to do is give you the visibility to understand what’s happening, the context to decide what you trust, and the ability to govern it.”

The gateway piece handles the cost problem. It shows requests, tokens, spend, providers and models, and lets admins set budgets. Link also made a point I wish more vendors made: most workloads don’t need the priciest model, so route them to smaller, cheaper ones and save the big guns for the teams that need them.

The iPad problem

The change management demo was my favorite, mostly because it showed a decision no single tool could make. Security wants to push an OS update to retail iPads because a vulnerability is being exploited right now. Normally that’s an easy approval. But Elara pulled in a change freeze from ServiceNow: those stores are in the middle of an inventory count, and those same iPads run the inventory app.

So it’s suddenly a business decision, not just a security one. Before approving, the admin can open an impact canvas showing how many devices, users and services the change would touch. Approve it, and that decision flows straight into execution.

The last demo closed the loop. Elara had caught an agent whose prompt appeared to contain an API key. Zoom out, and the pattern got worse: attempts to override instructions, use of unapproved tools, an attempt to pipe a download straight into a shell, and reads of a file that usually holds credentials. Each signal alone was mildly worrying. Together, as Link put it, they told a story, and I’d rather read that story in a replay than in an incident report.

Standalone, on purpose

Here’s something I missed during the keynote, and I suspect plenty of attendees did too. Elara doesn’t need the rest of Omnissa’s stack. Not Workspace ONE, not Horizon, not the digital employee experience tooling. McGrath was direct about it.

The connectors Link mentioned reach into other endpoint management tools like Intune, along with identity, security, experience and ITSM platforms. McGrath added that customers could be running Citrix or Nutanix underneath, and Elara would still work. When I asked Rangarajan about it, he said independence was a design point from the start.

That raises the obvious question: what will it cost? And when will it GA?

Cost and how it will be packaged – stay tuned.

Timing is a little clearer. McGrath expects Elara to reach general availability in the first half of next year, somewhere around the end of Q1 or in Q2. For now, customers can take a tour of Elara and join the beta waitlist.

One more detail I liked: Rangarajan said Elara was built the way an AI-first company would build it, with the product manager, designer and engineers all checking code into the same GitHub repo. The company is using AI across engineering, plus Salesforce, RFPs, technical docs and marketing, though he admits there’s still a way to go.

What an airline wants from it

Vendors love a friendly customer on stage, but the one from United Airlines gave the most useful answer of the morning. He’s a principal architect at United, responsible for something like 200,000 endpoints, around 2,000 applications, and more than a million automations a year. On top of that, his teams are now building agents, and lots of them.

On the keynote stage, United Airline’s Principal Architect said, “Do I know what it’s really doing? I see reports of ‘yeah, we put this out there, it’s working great.’ Do I know where else I can apply this?”

He framed United’s approach as “human plus AI,” a partnership where operational reliability comes first and a person makes the call. He first came to Elara for the audit and replay capabilities, then realized the agent registry mattered more once he saw how many agents his teams and neighboring teams had built. There are teams, he said, where he doesn’t have true visibility at all.

Not your father’s EUC company

Step back and the Elara news fits into a bigger identity shift. Omnissa now calls itself “the platform leader for governing digital work,” where a couple of years ago the pitch was end user computing. I asked Rangarajan what that change means for how the company builds.

“The concept of end user computing, to me, is going to become limiting. Do you consider agent users as endpoints? I think this concept of an agent as an endpoint is coming up too,” said Rangarajan.

He described a customer building a portal-style application instead of a chatbot: it runs in Chrome, but it acts like an agent and orchestrates work on your behalf. Some endpoints, like headless kiosks, may not have a person anywhere near them.

Independence has helped with that. Rangarajan says the carve-out from Broadcom is complete. Yet, unlike others, Omnissa still has specialized licensing so it can keep selling Horizon where vSphere is needed. Everything else is done, which opens doors that were once taboo. The Nutanix partnership is the obvious example. Channel partners are another, since the old VMware program required a big vSphere commitment and shut out frontline-device specialists.

Two misconceptions still linger. People still lump Omnissa in with Broadcom and VMware, and others think of it as merely an MDM company.

“We need a bigger megaphone,” said Rangarajan. He was smiling when he said it, but he meant it. Marketing budgets have been modest, and he expects Singh, who “likes to go big,” to change that.

But from my viewpoint, this event, Omnissa ONE, is doing a pretty good job of changing minds. It certainly has given me a new perspective.

Where this leaves us

Will Elara work as advertised? It’s a beta, the pricing is unsettled, and the company is asking customers to help shape it. Those are fair reasons to hold your enthusiasm in check.

Still, the problem is real, and this is the first product I’ve seen from an EUC vendor that treats AI governance as its own job, separate from any one management console. Rangarajan says demand for agents and Elara is “off the charts,” and that getting both into customers’ hands is priority number one for next year’s show.

Color me intrigued so far, and I can’t wait to see what the final product looks like.

##