September 2026 Pre-Release Notes

Last updated: October 2, 2026

This is a preview of the September release. Scope and timing can change before it ships. Final release notes will follow once the release is live.

Theme: Governing the Action, Not Just the Access

Lumos has always governed who has access. This release extends that to what happens after access is granted, starting with the tool calls your employees' AI agents make.

Expected highlights

  • MCP Governance [BETA]: See and control every tool call your AI agents make

  • Remediation Workflows: Fix Identity Intelligence findings from the issue itself

  • Jira Service Management Assignable Lumos Agent: Assign access tickets to Lumos

  • Account Finder Performance: Faster syncs, especially for large tenants

  • Connector updates: Six improved connectors and two new beta connectors

🛡 Intelligence & AI

MCP Governance [BETA]

MCP Governance sits in the path of every tool call an employee's AI agent makes. It logs each call against the person who ran it and returns allow or deny before the call runs.

What's new:

  • Support for Claude Code (including in Claude Desktop) and Codex

  • Inventory of every MCP server in use, including ones added locally

  • Per-tool allow or deny policies, including one-click Allow reads or Block writes

  • Albus answers questions about call history and drafts policies for your approval

Benefits:

  • See which agents touch which systems, and who is behind each call

  • Block a risky tool without blocking the whole server

Beta access is expected to open at the end of October through your CSM. The default policy is Allow, so nothing is blocked until you add a policy. Lumos never stores prompts, model responses or tool results.

Remediation Workflows

Each Identity Intelligence issue can now carry a fix that the agent builds for you. You review it, edit it if needed, and run it from the issue.

What's new:

  • Work status for each remediation, with cancel and retry

  • One run that fixes every open sub-issue under a parent

  • Manual task and notification steps for apps Lumos can't write to

Benefits:

  • Go from finding to fix in one place

  • Keep a person in every decision: the agent drafts, you launch

Available behind a feature flag. Reach out to your CSM to turn it on.

🔌 Integrations

Jira Service Management Assignable Lumos Agent

Assign an access ticket in Jira Service Management to Lumos. Lumos submits the request and keeps the ticket updated through approval and provisioning.

What's new:

  • Lumos Agent in the Jira Service Management assignee dropdown

  • Status comments on the ticket, and the ticket closes automatically when the request is done

  • Ticket link on the request, so approvers see where it came from

Benefits:

  • Stop re-entering access tickets in a second tool

  • Keep the ticket as your audit record

Available now in preview, with the announcement expected October 7. It requires the Lumos Forge app and the Lumos Jira integration. Help Center article

Account Finder Performance

Account Finder, the sync step that finds the accounts in your connected apps, now saves results in bulk. Large tenants see processing drop from hours to minutes, with fewer failed runs.

This is already live for every customer, with no setup and no change to results. Google Cloud and Microsoft Entra ID see the biggest drop in total sync time.

Existing Connector Improvements

  • Microsoft Entra ID: deprovision a user from all groups in one action

  • Lucid: detailed user roles

  • Snowflake: sync emails and names with read-only permissions

  • GitHub: support for OAuth refresh tokens

  • SAP ECC [BETA]: write capabilities

  • Tableau [BETA]: multiple authentication methods

The Entra, Lucid, Snowflake and GitHub updates apply to existing connections automatically. For SAP ECC and Tableau beta access, reach out to your CSM.

New Connectors [BETA]

  • Anthropic and Active Directory (AD) integrations for your non-human identity inventory

Available in Beta once the release ships. Reach out to your CSM to participate.