September 2026 Pre-Release Notes
Last updated: October 2, 2026
This is a preview of the September release. Scope and timing can change before it ships. Final release notes will follow once the release is live.
Theme: Governing the Action, Not Just the Access
Lumos has always governed who has access. This release extends that to what happens after access is granted, starting with the tool calls your employees' AI agents make.
Expected highlights
MCP Governance [BETA]: See and control every tool call your AI agents make
Remediation Workflows: Fix Identity Intelligence findings from the issue itself
Jira Service Management Assignable Lumos Agent: Assign access tickets to Lumos
Account Finder Performance: Faster syncs, especially for large tenants
Connector updates: Six improved connectors and two new beta connectors
🛡 Intelligence & AI
MCP Governance [BETA]
MCP Governance sits in the path of every tool call an employee's AI agent makes. It logs each call against the person who ran it and returns allow or deny before the call runs.
What's new:
Support for Claude Code (including in Claude Desktop) and Codex
Inventory of every MCP server in use, including ones added locally
Per-tool allow or deny policies, including one-click Allow reads or Block writes
Albus answers questions about call history and drafts policies for your approval
Benefits:
See which agents touch which systems, and who is behind each call
Block a risky tool without blocking the whole server
Beta access is expected to open at the end of October through your CSM. The default policy is Allow, so nothing is blocked until you add a policy. Lumos never stores prompts, model responses or tool results.
Remediation Workflows
Each Identity Intelligence issue can now carry a fix that the agent builds for you. You review it, edit it if needed, and run it from the issue.
What's new:
Work status for each remediation, with cancel and retry
One run that fixes every open sub-issue under a parent
Manual task and notification steps for apps Lumos can't write to
Benefits:
Go from finding to fix in one place
Keep a person in every decision: the agent drafts, you launch
Available behind a feature flag. Reach out to your CSM to turn it on.
🔌 Integrations
Jira Service Management Assignable Lumos Agent
Assign an access ticket in Jira Service Management to Lumos. Lumos submits the request and keeps the ticket updated through approval and provisioning.
What's new:
Lumos Agent in the Jira Service Management assignee dropdown
Status comments on the ticket, and the ticket closes automatically when the request is done
Ticket link on the request, so approvers see where it came from
Benefits:
Stop re-entering access tickets in a second tool
Keep the ticket as your audit record
Available now in preview, with the announcement expected October 7. It requires the Lumos Forge app and the Lumos Jira integration. Help Center article
Account Finder Performance
Account Finder, the sync step that finds the accounts in your connected apps, now saves results in bulk. Large tenants see processing drop from hours to minutes, with fewer failed runs.
This is already live for every customer, with no setup and no change to results. Google Cloud and Microsoft Entra ID see the biggest drop in total sync time.
Existing Connector Improvements
Microsoft Entra ID: deprovision a user from all groups in one action
Lucid: detailed user roles
Snowflake: sync emails and names with read-only permissions
GitHub: support for OAuth refresh tokens
SAP ECC [BETA]: write capabilities
Tableau [BETA]: multiple authentication methods
The Entra, Lucid, Snowflake and GitHub updates apply to existing connections automatically. For SAP ECC and Tableau beta access, reach out to your CSM.
New Connectors [BETA]
Anthropic and Active Directory (AD) integrations for your non-human identity inventory
Available in Beta once the release ships. Reach out to your CSM to participate.