August 2026 Pre-Release Notes

Last updated: August 20, 2026

This is a preview of what Lumos is planning for the August release. Scope and timing can change before the release ships, and items marked [TARGETED] are not yet confirmed. Final release notes will follow once the release is live.

Expected highlights

  • Sync Circuit Breakers: Stop bad upstream data before it removes access

  • Multi-System ITSM Routing: Send each request to the right ITSM system

  • Lifecycle Management on Account Workflows: Configure a workflow once, reuse it everywhere

  • Access Review Removals on Account Workflows: Retry a failed removal instead of chasing it

  • Access Reviews via MCP: Create, scope, and launch reviews from your agent

  • One New Integration: SAP ECC

  • Non-Human Identity Inventory [BETA] [TARGETED]: One owned list of every service identity

  • Multiple Offboarding Workflows [TARGETED]: Pick a pre-built termination playbook by name

  • Policy Drafts [TARGETED]: Edit a live policy without changing access

🛡 Intelligence & AI

Non-Human Identity Inventory [BETA] [TARGETED]

A single inventory of every non-human identity in your environment: service accounts, service principals, API identities, and workload roles, pulled from your connected systems into one list. Each identity can be assigned an owner and a business justification, so there's a named person accountable for it.

What's new:

  • One table of non-human identities across all connected sources

  • Assign an owner and business justification to any identity

  • Per-identity detail view showing its accounts and entitlements

  • Integrations: AWS, Entra ID, and OpenAI inventory

Planned as a Beta, and the date is the open question rather than the scope. Reach out to your CSM to participate once it lands.

✅ Access Reviews

Access Review Removals on Account Workflows

When a reviewer rejects access, Lumos has been running its own removal logic inside Access Reviews. That work moves onto the same account workflow platform that already powers the App Store and Lifecycle Management. In campaign setup, the single default removal method becomes a picker listing the deprovisioning workflows you already configured for that app, and removals gain the platform's error handling, retries, and audit trail.

What's new:

  • Pick a configured deprovisioning workflow per app during campaign setup

  • Choose a removal method per entitlement: automated, manual, or webhook

  • Merged apps route each entitlement to the workflow matching its source

  • Failed removals become actionable error tasks in the review and Task Center

  • Attach evidence to a removal: file, link, or auto-linked ITSM ticket

  • Live workflow record inside the review showing every step

Benefits:

  • Get the same removal behavior in reviews as everywhere else in Lumos

  • Reuse deprovisioning workflows you already built instead of configuring twice

  • Catch failed removals as visible tasks instead of silent failures

  • Close an audit with evidence and ticket links attached to the removal

Two changes to note: the default removal method setting in campaign setup is replaced by the workflow picker, and app admins and removers now receive notifications for error tasks, manual tasks, and evidence uploads that Lumos did not send before. ITSM tickets are created automatically for error and manual tasks.

Access Reviews via MCP

Access review campaigns can currently only be set up by clicking through Lumos. This release exposes the create, scope, assign, and launch path through the Lumos MCP server, so an admin can drive review setup from an AI agent instead. Permissions and audit logging work exactly as they do in the interface.

What's new:

  • Create a User Access Review (UAR) campaign from an MCP-enabled agent

  • Add scoped app reviews and re-sync with scope filters

  • Assign reviewers individually or in bulk

  • Assign by shortcut: app admin, permission owner, or manager

  • Launch a review with an optional custom note

Benefits:

  • Set up a campaign in one agent conversation instead of a UI session

  • Script review creation instead of repeating it by hand

  • Keep the same permissions and Activity Log entries as the interface

  • Build agent-driven patterns like risk-triggered certifications

Requires a Lumos MCP server connection.

My Tasks Filter Across Access Reviews

The All / My Tasks toggle that exists inside a single app review now appears two levels up: on the Access Reviews index page and on each individual campaign. An admin who is also a reviewer can see what needs their action without opening app reviews one at a time.

What's new:

  • All / My Tasks toggle on the Access Reviews index page

  • Same toggle within a single campaign, spanning its reviews

  • My Tasks filters to items where you are directly a reviewer

Benefits:

  • Separate your own review work from program oversight in one click

  • Stop clicking into app reviews to find your assignments

  • Get the same filtering pattern at every level of Access Reviews

The default stays All at every level, so nothing changes until you switch it.

🔄 Lifecycle Management

Lifecycle Management on Account Workflows

Onboarding, Movers, and Offboarding all move onto the same shared account workflow engine that already powers the App Store and Access Reviews. Instead of rebuilding the same provisioning or deprovisioning steps separately per product, you configure a workflow once per app and every stage reuses it. Offboarding gains error tasks, retries, and workflow records it did not have before.

What's new:

  • All three lifecycle stages resolve workflows from one Account Workflows table

  • Existing offboarding configuration migrates automatically off the Integrations tab

  • Fallback to the app's default workflow when none is set for a product

  • Per-account workflow override at offboarding time

  • Failed removals surface as actionable error tasks with retries

  • Every run produces a workflow record

Benefits:

  • Configure an app once and reuse it across every lifecycle stage

  • Catch failed offboarding removals instead of letting them slip through

  • Audit manual and failed removals in one place

  • Maintain less duplicate configuration

Two changes to note: offboarding configuration moves off the Integrations tab, and Lumos no longer notifies the affected employee on lifecycle-driven changes. Approver, manager, admin, and ITSM notifications are unchanged. Phased rollout.

Multiple Offboarding Workflows [TARGETED]

Lumos currently supports one offboarding workflow for the whole company, so whoever runs a manual termination decides app by app what to cut off, under time pressure. This lets you pre-build several named offboarding workflows, each with its own apps in scope and per-app action, and pick the right one by name at termination time.

What's new:

  • Library of named offboarding workflows in Lifecycle Management settings

  • Apps in scope set by condition builder, with per-app action overrides

  • Workflow picker in the manual offboarding dialog

Scope for the initial release is still being finalized. Your current offboarding configuration becomes the default workflow, so existing behavior continues unless you build new ones.

🧱 Platform

ITSM Configuration and Multi-System Routing

Lumos today allows one ITSM connection per tenant. This release lets you connect several at once and decide which requests go where. Set routing broadly for the whole tenant, then override it for a specific app, workflow, or task, and map Lumos states to your ITSM's statuses so ticket status stays in sync.

What's new:

  • Connect multiple ITSM systems in one tenant

  • Routing rules at tenant, app, workflow, or task level

  • Conditional rules for when, where, and with what fields tickets are created

  • Inbound sync for Jira, ServiceNow, Zendesk, and Freshworks

  • Closing a ticket in your ITSM resolves the matching Lumos task

  • Pre-production validation that surfaces ITSM error codes before go-live

  • Manual-only ticketing where you don't want automation

Benefits:

  • Route requests to the right queue without custom code or webhooks

  • Catch misconfiguration before production instead of failing silently

  • Keep one source of truth for task state wherever it was actioned

  • Adopt Lumos workflows without moving teams off their ITSM

Existing single-connection setups keep working; multiple configurations are additive.

Access Request Workflow Records

A complete record of what happened to an access request: every approval, provisioning action, and notification step, with status, timestamp, actor, and error detail. Instead of reconstructing a stuck request from the Activity Log, you open its record and see where it stopped and why.

What's new:

  • Visual workflow showing every step and its status

  • Step-level detail: actor, timestamp, outcome, and notes

  • Error detail and troubleshooting context on failed steps

  • Elapsed time per step and across the full request

  • Search and filter records by requester, app, date, or status

Benefits:

  • Find a stuck request in minutes without opening a support ticket

  • Show an auditor the full approval chain for any request

  • See which approval stages are slowing your requests down

No configuration required. Records populate automatically for new requests.

Policy Drafts from Published Policies [TARGETED]

Editing a live access policy in Lumos changes real access the moment you save, with no review step. This adds draft versions for already-published policies: branch a draft, edit and review it while the current version keeps enforcing, then publish to replace it.

What's new:

  • Create a draft of a published policy without touching live enforcement

  • Draft states move from Work in Progress to Ready to Publish

  • Comments and sharing on drafts, linked back to the published version

Scope for the initial release is still being finalized. If it lands, policy deletion also becomes a soft delete, so published versions are retained for audit.

🔌 Integrations

Sync Circuit Breakers

Circuit breakers watch your upstream identity sources and halt a sync when the incoming data looks wrong, so a bad export from an HR system or identity provider doesn't propagate into Lumos and downstream apps. Four breakers move from Beta to general availability with this release, on by default for every customer and every connected app, with thresholds you manage yourself.

What's new:

  • Mass account deactivation breaker trips at 50% of active accounts

  • Mass account absence breaker trips at 50% absent

  • Mass identity deactivation breaker trips at 50% of active identities

  • Empty account response breaker trips on any zero-account response

  • Domain-wide defaults in settings, with per-app overrides on each integration

  • Every configuration change requires a reason and is written to the audit trail

Benefits:

  • Prevent mass-offboarding and mass-lockout events caused by bad source data

  • Stop truncated or empty API responses from reading as "remove everything"

  • Change a threshold yourself instead of opening a support ticket

  • Override a rule for an app that legitimately returns zero accounts

Defaults apply domain-wide and take effect at each app's next sync. If you run an app that legitimately returns zero accounts, turn that rule off for that app before the release or its syncs will halt.

New Integrations

One new integration you can connect from the Lumos Integrations page with provisioning capabilities.

What's new:

  • SAP ECC 6.0

Benefits:

  • Extend coverage to legacy SAP estates

  • Run provisioning actions in Lumos ahead of identity provider work

Nothing connects until an admin sets it up.

Existing Connector Improvements

A batch of enhancements to integrations Lumos already supports, each one deepening what an existing connector can see or do.

What's new:

  • GitHub: connect all organizations inside an enterprise

  • AWS: script to connect multiple accounts programmatically

  • SAP Concur: choose a primary and secondary approver for spend management`

  • HashiCorp Vault: provisioning now supported for entitlements

  • 1Password: human-readable entitlement descriptions now sync

  • Gong: optional setting to sync last activity

Benefits:

  • Cover more use cases on connectors you already run

  • Cut manual setup for multi-account and multi-organization estates

  • Read clearer entitlement names in reviews and requests

If you use 1Password, entitlement names will display differently after this release.