August 2026 Pre-Release Notes
Last updated: August 20, 2026
This is a preview of what Lumos is planning for the August release. Scope and timing can change before the release ships, and items marked [TARGETED] are not yet confirmed. Final release notes will follow once the release is live.
Expected highlights
Sync Circuit Breakers: Stop bad upstream data before it removes access
Multi-System ITSM Routing: Send each request to the right ITSM system
Lifecycle Management on Account Workflows: Configure a workflow once, reuse it everywhere
Access Review Removals on Account Workflows: Retry a failed removal instead of chasing it
Access Reviews via MCP: Create, scope, and launch reviews from your agent
One New Integration: SAP ECC
Non-Human Identity Inventory [BETA] [TARGETED]: One owned list of every service identity
Multiple Offboarding Workflows [TARGETED]: Pick a pre-built termination playbook by name
Policy Drafts [TARGETED]: Edit a live policy without changing access
🛡 Intelligence & AI
Non-Human Identity Inventory [BETA] [TARGETED]
A single inventory of every non-human identity in your environment: service accounts, service principals, API identities, and workload roles, pulled from your connected systems into one list. Each identity can be assigned an owner and a business justification, so there's a named person accountable for it.
What's new:
One table of non-human identities across all connected sources
Assign an owner and business justification to any identity
Per-identity detail view showing its accounts and entitlements
Integrations: AWS, Entra ID, and OpenAI inventory
Planned as a Beta, and the date is the open question rather than the scope. Reach out to your CSM to participate once it lands.
✅ Access Reviews
Access Review Removals on Account Workflows
When a reviewer rejects access, Lumos has been running its own removal logic inside Access Reviews. That work moves onto the same account workflow platform that already powers the App Store and Lifecycle Management. In campaign setup, the single default removal method becomes a picker listing the deprovisioning workflows you already configured for that app, and removals gain the platform's error handling, retries, and audit trail.
What's new:
Pick a configured deprovisioning workflow per app during campaign setup
Choose a removal method per entitlement: automated, manual, or webhook
Merged apps route each entitlement to the workflow matching its source
Failed removals become actionable error tasks in the review and Task Center
Attach evidence to a removal: file, link, or auto-linked ITSM ticket
Live workflow record inside the review showing every step
Benefits:
Get the same removal behavior in reviews as everywhere else in Lumos
Reuse deprovisioning workflows you already built instead of configuring twice
Catch failed removals as visible tasks instead of silent failures
Close an audit with evidence and ticket links attached to the removal
Two changes to note: the default removal method setting in campaign setup is replaced by the workflow picker, and app admins and removers now receive notifications for error tasks, manual tasks, and evidence uploads that Lumos did not send before. ITSM tickets are created automatically for error and manual tasks.
Access Reviews via MCP
Access review campaigns can currently only be set up by clicking through Lumos. This release exposes the create, scope, assign, and launch path through the Lumos MCP server, so an admin can drive review setup from an AI agent instead. Permissions and audit logging work exactly as they do in the interface.
What's new:
Create a User Access Review (UAR) campaign from an MCP-enabled agent
Add scoped app reviews and re-sync with scope filters
Assign reviewers individually or in bulk
Assign by shortcut: app admin, permission owner, or manager
Launch a review with an optional custom note
Benefits:
Set up a campaign in one agent conversation instead of a UI session
Script review creation instead of repeating it by hand
Keep the same permissions and Activity Log entries as the interface
Build agent-driven patterns like risk-triggered certifications
Requires a Lumos MCP server connection.
My Tasks Filter Across Access Reviews
The All / My Tasks toggle that exists inside a single app review now appears two levels up: on the Access Reviews index page and on each individual campaign. An admin who is also a reviewer can see what needs their action without opening app reviews one at a time.
What's new:
All / My Tasks toggle on the Access Reviews index page
Same toggle within a single campaign, spanning its reviews
My Tasks filters to items where you are directly a reviewer
Benefits:
Separate your own review work from program oversight in one click
Stop clicking into app reviews to find your assignments
Get the same filtering pattern at every level of Access Reviews
The default stays All at every level, so nothing changes until you switch it.
🔄 Lifecycle Management
Lifecycle Management on Account Workflows
Onboarding, Movers, and Offboarding all move onto the same shared account workflow engine that already powers the App Store and Access Reviews. Instead of rebuilding the same provisioning or deprovisioning steps separately per product, you configure a workflow once per app and every stage reuses it. Offboarding gains error tasks, retries, and workflow records it did not have before.
What's new:
All three lifecycle stages resolve workflows from one Account Workflows table
Existing offboarding configuration migrates automatically off the Integrations tab
Fallback to the app's default workflow when none is set for a product
Per-account workflow override at offboarding time
Failed removals surface as actionable error tasks with retries
Every run produces a workflow record
Benefits:
Configure an app once and reuse it across every lifecycle stage
Catch failed offboarding removals instead of letting them slip through
Audit manual and failed removals in one place
Maintain less duplicate configuration
Two changes to note: offboarding configuration moves off the Integrations tab, and Lumos no longer notifies the affected employee on lifecycle-driven changes. Approver, manager, admin, and ITSM notifications are unchanged. Phased rollout.
Multiple Offboarding Workflows [TARGETED]
Lumos currently supports one offboarding workflow for the whole company, so whoever runs a manual termination decides app by app what to cut off, under time pressure. This lets you pre-build several named offboarding workflows, each with its own apps in scope and per-app action, and pick the right one by name at termination time.
What's new:
Library of named offboarding workflows in Lifecycle Management settings
Apps in scope set by condition builder, with per-app action overrides
Workflow picker in the manual offboarding dialog
Scope for the initial release is still being finalized. Your current offboarding configuration becomes the default workflow, so existing behavior continues unless you build new ones.
🧱 Platform
ITSM Configuration and Multi-System Routing
Lumos today allows one ITSM connection per tenant. This release lets you connect several at once and decide which requests go where. Set routing broadly for the whole tenant, then override it for a specific app, workflow, or task, and map Lumos states to your ITSM's statuses so ticket status stays in sync.
What's new:
Connect multiple ITSM systems in one tenant
Routing rules at tenant, app, workflow, or task level
Conditional rules for when, where, and with what fields tickets are created
Inbound sync for Jira, ServiceNow, Zendesk, and Freshworks
Closing a ticket in your ITSM resolves the matching Lumos task
Pre-production validation that surfaces ITSM error codes before go-live
Manual-only ticketing where you don't want automation
Benefits:
Route requests to the right queue without custom code or webhooks
Catch misconfiguration before production instead of failing silently
Keep one source of truth for task state wherever it was actioned
Adopt Lumos workflows without moving teams off their ITSM
Existing single-connection setups keep working; multiple configurations are additive.
Access Request Workflow Records
A complete record of what happened to an access request: every approval, provisioning action, and notification step, with status, timestamp, actor, and error detail. Instead of reconstructing a stuck request from the Activity Log, you open its record and see where it stopped and why.
What's new:
Visual workflow showing every step and its status
Step-level detail: actor, timestamp, outcome, and notes
Error detail and troubleshooting context on failed steps
Elapsed time per step and across the full request
Search and filter records by requester, app, date, or status
Benefits:
Find a stuck request in minutes without opening a support ticket
Show an auditor the full approval chain for any request
See which approval stages are slowing your requests down
No configuration required. Records populate automatically for new requests.
Policy Drafts from Published Policies [TARGETED]
Editing a live access policy in Lumos changes real access the moment you save, with no review step. This adds draft versions for already-published policies: branch a draft, edit and review it while the current version keeps enforcing, then publish to replace it.
What's new:
Create a draft of a published policy without touching live enforcement
Draft states move from Work in Progress to Ready to Publish
Comments and sharing on drafts, linked back to the published version
Scope for the initial release is still being finalized. If it lands, policy deletion also becomes a soft delete, so published versions are retained for audit.
🔌 Integrations
Sync Circuit Breakers
Circuit breakers watch your upstream identity sources and halt a sync when the incoming data looks wrong, so a bad export from an HR system or identity provider doesn't propagate into Lumos and downstream apps. Four breakers move from Beta to general availability with this release, on by default for every customer and every connected app, with thresholds you manage yourself.
What's new:
Mass account deactivation breaker trips at 50% of active accounts
Mass account absence breaker trips at 50% absent
Mass identity deactivation breaker trips at 50% of active identities
Empty account response breaker trips on any zero-account response
Domain-wide defaults in settings, with per-app overrides on each integration
Every configuration change requires a reason and is written to the audit trail
Benefits:
Prevent mass-offboarding and mass-lockout events caused by bad source data
Stop truncated or empty API responses from reading as "remove everything"
Change a threshold yourself instead of opening a support ticket
Override a rule for an app that legitimately returns zero accounts
Defaults apply domain-wide and take effect at each app's next sync. If you run an app that legitimately returns zero accounts, turn that rule off for that app before the release or its syncs will halt.
New Integrations
One new integration you can connect from the Lumos Integrations page with provisioning capabilities.
What's new:
SAP ECC 6.0
Benefits:
Extend coverage to legacy SAP estates
Run provisioning actions in Lumos ahead of identity provider work
Nothing connects until an admin sets it up.
Existing Connector Improvements
A batch of enhancements to integrations Lumos already supports, each one deepening what an existing connector can see or do.
What's new:
GitHub: connect all organizations inside an enterprise
AWS: script to connect multiple accounts programmatically
SAP Concur: choose a primary and secondary approver for spend management`
HashiCorp Vault: provisioning now supported for entitlements
1Password: human-readable entitlement descriptions now sync
Gong: optional setting to sync last activity
Benefits:
Cover more use cases on connectors you already run
Cut manual setup for multi-account and multi-organization estates
Read clearer entitlement names in reviews and requests
If you use 1Password, entitlement names will display differently after this release.