August 2026 Product Release Notes

Last updated: August 27, 2026

Theme: One Governance Model for Every Identity

Governance now sits under every identity and every access change in Lumos. The non-human identity inventory shows you what is actually out there, ownership and IT service management routing turn that visibility into accountability, and one shared access change model means a revocation or a provisioning run works the same way in every product.

Highlights

  • Non-Human Identity Inventory [BETA]: See and own every service account in one place

  • Standardized Access Changes: Configure one workflow per app, reuse it everywhere

  • ITSM Configuration: Route access tickets to the right queue, per team

  • Sync Circuit Breakers: Stop bad upstream sync data at the door

  • Entitlements Tab on the Identity View: See every permission a person holds

  • Pre-Approval Rules on Conditions: Auto-approve with the platform's full condition language

  • Draft Versions for Access Policies: Edit a live policy behind a draft

  • August Connectors: SAP ECC, AWS, Entra ID, and OpenAI inventory

๐Ÿ›ก Intelligence & AI

Non-Human Identity Inventory

  • BETA

  • Target Availability: First rollouts start September 4, 2026. No general availability date confirmed yet.

  • Enablement: Requires your non-human identity sources (AWS, Entra ID) connected to Lumos. Ask your CSM to participate.

A dedicated inventory of every non-human identity (NHI) in your environment: service accounts, service principals, API identities, and workload roles. You set an owner and a business justification on each one, and that ownership carries through to the security agents, remediation, and access reviews that read from the same inventory.

What's new:

  • Single table of every non-human identity, with source, type, last activity, and status

  • Owner and Business Justification fields you set directly on any identity

  • Per-identity detail view showing that identity's accounts and entitlements

  • Filter and sort the full inventory instead of checking each connected system

  • Ownership set once is reused by the security agents and remediation

  • AWS, Entra ID, and OpenAI non-human identity inventory Betas

Benefits:

  • See every non-human identity in one place instead of piecing it together

  • Make accountability explicit rather than tribal knowledge

  • Act on an agent finding without first hunting for an owner

  • Give non-human identity reviews a real substrate to read from

  • Feed the non-human identity inventory from your AWS, Entra ID, and OpenAI estates

๐Ÿงฑ Platform

Standardized Access Changes

  • Target Availability: August 31, 2026

  • Enablement: No setup required. Existing configurations migrate automatically.

Every access change in Lumos now runs through one workflow model. Provisioning and deprovisioning workflows become standalone objects you configure once per app or per entitlement, then reuse across the App Store, Onboarding, Movers, Offboarding, and Access Reviews. Existing configurations migrate automatically, and behavior stays the same by default.

What's new:

  • One Account Workflows table per app, with a "Used In" column per product

  • Every app ships with working default provisioning and deprovisioning workflows

  • Access Reviews can pick any deprovisioning workflow as its removal method

  • Entitlement-level workflows in the App > Entitlements side panel

  • Editing a shared workflow warns you which products it affects

  • Identical behavior across the product, the API, and MCP

Benefits:

  • Configure provisioning once instead of once per product

  • Hand an auditor a step-level workflow record for any removal

  • Start a new app with working defaults and no setup

  • Skip the migration work, because current setups carry over unchanged

Help Center Article

IT Service Management (ITSM) Configuration

  • Availability: Now live

  • Enablement: Ask your CSM for setup support on multi-system configurations

Connect more than one ITSM system to a single Lumos tenant and route access tickets to the queue that owns them. Routing rules run at the tenant, app, workflow, or task level, and Lumos validates your status mappings before they reach production.

What's new:

  • Multiple ITSM connections per tenant, including ServiceNow, Jira, Zendesk, and Freshservice

  • Priority-ordered routing rules at the tenant, app, workflow, or task level

  • Configurable status transition mappings between Lumos states and ITSM statuses

  • Transition validation that surfaces ITSM error codes in admin settings

  • Two instances of the same ITSM system supported side by side

Benefits:

  • Route engineering and HR requests to different systems without custom code

  • Catch a bad mapping in settings instead of in production

  • Retire the webhook workarounds built to get per-app routing

  • Keep ITSM behavior consistent across approval, provisioning, and deprovisioning

Help Center Article

Pre-Approval Rules on the Conditions Framework

  • Target Availability: September 4, 2026

  • Enablement: No setup required. Existing rules migrate automatically.

Pre-approval rules are rebuilt on the same conditions framework that flexible approvals already use. You get the full attribute set, condition grouping, and Lumos Expression Language, plus one rule model whether you configure it in the product, through MCP, or through the API. Existing rules migrate with no change in behavior.

What's new:

  • Full condition expressiveness, including grouping and Lumos Expression Language

  • Updated condition builder for pre-approval rules

  • Same rules readable and writable through GraphQL, MCP, and the public API

  • Terraform-compatible, so pre-approvals live alongside approvals in config as code

  • Existing rules migrate automatically, verified for identical outcomes

Benefits:

  • Auto-approve the policies your old rules could not express

  • Learn one condition language instead of two

  • Manage pre-approvals in the same Terraform files as approvals

  • Keep every existing rule working through the migration

Help Center Article

Draft Versions for Published Access Policies

  • Target Availability: Rolling out September 10 through September 15, 2026

  • Enablement: No setup required

Access policy drafts now extend to policies that are already live. Create a draft from a published policy, refine and review it while the current version keeps enforcing, then publish when it is ready. Every published version is archived, and deleting a policy disables it rather than destroying its history.

What's new:

  • Create one draft from any published policy without touching live enforcement

  • Draft states of Work in Progress and Ready to Publish

  • Comments and sharing on drafts, with a link to the published version

  • Publishing archives the prior version and checks conditions for conflicts

  • Soft deletion, so a deleted policy stops evaluating but keeps its versions

  • Edits by anyone other than an IAM admin create a draft automatically

Benefits:

  • Refine an enforced policy with zero impact until you publish

  • Catch a mis-scoped edit in review instead of in production

  • Answer audit questions from version history rather than memory

  • Move policy review into Lumos instead of screenshots and threads

Entitlements Tab on the Identity View

  • Target Availability: September 4, 2026

  • Enablement: No setup required

Open a human identity and flip to a new Entitlements tab to see every active entitlement that person holds across every connected app. This is the list an auditor asks for first, and it no longer takes a query or a walk through each account.

What's new:

  • Entitlements tab beside Accounts on the identity view

  • Columns for entitlement name, display name, description, type, source, and tags

  • Search and filter on every column

  • Active entitlements only, with entitlements from deactivated accounts excluded

Benefits:

  • Answer "what does this person have access to" in one click

  • Cut incident response time when you need a full permission list

  • Skip the per-account walk through a person's access

๐Ÿ”„ Lifecycle Management

Onboarding, Movers, and Offboarding on Account Workflows

  • Availability: Now live

  • Enablement: No setup required. Existing offboarding workflows migrate automatically, and the change reaches each domain as its rollout segment is enabled.

All three lifecycle products now resolve their per-app provisioning and deprovisioning workflows from the same Account Workflows table the rest of Lumos uses. Offboarding moves off its own engine, so it gains workflow records, error tasks, and retries. The set of apps that get offboarded does not change.

What's new:

  • Onboarding, Movers, and Offboarding all resolve workflows from one shared table

  • Offboarding configuration moves from the Integrations tab to Account Workflows

  • Failed removals surface as error tasks with workflow records and retries

  • Offboarding dialog shows the workflow that will run, with a per-account override

  • Lifecycle-driven changes no longer notify the affected employee

Benefits:

  • Update one workflow and have every lifecycle stage pick it up

  • Catch a failed offboarding removal instead of finding it later

  • Stop maintaining offboarding apart from your other access workflows

  • Keep joiners, movers, and leavers out of notification noise

Help Center Article ยท Help Center Article ยท Help Center Article

โœ… Access Reviews

Access Review Removals on Account Workflows

  • Target Availability: Rollout starts September 4, 2026 and continues through end of September.

  • Enablement: Requires the ITSM integration enabled for Access Reviews where you want ticket linkage

Account and entitlement removals in User Access Reviews (UARs) now run on the same workflow engine as the rest of Lumos. During campaign setup you pick from the deprovisioning workflows already configured for the app or entitlement, and failures and manual steps become tasks you can resolve inside the review.

What's new:

  • Workflow picker replaces the single default removal method in campaign setup

  • Each entitlement removes through the workflow matching its source, even in merged apps

  • Failed removals become error tasks you can action individually or in bulk

  • Manual steps surface as tasks in the review and the Task Center

  • Evidence capture by file, link, or auto-linked ITSM ticket, including bulk add

  • Workflow Record drawer showing live removal state inside the review

Benefits:

  • Reuse the deprovisioning workflows you already configured elsewhere

  • Stop losing failed removals to silence

  • Resolve manual steps and attach evidence without leaving the review

  • Hand auditors an ITSM ticket and a workflow record per removal

User Access Review Table: My Tasks Filter

  • Availability: Now live

  • Enablement: No setup required

The My Tasks filter that reviewers use inside an individual app review now works two levels up, on the Access Reviews campaigns page and within each campaign. Admins who also review can separate their own work from everything they oversee.

What's new:

  • All and My Tasks toggle on the Access Reviews campaigns page

  • Same toggle within a campaign, filtering across its reviews

  • Default stays All, so oversight views are unchanged

Benefits:

  • Find the reviews waiting on you without opening each app review

  • Keep the program-wide view one toggle away

  • Use one filtering pattern at every level of Access Reviews

๐Ÿ”Œ Integrations

Sync Circuit Breakers

  • Availability: Now live

  • Enablement: On by default. Turn off the empty account response rule for any app that legitimately returns zero accounts.

The four sync circuit breakers are generally available and on by default for every customer and every connected app. A sync that would deactivate, remove, or wipe a large share of your accounts or identities is halted before the change is installed, and you configure the thresholds yourself.

What's new:

  • Mass account deactivation breaker, on at 50% of active accounts

  • Mass account absence breaker, on at 50% of active accounts absent

  • Empty account response breaker, on for any response of zero accounts

  • Mass identity deactivation breaker, on at 50% of active identities

  • Domain-wide defaults in settings, with per-app overrides on each integration

  • Every settings change requires a reason and is written to the audit trail

Benefits:

  • Stop bad upstream sync data before it reaches your accounts

  • Tune thresholds yourself instead of filing a request

  • Prevent a truncated or empty payload from reading as a mass removal

  • Show auditors who changed a threshold and why

Help Center Article ยท Help Center Article

August Connectors: New Integrations

  • Target Availability: August 31, 2026

  • Enablement: Connect from the Available tab on the Integrations page

One new integration is available on the Integrations page.

What's new:

  • SAP ECC 6.0 [BETA]

Benefits:

  • Extend coverage to SAP ECC without a custom integration

  • Bring more provisioning actions directly into Lumos

August Connectors: Existing Integration Improvements

  • Target Availability: August 31, 2026

  • Enablement: Available on your existing connections. The Gong last activity sync is an optional setting.

Six connectors you already run gained capabilities customers asked for, from broader organization coverage to entitlement provisioning.

What's new:

  • GitHub: connect every organization inside an enterprise

  • AWS Identity and Access Management: script to connect multiple accounts programmatically

  • SAP Concur: choose a primary or secondary approver for spend management

  • HashiCorp Vault: provisioning now supported for entitlements

  • 1Password: human-readable entitlement descriptions now sync

  • Gong: optional setting to sync last activity

Benefits:

  • Model more of your access in the connectors you already run

  • Cut the manual setup for multi-account and multi-organization estates

  • Read entitlement names your reviewers can actually interpret

Coming soon

  • Remediation Workflows: Close an identity finding with a guided fix

  • Multiple Workflows for Manual Offboardings: Match the exit process to the situation

  • User Access Review Admin MCP: Run and monitor reviews from an AI agent

  • September Connectors: More new integrations and connector improvements