September 2026 Release Notes
Last updated: October 7, 2026
Theme: Governing the Action, Not Just the Access
Lumos has always governed who has access. This release extends that to what happens after access is granted: an AI agent calling a tool, a workflow running a fix, or an agent handling a request on someone's behalf. A person still decides, and every action lands in the same audit trail.
Highlights
MCP Governance [BETA]: See and control every tool call AI agents make
Remediation Workflows: Run the agent's drafted fix right from the issue
Access Request Agent: Full Request Lifecycle [BETA]: Check, cancel, and file requests for others in chat
Access Request Agent in Slack [BETA]: Request access by mentioning Lumos in Slack
Jira Service Management Agent: Assign an access ticket to Lumos and move on
Approval by Entitlement Owner: Route every request to the permission's owner automatically
Anthropic NHI Connector [BETA]: Inventory Claude agents, service accounts, and API keys
🛡 Intelligence & AI
MCP Governance
BETA
Availability: Now live as a design partner beta. No general availability date confirmed yet.
Enablement: Ask your CSM to join the design partner beta
MCP Governance puts Lumos in the path of every tool call your employees' AI coding agents make. Lumos logs each call against the person who triggered it and answers allow or deny per tool before the call runs, based on what that person holds in Lumos. It ships set to Allow, so nothing is blocked until you add a policy.
What's new:
Support for Claude Code and Codex, including Claude Code in the Desktop app
Coverage for MCP calls, Bash commands, and file operations
Inventory of every MCP server in use, including servers added locally
Call history you can filter by person, server, or tool, with volume over time
Per-tool allow or deny policies, ordered so the first match wins
One-click Allow reads or Block writes on any server
Albus answers usage questions and drafts policies for your approval
Prompts, model responses, and tool results are never stored
Benefits:
See which MCP servers and tools your teams actually use
Stop risky writes before they run without blocking reads
Tie every agent action back to the person behind it
Roll out at your own pace, then flip the default to Block
Remediation Workflows
Availability: Now live
Enablement: Ask your CSM to turn it on for your organization
Identity Intelligence issues now come with a remediation workflow the agent assembled from Lumos Flows. You review the steps, edit them for that issue if needed, and run the fix from the issue itself. The agent drafts and a person launches, so nothing runs unattended.
What's new:
Agent-built remediation workflow attached to the issue
Work status column: In Progress, Completed, Failed, Cancelled, or Manual
Cancel a running remediation, or retry a failed or cancelled one
Per-issue step editing that leaves the shared workflow untouched
Sub-issues per entity, remediated together from the parent issue
New Manual Task and Send Notification steps
Benefits:
Close findings without leaving the issue page
Keep a person in every remediation decision
Cover apps Lumos can't write to with assigned manual tasks
Fix a batch of findings in one run, with status per entity
Keep an audit trail through the same Flows engine that runs provisioning
Access Request Agent: Full Request Lifecycle
BETA
Availability: Now live. General availability targeted for November 4, 2026.
Enablement: Requires the Access Request Agent. Existing intake fields work as-is. Ask your CSM to participate.
The Access Request Agent now stays with a request after it is submitted. Requesters can check status, cancel, and answer the intake questions your admins configured, and IT admins can submit requests on someone else's behalf, all in the same conversation.
What's new:
Status checks on any pending request, from approval stage to provisioning
Cancel a pending request from the conversation
Configured intake fields asked conversationally and written onto the request
On-behalf-of requests, with requester and target confirmed by name before submitting
Asks for more detail instead of guessing when several people match a name
Benefits:
Cut "where is my request?" tickets to IT
Let requesters clear duplicate or stale requests themselves
Keep approver context on apps with intake fields
Let IT file for employees without re-typing their request
Access Request Agent in Slack
BETA
Target Availability: October 12, 2026. General availability targeted for November 4, 2026.
Enablement: Requires the Lumos Slack integration. Ask your CSM to participate.
Employees can mention the Lumos app in any Slack channel where it is present, or send it a DM, to request access. The agent clarifies what's needed, shows a request card to confirm, and submits it with the same policy enforcement and audit trail as the web.
What's new:
Mention Lumos in a channel, or DM it, to start a request
Follow-up question when the request is missing details
Request card for the employee to review and confirm
Confirmation with a request ID and a link to track status
Same approval workflow as requests made in the web app
Benefits:
Turn Slack access asks into tracked, governed requests
Stop routing Slack messages into Lumos by hand
Let employees request access without needing to know Lumos
🧱 Platform
Approval by Entitlement Owner
Availability: Now live
Enablement: Add Entitlement Owner to a stage in each app's approval workflow. Permissions need an owner set.
Entitlement Owner is a new approver you can add to any stage of an App Store approval workflow. Lumos looks up who owns the requested permission at the moment of the request and sends them the approval task, so one workflow per app covers every permission under it.
What's new:
Entitlement Owner approver option for any approval workflow stage
Owners resolved from Lumos Owner (set in the UI or by CSV) and Synced Owner
Multi-permission requests split so each owner approves only their own
Both owners get the task when the two owner fields differ
Org admins notified when no owner resolves and no other approver exists
New permissions inherit the app's workflow on their next sync
Benefits:
Set up one workflow per app instead of one per permission
Cover new groups on day one with no admin work
Send approvals to the person who owns the access
Catch ownership gaps instead of letting requests stall
Account Finder Performance
Availability: Now live
Enablement: On by default. No setup required.
Account Finder, the sync step that discovers which accounts exist in each connected app, now saves discovered accounts in bulk. For large tenants this cuts processing time from hours to minutes, with the biggest drop in total sync time for Google Cloud and Microsoft Entra ID. Okta customers will see a smaller change in total sync time for now.
What's new:
Discovered accounts saved in large parallel batches instead of one user at a time
Each discovered app created once instead of once per user
Lower memory use, so large tenants no longer fail partway through a run
Applies to Okta, Entra ID, Google Workspace, Google Cloud, OneLogin, JumpCloud, Atlassian, and custom connectors
Benefits:
Get fresh account data sooner after each sync
Reduce failed sync runs on large tenants
Get the improvement with no configuration changes
🔌 Integrations
Jira Service Management: Assignable Lumos Agent
Availability: Now live
Enablement: Install the Lumos app from the Atlassian Marketplace. Requires the Lumos Jira integration.
Lumos is now an assignable agent in Jira Service Management. When a service desk agent assigns an access ticket to Lumos, Lumos reads the ticket, resolves the user, app, and permission against your App Store catalog, submits the request, and keeps the ticket updated until it closes.
What's new:
Lumos Agent in the Jira assignee dropdown through the Lumos Forge app
Resolves user, app, permission, duration, and justification from the ticket
Requests run through your existing approval and provisioning workflows
Status syncs to the ticket; comment to ask for status or cancel
Ticket closes when the request is completed, denied, cancelled, or expired
Each request carries the ticket ID and link for approvers
Benefits:
Replace manual re-entry with a single assignment
Keep employees in the ticketing workflow they already know
Link the ticket, request, and approval in one audit trail
New NHI Inventory Connectors
BETA
Availability: Anthropic is now live. Active Directory is coming soon. No general availability date confirmed yet.
Enablement: Ask your CSM to participate
Two new integrations bring non-human identities (NHIs) into your Lumos inventory. Anthropic covers the agents, service accounts, and API keys teams create in the Claude Console. Active Directory covers the service accounts and computer accounts in on-prem and hybrid environments.
What's new:
Anthropic: every Managed Agent, service account, and API key in your Claude Console org
Anthropic: the workspaces and roles each one can reach
Anthropic: flags keys with no expiry and keys tied to a person
Active Directory: service accounts, computer accounts, and managed service accounts
Active Directory: the hosts, services, and groups each one can reach, including Domain Admins
Benefits:
Find AI agents and API keys nobody inventoried or owns
Spot NHIs sitting in privileged AD groups
See NHIs from more of your environment in one inventory
Existing Connector Improvements
Availability: Now live
Enablement: No setup required for generally available updates. SAP ECC provisioning and Tableau multi-auth are in early access; ask your CSM.
Several existing connectors gain new capabilities this release. Generally available updates apply to existing connections automatically.
What's new:
Microsoft Entra ID: Remove a departing user from all their groups in one offboarding step
Snowflake: Emails and names sync with a least-privilege role, so accounts match in access reviews
GitHub: Expiring OAuth tokens refresh automatically
Lucid: Detailed role data, such as Account Owner, Billing Admin, and Team Admin
SAP Concur: Primary Expense approver updates automatically when a manager changes
AWS NHI: Connect every AWS account at once with a CloudFormation StackSet
SAP ECC (beta): Provisioning support for accounts and role assignments
Tableau (beta): Connected Apps authentication alongside personal access tokens
Benefits:
Remove a user from every Entra ID group in one action
Give Snowflake only the read-only access Lumos needs
Keep SAP Concur approvers current without manual updates
Onboard every AWS account in one step instead of one at a time
Coming soon
Agent Runs via API & MCP: Start Lumos agent runs from pipelines and integrations
Bulk Access Changes [BETA]: Request access for a whole team in one submission
RBAC Agent in the Catalog: Start role mining with one-click enrollment