September 2026 Release Notes

Last updated: October 7, 2026

Theme: Governing the Action, Not Just the Access

Lumos has always governed who has access. This release extends that to what happens after access is granted: an AI agent calling a tool, a workflow running a fix, or an agent handling a request on someone's behalf. A person still decides, and every action lands in the same audit trail.

Highlights

  • MCP Governance [BETA]: See and control every tool call AI agents make

  • Remediation Workflows: Run the agent's drafted fix right from the issue

  • Access Request Agent: Full Request Lifecycle [BETA]: Check, cancel, and file requests for others in chat

  • Access Request Agent in Slack [BETA]: Request access by mentioning Lumos in Slack

  • Jira Service Management Agent: Assign an access ticket to Lumos and move on

  • Approval by Entitlement Owner: Route every request to the permission's owner automatically

  • Anthropic NHI Connector [BETA]: Inventory Claude agents, service accounts, and API keys

🛡 Intelligence & AI

MCP Governance

  • BETA

  • Availability: Now live as a design partner beta. No general availability date confirmed yet.

  • Enablement: Ask your CSM to join the design partner beta

MCP Governance puts Lumos in the path of every tool call your employees' AI coding agents make. Lumos logs each call against the person who triggered it and answers allow or deny per tool before the call runs, based on what that person holds in Lumos. It ships set to Allow, so nothing is blocked until you add a policy.

What's new:

  • Support for Claude Code and Codex, including Claude Code in the Desktop app

  • Coverage for MCP calls, Bash commands, and file operations

  • Inventory of every MCP server in use, including servers added locally

  • Call history you can filter by person, server, or tool, with volume over time

  • Per-tool allow or deny policies, ordered so the first match wins

  • One-click Allow reads or Block writes on any server

  • Albus answers usage questions and drafts policies for your approval

  • Prompts, model responses, and tool results are never stored

Benefits:

  • See which MCP servers and tools your teams actually use

  • Stop risky writes before they run without blocking reads

  • Tie every agent action back to the person behind it

  • Roll out at your own pace, then flip the default to Block

Remediation Workflows

  • Availability: Now live

  • Enablement: Ask your CSM to turn it on for your organization

Identity Intelligence issues now come with a remediation workflow the agent assembled from Lumos Flows. You review the steps, edit them for that issue if needed, and run the fix from the issue itself. The agent drafts and a person launches, so nothing runs unattended.

What's new:

  • Agent-built remediation workflow attached to the issue

  • Work status column: In Progress, Completed, Failed, Cancelled, or Manual

  • Cancel a running remediation, or retry a failed or cancelled one

  • Per-issue step editing that leaves the shared workflow untouched

  • Sub-issues per entity, remediated together from the parent issue

  • New Manual Task and Send Notification steps

Benefits:

  • Close findings without leaving the issue page

  • Keep a person in every remediation decision

  • Cover apps Lumos can't write to with assigned manual tasks

  • Fix a batch of findings in one run, with status per entity

  • Keep an audit trail through the same Flows engine that runs provisioning

Access Request Agent: Full Request Lifecycle

  • BETA

  • Availability: Now live. General availability targeted for November 4, 2026.

  • Enablement: Requires the Access Request Agent. Existing intake fields work as-is. Ask your CSM to participate.

The Access Request Agent now stays with a request after it is submitted. Requesters can check status, cancel, and answer the intake questions your admins configured, and IT admins can submit requests on someone else's behalf, all in the same conversation.

What's new:

  • Status checks on any pending request, from approval stage to provisioning

  • Cancel a pending request from the conversation

  • Configured intake fields asked conversationally and written onto the request

  • On-behalf-of requests, with requester and target confirmed by name before submitting

  • Asks for more detail instead of guessing when several people match a name

Benefits:

  • Cut "where is my request?" tickets to IT

  • Let requesters clear duplicate or stale requests themselves

  • Keep approver context on apps with intake fields

  • Let IT file for employees without re-typing their request

Access Request Agent in Slack

  • BETA

  • Target Availability: October 12, 2026. General availability targeted for November 4, 2026.

  • Enablement: Requires the Lumos Slack integration. Ask your CSM to participate.

Employees can mention the Lumos app in any Slack channel where it is present, or send it a DM, to request access. The agent clarifies what's needed, shows a request card to confirm, and submits it with the same policy enforcement and audit trail as the web.

What's new:

  • Mention Lumos in a channel, or DM it, to start a request

  • Follow-up question when the request is missing details

  • Request card for the employee to review and confirm

  • Confirmation with a request ID and a link to track status

  • Same approval workflow as requests made in the web app

Benefits:

  • Turn Slack access asks into tracked, governed requests

  • Stop routing Slack messages into Lumos by hand

  • Let employees request access without needing to know Lumos

🧱 Platform

Approval by Entitlement Owner

  • Availability: Now live

  • Enablement: Add Entitlement Owner to a stage in each app's approval workflow. Permissions need an owner set.

Entitlement Owner is a new approver you can add to any stage of an App Store approval workflow. Lumos looks up who owns the requested permission at the moment of the request and sends them the approval task, so one workflow per app covers every permission under it.

What's new:

  • Entitlement Owner approver option for any approval workflow stage

  • Owners resolved from Lumos Owner (set in the UI or by CSV) and Synced Owner

  • Multi-permission requests split so each owner approves only their own

  • Both owners get the task when the two owner fields differ

  • Org admins notified when no owner resolves and no other approver exists

  • New permissions inherit the app's workflow on their next sync

Benefits:

  • Set up one workflow per app instead of one per permission

  • Cover new groups on day one with no admin work

  • Send approvals to the person who owns the access

  • Catch ownership gaps instead of letting requests stall

Help Center Article

Account Finder Performance

  • Availability: Now live

  • Enablement: On by default. No setup required.

Account Finder, the sync step that discovers which accounts exist in each connected app, now saves discovered accounts in bulk. For large tenants this cuts processing time from hours to minutes, with the biggest drop in total sync time for Google Cloud and Microsoft Entra ID. Okta customers will see a smaller change in total sync time for now.

What's new:

  • Discovered accounts saved in large parallel batches instead of one user at a time

  • Each discovered app created once instead of once per user

  • Lower memory use, so large tenants no longer fail partway through a run

  • Applies to Okta, Entra ID, Google Workspace, Google Cloud, OneLogin, JumpCloud, Atlassian, and custom connectors

Benefits:

  • Get fresh account data sooner after each sync

  • Reduce failed sync runs on large tenants

  • Get the improvement with no configuration changes

🔌 Integrations

Jira Service Management: Assignable Lumos Agent

  • Availability: Now live

  • Enablement: Install the Lumos app from the Atlassian Marketplace. Requires the Lumos Jira integration.

Lumos is now an assignable agent in Jira Service Management. When a service desk agent assigns an access ticket to Lumos, Lumos reads the ticket, resolves the user, app, and permission against your App Store catalog, submits the request, and keeps the ticket updated until it closes.

What's new:

  • Lumos Agent in the Jira assignee dropdown through the Lumos Forge app

  • Resolves user, app, permission, duration, and justification from the ticket

  • Requests run through your existing approval and provisioning workflows

  • Status syncs to the ticket; comment to ask for status or cancel

  • Ticket closes when the request is completed, denied, cancelled, or expired

  • Each request carries the ticket ID and link for approvers

Benefits:

  • Replace manual re-entry with a single assignment

  • Keep employees in the ticketing workflow they already know

  • Link the ticket, request, and approval in one audit trail

Help Center Article

New NHI Inventory Connectors

  • BETA

  • Availability: Anthropic is now live. Active Directory is coming soon. No general availability date confirmed yet.

  • Enablement: Ask your CSM to participate

Two new integrations bring non-human identities (NHIs) into your Lumos inventory. Anthropic covers the agents, service accounts, and API keys teams create in the Claude Console. Active Directory covers the service accounts and computer accounts in on-prem and hybrid environments.

What's new:

  • Anthropic: every Managed Agent, service account, and API key in your Claude Console org

  • Anthropic: the workspaces and roles each one can reach

  • Anthropic: flags keys with no expiry and keys tied to a person

  • Active Directory: service accounts, computer accounts, and managed service accounts

  • Active Directory: the hosts, services, and groups each one can reach, including Domain Admins

Benefits:

  • Find AI agents and API keys nobody inventoried or owns

  • Spot NHIs sitting in privileged AD groups

  • See NHIs from more of your environment in one inventory

Existing Connector Improvements

  • Availability: Now live

  • Enablement: No setup required for generally available updates. SAP ECC provisioning and Tableau multi-auth are in early access; ask your CSM.

Several existing connectors gain new capabilities this release. Generally available updates apply to existing connections automatically.

What's new:

  • Microsoft Entra ID: Remove a departing user from all their groups in one offboarding step

  • Snowflake: Emails and names sync with a least-privilege role, so accounts match in access reviews

  • GitHub: Expiring OAuth tokens refresh automatically

  • Lucid: Detailed role data, such as Account Owner, Billing Admin, and Team Admin

  • SAP Concur: Primary Expense approver updates automatically when a manager changes

  • AWS NHI: Connect every AWS account at once with a CloudFormation StackSet

  • SAP ECC (beta): Provisioning support for accounts and role assignments

  • Tableau (beta): Connected Apps authentication alongside personal access tokens

Benefits:

  • Remove a user from every Entra ID group in one action

  • Give Snowflake only the read-only access Lumos needs

  • Keep SAP Concur approvers current without manual updates

  • Onboard every AWS account in one step instead of one at a time

Coming soon

  • Agent Runs via API & MCP: Start Lumos agent runs from pipelines and integrations

  • Bulk Access Changes [BETA]: Request access for a whole team in one submission

  • RBAC Agent in the Catalog: Start role mining with one-click enrollment