
Identity & Access Management
Lumos Autonomous Identity
Autonomous IGA platform using AI agents to govern access for human, machine, and AI identities.
Lumos Autonomous Identity Overview
What it does
Lumos Autonomous Identity is an identity governance and administration platform that manages who holds access to which applications and entitlements across SaaS, cloud, and on-premises systems. It governs employees, service accounts, API keys, workload identities, and AI agents in one model, and its distinguishing choice is to run governance continuously through AI agents rather than through periodic ticket-driven campaigns, so access is certified, granted, and revoked on an ongoing basis instead of quarterly.
How it works
The platform connects to HR systems, identity providers, and more than 300 applications through API integrations, then builds an entitlement map linking every account and permission to a person or a machine owner. Named components handle each stage: AppStore for self-service and time-bound access requests, Lifecycle Management for HRIS-driven joiner-mover-leaver workflows, Access Reviews for certification campaigns with segregation-of-duties checks and closed-loop revocation, Identity Analytics for reporting, and the Identity Agent Force, six specialized agents including a Role-Mining Agent and an NHI Owner Hunter. Agents act continuously and escalate only the decisions that need a human.
Credentials and traction
Lumos holds SOC 2 Type II and ISO 27001 certifications and operates under GDPR and CCPA. It was named a Strong Performer in the 2026 Gartner Peer Insights Voice of the Customer for Identity Governance and Administration. Adopters span technology, financial services, and consumer goods, including Mars, Netskope, GitLab, Assurant, Pinterest, and Roku, and the platform targets mid-market and enterprise IT and security teams governing hundreds of applications.
Key Capabilities
mapped to solution categoriesSelf-service access request catalog with configurable, policy-driven approval workflows.
Discovery, modeling, and management of fine-grained entitlements and access rights across applications and systems.
Periodic and event-driven campaigns for reviewers to attest to and revoke user access.
Role mining, modeling, and administration to standardize access through roles.
Definition and enforcement of segregation-of-duties and access policies to detect and prevent toxic access combinations.
Automated fulfillment of access changes to target systems through connectors, with manual fulfillment fallback.
Analytics that score identity and access risk, surface outliers, and recommend certification or remediation.
Uses predictive and prescriptive analytics and AI assistants to recommend access decisions, certifications and policy improvements.
Manages the life cycle of machine identities such as devices, workloads, services and RPA bots and their associated accounts.
Automated joiner, mover, and leaver processes that create, change, and revoke identities and their access across connected systems.
Flags dormant and zombie accounts, weak access policies, and identity misconfigurations (such as missing MFA or risky discretionary access) so they can be cleaned up before attackers use them.
Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.
Detects indicators of identity compromise and attack activity (anomalous login sequences, MFA fatigue patterns, impossible travel), at the posture layer, enabling detection of active attacks alongside the static risk posture view. Distinct from EDR identity threat detection, which operates as real-time behavioral detection during an active attack.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.