
Identity & Access Management
Lumos Autonomous Identity
Autonomous IGA platform using AI agents to govern access for human, machine, and AI identities.
Lumos Autonomous Identity Overview
What it does
Lumos Autonomous Identity is an identity governance and administration platform that manages who holds access to which applications and entitlements across SaaS, cloud, and on-premises systems. It governs employees, service accounts, API keys, workload identities, and AI agents in one model, and its distinguishing choice is to run governance continuously through AI agents rather than through periodic ticket-driven campaigns, so access is certified, granted, and revoked on an ongoing basis instead of quarterly.
How it works
The platform connects to HR systems, identity providers, and more than 300 applications through API integrations, then builds an entitlement map linking every account and permission to a person or a machine owner. Named components handle each stage: AppStore for self-service and time-bound access requests, Lifecycle Management for HRIS-driven joiner-mover-leaver workflows, Access Reviews for certification campaigns with segregation-of-duties checks and closed-loop revocation, Identity Analytics for reporting, and the Identity Agent Force, six specialized agents including a Role-Mining Agent and an NHI Owner Hunter. Agents act continuously and escalate only the decisions that need a human.
Credentials and traction
Lumos holds SOC 2 Type II and ISO 27001 certifications and operates under GDPR and CCPA. It was named a Strong Performer in the 2026 Gartner Peer Insights Voice of the Customer for Identity Governance and Administration. Adopters span technology, financial services, and consumer goods, including Mars, Netskope, GitLab, Assurant, Pinterest, and Roku, and the platform targets mid-market and enterprise IT and security teams governing hundreds of applications.
Key Capabilities
mapped to solution categoriesDefines static segregation-of-duties rules as conflicting roles and entitlements, blocks toxic combinations at request time, and continuously monitors for SOD violations with alerts and mitigating-control tracking. Static SOD became a mandatory IGA capability in 2026; predictive dynamic SOD analysis is a separate feature.
Automated joiner, mover, and leaver processes for workforce and workload identities, including AI agents, that create, change, and revoke identities and their access across connected systems, correlating identity and application data from multiple authoritative sources (HR, directories, contractor systems) into one identity record.
Automated fulfillment of access changes to target systems through prebuilt out-of-the-box connectors (for example SAP, Workday, Microsoft 365), purpose-built custom connectors for homegrown platforms, and standards-based provisioning (SCIM 2.0), with ITSM ticket-based manual fulfillment as the fallback for applications no connector reaches.
Produces audit evidence mapped to specific regulatory mandates (NIS2, DORA, SOX, GDPR, HIPAA): automated regulation-specific reports, scheduled and ad hoc exports, and immutable audit trails that demonstrate continuous audit readiness rather than point-in-time evidence collection. Basic access reporting is table stakes; assign only when controls are mapped to named regulations.
Continuously discovers entitlements across applications and systems, reconciles them against what is actually granted in each target, and enriches each entitlement with a description, owner, and risk level so requesters and reviewers understand what they are approving. Fine-grained runtime entitlements are covered by Fine-Grained Authorization Policy Orchestration.
Governs workload identities (service accounts, applications, containers, RPA bots, and AI agents) and their accounts through the same lifecycle, ownership, certification, and policy controls as workforce identities: assigns a business sponsor and technical owner, records purpose, and removes the identity and its access when it is no longer justified.
Grants entitlements for a defined, limited period and automatically revokes or re-reviews them when the period expires, so temporary, project-based, and elevated access does not accumulate as standing entitlements.
Applies predictive and prescriptive analytics and AI assistants to governance decisions: recommends approvals and certification outcomes, proposes role and policy models from access patterns, flags anomalous access for review, and answers natural-language questions about who has access and why. Distinct from Identity Analytics and Risk Scoring, which supplies the descriptive risk scores these recommendations build on.
Self-service access request catalog with configurable, policy-driven approval workflows.
Lets administrators build and modify governance workflows (approvals, certifications, lifecycle events, remediation) in a low-code or no-code designer, so process changes do not require vendor professional services or custom code.
Access review campaigns in which reviewers attest to or revoke access for workforce and workload identities, including AI agents, down to the entitlement level. Certifications are event-triggered (a transfer, a risk change, a new entitlement) as well as scheduled, and risk context and recommendations are surfaced so reviewers act on exceptions instead of rubber-stamping every line.
Descriptive and diagnostic analytics over identity and access data: scores each identity's risk from its entitlements, peer-group outliers, orphaned and dormant accounts, and SOD exposure, and feeds those scores into certification prioritization and remediation. Predictive and prescriptive recommendations belong to AI-Assisted Identity Governance.
Role mining, modeling, and administration to standardize access through roles.
Integrates identity data, activity, relationships, and configuration from directories, identity providers, IGA, PAM, cloud platforms, and SaaS applications, including applications not yet connected to any IAM tool, into one correlated inventory of every human and non-human actor with its accounts and entitlements, the single view on which posture assessment and analytics run.
Flags identity-object hygiene problems: dormant and orphaned accounts, accounts without MFA enrolled, shared or generic accounts, weak or non-expiring passwords, and risky discretionary permissions, so they are cleaned up before attackers use them. Configuration of the identity providers and access policies themselves is covered by IAM Policy and Configuration Assessment.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Fixes identity posture findings instead of only reporting them: revokes unused or excessive entitlements, enforces MFA, disables dormant accounts, and corrects policy drift, either directly or through IGA, PAM, and identity provider connectors, with approval workflows for higher-risk changes. Distinct from ITDR response actions, which act on active attacks.
Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Surfaces indicators of identity compromise from posture and activity telemetry (anomalous login sequences, MFA fatigue patterns, impossible travel, sudden privilege changes) and routes them for response, so posture findings and active-attack signals sit in one risk view. This is the posture-layer signal: real-time detection, response playbooks, and recovery are the Identity Threat Detection and Response (ITDR) niche vocabulary, and EDR identity detection covers endpoint-side behavior.
Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Lumos Autonomous Identity fits your stack
Add Lumos Autonomous Identity to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.