Security Stack Logo
Lumos Autonomous Identity logo

Identity & Access Management

Lumos Autonomous Identity

Autonomous IGA platform using AI agents to govern access for human, machine, and AI identities.

Identity Governance and Administration (IGA)Identity Security Posture Management (ISPM)

Lumos Autonomous Identity Overview

What it does

Lumos Autonomous Identity is an identity governance and administration platform that manages who holds access to which applications and entitlements across SaaS, cloud, and on-premises systems. It governs employees, service accounts, API keys, workload identities, and AI agents in one model, and its distinguishing choice is to run governance continuously through AI agents rather than through periodic ticket-driven campaigns, so access is certified, granted, and revoked on an ongoing basis instead of quarterly.

How it works

The platform connects to HR systems, identity providers, and more than 300 applications through API integrations, then builds an entitlement map linking every account and permission to a person or a machine owner. Named components handle each stage: AppStore for self-service and time-bound access requests, Lifecycle Management for HRIS-driven joiner-mover-leaver workflows, Access Reviews for certification campaigns with segregation-of-duties checks and closed-loop revocation, Identity Analytics for reporting, and the Identity Agent Force, six specialized agents including a Role-Mining Agent and an NHI Owner Hunter. Agents act continuously and escalate only the decisions that need a human.

Credentials and traction

Lumos holds SOC 2 Type II and ISO 27001 certifications and operates under GDPR and CCPA. It was named a Strong Performer in the 2026 Gartner Peer Insights Voice of the Customer for Identity Governance and Administration. Adopters span technology, financial services, and consumer goods, including Mars, Netskope, GitLab, Assurant, Pinterest, and Roku, and the platform targets mid-market and enterprise IT and security teams governing hundreds of applications.

Key Capabilities

mapped to solution categories
Identity Governance and Administration (IGA)

Self-service access request catalog with configurable, policy-driven approval workflows.

Discovery, modeling, and management of fine-grained entitlements and access rights across applications and systems.

Periodic and event-driven campaigns for reviewers to attest to and revoke user access.

Role mining, modeling, and administration to standardize access through roles.

Definition and enforcement of segregation-of-duties and access policies to detect and prevent toxic access combinations.

Automated fulfillment of access changes to target systems through connectors, with manual fulfillment fallback.

Analytics that score identity and access risk, surface outliers, and recommend certification or remediation.

Uses predictive and prescriptive analytics and AI assistants to recommend access decisions, certifications and policy improvements.

Manages the life cycle of machine identities such as devices, workloads, services and RPA bots and their associated accounts.

Automated joiner, mover, and leaver processes that create, change, and revoke identities and their access across connected systems.

Identity Security Posture Management (ISPM)

Flags dormant and zombie accounts, weak access policies, and identity misconfigurations (such as missing MFA or risky discretionary access) so they can be cleaned up before attackers use them.

Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.

Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.

Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.

Detects indicators of identity compromise and attack activity (anomalous login sequences, MFA fatigue patterns, impossible travel), at the posture layer, enabling detection of active attacks alongside the static risk posture view. Distinct from EDR identity threat detection, which operates as real-time behavioral detection during an active attack.

Compliance

certifications
CCPAGDPRISO 27001SOC 2 Type II

Integrations

compatible tools
1PasswordActive DirectoryADP Workforce NowAsanaAWS (IAM Identity Center)BoxDatadogDocuSignDropboxGitHubGoogle WorkspaceHiBobHubSpotJiraMicrosoft Entra IDNetSuiteNotionOktaSalesforceServiceNowSlackSnowflakeWorkdayZendeskZoom

Implementation & support

Deployment model
SaaS
Pricing structure
Custom / Enterprise
Support channels
DocumentationKnowledge BaseTraining / Academy

Info last updated on July 26, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.