ConductorOne (C1) vs Lumos vs Zluri: SaaS access governance compared
C1 (formerly ConductorOne), Lumos and Zluri compared on access reviews, JIT access, Slack, Teams and ITSM requests, AI agent governance and hosting, from vendor docs.
Short answer
Choose C1 (formerly ConductorOne) if you run cloud infrastructure with an identity team, want just-in-time access to AWS and GCP, requests in Slack or Teams, and an MCP Gateway that grades every agent tool call by risk, and US hosting is acceptable. Choose Lumos if you have 200 employees or more and want an autonomous identity platform: agents that run reviews and JIT grants, an AppStore with grants from 2 hours to 90 days, Jira or ServiceNow ticket sync, and since September 2026 tool-call policy in Claude Code and Codex. Choose Zluri if SaaS management is as much the job as access: discovery from eight sources, licence and spend optimisation, and requests in Slack or approved in Jira Service Management. None of the three documents prompt-level DLP or EU hosting with a French-language product; Lutril, listed last, governs employees and AI agents with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP, and hosting in France.
Where each one starts
C1 (formerly ConductorOne)
The identity platform built for the AI era: identity governance, lifecycle, just-in-time access, an LLM Gateway, an MCP Gateway, Vault, Agents and Bridge, with 400+ connectors and an open-source connector SDK. Rebranded from ConductorOne to C1 in April 2026. Customers include enterprise and hypergrowth companies, and C1 runs a small and mid-size business offer with deployment experts and requests in Slack or Teams. US sub-processors.
Lumos
Identity management for the agentic era: the autonomous identity platform, with agents that continuously govern access for every human, machine and AI. Albus and an Identity Agent Force run access reviews, JIT grants, role mining and NHI ownership; an AppStore handles self-service requests; MCP Governance checks agent tool calls. Built for mid-market and enterprise, generally 200 employees or more, by its own account. 300+ integrations.
Zluri
Identity security for autonomous enterprises: discover, govern and secure every human and non-human identity, across identity visibility, IGA, ISPM and SaaS management. Started as a SaaS management platform and is a Leader in Gartner's Magic Quadrant for SaaS Management Platforms in 2024 and 2025. Discovery from eight sources, Slack-native requests, 300+ connectors.
Lutril
Access governance for employees and AI agents in one policy layer: discovery the day you connect Google Workspace or Microsoft 365, requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy that checks every agent tool call with prompt DLP and a global kill switch. Built by a practising CISO, hosted in France, in French and English.
Capability by capability
| Capability | C1 (formerly ConductorOne) | Lumos | Zluri | Lutril |
|---|---|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | YesShadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitoredSource 3 | YesGoogle scope to discover apps employees signed into with Google; Microsoft 365 report and audit scopesSource 21 | YesGoogle Workspace and Entra ID integrations: accounts, usage, third-party apps connectedSource 38 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Not documented | PartialBrowser sessions cited as a signal; no extension documented in the help centreSource 22 | YesChrome, Firefox, Edge and Brave; logs URLs and titles, no contentSource 39 | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | YesPolicy auto-creates a revoke task on denial; connector deprovisions, manual task otherwiseSource 4 | YesAuto-revoke rejected access through downstream integrationsSource 23 | PartialRemediation playbooks run after an admin concludes the review; manual task for non-integrated appsSource 40 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Yes/c1 request in Slack; approve or deny without leaving SlackSource 5 | YesSlack app for requests, approver notifications and remindersSource 24 | YesRequest, approve and reject in Slack; provisioning playbook on approvalSource 41 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | YesApprove and deny in Teams since November 2025; create requests in Teams since early 2026Source 6 | PartialRequests flow into Teams; approval inside Teams not explicitly documentedSource 25 | Not offeredNotification channels documented as email and SlackSource 42 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | YesGrant revoked when the window closes; AWS and GCP JIT quickstarts; expiry remindersSource 7 | YesDurations from 2 hours to 90 days, or unlimited, with automatic revocationSource 26 | YesTime-bound access as a policy condition; vendor states it has no dedicated JIT workflowSource 43 | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Access requests tracked in an ITSM (Jira Service Management, ServiceNow) | YesProvisioning tickets in Jira Cloud, Jira Data Center, ServiceNow, Freshservice, Linear, HaloITSM; requests start in C1Source 8 | YesJira or ServiceNow ticket per request, approver group routing, two-way status syncSource 27 | YesRequest and approval in Jira; Zluri provisions and adds a note to the ticketSource 44 | Not offeredRequests and approvals run in Slack, Teams and the app UI |
| Onboarding triggered by the HRIS | YesInbound webhooks for Workday and BambooHR; SAP SuccessFactors connectorSource 9 | YesWorkday, BambooHR, Rippling, ADP Workforce Now, Oracle HCMSource 28 | YesHiBob, Personio, BambooHR, Workday; set up with a customer success managerSource 45 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | YesDeprovision via connector, IdP, ticket, webhook or manual task; not all connectors support itSource 10 | YesOne-click offboarding for SSO and non-SSO appsSource 29 | YesRevokes access to SSO and non-SSO appsSource 46 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | YesFinds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configsSource 11 | PartialShadow IT and AI discovered and monitored; method not documentedSource 30 | YesAI apps across 37+ sub-categories; AI agents discovered as NHIsSource 47 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesIdentities and NHI dashboard with ownership status; standalone agents get their own identitySource 12 | YesEvery NHI mapped to a human owner; Agent Ownership FinderSource 31 | YesService accounts, tokens, bots and AI agents with enforced ownershipSource 48 | YesOwner, model and scopes on every agent; offboarded like an employee |
| Policy enforced on each AI agent tool call (MCP) | YesMCP Gateway: reads auto-approve, writes go to an approver, destructive calls denied by defaultSource 12 | YesMCP Governance, September 2026: tool-use hook in Claude Code and Codex; vendor states it is not a gatewaySource 32 | Not documented | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not offeredLLM Gateway does routing and cost; DLP hooks described as being builtSource 13 | Not documented | Not offeredVendor: does not capture prompt content or the data payloads sent to AI modelsSource 47 | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not offeredSub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documentedSource 14 | Not documentedPrivacy policy mentions transfers outside the EEA; no region or language option found | PartialAWS-hosted; only the PII vault region is customer-selectable; no French UI documentedSource 49 | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesAudit-ready reports on demand; evidence timestamped, attributed and exportableSource 15 | YesEvidence-backed reports formatted for SOC 2, SOX and ISO 27001Source 23 | YesCertification exports in CSV and timestamped PDF for SOC 2, ISO 27001, SOXSource 40 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Yes400+ prebuilt connectors, plus an open-source connector SDKSource 16 | Yes300+ integrationsSource 34 | Yes300+ connectorsSource 50 | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offeredPricing page without figures; platform tiers by managed identities, or usage-based tokensSource 2 | Not offeredPricing page without figuresSource 20 | Not offeredPricing page is a demo requestSource 37 | Not offeredOn request |
Choose C1 (formerly ConductorOne) if
- You run cloud infrastructure and want just-in-time access to AWS and GCP, requested from the web, Slack, Teams, the CLI or MCP.
- AI agents already call your tools through MCP and you want a gateway that evaluates identity and risk on every call and routes writes to an approver.
- You need 400+ connectors and an open-source SDK to build connectors for in-house systems.
- Provisioning must land as tickets in Jira, ServiceNow, Freshservice, Linear or HaloITSM, and US hosting is acceptable.
Choose Lumos if
- You have 200 employees or more, the size Lumos says it is built for, and an IT team to run the platform.
- You want agents to run access reviews, role mining and JIT grants, with a self-service AppStore and grants from 2 hours to 90 days.
- Access requests must be tracked in Jira or ServiceNow with status synced both ways.
- Your developers use Claude Code or Codex and you want tool-call policy enforced in the client rather than through a gateway.
Choose Zluri if
- SaaS spend, licence reclamation and renewals matter as much as access.
- Much of your access sits outside SSO and requests come from non-technical teams, the fit Zluri describes for itself.
- Requests start and are approved in Jira Service Management, and provisioning should follow automatically.
- Your team lives in Slack and does not need Microsoft Teams.
Choose Lutril if
- You are a mid-market company without an IAM team and need discovery, reviews and offboarding running in weeks.
- Review decisions should execute in the connected tool, with decisions and revocation proof in one campaign export.
- AI agents call your SaaS tools and you want an MCP proxy with policy on every call, prompt DLP, a WORM log and a global kill switch.
- Requests and approvals must run in Slack, Microsoft Teams and the app UI, time-boxed from one hour to seven days and auto-revoked.
- Your data has to stay in the EU, or your team works in French.
Questions buyers ask
How does Lumos compare to C1 (formerly ConductorOne)?
Both govern human, non-human and AI identities with access reviews that revoke, Slack requests, time-boxed grants, HRIS-driven lifecycle and ITSM ticketing. C1 documents approvals in Microsoft Teams, just-in-time access to AWS and GCP, 400+ connectors with an open-source SDK, and an MCP Gateway in front of agent tool calls with risk-graded approvals. Lumos says it is built for companies of 200 employees and up, runs reviews and JIT grants through its Identity Agent Force, and since September 2026 enforces tool-call policy through a hook in Claude Code and Codex, which it states is not a gateway. Neither documents an EU hosting region; C1's sub-processors are in the United States.
ConductorOne vs Zluri: which one should I choose?
C1 starts from identity governance and infrastructure: JIT access to cloud accounts, requests from the web, Slack, Teams, the CLI or MCP, and an MCP Gateway for agents. Zluri starts from SaaS management: discovery from eight sources, licence and spend optimisation, Slack requests and certifications. Zluri's own comparison credits C1 with JIT access to cloud infrastructure and describes its own time-bound access as a policy condition rather than a dedicated JIT workflow. Pick C1 for engineering-led, infrastructure-heavy access and agent tool calls; pick Zluri when spend and the SaaS apps outside SSO are the main problem.
Is Lumos or Zluri better for SaaS access governance?
It depends on whether access or spend leads. Lumos auto-revokes rejected access through its integrations, runs grants from 2 hours to 90 days and syncs requests with Jira or ServiceNow; it says it targets companies of 200 employees and up. Zluri adds licence and spend optimisation and a browser extension for discovery; its review remediation runs after an admin concludes the review, and its notifications are documented in email and Slack. Neither documents approvals inside Microsoft Teams or an EU region with a French-language product.
How does Lumos handle access management, JIT provisioning and ITSM?
Requests go through the Lumos AppStore, Slack or an MCP server. Grants last from 2 hours to 90 days, or unlimited, and are revoked automatically, and a Just-in-Time agent is part of its Identity Agent Force. The ITSM integration creates a Jira or ServiceNow ticket per request, routes it to an approver group, syncs status both ways and provisions on approval. Lifecycle runs from Workday, BambooHR, Rippling, ADP Workforce Now or Oracle HCM. Lumos does not publish prices.
What are Lumos's main competitors?
The products most often compared with Lumos are C1 (formerly ConductorOne), Zluri, Torii, Okta Identity Governance and SailPoint; Lumos publishes its own comparison pages for C1 and Zluri. On this page, C1 documents infrastructure JIT, Teams approvals and a gateway for agent tool calls, and Zluri documents SaaS spend management and a browser extension. Lutril governs employees and AI agents in one policy layer, with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP and hosting in France.
How does C1 compare to Oleria?
Oleria describes itself as a usage-aware identity security platform: adaptive identity governance, ISPM, NHI and AI agent governance and ITDR, with usage data down to resources such as files. C1 describes itself as the identity platform built for the AI era, with lifecycle, access, JIT, an LLM Gateway and an MCP Gateway. Oleria is not scored in the matrix above. Compare them on whether you need usage-level visibility into resources or policy enforced on each agent tool call.
Sources
- 1C1 homepageread on September 26, 2026
- 2C1 pricingread on September 2, 2026
- 3C1 docs, shadow appsread on September 2, 2026
- 4C1 docs, policiesread on September 2, 2026
- 5C1 docs, Slack applicationread on September 2, 2026
- 6C1 blog, advanced Microsoft Teams integrationread on September 2, 2026
- 7C1 docs, replace standing access with JIT accessread on September 26, 2026
- 8C1 docs, integrate an external ticketing systemread on September 26, 2026
- 9C1 docs, inbound webhooksread on September 2, 2026
- 10C1 docs, provisioningread on September 2, 2026
- 11C1, shadow AI discoveryread on September 2, 2026
- 12C1, MCP Gatewayread on September 26, 2026
- 13C1 blog, AI access management, your questions answeredread on September 2, 2026
- 14C1 legal, sub-processorsread on September 2, 2026
- 15C1, Complyread on September 2, 2026
- 16C1 integrationsread on September 2, 2026
- 17C1, small and mid-size businessesread on September 26, 2026
- 18C1 blog, we are C1read on September 2, 2026
- 19Lumos homepageread on September 26, 2026
- 20Lumos pricingread on September 2, 2026
- 21Lumos help, connecting Google Workspaceread on September 2, 2026
- 22Lumos, Zluri alternatives and competitorsread on September 26, 2026
- 23Lumos, access reviewsread on September 2, 2026
- 24Lumos help, connecting Slackread on September 2, 2026
- 25Lumos, Microsoft Teams integrationread on September 2, 2026
- 26Lumos help, AppStore quick startread on September 2, 2026
- 27Lumos developers, ITSM integrationread on September 26, 2026
- 28Lumos, lifecycle managementread on September 2, 2026
- 29Lumos, JML workflow orchestrationread on September 2, 2026
- 30Lumos, identity security postureread on September 2, 2026
- 31Lumos, non-human identitiesread on September 2, 2026
- 32Lumos blog, introducing MCP Governanceread on September 26, 2026
- 33Lumos privacy policyread on September 2, 2026
- 34Lumos integrationsread on September 2, 2026
- 35Lumos, ConductorOne competitors and alternativesread on September 26, 2026
- 36Zluri homepageread on September 26, 2026
- 37Zluri pricingread on September 2, 2026
- 38Zluri help, Google Workspace integrationread on September 2, 2026
- 39Zluri, how the discovery engine worksread on September 2, 2026
- 40Zluri help, closing and completing certificationsread on September 2, 2026
- 41Zluri, access requestsread on September 2, 2026
- 42Zluri help, notification customizationread on September 2, 2026
- 43Zluri, Zluri vs ConductorOneread on September 26, 2026
- 44Zluri help, zero touch onboarding via Jiraread on September 26, 2026
- 45Zluri help, zero touch onboardingread on September 2, 2026
- 46Zluri, secure deprovisioningread on September 2, 2026
- 47Zluri, shadow AI governance toolsread on September 26, 2026
- 48Zluri, identity visibility and intelligenceread on September 2, 2026
- 49Zluri securityread on September 2, 2026
- 50Zluri integrationsread on September 2, 2026
- 51Oleria homepageread on September 26, 2026
Lutril wrote this page. Facts about C1 (formerly ConductorOne), Lumos, Zluri come from their public documentation as of September 26, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.
Related reading
- SOC 2 Wants Proof. Not a Spreadsheet.
- Just-in-Time Access: How to Eliminate Standing Privilege
- MCP Governance: How to Control What AI Agents Can Do in Your SaaS
- Shadow IT: Your IT Team Knows About 40 SaaS Apps. You Have 130.
- MCP Proxy: Every tool call runs through policy.
- Agent Registry: One source of truth for every agent.
- Lutril vs C1 (formerly ConductorOne)
- Lutril vs Lumos
- Lutril vs Zluri
- Best access management tools for SaaS apps in 2026: Lumos, Zluri, Torii, BetterCloud, AccessOwl and Lutril