# ConductorOne (C1) vs Lumos vs Zluri: SaaS access governance compared

> C1 (formerly ConductorOne), Lumos and Zluri compared on access reviews, JIT access, Slack, Teams and ITSM requests, AI agent governance and hosting, from vendor docs.

Source: https://www.lutril.com/compare/conductorone-vs-lumos-vs-zluri
Last reviewed: 2026-09-26

---

## Short answer

Choose C1 (formerly ConductorOne) if you run cloud infrastructure with an identity team, want just-in-time access to AWS and GCP, requests in Slack or Teams, and an MCP Gateway that grades every agent tool call by risk, and US hosting is acceptable. Choose Lumos if you have 200 employees or more and want an autonomous identity platform: agents that run reviews and JIT grants, an AppStore with grants from 2 hours to 90 days, Jira or ServiceNow ticket sync, and since September 2026 tool-call policy in Claude Code and Codex. Choose Zluri if SaaS management is as much the job as access: discovery from eight sources, licence and spend optimisation, and requests in Slack or approved in Jira Service Management. None of the three documents prompt-level DLP or EU hosting with a French-language product; Lutril, listed last, governs employees and AI agents with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP, and hosting in France.

## Where each one starts

**C1 (formerly ConductorOne).** The identity platform built for the AI era: identity governance, lifecycle, just-in-time access, an LLM Gateway, an MCP Gateway, Vault, Agents and Bridge, with 400+ connectors and an open-source connector SDK. Rebranded from ConductorOne to C1 in April 2026. Customers include enterprise and hypergrowth companies, and C1 runs a small and mid-size business offer with deployment experts and requests in Slack or Teams. US sub-processors.

**Lumos.** Identity management for the agentic era: the autonomous identity platform, with agents that continuously govern access for every human, machine and AI. Albus and an Identity Agent Force run access reviews, JIT grants, role mining and NHI ownership; an AppStore handles self-service requests; MCP Governance checks agent tool calls. Built for mid-market and enterprise, generally 200 employees or more, by its own account. 300+ integrations.

**Zluri.** Identity security for autonomous enterprises: discover, govern and secure every human and non-human identity, across identity visibility, IGA, ISPM and SaaS management. Started as a SaaS management platform and is a Leader in Gartner's Magic Quadrant for SaaS Management Platforms in 2024 and 2025. Discovery from eight sources, Slack-native requests, 300+ connectors.

**Lutril.** Access governance for employees and AI agents in one policy layer: discovery the day you connect Google Workspace or Microsoft 365, requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy that checks every agent tool call with prompt DLP and a global kill switch. Built by a practising CISO, hosted in France, in French and English.

## Capability by capability

| Capability | C1 (formerly ConductorOne) | Lumos | Zluri | Lutril |
| --- | --- | --- | --- | --- |
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | Yes: Shadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitored [3] | Yes: Google scope to discover apps employees signed into with Google; Microsoft 365 report and audit scopes [21] | Yes: Google Workspace and Entra ID integrations: accounts, usage, third-party apps connected [38] | Yes: Google Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Not documented | Partial: Browser sessions cited as a signal; no extension documented in the help centre [22] | Yes: Chrome, Firefox, Edge and Brave; logs URLs and titles, no content [39] | Yes: Chrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | Yes: Policy auto-creates a revoke task on denial; connector deprovisions, manual task otherwise [4] | Yes: Auto-revoke rejected access through downstream integrations [23] | Partial: Remediation playbooks run after an admin concludes the review; manual task for non-integrated apps [40] | Yes: Decisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Yes: /c1 request in Slack; approve or deny without leaving Slack [5] | Yes: Slack app for requests, approver notifications and reminders [24] | Yes: Request, approve and reject in Slack; provisioning playbook on approval [41] | Yes: Requests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | Yes: Approve and deny in Teams since November 2025; create requests in Teams since early 2026 [6] | Partial: Requests flow into Teams; approval inside Teams not explicitly documented [25] | Not offered: Notification channels documented as email and Slack [42] | Yes: Same flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | Yes: Grant revoked when the window closes; AWS and GCP JIT quickstarts; expiry reminders [7] | Yes: Durations from 2 hours to 90 days, or unlimited, with automatic revocation [26] | Yes: Time-bound access as a policy condition; vendor states it has no dedicated JIT workflow [43] | Yes: One hour to seven days; an approver can shorten, never extend; auto-revoked |
| Access requests tracked in an ITSM (Jira Service Management, ServiceNow) | Yes: Provisioning tickets in Jira Cloud, Jira Data Center, ServiceNow, Freshservice, Linear, HaloITSM; requests start in C1 [8] | Yes: Jira or ServiceNow ticket per request, approver group routing, two-way status sync [27] | Yes: Request and approval in Jira; Zluri provisions and adds a note to the ticket [44] | Not offered: Requests and approvals run in Slack, Teams and the app UI |
| Onboarding triggered by the HRIS | Yes: Inbound webhooks for Workday and BambooHR; SAP SuccessFactors connector [9] | Yes: Workday, BambooHR, Rippling, ADP Workforce Now, Oracle HCM [28] | Yes: HiBob, Personio, BambooHR, Workday; set up with a customer success manager [45] | Yes: Lucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | Yes: Deprovision via connector, IdP, ticket, webhook or manual task; not all connectors support it [10] | Yes: One-click offboarding for SSO and non-SSO apps [29] | Yes: Revokes access to SSO and non-SSO apps [46] | Yes: Native connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | Yes: Finds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configs [11] | Partial: Shadow IT and AI discovered and monitored; method not documented [30] | Yes: AI apps across 37+ sub-categories; AI agents discovered as NHIs [47] | Yes: Sign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | Yes: Identities and NHI dashboard with ownership status; standalone agents get their own identity [12] | Yes: Every NHI mapped to a human owner; Agent Ownership Finder [31] | Yes: Service accounts, tokens, bots and AI agents with enforced ownership [48] | Yes: Owner, model and scopes on every agent; offboarded like an employee |
| Policy enforced on each AI agent tool call (MCP) | Yes: MCP Gateway: reads auto-approve, writes go to an approver, destructive calls denied by default [12] | Yes: MCP Governance, September 2026: tool-use hook in Claude Code and Codex; vendor states it is not a gateway [32] | Not documented | Yes: Lutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not offered: LLM Gateway does routing and cost; DLP hooks described as being built [13] | Not documented | Not offered: Vendor: does not capture prompt content or the data payloads sent to AI models [47] | Yes: Detect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not offered: Sub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documented [14] | Not documented: Privacy policy mentions transfers outside the EEA; no region or language option found | Partial: AWS-hosted; only the PII vault region is customer-selectable; no French UI documented [49] | Yes: OVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | Yes: Audit-ready reports on demand; evidence timestamped, attributed and exportable [15] | Yes: Evidence-backed reports formatted for SOC 2, SOX and ISO 27001 [23] | Yes: Certification exports in CSV and timestamped PDF for SOC 2, ISO 27001, SOX [40] | Yes: Campaign export with decisions and revocation proof, one link |
| Native integrations | Yes: 400+ prebuilt connectors, plus an open-source connector SDK [16] | Yes: 300+ integrations [34] | Yes: 300+ connectors [50] | Yes: More than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offered: Pricing page without figures; platform tiers by managed identities, or usage-based tokens [2] | Not offered: Pricing page without figures [20] | Not offered: Pricing page is a demo request [37] | Not offered: On request |

## Choose C1 (formerly ConductorOne) if

- You run cloud infrastructure and want just-in-time access to AWS and GCP, requested from the web, Slack, Teams, the CLI or MCP.
- AI agents already call your tools through MCP and you want a gateway that evaluates identity and risk on every call and routes writes to an approver.
- You need 400+ connectors and an open-source SDK to build connectors for in-house systems.
- Provisioning must land as tickets in Jira, ServiceNow, Freshservice, Linear or HaloITSM, and US hosting is acceptable.

## Choose Lumos if

- You have 200 employees or more, the size Lumos says it is built for, and an IT team to run the platform.
- You want agents to run access reviews, role mining and JIT grants, with a self-service AppStore and grants from 2 hours to 90 days.
- Access requests must be tracked in Jira or ServiceNow with status synced both ways.
- Your developers use Claude Code or Codex and you want tool-call policy enforced in the client rather than through a gateway.

## Choose Zluri if

- SaaS spend, licence reclamation and renewals matter as much as access.
- Much of your access sits outside SSO and requests come from non-technical teams, the fit Zluri describes for itself.
- Requests start and are approved in Jira Service Management, and provisioning should follow automatically.
- Your team lives in Slack and does not need Microsoft Teams.

## Choose Lutril if

- You are a mid-market company without an IAM team and need discovery, reviews and offboarding running in weeks.
- Review decisions should execute in the connected tool, with decisions and revocation proof in one campaign export.
- AI agents call your SaaS tools and you want an MCP proxy with policy on every call, prompt DLP, a WORM log and a global kill switch.
- Requests and approvals must run in Slack, Microsoft Teams and the app UI, time-boxed from one hour to seven days and auto-revoked.
- Your data has to stay in the EU, or your team works in French.

## Frequently asked questions

### How does Lumos compare to C1 (formerly ConductorOne)?

Both govern human, non-human and AI identities with access reviews that revoke, Slack requests, time-boxed grants, HRIS-driven lifecycle and ITSM ticketing. C1 documents approvals in Microsoft Teams, just-in-time access to AWS and GCP, 400+ connectors with an open-source SDK, and an MCP Gateway in front of agent tool calls with risk-graded approvals. Lumos says it is built for companies of 200 employees and up, runs reviews and JIT grants through its Identity Agent Force, and since September 2026 enforces tool-call policy through a hook in Claude Code and Codex, which it states is not a gateway. Neither documents an EU hosting region; C1's sub-processors are in the United States.

### ConductorOne vs Zluri: which one should I choose?

C1 starts from identity governance and infrastructure: JIT access to cloud accounts, requests from the web, Slack, Teams, the CLI or MCP, and an MCP Gateway for agents. Zluri starts from SaaS management: discovery from eight sources, licence and spend optimisation, Slack requests and certifications. Zluri's own comparison credits C1 with JIT access to cloud infrastructure and describes its own time-bound access as a policy condition rather than a dedicated JIT workflow. Pick C1 for engineering-led, infrastructure-heavy access and agent tool calls; pick Zluri when spend and the SaaS apps outside SSO are the main problem.

### Is Lumos or Zluri better for SaaS access governance?

It depends on whether access or spend leads. Lumos auto-revokes rejected access through its integrations, runs grants from 2 hours to 90 days and syncs requests with Jira or ServiceNow; it says it targets companies of 200 employees and up. Zluri adds licence and spend optimisation and a browser extension for discovery; its review remediation runs after an admin concludes the review, and its notifications are documented in email and Slack. Neither documents approvals inside Microsoft Teams or an EU region with a French-language product.

### How does Lumos handle access management, JIT provisioning and ITSM?

Requests go through the Lumos AppStore, Slack or an MCP server. Grants last from 2 hours to 90 days, or unlimited, and are revoked automatically, and a Just-in-Time agent is part of its Identity Agent Force. The ITSM integration creates a Jira or ServiceNow ticket per request, routes it to an approver group, syncs status both ways and provisions on approval. Lifecycle runs from Workday, BambooHR, Rippling, ADP Workforce Now or Oracle HCM. Lumos does not publish prices.

### What are Lumos's main competitors?

The products most often compared with Lumos are C1 (formerly ConductorOne), Zluri, Torii, Okta Identity Governance and SailPoint; Lumos publishes its own comparison pages for C1 and Zluri. On this page, C1 documents infrastructure JIT, Teams approvals and a gateway for agent tool calls, and Zluri documents SaaS spend management and a browser extension. Lutril governs employees and AI agents in one policy layer, with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP and hosting in France.

### How does C1 compare to Oleria?

Oleria describes itself as a usage-aware identity security platform: adaptive identity governance, ISPM, NHI and AI agent governance and ITDR, with usage data down to resources such as files. C1 describes itself as the identity platform built for the AI era, with lifecycle, access, JIT, an LLM Gateway and an MCP Gateway. Oleria is not scored in the matrix above. Compare them on whether you need usage-level visibility into resources or policy enforced on each agent tool call.

## Sources

1. [C1 homepage](https://www.c1.ai/) (accessed 2026-09-26)
2. [C1 pricing](https://www.c1.ai/pricing) (accessed 2026-09-02)
3. [C1 docs, shadow apps](https://www.c1.ai/docs/product/admin/shadow-apps) (accessed 2026-09-02)
4. [C1 docs, policies](https://www.c1.ai/docs/product/admin/policies) (accessed 2026-09-02)
5. [C1 docs, Slack application](https://www.c1.ai/docs/product/admin/slack-application) (accessed 2026-09-02)
6. [C1 blog, advanced Microsoft Teams integration](https://www.c1.ai/blog/introducing-conductorones-advanced-microsoft-teams-integration/) (accessed 2026-09-02)
7. [C1 docs, replace standing access with JIT access](https://www.c1.ai/docs/product/use-cases/jit-access) (accessed 2026-09-26)
8. [C1 docs, integrate an external ticketing system](https://www.c1.ai/docs/product/admin/external-ticketing) (accessed 2026-09-26)
9. [C1 docs, inbound webhooks](https://www.c1.ai/docs/product/admin/webhooks-inbound) (accessed 2026-09-02)
10. [C1 docs, provisioning](https://www.c1.ai/docs/product/admin/provisioning) (accessed 2026-09-02)
11. [C1, shadow AI discovery](https://www.c1.ai/solutions/shadow-ai-discovery) (accessed 2026-09-02)
12. [C1, MCP Gateway](https://www.c1.ai/products/mcp-gateway) (accessed 2026-09-26)
13. [C1 blog, AI access management, your questions answered](https://www.c1.ai/blog/ai-access-management-your-questions-answered) (accessed 2026-09-02)
14. [C1 legal, sub-processors](https://www.c1.ai/legal/subprocessors) (accessed 2026-09-02)
15. [C1, Comply](https://www.c1.ai/products/comply) (accessed 2026-09-02)
16. [C1 integrations](https://www.c1.ai/integrations) (accessed 2026-09-02)
17. [C1, small and mid-size businesses](https://www.c1.ai/solutions/teams/small-mid-size-businesses) (accessed 2026-09-26)
18. [C1 blog, we are C1](https://www.c1.ai/blog/wearec1) (accessed 2026-09-02)
19. [Lumos homepage](https://www.lumos.com) (accessed 2026-09-26)
20. [Lumos pricing](https://www.lumos.com/pricing) (accessed 2026-09-02)
21. [Lumos help, connecting Google Workspace](https://lumos.help.usepylon.com/articles/1877502581-connecting-google-workspace) (accessed 2026-09-02)
22. [Lumos, Zluri alternatives and competitors](https://www.lumos.com/identity-matters/identity-governance/zluri-alternatives-and-competitors) (accessed 2026-09-26)
23. [Lumos, access reviews](https://www.lumos.com/products/access-reviews) (accessed 2026-09-02)
24. [Lumos help, connecting Slack](https://support.lumos.com/articles/3448469670-connecting-slack) (accessed 2026-09-02)
25. [Lumos, Microsoft Teams integration](https://www.lumos.com/integrations/microsoft-teams) (accessed 2026-09-02)
26. [Lumos help, AppStore quick start](https://support.lumos.com/articles/7910043985-lumos-appstore-quick-start-guide) (accessed 2026-09-02)
27. [Lumos developers, ITSM integration](https://developers.lumos.com/docs/itsm-integration) (accessed 2026-09-26)
28. [Lumos, lifecycle management](https://www.lumos.com/products/lifecycle-management) (accessed 2026-09-02)
29. [Lumos, JML workflow orchestration](https://www.lumos.com/solutions/jml-workflow-orchestration) (accessed 2026-09-02)
30. [Lumos, identity security posture](https://www.lumos.com/solutions/identity-security-posture) (accessed 2026-09-02)
31. [Lumos, non-human identities](https://www.lumos.com/solutions/non-human-identities) (accessed 2026-09-02)
32. [Lumos blog, introducing MCP Governance](https://www.lumos.com/blog/mcp-governance-runtime-agent-access-control) (accessed 2026-09-26)
33. [Lumos privacy policy](https://www.lumos.com/privacy) (accessed 2026-09-02)
34. [Lumos integrations](https://www.lumos.com/integrations) (accessed 2026-09-02)
35. [Lumos, ConductorOne competitors and alternatives](https://www.lumos.com/identity-matters/identity-governance/conductorone-competitors-and-alternatives) (accessed 2026-09-26)
36. [Zluri homepage](https://www.zluri.com) (accessed 2026-09-26)
37. [Zluri pricing](https://www.zluri.com/pricing) (accessed 2026-09-02)
38. [Zluri help, Google Workspace integration](https://help.zluri.com/docs/google-workspace-integration) (accessed 2026-09-02)
39. [Zluri, how the discovery engine works](https://www.zluri.com/blog/how-zluris-discovery-engine-works) (accessed 2026-09-02)
40. [Zluri help, closing and completing certifications](https://help.zluri.com/docs/closing-and-completing-certifications) (accessed 2026-09-02)
41. [Zluri, access requests](https://www.zluri.com/features/access-requests) (accessed 2026-09-02)
42. [Zluri help, notification customization](https://help.zluri.com/docs/notification-customization) (accessed 2026-09-02)
43. [Zluri, Zluri vs ConductorOne](https://www.zluri.com/blog/zluri-vs-conductorone) (accessed 2026-09-26)
44. [Zluri help, zero touch onboarding via Jira](https://help.zluri.com/docs/zero-touch-onboarding-jira-itsm) (accessed 2026-09-26)
45. [Zluri help, zero touch onboarding](https://help.zluri.com/docs/zero-touch-onboarding) (accessed 2026-09-02)
46. [Zluri, secure deprovisioning](https://www.zluri.com/features/secure-deprovisioning) (accessed 2026-09-02)
47. [Zluri, shadow AI governance tools](https://www.zluri.com/eye-on-identity/shadow-ai-governance-tools) (accessed 2026-09-26)
48. [Zluri, identity visibility and intelligence](https://www.zluri.com/products/identity-visibility-and-intelligence) (accessed 2026-09-02)
49. [Zluri security](https://www.zluri.com/security) (accessed 2026-09-02)
50. [Zluri integrations](https://www.zluri.com/integrations) (accessed 2026-09-02)
51. [Oleria homepage](https://www.oleria.com) (accessed 2026-09-26)

Lutril wrote this page. Facts about C1 (formerly ConductorOne), Lumos, Zluri come from their public documentation as of 2026-09-26. Spotted an error? Write to hello@lutril.com.
