# Lutril vs C1 (formerly ConductorOne)

> C1, the identity platform formerly known as ConductorOne, governs human, non-human and AI identities for Fortune 500 and hypergrowth enterprises, with an MCP Gateway. Lutril delivers access governance for employees and AI agents to mid-market teams, in the EU and in French. Where each fits.

Source: https://www.lutril.com/compare/lutril-vs-conductorone
Last reviewed: 2026-09-02

---

## Short answer

C1 and Lutril are the two products on this site that govern AI agents at the tool-call level: both register agents as identities and both enforce policy in front of MCP tool calls. C1 is built for Fortune 500 and hypergrowth enterprises, with 400+ connectors, an open-source connector SDK, Slack and Teams requests and a consumption-billed AI access module; its sub-processors are in the United States and prompt DLP is described as in progress. Lutril is built for mid-market teams: the same request, review and lifecycle outcomes in Slack, Teams and the app UI, prompt DLP shipped in the MCP proxy, a browser extension for shadow SaaS and AI, EU hosting and a French-language product.

## Where each one starts

**C1 (formerly ConductorOne).** An AI-native identity platform governing access for human, non-human and AI identities, and the control plane for the agentic enterprise: Lifecycle, Access, Comply, LLM Gateway, MCP Gateway, Vault, Worker and Bridge. Rebranded from ConductorOne to C1 in April 2026. San Francisco and Portland, founded late 2020, $79M Series B led by Greycroft in October 2025, more than $100M raised.

**Lutril.** Access governance for employees and AI agents in one product: discovery from Google Workspace and Microsoft 365, a Chrome extension and code scanning; requests in Slack, Teams and the app UI with automatic expiry; reviews that revoke; HRIS-driven lifecycle; and an MCP proxy with policy on every call, prompt DLP and a global kill switch. Hosted in France, in French and English.

## Capability by capability

| Capability | C1 (formerly ConductorOne) | Lutril |
| --- | --- | --- |
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | Yes: Shadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitored [3] | Yes: Google Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Not documented | Yes: Chrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | Yes: Policy auto-creates a revoke task on denial; connector deprovisions, manual task otherwise [4] | Yes: Decisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Yes: /c1 request in Slack; approve or deny without leaving Slack [5] | Yes: Requests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | Yes: Approve and deny in Teams since November 2025; create requests in Teams since early 2026 [6] | Yes: Same flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | Yes: Time-limited grants expire automatically with reminders [7] | Yes: One hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | Yes: Inbound webhooks for Workday and BambooHR; SAP SuccessFactors connector [8] | Yes: Lucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | Yes: Deprovision via connector, IdP, ticket, webhook or manual task; not all connectors support it [9] | Yes: Native connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | Yes: Finds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configs [10] | Yes: Sign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | Yes: Identities and NHI dashboard with ownership status; standalone agents get their own identity [11] | Yes: Owner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | Yes: MCP Gateway: identity-aware policy in front of every MCP tool call; approval for high-risk calls [11] | Yes: Lutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not offered: LLM Gateway does routing and cost; DLP hooks described as being built [12] | Yes: Detect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not offered: Sub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documented [13] | Yes: OVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | Yes: Audit-ready reports on demand; evidence timestamped, attributed and exportable [14] | Yes: Campaign export with decisions and revocation proof, one link |
| Native integrations | Yes: 400+ prebuilt connectors, plus an open-source connector SDK [15] | Yes: More than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offered: Pricing page without figures; platform tiers by managed identities, or usage-based tokens [2] | Not offered: On request |

## Choose C1 (formerly ConductorOne) if

- You are a large or hypergrowth enterprise with hybrid infrastructure: Active Directory, LDAP, databases, cloud, and a team to run a platform.
- You need an open-source connector SDK to build integrations for in-house systems.
- US hosting is acceptable and AI agent access can be billed on consumption.

## Choose Lutril if

- You are a mid-market company and want agent governance, prompt DLP and a kill switch shipped in one product, priced on the people and agents governed.
- Your data has to stay in the EU, or your team works in French.
- You want a browser extension and mailbox scanning to catch the SaaS and AI tools that never touch the identity provider.
- Reviews and approvals should happen in Slack, Teams or the app UI, not in a web console only.

## Frequently asked questions

### What is C1, and what happened to ConductorOne?

ConductorOne rebranded to C1 on April 6, 2026; conductorone.com now redirects to c1.ai. The product is the same identity platform, positioned as AI-native and as a control plane for the agentic enterprise, with an MCP Gateway and an LLM Gateway alongside lifecycle, access and compliance modules.

### Both have an MCP gateway. What is the difference?

Both put identity-aware policy in front of MCP tool calls and register agents as identities. C1 documents auto-approval for low-risk calls and human approval for high-risk ones, with a consumption-billed AI access module. Lutril's MCP proxy adds prompt-level DLP that redacts PII and secrets before the model sees them, a WORM audit log, a global kill switch, and one MCP endpoint that exposes any connected SaaS tool, all in the base product.

### Which one fits a company of 150 to 1,500 people?

C1 targets Fortune 500 and hypergrowth enterprises and also publishes an SMB solution page. Lutril is designed for mid-market teams without an IAM function, with discovery starting the day you connect Google Workspace or Microsoft 365 and requests running where people already work.

### Where is each product hosted?

C1's sub-processor list is US-based and its data processing agreement authorises transfers from the EEA to the United States. Lutril is hosted at OVHcloud in France, with Cloudflare at the edge.

## Sources

1. [C1 homepage](https://www.c1.ai/) (accessed 2026-09-02)
2. [C1 pricing](https://www.c1.ai/pricing) (accessed 2026-09-02)
3. [C1 docs, shadow apps](https://www.c1.ai/docs/product/admin/shadow-apps) (accessed 2026-09-02)
4. [C1 docs, policies](https://www.c1.ai/docs/product/admin/policies) (accessed 2026-09-02)
5. [C1 docs, Slack application](https://www.c1.ai/docs/product/admin/slack-application) (accessed 2026-09-02)
6. [C1 blog, advanced Microsoft Teams integration](https://www.c1.ai/blog/introducing-conductorones-advanced-microsoft-teams-integration/) (accessed 2026-09-02)
7. [C1 docs, create requests](https://www.c1.ai/docs/product/how-to/create-requests) (accessed 2026-09-02)
8. [C1 docs, inbound webhooks](https://www.c1.ai/docs/product/admin/webhooks-inbound) (accessed 2026-09-02)
9. [C1 docs, provisioning](https://www.c1.ai/docs/product/admin/provisioning) (accessed 2026-09-02)
10. [C1, shadow AI discovery](https://www.c1.ai/solutions/shadow-ai-discovery) (accessed 2026-09-02)
11. [C1, MCP Gateway](https://www.c1.ai/products/mcp-gateway) (accessed 2026-09-02)
12. [C1 blog, AI access management, your questions answered](https://www.c1.ai/blog/ai-access-management-your-questions-answered) (accessed 2026-09-02)
13. [C1 legal, sub-processors](https://www.c1.ai/legal/subprocessors) (accessed 2026-09-02)
14. [C1, Comply](https://www.c1.ai/products/comply) (accessed 2026-09-02)
15. [C1 integrations](https://www.c1.ai/integrations) (accessed 2026-09-02)
16. [C1 blog, we are C1](https://www.c1.ai/blog/wearec1) (accessed 2026-09-02)
17. [C1 press, $79M Series B](https://www.c1.ai/news/press-release/conductorone-raises-79-million-series-b) (accessed 2026-09-02)
18. [C1 docs, review tasks](https://www.c1.ai/docs/product/how-to/review-tasks) (accessed 2026-09-02)

Lutril wrote this page. Facts about C1 (formerly ConductorOne) come from their public documentation as of 2026-09-02. Spotted an error? Write to hello@lutril.com.
