Lutril vs Lumos
Lumos is an autonomous identity platform for mid-market and enterprise companies of 200 employees and up, with agentic access reviews and Slack requests. Lutril is access governance for employees and AI agents, in Slack, Teams and the app UI, hosted in the EU, with an MCP proxy. Where each fits, and the Lumos alternatives question answered.
Short answer
Lumos and Lutril overlap on the core: SaaS discovery from Google Workspace and Microsoft 365, access reviews whose rejections auto-revoke, Slack requests with time-boxed grants, HRIS-driven lifecycle and an owner on every non-human identity. They differ on three things. Lumos targets companies of 200 employees and up and says a small team may find it more than it needs; Lutril is built for teams without an IAM function. Lumos ships MCP servers that expose its own product to assistants, while Lutril's MCP proxy sits in front of every SaaS tool and enforces policy on each agent call, with prompt DLP and a kill switch. And Lumos documents no EU hosting region or French UI, where Lutril is hosted in France and available in French.
Where each one starts
Lumos
The autonomous identity platform: agents that continuously govern access for every human, machine and AI, with an AI layer called Albus and an Identity Agent Force of out-of-the-box agents. San Francisco, $85M+ raised, Series B led by Scale in 2024, a Strong Performer in Gartner's 2026 Voice of the Customer for IGA. Requests in Slack, the IT system or through MCP; 300+ integrations.
Lutril
Access governance for employees and AI agents in one policy layer: discovery the day you connect Google Workspace or Microsoft 365, requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy that checks every agent tool call with prompt DLP and a global kill switch. Built by a practising CISO, hosted in France, in French and English.
Capability by capability
| Capability | Lumos | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | YesGoogle scope to discover apps employees signed into with Google; Microsoft 365 report and audit scopesSource 3 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | PartialBrowser sessions cited as a signal; no extension documented in the help centreSource 4 | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | YesAuto-revoke rejected access through downstream integrationsSource 5 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | YesSlack app for requests, approver notifications and remindersSource 6 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | PartialRequests flow into Teams; approval inside Teams not explicitly documentedSource 7 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | YesDurations from 2 hours to 90 days, or unlimited, with automatic revocationSource 8 | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | YesWorkday, BambooHR, Rippling, ADP Workforce Now, Oracle HCMSource 9 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | YesOne-click offboarding for SSO and non-SSO appsSource 10 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | PartialShadow IT and AI discovered and monitored; method not documentedSource 11 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesEvery NHI mapped to a human owner; Agent Ownership FinderSource 12 | YesOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | Not offeredShips MCP servers exposing Lumos's own tools; not a proxy over third-party agent callsSource 13 | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not documented | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not documentedPrivacy policy mentions transfers outside the EEA; no region or language option found | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesEvidence-backed reports formatted for SOC 2, SOX and ISO 27001Source 5 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Yes300+ integrationsSource 15 | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offeredPricing page without figuresSource 2 | Not offeredOn request |
Choose Lumos if
- You have 200 employees or more, an IT or IAM team to run it, and want AI-assisted reviews and an agent workforce inside the identity platform.
- Your HRIS is Workday, ADP or Oracle HCM and your integrations are already in Lumos's catalogue.
- US hosting is acceptable and an English-only product is fine.
Choose Lutril if
- You are a mid-market company without an IAM team and need discovery, reviews and offboarding running in weeks.
- AI agents call your SaaS tools and you need a proxy that enforces policy on each MCP call, with prompt DLP and a kill switch, not only ownership mapping.
- Requests and approvals must run in Microsoft Teams as well as Slack.
- Your data has to stay in the EU, or your team works in French.
Questions buyers ask
What are the best alternatives to Lumos for access reviews?
Look for a tool whose review decisions execute the removal, that covers apps outside SSO, and that exports evidence an auditor accepts. Lutril, C1 (formerly ConductorOne), Zluri, Torii and Okta Identity Governance all run campaigns; they differ on automatic remediation, Teams support, EU hosting and AI agent coverage. Lutril's campaigns include registered AI agents alongside employees, execute removals in the connected tool, and export one link with the decisions and the revocation proof.
Does Lumos govern AI agents through MCP?
Lumos governs non-human identities, maps each to a human owner and ships MCP servers so assistants can request access or administer Lumos itself. It does not document a proxy that sits in front of third-party SaaS tools and enforces policy on each agent tool call. That proxy is what Lutril's MCP proxy is: one endpoint for every connected tool, role-based policy per call, a WORM log, prompt DLP and a global kill switch.
Is Lumos suitable for a company of 80 people?
Lumos's own comparison content says it targets mid-market and enterprise, generally 200 or more employees, and that a small team may find it more capability than it needs. Lutril is designed for teams with no dedicated IAM function, with discovery starting the day you connect your workspace.
Where is each product hosted?
Lumos's privacy policy refers to transfers outside the EEA with safeguards; we found no documented EU region or French-language option. Lutril is hosted at OVHcloud in France, with Cloudflare at the edge, and the product and documentation exist in French and English.
Sources
- 1Lumos homepageread on September 2, 2026
- 2Lumos pricingread on September 2, 2026
- 3Lumos help, connecting Google Workspaceread on September 2, 2026
- 4Lumos, Zluri alternatives and competitorsread on September 2, 2026
- 5Lumos, access reviewsread on September 2, 2026
- 6Lumos help, connecting Slackread on September 2, 2026
- 7Lumos, Microsoft Teams integrationread on September 2, 2026
- 8Lumos help, AppStore quick startread on September 2, 2026
- 9Lumos, lifecycle managementread on September 2, 2026
- 10Lumos, JML workflow orchestrationread on September 2, 2026
- 11Lumos, identity security postureread on September 2, 2026
- 12Lumos, non-human identitiesread on September 2, 2026
- 13Lumos developers, MCPread on September 2, 2026
- 14Lumos privacy policyread on September 2, 2026
- 15Lumos integrationsread on September 2, 2026
- 16Lumos, ConductorOne competitors and alternativesread on September 2, 2026
- 17Lumos, aboutread on September 2, 2026
Lutril wrote this page. Facts about Lumos come from their public documentation as of September 2, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.
Related reading
- SOC 2 Wants Proof. Not a Spreadsheet.
- MCP Governance: How to Control What AI Agents Can Do in Your SaaS
- MCP Proxy: Every tool call runs through policy.
- Lutril vs Zluri
- Lutril vs C1 (formerly ConductorOne)
- Best identity governance (IGA) tools for a fast-growing startup: Lumos, C1, Okta Identity Governance, SailPoint and Lutril