Lutril vs Zluri
Zluri is a SaaS management platform turned identity security suite, a Gartner Magic Quadrant Leader for SMPs, with eight discovery methods and Slack-native requests. Lutril is access governance for employees and AI agents, in Slack, Teams and the app UI, hosted in the EU, with an MCP proxy. Where each fits.
Short answer
Choose Zluri if SaaS management is the centre of the job: discovery from eight parallel sources against a 240,000-app library, licence and spend optimisation, and Slack-native requests with time-boxed grants, for an enterprise or mid-market team. Choose Lutril if the job is access governance across employees and AI agents: reviews whose decisions execute without waiting for an admin to conclude the review, requests in Microsoft Teams as well as Slack, an MCP proxy with policy on each agent tool call and prompt DLP, and hosting in the EU with a French-language product. Zluri states it does not capture prompt content and documents notifications only in email and Slack.
Where each one starts
Zluri
Identity security for autonomous enterprises: discover, govern and secure every human and non-human identity, across four lines (identity visibility, IGA, ISPM and SaaS management). Milpitas, founded 2020, $32M raised with a Series B led by Lightspeed in 2023, a Leader in Gartner's Magic Quadrant for SaaS Management Platforms in 2024 and 2025. 300+ connectors.
Lutril
Access governance for employees and AI agents: discovery from Google Workspace and Microsoft 365, a Chrome extension and code scanning; requests in Slack, Teams and the app UI with automatic expiry; reviews that revoke; HRIS-driven lifecycle; and an MCP proxy with prompt DLP and a global kill switch. Hosted in France, in French and English.
Capability by capability
| Capability | Zluri | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | YesGoogle Workspace and Entra ID integrations: accounts, usage, third-party apps connectedSource 3 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | YesChrome, Firefox, Edge and Brave; logs URLs and titles, no contentSource 4 | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | PartialRemediation playbooks run after an admin concludes the review; manual task for non-integrated appsSource 5 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | YesRequest, approve and reject in Slack; provisioning playbook on approvalSource 6 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | Not offeredNotification channels documented as email and SlackSource 7 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | YesAccess duration on requests; deprovisioning playbook on expirySource 8 | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | YesHiBob, Personio, BambooHR, Workday; set up with a customer success managerSource 9 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | YesRevokes access to SSO and non-SSO appsSource 10 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | YesAI apps across 37+ sub-categories; AI agents discovered as NHIsSource 11 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesService accounts, tokens, bots and AI agents with enforced ownershipSource 12 | YesOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | Not documented | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not offeredVendor: does not capture prompt content or the data payloads sent to AI modelsSource 11 | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | PartialAWS-hosted; only the PII vault region is customer-selectable; no French UI documentedSource 13 | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesCertification exports in CSV and timestamped PDF for SOC 2, ISO 27001, SOXSource 5 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Yes300+ connectorsSource 14 | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offeredPricing page is a demo requestSource 2 | Not offeredOn request |
Choose Zluri if
- SaaS spend, licence reclamation and renewals are as important to you as access.
- You want discovery from finance systems, CASB and MDM in addition to the identity provider.
- Your team lives in Slack and does not need Microsoft Teams.
Choose Lutril if
- Review decisions should execute in the tool the moment the reviewer decides, with the proof attached.
- Requests and approvals must run in Microsoft Teams as well as Slack and the app UI.
- AI agents need policy on each MCP tool call and prompt-level DLP, not only an inventory with owners.
- Your data has to stay in the EU, or your team works in French.
Questions buyers ask
Is Zluri an access governance tool or a SaaS management tool?
Both, by its own positioning: it started as a SaaS management platform and now sells identity governance and posture lines on the same discovery engine. Lutril is access governance first, for employees and AI agents, with shadow IT and shadow AI discovery as the entry point rather than spend management.
Do Zluri access reviews revoke access automatically?
Zluri's documentation says remediation playbooks run after the admin clicks Conclude Review, automatically for integrated apps and as a manual task otherwise. In Lutril each keep-or-remove decision executes in the connected tool, and the campaign export carries the revocation proof next to the decision.
Which one supports Microsoft Teams?
Zluri documents email and Slack as notification channels and manages Teams as an application. Lutril runs requests, approvals and expiry warnings in Slack, Microsoft Teams and the app UI.
Can either one see what employees send to AI tools?
Zluri states it does not capture prompt content, keystrokes or the payloads sent to AI models; its shadow AI coverage is usage and identity based. Lutril adds prompt-level DLP at the proxy layer: detect and redact PII and secrets before they reach the model, with a per-model policy and an immutable log.
Sources
- 1Zluri homepageread on September 2, 2026
- 2Zluri pricingread on September 2, 2026
- 3Zluri help, Google Workspace integrationread on September 2, 2026
- 4Zluri, how the discovery engine worksread on September 2, 2026
- 5Zluri help, closing and completing certificationsread on September 2, 2026
- 6Zluri, access requestsread on September 2, 2026
- 7Zluri help, notification customizationread on September 2, 2026
- 8Zluri help, automation rulesread on September 2, 2026
- 9Zluri help, zero touch onboardingread on September 2, 2026
- 10Zluri, secure deprovisioningread on September 2, 2026
- 11Zluri, shadow AI governance toolsread on September 2, 2026
- 12Zluri, identity visibility and intelligenceread on September 2, 2026
- 13Zluri securityread on September 2, 2026
- 14Zluri integrationsread on September 2, 2026
- 15Zluri, Series B fundingread on September 2, 2026
Lutril wrote this page. Facts about Zluri come from their public documentation as of September 2, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.