ConductorOne (C1) vs Lumos vs Zluri: SaaS access governance compared
C1 (formerly ConductorOne), Lumos and Zluri compared on access reviews, JIT access, Slack, Teams and ITSM requests, AI agent governance and hosting, from vendor docs.
Cette page n’est pas encore traduite. Voici la version anglaise.
Réponse courte
Choose C1 (formerly ConductorOne) if you run cloud infrastructure with an identity team, want just-in-time access to AWS and GCP, requests in Slack or Teams, and an MCP Gateway that grades every agent tool call by risk, and US hosting is acceptable. Choose Lumos if you have 200 employees or more and want an autonomous identity platform: agents that run reviews and JIT grants, an AppStore with grants from 2 hours to 90 days, Jira or ServiceNow ticket sync, and since September 2026 tool-call policy in Claude Code and Codex. Choose Zluri if SaaS management is as much the job as access: discovery from eight sources, licence and spend optimisation, and requests in Slack or approved in Jira Service Management. None of the three documents prompt-level DLP or EU hosting with a French-language product; Lutril, listed last, governs employees and AI agents with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP, and hosting in France.
D'où part chaque produit
C1 (formerly ConductorOne)
The identity platform built for the AI era: identity governance, lifecycle, just-in-time access, an LLM Gateway, an MCP Gateway, Vault, Agents and Bridge, with 400+ connectors and an open-source connector SDK. Rebranded from ConductorOne to C1 in April 2026. Customers include enterprise and hypergrowth companies, and C1 runs a small and mid-size business offer with deployment experts and requests in Slack or Teams. US sub-processors.
Lumos
Identity management for the agentic era: the autonomous identity platform, with agents that continuously govern access for every human, machine and AI. Albus and an Identity Agent Force run access reviews, JIT grants, role mining and NHI ownership; an AppStore handles self-service requests; MCP Governance checks agent tool calls. Built for mid-market and enterprise, generally 200 employees or more, by its own account. 300+ integrations.
Zluri
Identity security for autonomous enterprises: discover, govern and secure every human and non-human identity, across identity visibility, IGA, ISPM and SaaS management. Started as a SaaS management platform and is a Leader in Gartner's Magic Quadrant for SaaS Management Platforms in 2024 and 2025. Discovery from eight sources, Slack-native requests, 300+ connectors.
Lutril
Access governance for employees and AI agents in one policy layer: discovery the day you connect Google Workspace or Microsoft 365, requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy that checks every agent tool call with prompt DLP and a global kill switch. Built by a practising CISO, hosted in France, in French and English.
Capacité par capacité
| Capacité | C1 (formerly ConductorOne) | Lumos | Zluri | Lutril |
|---|---|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | OuiShadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitoredSource 3 | OuiGoogle scope to discover apps employees signed into with Google; Microsoft 365 report and audit scopesSource 21 | OuiGoogle Workspace and Entra ID integrations: accounts, usage, third-party apps connectedSource 38 | OuiGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Non documenté | PartielBrowser sessions cited as a signal; no extension documented in the help centreSource 22 | OuiChrome, Firefox, Edge and Brave; logs URLs and titles, no contentSource 39 | OuiChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | OuiPolicy auto-creates a revoke task on denial; connector deprovisions, manual task otherwiseSource 4 | OuiAuto-revoke rejected access through downstream integrationsSource 23 | PartielRemediation playbooks run after an admin concludes the review; manual task for non-integrated appsSource 40 | OuiDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Oui/c1 request in Slack; approve or deny without leaving SlackSource 5 | OuiSlack app for requests, approver notifications and remindersSource 24 | OuiRequest, approve and reject in Slack; provisioning playbook on approvalSource 41 | OuiRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | OuiApprove and deny in Teams since November 2025; create requests in Teams since early 2026Source 6 | PartielRequests flow into Teams; approval inside Teams not explicitly documentedSource 25 | Non proposéNotification channels documented as email and SlackSource 42 | OuiSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | OuiGrant revoked when the window closes; AWS and GCP JIT quickstarts; expiry remindersSource 7 | OuiDurations from 2 hours to 90 days, or unlimited, with automatic revocationSource 26 | OuiTime-bound access as a policy condition; vendor states it has no dedicated JIT workflowSource 43 | OuiOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Access requests tracked in an ITSM (Jira Service Management, ServiceNow) | OuiProvisioning tickets in Jira Cloud, Jira Data Center, ServiceNow, Freshservice, Linear, HaloITSM; requests start in C1Source 8 | OuiJira or ServiceNow ticket per request, approver group routing, two-way status syncSource 27 | OuiRequest and approval in Jira; Zluri provisions and adds a note to the ticketSource 44 | Non proposéRequests and approvals run in Slack, Teams and the app UI |
| Onboarding triggered by the HRIS | OuiInbound webhooks for Workday and BambooHR; SAP SuccessFactors connectorSource 9 | OuiWorkday, BambooHR, Rippling, ADP Workforce Now, Oracle HCMSource 28 | OuiHiBob, Personio, BambooHR, Workday; set up with a customer success managerSource 45 | OuiLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | OuiDeprovision via connector, IdP, ticket, webhook or manual task; not all connectors support itSource 10 | OuiOne-click offboarding for SSO and non-SSO appsSource 29 | OuiRevokes access to SSO and non-SSO appsSource 46 | OuiNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | OuiFinds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configsSource 11 | PartielShadow IT and AI discovered and monitored; method not documentedSource 30 | OuiAI apps across 37+ sub-categories; AI agents discovered as NHIsSource 47 | OuiSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | OuiIdentities and NHI dashboard with ownership status; standalone agents get their own identitySource 12 | OuiEvery NHI mapped to a human owner; Agent Ownership FinderSource 31 | OuiService accounts, tokens, bots and AI agents with enforced ownershipSource 48 | OuiOwner, model and scopes on every agent; offboarded like an employee |
| Policy enforced on each AI agent tool call (MCP) | OuiMCP Gateway: reads auto-approve, writes go to an approver, destructive calls denied by defaultSource 12 | OuiMCP Governance, September 2026: tool-use hook in Claude Code and Codex; vendor states it is not a gatewaySource 32 | Non documenté | OuiLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Non proposéLLM Gateway does routing and cost; DLP hooks described as being builtSource 13 | Non documenté | Non proposéVendor: does not capture prompt content or the data payloads sent to AI modelsSource 47 | OuiDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Non proposéSub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documentedSource 14 | Non documentéPrivacy policy mentions transfers outside the EEA; no region or language option found | PartielAWS-hosted; only the PII vault region is customer-selectable; no French UI documentedSource 49 | OuiOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | OuiAudit-ready reports on demand; evidence timestamped, attributed and exportableSource 15 | OuiEvidence-backed reports formatted for SOC 2, SOX and ISO 27001Source 23 | OuiCertification exports in CSV and timestamped PDF for SOC 2, ISO 27001, SOXSource 40 | OuiCampaign export with decisions and revocation proof, one link |
| Native integrations | Oui400+ prebuilt connectors, plus an open-source connector SDKSource 16 | Oui300+ integrationsSource 34 | Oui300+ connectorsSource 50 | OuiMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Non proposéPricing page without figures; platform tiers by managed identities, or usage-based tokensSource 2 | Non proposéPricing page without figuresSource 20 | Non proposéPricing page is a demo requestSource 37 | Non proposéOn request |
Choisissez C1 (formerly ConductorOne) si
- You run cloud infrastructure and want just-in-time access to AWS and GCP, requested from the web, Slack, Teams, the CLI or MCP.
- AI agents already call your tools through MCP and you want a gateway that evaluates identity and risk on every call and routes writes to an approver.
- You need 400+ connectors and an open-source SDK to build connectors for in-house systems.
- Provisioning must land as tickets in Jira, ServiceNow, Freshservice, Linear or HaloITSM, and US hosting is acceptable.
Choisissez Lumos si
- You have 200 employees or more, the size Lumos says it is built for, and an IT team to run the platform.
- You want agents to run access reviews, role mining and JIT grants, with a self-service AppStore and grants from 2 hours to 90 days.
- Access requests must be tracked in Jira or ServiceNow with status synced both ways.
- Your developers use Claude Code or Codex and you want tool-call policy enforced in the client rather than through a gateway.
Choisissez Zluri si
- SaaS spend, licence reclamation and renewals matter as much as access.
- Much of your access sits outside SSO and requests come from non-technical teams, the fit Zluri describes for itself.
- Requests start and are approved in Jira Service Management, and provisioning should follow automatically.
- Your team lives in Slack and does not need Microsoft Teams.
Choisissez Lutril si
- You are a mid-market company without an IAM team and need discovery, reviews and offboarding running in weeks.
- Review decisions should execute in the connected tool, with decisions and revocation proof in one campaign export.
- AI agents call your SaaS tools and you want an MCP proxy with policy on every call, prompt DLP, a WORM log and a global kill switch.
- Requests and approvals must run in Slack, Microsoft Teams and the app UI, time-boxed from one hour to seven days and auto-revoked.
- Your data has to stay in the EU, or your team works in French.
Les questions que se posent les acheteurs
How does Lumos compare to C1 (formerly ConductorOne)?
Both govern human, non-human and AI identities with access reviews that revoke, Slack requests, time-boxed grants, HRIS-driven lifecycle and ITSM ticketing. C1 documents approvals in Microsoft Teams, just-in-time access to AWS and GCP, 400+ connectors with an open-source SDK, and an MCP Gateway in front of agent tool calls with risk-graded approvals. Lumos says it is built for companies of 200 employees and up, runs reviews and JIT grants through its Identity Agent Force, and since September 2026 enforces tool-call policy through a hook in Claude Code and Codex, which it states is not a gateway. Neither documents an EU hosting region; C1's sub-processors are in the United States.
ConductorOne vs Zluri: which one should I choose?
C1 starts from identity governance and infrastructure: JIT access to cloud accounts, requests from the web, Slack, Teams, the CLI or MCP, and an MCP Gateway for agents. Zluri starts from SaaS management: discovery from eight sources, licence and spend optimisation, Slack requests and certifications. Zluri's own comparison credits C1 with JIT access to cloud infrastructure and describes its own time-bound access as a policy condition rather than a dedicated JIT workflow. Pick C1 for engineering-led, infrastructure-heavy access and agent tool calls; pick Zluri when spend and the SaaS apps outside SSO are the main problem.
Is Lumos or Zluri better for SaaS access governance?
It depends on whether access or spend leads. Lumos auto-revokes rejected access through its integrations, runs grants from 2 hours to 90 days and syncs requests with Jira or ServiceNow; it says it targets companies of 200 employees and up. Zluri adds licence and spend optimisation and a browser extension for discovery; its review remediation runs after an admin concludes the review, and its notifications are documented in email and Slack. Neither documents approvals inside Microsoft Teams or an EU region with a French-language product.
How does Lumos handle access management, JIT provisioning and ITSM?
Requests go through the Lumos AppStore, Slack or an MCP server. Grants last from 2 hours to 90 days, or unlimited, and are revoked automatically, and a Just-in-Time agent is part of its Identity Agent Force. The ITSM integration creates a Jira or ServiceNow ticket per request, routes it to an approver group, syncs status both ways and provisions on approval. Lifecycle runs from Workday, BambooHR, Rippling, ADP Workforce Now or Oracle HCM. Lumos does not publish prices.
What are Lumos's main competitors?
The products most often compared with Lumos are C1 (formerly ConductorOne), Zluri, Torii, Okta Identity Governance and SailPoint; Lumos publishes its own comparison pages for C1 and Zluri. On this page, C1 documents infrastructure JIT, Teams approvals and a gateway for agent tool calls, and Zluri documents SaaS spend management and a browser extension. Lutril governs employees and AI agents in one policy layer, with requests in Slack, Teams and the app UI, an MCP proxy with prompt DLP and hosting in France.
How does C1 compare to Oleria?
Oleria describes itself as a usage-aware identity security platform: adaptive identity governance, ISPM, NHI and AI agent governance and ITDR, with usage data down to resources such as files. C1 describes itself as the identity platform built for the AI era, with lifecycle, access, JIT, an LLM Gateway and an MCP Gateway. Oleria is not scored in the matrix above. Compare them on whether you need usage-level visibility into resources or policy enforced on each agent tool call.
Sources
- 1C1 homepageconsulté le 26 septembre 2026
- 2C1 pricingconsulté le 2 septembre 2026
- 3C1 docs, shadow appsconsulté le 2 septembre 2026
- 4C1 docs, policiesconsulté le 2 septembre 2026
- 5C1 docs, Slack applicationconsulté le 2 septembre 2026
- 6C1 blog, advanced Microsoft Teams integrationconsulté le 2 septembre 2026
- 7C1 docs, replace standing access with JIT accessconsulté le 26 septembre 2026
- 8C1 docs, integrate an external ticketing systemconsulté le 26 septembre 2026
- 9C1 docs, inbound webhooksconsulté le 2 septembre 2026
- 10C1 docs, provisioningconsulté le 2 septembre 2026
- 11C1, shadow AI discoveryconsulté le 2 septembre 2026
- 12C1, MCP Gatewayconsulté le 26 septembre 2026
- 13C1 blog, AI access management, your questions answeredconsulté le 2 septembre 2026
- 14C1 legal, sub-processorsconsulté le 2 septembre 2026
- 15C1, Complyconsulté le 2 septembre 2026
- 16C1 integrationsconsulté le 2 septembre 2026
- 17C1, small and mid-size businessesconsulté le 26 septembre 2026
- 18C1 blog, we are C1consulté le 2 septembre 2026
- 19Lumos homepageconsulté le 26 septembre 2026
- 20Lumos pricingconsulté le 2 septembre 2026
- 21Lumos help, connecting Google Workspaceconsulté le 2 septembre 2026
- 22Lumos, Zluri alternatives and competitorsconsulté le 26 septembre 2026
- 23Lumos, access reviewsconsulté le 2 septembre 2026
- 24Lumos help, connecting Slackconsulté le 2 septembre 2026
- 25Lumos, Microsoft Teams integrationconsulté le 2 septembre 2026
- 26Lumos help, AppStore quick startconsulté le 2 septembre 2026
- 27Lumos developers, ITSM integrationconsulté le 26 septembre 2026
- 28Lumos, lifecycle managementconsulté le 2 septembre 2026
- 29Lumos, JML workflow orchestrationconsulté le 2 septembre 2026
- 30Lumos, identity security postureconsulté le 2 septembre 2026
- 31Lumos, non-human identitiesconsulté le 2 septembre 2026
- 32Lumos blog, introducing MCP Governanceconsulté le 26 septembre 2026
- 33Lumos privacy policyconsulté le 2 septembre 2026
- 34Lumos integrationsconsulté le 2 septembre 2026
- 35Lumos, ConductorOne competitors and alternativesconsulté le 26 septembre 2026
- 36Zluri homepageconsulté le 26 septembre 2026
- 37Zluri pricingconsulté le 2 septembre 2026
- 38Zluri help, Google Workspace integrationconsulté le 2 septembre 2026
- 39Zluri, how the discovery engine worksconsulté le 2 septembre 2026
- 40Zluri help, closing and completing certificationsconsulté le 2 septembre 2026
- 41Zluri, access requestsconsulté le 2 septembre 2026
- 42Zluri help, notification customizationconsulté le 2 septembre 2026
- 43Zluri, Zluri vs ConductorOneconsulté le 26 septembre 2026
- 44Zluri help, zero touch onboarding via Jiraconsulté le 26 septembre 2026
- 45Zluri help, zero touch onboardingconsulté le 2 septembre 2026
- 46Zluri, secure deprovisioningconsulté le 2 septembre 2026
- 47Zluri, shadow AI governance toolsconsulté le 26 septembre 2026
- 48Zluri, identity visibility and intelligenceconsulté le 2 septembre 2026
- 49Zluri securityconsulté le 2 septembre 2026
- 50Zluri integrationsconsulté le 2 septembre 2026
- 51Oleria homepageconsulté le 26 septembre 2026
Cette page a été rédigée par Lutril. Les faits concernant C1 (formerly ConductorOne), Lumos, Zluri proviennent de leur documentation publique au 26 septembre 2026 ; la mention « Non documenté » signifie que nous n'avons trouvé aucune source publique qui confirme ou infirme la capacité. Une erreur ? Écrivez à hello@lutril.com et nous corrigerons.
Pour aller plus loin
- SOC 2 veut des preuves. Pas un tableur.
- Accès juste-à-temps : comment supprimer le privilège permanent
- Gouvernance MCP : comment contrôler ce que les agents IA peuvent faire dans vos SaaS
- Shadow IT : votre équipe IT connaît 40 applications SaaS. Vous en avez 130.
- Proxy MCP: Chaque appel d’outil passe par la politique.
- Registre des agents: Une seule source de vérité pour chaque agent.
- Lutril vs C1 (formerly ConductorOne)
- Lutril vs Lumos
- Lutril vs Zluri
- Best access management tools for SaaS apps in 2026: Lumos, Zluri, Torii, BetterCloud, AccessOwl and Lutril