Lutril vs C1 (formerly ConductorOne)
C1, the identity platform formerly known as ConductorOne, governs human, non-human and AI identities for Fortune 500 and hypergrowth enterprises, with an MCP Gateway. Lutril delivers access governance for employees and AI agents to mid-market teams, in the EU and in French. Where each fits.
Cette page n’est pas encore traduite. Voici la version anglaise.
Réponse courte
C1 and Lutril are the two products on this site that govern AI agents at the tool-call level: both register agents as identities and both enforce policy in front of MCP tool calls. C1 is built for Fortune 500 and hypergrowth enterprises, with 400+ connectors, an open-source connector SDK, Slack and Teams requests and a consumption-billed AI access module; its sub-processors are in the United States and prompt DLP is described as in progress. Lutril is built for mid-market teams: the same request, review and lifecycle outcomes in Slack, Teams and the app UI, prompt DLP shipped in the MCP proxy, a browser extension for shadow SaaS and AI, EU hosting and a French-language product.
D'où part chaque produit
C1 (formerly ConductorOne)
An AI-native identity platform governing access for human, non-human and AI identities, and the control plane for the agentic enterprise: Lifecycle, Access, Comply, LLM Gateway, MCP Gateway, Vault, Worker and Bridge. Rebranded from ConductorOne to C1 in April 2026. San Francisco and Portland, founded late 2020, $79M Series B led by Greycroft in October 2025, more than $100M raised.
Lutril
Access governance for employees and AI agents in one product: discovery from Google Workspace and Microsoft 365, a Chrome extension and code scanning; requests in Slack, Teams and the app UI with automatic expiry; reviews that revoke; HRIS-driven lifecycle; and an MCP proxy with policy on every call, prompt DLP and a global kill switch. Hosted in France, in French and English.
Capacité par capacité
| Capacité | C1 (formerly ConductorOne) | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | OuiShadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitoredSource 3 | OuiGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Non documenté | OuiChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | OuiPolicy auto-creates a revoke task on denial; connector deprovisions, manual task otherwiseSource 4 | OuiDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Oui/c1 request in Slack; approve or deny without leaving SlackSource 5 | OuiRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | OuiApprove and deny in Teams since November 2025; create requests in Teams since early 2026Source 6 | OuiSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | OuiTime-limited grants expire automatically with remindersSource 7 | OuiOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | OuiInbound webhooks for Workday and BambooHR; SAP SuccessFactors connectorSource 8 | OuiLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | OuiDeprovision via connector, IdP, ticket, webhook or manual task; not all connectors support itSource 9 | OuiNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | OuiFinds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configsSource 10 | OuiSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | OuiIdentities and NHI dashboard with ownership status; standalone agents get their own identitySource 11 | OuiOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | OuiMCP Gateway: identity-aware policy in front of every MCP tool call; approval for high-risk callsSource 11 | OuiLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Non proposéLLM Gateway does routing and cost; DLP hooks described as being builtSource 12 | OuiDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Non proposéSub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documentedSource 13 | OuiOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | OuiAudit-ready reports on demand; evidence timestamped, attributed and exportableSource 14 | OuiCampaign export with decisions and revocation proof, one link |
| Native integrations | Oui400+ prebuilt connectors, plus an open-source connector SDKSource 15 | OuiMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Non proposéPricing page without figures; platform tiers by managed identities, or usage-based tokensSource 2 | Non proposéOn request |
Choisissez C1 (formerly ConductorOne) si
- You are a large or hypergrowth enterprise with hybrid infrastructure: Active Directory, LDAP, databases, cloud, and a team to run a platform.
- You need an open-source connector SDK to build integrations for in-house systems.
- US hosting is acceptable and AI agent access can be billed on consumption.
Choisissez Lutril si
- You are a mid-market company and want agent governance, prompt DLP and a kill switch shipped in one product, priced on the people and agents governed.
- Your data has to stay in the EU, or your team works in French.
- You want a browser extension and mailbox scanning to catch the SaaS and AI tools that never touch the identity provider.
- Reviews and approvals should happen in Slack, Teams or the app UI, not in a web console only.
Les questions que se posent les acheteurs
What is C1, and what happened to ConductorOne?
ConductorOne rebranded to C1 on April 6, 2026; conductorone.com now redirects to c1.ai. The product is the same identity platform, positioned as AI-native and as a control plane for the agentic enterprise, with an MCP Gateway and an LLM Gateway alongside lifecycle, access and compliance modules.
Both have an MCP gateway. What is the difference?
Both put identity-aware policy in front of MCP tool calls and register agents as identities. C1 documents auto-approval for low-risk calls and human approval for high-risk ones, with a consumption-billed AI access module. Lutril's MCP proxy adds prompt-level DLP that redacts PII and secrets before the model sees them, a WORM audit log, a global kill switch, and one MCP endpoint that exposes any connected SaaS tool, all in the base product.
Which one fits a company of 150 to 1,500 people?
C1 targets Fortune 500 and hypergrowth enterprises and also publishes an SMB solution page. Lutril is designed for mid-market teams without an IAM function, with discovery starting the day you connect Google Workspace or Microsoft 365 and requests running where people already work.
Where is each product hosted?
C1's sub-processor list is US-based and its data processing agreement authorises transfers from the EEA to the United States. Lutril is hosted at OVHcloud in France, with Cloudflare at the edge.
Sources
- 1C1 homepageconsulté le 2 septembre 2026
- 2C1 pricingconsulté le 2 septembre 2026
- 3C1 docs, shadow appsconsulté le 2 septembre 2026
- 4C1 docs, policiesconsulté le 2 septembre 2026
- 5C1 docs, Slack applicationconsulté le 2 septembre 2026
- 6C1 blog, advanced Microsoft Teams integrationconsulté le 2 septembre 2026
- 7C1 docs, create requestsconsulté le 2 septembre 2026
- 8C1 docs, inbound webhooksconsulté le 2 septembre 2026
- 9C1 docs, provisioningconsulté le 2 septembre 2026
- 10C1, shadow AI discoveryconsulté le 2 septembre 2026
- 11C1, MCP Gatewayconsulté le 2 septembre 2026
- 12C1 blog, AI access management, your questions answeredconsulté le 2 septembre 2026
- 13C1 legal, sub-processorsconsulté le 2 septembre 2026
- 14C1, Complyconsulté le 2 septembre 2026
- 15C1 integrationsconsulté le 2 septembre 2026
- 16C1 blog, we are C1consulté le 2 septembre 2026
- 17C1 press, $79M Series Bconsulté le 2 septembre 2026
- 18C1 docs, review tasksconsulté le 2 septembre 2026
Cette page a été rédigée par Lutril. Les faits concernant C1 (formerly ConductorOne) proviennent de leur documentation publique au 2 septembre 2026 ; la mention « Non documenté » signifie que nous n'avons trouvé aucune source publique qui confirme ou infirme la capacité. Une erreur ? Écrivez à hello@lutril.com et nous corrigerons.
Pour aller plus loin
- Gouvernance MCP : comment contrôler ce que les agents IA peuvent faire dans vos SaaS
- La faille de gouvernance de l’IA
- Proxy MCP: Chaque appel d’outil passe par la politique.
- Registre des agents: Une seule source de vérité pour chaque agent.
- Lutril vs Lumos
- Lutril vs Okta Identity Governance
- MCP gateways compared: MintMCP, Cerbos, Datawiza and Lutril