# Lutril vs Lumos

> Lumos is an autonomous identity platform for mid-market and enterprise companies of 200 employees and up, with agentic access reviews and Slack requests. Lutril is access governance for employees and AI agents, in Slack, Teams and the app UI, hosted in the EU, with an MCP proxy. Where each fits, and the Lumos alternatives question answered.

Source: https://www.lutril.com/fr/compare/lutril-vs-lumos
Dernière relecture: 2026-09-02

---

## Réponse courte

Lumos and Lutril overlap on the core: SaaS discovery from Google Workspace and Microsoft 365, access reviews whose rejections auto-revoke, Slack requests with time-boxed grants, HRIS-driven lifecycle and an owner on every non-human identity. They differ on three things. Lumos targets companies of 200 employees and up and says a small team may find it more than it needs; Lutril is built for teams without an IAM function. Lumos ships MCP servers that expose its own product to assistants, while Lutril's MCP proxy sits in front of every SaaS tool and enforces policy on each agent call, with prompt DLP and a kill switch. And Lumos documents no EU hosting region or French UI, where Lutril is hosted in France and available in French.

## D'où part chaque produit

**Lumos.** The autonomous identity platform: agents that continuously govern access for every human, machine and AI, with an AI layer called Albus and an Identity Agent Force of out-of-the-box agents. San Francisco, $85M+ raised, Series B led by Scale in 2024, a Strong Performer in Gartner's 2026 Voice of the Customer for IGA. Requests in Slack, the IT system or through MCP; 300+ integrations.

**Lutril.** Access governance for employees and AI agents in one policy layer: discovery the day you connect Google Workspace or Microsoft 365, requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy that checks every agent tool call with prompt DLP and a global kill switch. Built by a practising CISO, hosted in France, in French and English.

## Capacité par capacité

| Capacité | Lumos | Lutril |
| --- | --- | --- |
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | Oui: Google scope to discover apps employees signed into with Google; Microsoft 365 report and audit scopes [3] | Oui: Google Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Partiel: Browser sessions cited as a signal; no extension documented in the help centre [4] | Oui: Chrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | Oui: Auto-revoke rejected access through downstream integrations [5] | Oui: Decisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Oui: Slack app for requests, approver notifications and reminders [6] | Oui: Requests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | Partiel: Requests flow into Teams; approval inside Teams not explicitly documented [7] | Oui: Same flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | Oui: Durations from 2 hours to 90 days, or unlimited, with automatic revocation [8] | Oui: One hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | Oui: Workday, BambooHR, Rippling, ADP Workforce Now, Oracle HCM [9] | Oui: Lucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | Oui: One-click offboarding for SSO and non-SSO apps [10] | Oui: Native connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | Partiel: Shadow IT and AI discovered and monitored; method not documented [11] | Oui: Sign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | Oui: Every NHI mapped to a human owner; Agent Ownership Finder [12] | Oui: Owner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | Non proposé: Ships MCP servers exposing Lumos's own tools; not a proxy over third-party agent calls [13] | Oui: Lutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Non documenté | Oui: Detect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Non documenté: Privacy policy mentions transfers outside the EEA; no region or language option found | Oui: OVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | Oui: Evidence-backed reports formatted for SOC 2, SOX and ISO 27001 [5] | Oui: Campaign export with decisions and revocation proof, one link |
| Native integrations | Oui: 300+ integrations [15] | Oui: More than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Non proposé: Pricing page without figures [2] | Non proposé: On request |

## Choisissez Lumos si

- You have 200 employees or more, an IT or IAM team to run it, and want AI-assisted reviews and an agent workforce inside the identity platform.
- Your HRIS is Workday, ADP or Oracle HCM and your integrations are already in Lumos's catalogue.
- US hosting is acceptable and an English-only product is fine.

## Choisissez Lutril si

- You are a mid-market company without an IAM team and need discovery, reviews and offboarding running in weeks.
- AI agents call your SaaS tools and you need a proxy that enforces policy on each MCP call, with prompt DLP and a kill switch, not only ownership mapping.
- Requests and approvals must run in Microsoft Teams as well as Slack.
- Your data has to stay in the EU, or your team works in French.

## Questions fréquentes

### What are the best alternatives to Lumos for access reviews?

Look for a tool whose review decisions execute the removal, that covers apps outside SSO, and that exports evidence an auditor accepts. Lutril, C1 (formerly ConductorOne), Zluri, Torii and Okta Identity Governance all run campaigns; they differ on automatic remediation, Teams support, EU hosting and AI agent coverage. Lutril's campaigns include registered AI agents alongside employees, execute removals in the connected tool, and export one link with the decisions and the revocation proof.

### Does Lumos govern AI agents through MCP?

Lumos governs non-human identities, maps each to a human owner and ships MCP servers so assistants can request access or administer Lumos itself. It does not document a proxy that sits in front of third-party SaaS tools and enforces policy on each agent tool call. That proxy is what Lutril's MCP proxy is: one endpoint for every connected tool, role-based policy per call, a WORM log, prompt DLP and a global kill switch.

### Is Lumos suitable for a company of 80 people?

Lumos's own comparison content says it targets mid-market and enterprise, generally 200 or more employees, and that a small team may find it more capability than it needs. Lutril is designed for teams with no dedicated IAM function, with discovery starting the day you connect your workspace.

### Where is each product hosted?

Lumos's privacy policy refers to transfers outside the EEA with safeguards; we found no documented EU region or French-language option. Lutril is hosted at OVHcloud in France, with Cloudflare at the edge, and the product and documentation exist in French and English.

## Sources

1. [Lumos homepage](https://www.lumos.com) (consulté le 2026-09-02)
2. [Lumos pricing](https://www.lumos.com/pricing) (consulté le 2026-09-02)
3. [Lumos help, connecting Google Workspace](https://lumos.help.usepylon.com/articles/1877502581-connecting-google-workspace) (consulté le 2026-09-02)
4. [Lumos, Zluri alternatives and competitors](https://www.lumos.com/identity-matters/identity-governance/zluri-alternatives-and-competitors) (consulté le 2026-09-02)
5. [Lumos, access reviews](https://www.lumos.com/products/access-reviews) (consulté le 2026-09-02)
6. [Lumos help, connecting Slack](https://support.lumos.com/articles/3448469670-connecting-slack) (consulté le 2026-09-02)
7. [Lumos, Microsoft Teams integration](https://www.lumos.com/integrations/microsoft-teams) (consulté le 2026-09-02)
8. [Lumos help, AppStore quick start](https://support.lumos.com/articles/7910043985-lumos-appstore-quick-start-guide) (consulté le 2026-09-02)
9. [Lumos, lifecycle management](https://www.lumos.com/products/lifecycle-management) (consulté le 2026-09-02)
10. [Lumos, JML workflow orchestration](https://www.lumos.com/solutions/jml-workflow-orchestration) (consulté le 2026-09-02)
11. [Lumos, identity security posture](https://www.lumos.com/solutions/identity-security-posture) (consulté le 2026-09-02)
12. [Lumos, non-human identities](https://www.lumos.com/solutions/non-human-identities) (consulté le 2026-09-02)
13. [Lumos developers, MCP](https://developers.lumos.com/docs/mcp) (consulté le 2026-09-02)
14. [Lumos privacy policy](https://www.lumos.com/privacy) (consulté le 2026-09-02)
15. [Lumos integrations](https://www.lumos.com/integrations) (consulté le 2026-09-02)
16. [Lumos, ConductorOne competitors and alternatives](https://www.lumos.com/identity-matters/identity-governance/conductorone-competitors-and-alternatives) (consulté le 2026-09-02)
17. [Lumos, about](https://www.lumos.com/company/about) (consulté le 2026-09-02)

Cette page a été rédigée par Lutril. Les faits concernant Lumos proviennent de leur documentation publique au 2026-09-02. Une erreur ? Écrivez à hello@lutril.com.
