BreakingLumos deploys a six-agent identity workforceHuman, machine and AI access move onto one control layer$85M+ raised
Company profile / Identity security

Lumos Is Putting Software Agents on the Identity Night Shift

Lumos began by replacing the IT ticket queue with an internal app store. Six years later, it is betting that the next identity administrator will be a coordinated crew of software agents - with humans reserved for the judgment calls.

The first version of Lumos solved a problem so ordinary that it was easy to miss its strategic value. An employee needed an app. They filed a ticket. Someone in IT checked a policy, chased an approval, created the account, and closed the ticket. The employee waited. The IT team repeated the ritual. Lumos turned that queue into an internal AppStore, giving workers a familiar place to find approved software and request the access they needed.

It was a tidy product idea with a much larger implication. Every request reveals something about identity: who the person is, what job they do, which system they need, who should approve it, how much privilege is appropriate, and when that privilege should disappear. Capture enough of those decisions and the little app catalog becomes a working map of how a company grants trust.

That map is now the center of Lumos. The San Francisco company, founded in 2020 by Stanford computer science graduate students Andrej Safundzic, Alan Flores-López, and Leo Mehr, describes its product as an autonomous identity platform. It connects the scattered facts held by an HR system, an identity provider, cloud accounts, directories, databases, and hundreds of SaaS applications. Then it turns those facts into decisions and, when policy permits, actions.

300+ready-made integrations across cloud, SaaS and on-prem systems
$85M+total capital raised, according to the company
6initial agents in the Identity Agent Force

The company directory grew teeth

Identity software has long been good at directories and less good at the messy reality behind them. A record might say that Maya works in finance and belongs to an Okta group. It may not say that she changed teams three months ago, still holds an admin permission in a billing tool, stopped using a design application, and owns a service account no one else remembers. Those details sit in different systems, under different names, with different owners.

Lumos pulls identities, accounts, entitlements, usage signals, and organizational attributes into a common model. Its public architecture supports a coexistence approach: a customer can keep Okta or Microsoft Entra as an identity provider and retain an established governance suite such as SailPoint or Saviynt, while using Lumos first for visibility, reviews, or self-service provisioning. That makes adoption less like heart surgery and more like adding an observatory above the existing machinery.

The Lumos identity loop Four stages connect identity data to reasoning, action and evidence. 01 / OBSERVEidentities + usage 02 / REASONcontext + policy 03 / ACTgrant + revoke 04 / PROVElogs + evidence
THE ACCESS LAUNDROMAT. Dirty identity data enters; policy, action and receipts come out. The difficult socks still go to a human.

The product covers access reviews, joiner-mover-leaver automation, just-in-time privileged access, role mining, identity analytics, non-human identities, compliance reporting, and software-license recovery. Employees can request access in Slack or an IT system. A temporary grant can expire on schedule. A rejected review item can trigger an actual removal instead of spawning another ticket. That final step matters: governance that only recommends is a weather report; governance that can enforce is an operating system.

“Most companies still can’t answer the most basic identity question - who has access to what, and should they?”Andrej Safundzic / CEO and co-founder

Meet the agents with the unglamorous jobs

In 2025, Lumos introduced Albus, a multi-agent system built for identity governance. The name continues the company’s unusually cheerful wizard motif: Lumos means light, its employees are “Alchemists,” and Albus is meant to illuminate the permissions buried in enterprise systems. The company’s pink-and-orange palette also looks like it wandered into cybersecurity from a candy shop. The playfulness is deliberate. One of its published culture values is “Paint in Pink,” shorthand for bringing a point of view and some levity to serious work.

Albus analyzes usage, peer behavior, HR attributes, organizational structure, entitlement sensitivity, and policy. In a review, it can identify access that has gone unused, differs from a worker’s peer group, or creates a separation-of-duties conflict. It explains the reason in ordinary language, certifies routine items, and surfaces the ambiguous cases. For role mining, it studies how teams actually work and drafts combinations of birthright, requestable, universal, and restricted access. People can challenge the proposal before it becomes policy.

Access Review Agent

Certifies routine access and forwards exceptions that need a person’s judgment.

Access Request Agent

Grants policy-compliant access for a defined period, then takes it back.

Role Mining Agent

Finds real usage patterns and drafts least-privilege roles that can evolve.

Entitlement Analyst

Translates cryptic permissions into language an approver can understand.

NHI Owner Hunter

Finds dormant or oversized service accounts, keys, and tokens.

Agent Ownership Finder

Catalogs AI agents and other non-human identities, then assigns human owners.

Those jobs became the first six members of the Identity Agent Force in June 2026. The language is theatrical; the division of labor is practical. One agent translates permissions, another looks for owners, another handles requests. Each sits on the same identity map and memory of how the customer operates. The intended operating model is not a chatbot waiting for prompts. It is background work with an escalation queue.

Why customers buy the plumbing

Lumos sells enterprise software through a sales-led process; public pricing is not listed. The buyer is usually in IT, security, identity, or compliance, but the economic case crosses those boundaries. Remove an unused account and the company may shrink its attack surface, recover a license, reduce an audit exception, and avoid a service ticket with the same action. That shared return helps explain why Lumos has stretched across categories that vendors traditionally sold separately.

Its named customers include GitHub, Pinterest, Roku, MongoDB, Mars, GitLab, Netskope, Chegg, Checkr, Prosper, ChargePoint, Intercom, and Marqeta. The range matters: Lumos says it serves fast-growing companies as well as global enterprises with more than 100,000 workers. Customer accounts describe concrete outcomes. Checkr reported that tickets fell 20 percent while software savings reached $230,000. Prosper said its access-request ticket volume dropped by roughly 72 percent. Roku reported a 98 percent reduction in time to access. These are company case studies, not universal promises, but they show the four budgets Lumos can touch: time, software, risk, and audit labor.

One platform / four buying conversations
IGA
reviews · roles · lifecycle
PAM
time-boxed privilege
SaaS mgmt
discovery · licenses
Agent security
ownership · NHI risk

The competitive field is crowded. SailPoint, Saviynt, One Identity, and Omada anchor traditional identity governance. Microsoft and Okta can bundle governance with broader identity platforms. ConductorOne, Zilla Security, Opal, and Veza offer newer approaches to access control and visibility. CyberArk owns deep privileged-access credibility, while BetterCloud, Torii, Zluri, and Productiv approach the estate through SaaS operations.

Lumos’ distinction is the combination. It joins granular identity data, self-service access, access certification, privileged workflows, SaaS usage, and license economics on one graph, then gives agents permission to work across that graph. The Integration Hub - more than 300 ready-made connectors, an SDK, and an AI-assisted builder - is not glamorous, but it is the moat-shaped part. An agent cannot revoke what the platform cannot reach, and it cannot explain what it cannot see.

A startup grows into its premise

Lumos stayed in stealth for roughly two years and said it was near $1 million in annual recurring revenue before its 2022 public launch. That year it announced more than $30 million in total financing, with Andreessen Horowitz leading its Series A. In May 2024, Scale Venture Partners led a $35 million Series B after the company reported ninefold revenue growth since the prior raise. Lumos now says it has raised more than $85 million, although it has not publicly itemized all of the capital that bridges the announced rounds to that total.

The company also bought Fastgen’s low-code workflow-builder technology in December 2024. It was a revealing acquisition. Identity programs contain exceptions: an old database, a custom approval route, a strange contractor rule. The fastest way to become a platform is not to pretend those oddities do not exist; it is to make them programmable.

2020

Three Stanford computer science graduate students found Lumos and begin building in stealth.

2022

The internal AppStore launches publicly alongside more than $30 million in announced funding.

2024

A $35 million Series B follows 9x reported revenue growth; Fastgen’s workflow technology joins the platform.

2025

The Integration Hub, Autonomous Identity Platform, Albus, and agentic access reviews arrive.

2026

Identity Security Agents expand into the six-member Identity Agent Force.

The larger bet is that identity governance will stop behaving like tax season. Quarterly campaigns and giant entitlement tables create review fatigue; managers approve what they do not understand because the work must end somehow. Continuous software agents could change the rhythm. They can watch for a role change, a dormant token, or an unusual permission as it happens, preserve the evidence, and ask for help only when policy runs out.

There is an important restraint inside that pitch. Lumos repeatedly describes humans as remaining in control. That is not just comforting copy. Identity decisions can lock someone out of work, interrupt production, or expose sensitive data. Autonomy earns trust in increments: clear explanations, narrow authority, reversible actions, audit trails, and useful escalation. The company that began by shortening a ticket queue now has to prove that its agents know when to stop.

If it succeeds, Lumos will not make identity management disappear. It will change what the people doing it spend their time on. The ordinary approvals, removals, owner hunts, and evidence gathering move to the night shift. The humans design the system, settle the exceptions, and decide what trust should mean. That is less cinematic than replacing the security team. It is also a better product.

Identity governanceAgentic AIEnterprise SaaSAccess managementCybersecuritySan Francisco