Discover how Lumos and Albus, the first agentic AI for identity governance, transform role mining from a manual, error‑prone process into an intelligent, automated workflow. Learn how Albus analyzes attributes, maps access, and validates policies to deliver scalable, context‑aware RBAC and ABAC governance.


Every customer call starts the same way: no one wants to manage access with spreadsheets, CSVs and guesswork. Authorization policies are too critical for security and compliance to be manual. That’s why we built Albus - the first truly agentic AI for identity governance - to bring autonomy, context, and clarity to role mining at scale.
As organizations adopt GenAI and agentic frameworks, they’re demanding better visibility, governance, and automation – without the complexity or the slowdown. But building right-sized access controls isn’t as easy as it sounds. IT and security teams still struggle to untangle messy attributes, inherited permissions, and evolving org structures.
Here’s why:
The idea behind role mining, first introduced in 2003, is simple: analyze user permissions, system logs, and access patterns to group users with shared needs. In practice, though, it’s anything but simple.
Albus makes role mining intelligent, contextual and collaborative. It is designed to handle the scale and complexity of a dynamic environment. Albus learns and understands context and adapts to your environment continuously; acting like a trusted teammate.
Albus goes beyond other static AI wrappers when it comes to managing access. It understands why access matters. It learns context. It makes recommendations. It asks clarifying questions. And, it acts with human oversight, always giving evidence-backed explanations so your teams always know how roles and policies are crafted and why.
Policy and role mining doesn’t have to be a black box. With Albus, our AI identity agent, Lumos helps IT and security teams uncover, map, and operationalize access policies through three clear, data-driven steps; each guided by intuitive prompts and automated insights.
Albus analyzes and understands your identity landscape including users, cost centers and other key attributes. It comes up with the evaluation criteria and ranks it across multiple dimensions to strike the optimal balance between manageability, granularity and coverage.

Albus Prompt: Show me all user attributes in my source of truth (look at custom attributes) and create a table for each user attribute type and what percentage of the whole population (only active human identities) have one.
With the right visibility and intelligence in place, Albus now maps the access distribution across the entire application landscape. It groups it into different buckets of access types like:
It analyzes multiple dimensions like who has what access, their attributes (role, title, department, etc) , entitlement types (read, admin, etc), and how access is actually used.

Albus Prompt: “Score my attributes for building policies based on coverage, granularity, and manageability.”

Albus Prompt: Suggest access policies for me looking at the dimensions of worker type and team.
Albus generates right-sized RBAC/ABAC access policies and provides full transparency for review. Engage with business app owners and role owners to review findings and validate access patterns. They can confirm compliance requirements and help you fine-tune policies based on findings. Through each step of the process, Albus learns with your feedback and dynamically adapts to adjust roles and policy recommendations to meet your organizational needs. Albus enforces ABAC/RBAC access policies through your automation workflows or Lumos Lifecycle Management.

Albus Prompt: Create an access policy for [specific team]. List birthright vs. self-service recommendations.
Lumos doesn’t just mine roles using static models. It delivers a self-governing, learning access model that scales with your organization.
Role mining doesn’t have to be a painful data exercise or become a major architectural overhaul. With Albus, Lumos transforms it into a continuous, AI-driven process - one that understands context, enforces least privilege, and scales securely as your business grows.
Getting started is simple:
Want to see more Albus prompts? Check here.
Ready for a free assessment with Albus? Book here.
Short on time? Attend our webinar “Bring Agentic AI to your IGA” for a live demo of Lumos’ AI-native autonomous platform and see a real-time role mining exercise. Register here.
Book a 1:1 demo with us and enable your IT and Security teams to achieve more.