Identity risk moves fast. Remediation must move faster. Agents monitor your environment continuously, surface findings the moment they appear, and fix them at scale, with you setting the level of autonomy. Humans design the system, agents do the work.



Risk builds faster than human-led identity programs can operate, while dormant access, privilege creep, and unowned NHIs pile up between review cycles. Identity Security Agents change the model. They work continuously alongside your team to find risk, prioritize it and drive remediation, closing the gap between “we found it” and “it's fixed.”
Agents monitor your identity environment continuously, not just during scheduled campaigns. They catch new risks as they emerge, to improve your posture in real time instead of at quarterly check-ins.
Tell an agent what to do in plain language, review its first output, and refine with feedback. It carries your exceptions and priorities forward from there without config files or a rules engine to maintain.
Because agents run on Lumos's full IGA platform, a fix can become governance policy rather than a one-time patch, so the same risk doesn't come back next quarter.
Each agent targets one class of identity risk: dormant access, SoD conflicts, privilege sprawl, or unowned NHIs.
Tell an agent what to do in plain language once; it learns your environment's exceptions and priorities in that same session.
Agents act on Lumos's full IGA platform, so a fix becomes governance policy, not a one-time patch.
A distinct set of agents focused on finding and fixing security risk, not the full governance roster. For agents that run reviews, requests, and role mining across the identity lifecycle, see Identity Agent Force.
Finds accounts and entitlements that exceed your inactivity threshold and removes them or routes unclear cases for review.
Cross-references entitlements against your Segregation of Duties policies, flags conflicts, and surfaces the evidence to resolve them.
Identifies over-provisioned and privileged access that no longer matches a user's role and right-sizes it automatically within prebuilt guardrails.
Monitors service accounts, API keys, and workload identities for missing owners or stale credentials and assigns or escalates ownership before it becomes a blind spot.
Each agent targets one class of identity risk: dormant access, SoD conflicts, privilege sprawl, or unowned NHIs.


Tell agents what to do in plain English. Describe the job, review the output, give feedback. Agents learn your environment's priorities and exceptions in a single session. No config files. No complex rules engines.
Because the Lumos platform is a full IGA solution, agents aren’t limited to remediation, they can translate security findings into durable governance policy. Point-in-time fixes can become programmatic rules that prevent the same issue from recurring.









Why visibility alone isn't enough, what intelligence means for identity, and how to think about AI features versus agents that act.
Manual identity governance can't keep up with rising machine identities and evolving attacks. Why 2026 marks a turning point.
Identity security agents are AI agents that continuously monitor an identity environment for specific security risks: dormant access, privilege creep, SoD conflicts, unowned non-human identities, and remediate them automatically within guardrails a human sets. Lumos's Identity Security Agents run this way, closing the gap between finding a risk and fixing it.
Albus is Lumos's AI identity agent for governance workflows like role design, reviews, and investigations. The Identity Agent Force is the broader roster of agents across the full identity lifecycle. Identity Security Agents is narrower by design: agents purpose-built for continuous security monitoring and remediation. They can draw on the same underlying access graph, but each is scoped to a different job.
That's your call. Start with full oversight, where agents surface findings for review before anything executes, and delegate broader remediation as confidence grows. Every dismissed finding is logged and informs the agent going forward.
Agents can be calibrated in a single session. Assign a job in plain language, review the first round of output, and give feedback. The agent carries your environment's priorities and exceptions forward from there.

Govern every human, machine, and AI in your business with a free identity assessment today.
Book a Demo