From offer letter to exit interview, automate every access decision with Joiner-Mover-Leaver workflows. Ensure employees are productive on day one, secure during role changes, and instantly off boarded when they leave.







Lumos orchestrates Joiner-Mover-Leaver workflows across your HRIS, IdP, and applications so every access change happens automatically, accurately, and on time — no manual tickets, scripts, or human intervention required.
Reduce access delays for new hires. Lumos detects hiring events in your HRIS and automatically provisions birthright applications based on role and department, so employees can get to work on day one.
New team? No problem. Lumos detects job title or department updates and orchestrates Mover workflows that remove unnecessary permissions and provision the right tools — maintaining least privilege as employees move.
Termination events or manual deactivation trigger Leaver workflows that revoke access across SaaS, cloud infrastructure, and internal tools. Lumos ensures accounts are fully deprovisioned to reduce risk and reclaim licenses.

Lumos connects your HRIS, IdP, and applications to translate people data changes into downstream access actions. Updates in systems like Workday, BambooHR, or Rippling trigger workflows across Okta, Microsoft Entra, SaaS applications, and infrastructure—helping keep access aligned with organizational changes.
Grant access for a fixed period or ahead of a start date. Lumos supports time-bound lifecycle policies that provision and revoke access on defined schedules — perfect for temporary workers, on-call employees, and interns.


Not sure which applications a role requires? Time to take out the guesswork. Albus analyzes usage patterns across peer users to suggest baseline access for each role — supporting more consistent, data-driven access policies.







Yes. Lumos ensures Day 1 readiness by automatically creating accounts in your primary directory (Entra ID, Okta, AD), their primary email ID, and relevant SaaS apps as soon as the user is created in the HRIS system.
Lumos puts the Mover process on autopilot to prevent access accumulation. A change in your HRIS, such as Workday, automatically triggers the appropriate role and group changes, ensuring employees instantly get the new access they need while losing access they no longer require.
Lumos enforces a secure, zero-touch off-boarding process. On the user’s designated last day, the system automatically disables accounts and removes access across your directories and SaaS applications, closing security gaps immediately.
Okta manages access to apps behind the SSO. Lumos goes deeper. We manage fine-grained permissions like roles, groups, project levels, and can provision or de-provision apps that aren't connected to Okta (via direct API or browser agents), giving you complete coverage.
Lumos builds gentle reminders and escalations into the workflow. If a request sits in Slack for too long, the bot reminds the approver. You can also configure fallback approvers or auto-expiry rules to ensure requests never get stuck in limbo.
The role of IGA is to ensure secure, compliant, and efficient access to resources across an organization. It enables IT and security teams to manage the entire identity lifecycle, enforce access policies, reduce overprovisioning, and streamline audits. With Lumos, the role of IGA expands: integrating automation, visibility, and AI into one unified platform that transforms identity governance from a manual chore into a strategic advantage.
Book a 1:1 demo with us and enable your IT and Security teams to achieve more.