Security & Identity · Integration

Lumos

Add Lumos to your product for your customers, and give your AI agents governed access to it.

Embed a Lumos integration so who has access to what is visible and actionable inside your product, using each customer's own identity governance tenant. Lumos handles app entitlements, access requests, access reviews and lifecycle automation, so your product can ask for access where the work happens while the approval and the record of it stay in Lumos. Only the scopes you enable are requested, every customer grants access to their own tenant, and each call is recorded, which is what makes an automated access change reviewable after the fact. fastn owns the auth and API upkeep, and the same governed connection gives your AI agents scoped, audited access.

Start freeBook a demo

In your product

Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.

Let customers connect their own Lumos tenant so entitlements and who holds them are visible inside your product.

Raise an access request from your product so a user asks where the work is while approval still runs in Lumos.

React to a granted or revoked entitlement with an event trigger so your product provisions or removes its own access in step.

Read access review state per tenant so your product can show what still needs certifying before an audit.

For your AI agents

Governed, audited access for the agents you build, through the MCP server.

An agent answers who has access to an application and how they got it, reading the customer's own tenant.

An agent raises an access request on a user's behalf within scoped permissions, with every action attributed and audited.

An agent prepares an access review by listing entitlements that look unused, leaving the decision to a human.

Example prompt

Who has admin access to this app in Lumos, when was it last reviewed, and which grants look unused?

Set up Lumos in 4 steps

  1. 01Enable the Lumos connector in your fastn dashboard.
  2. 02Have each customer authorise their own Lumos tenant and grant only the scopes you enable.
  3. 03Map the entitlement, request and review fields your product uses, then enable triggers.
  4. 04Call it from your product and expose the same connection to your agents through the MCP gateway.

Why teams use the Lumos integration

What you get by embedding it with fastn instead of building it yourself.

  • Ship a Lumos integration without building it. Your customers connect their own Lumos account inside your product and work their users, groups and roles there, with no per-customer code on your side.
  • Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Lumos update is not your on-call problem.
  • One integration serves your product and your agents. The same governed Lumos connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.

Used by these teams

Security & IT

Compare with

OktaMicrosoft Entra IDJumpCloud

Often used alongside

Tools the same teams tend to run next to Lumos, across other categories.

ServiceNowDatadogPagerDutyAWS CloudWatch

Lumos integration FAQ

How do I add a Lumos integration to my product?

Enable the Lumos connector in your fastn dashboard, then let each customer authenticate their own Lumos account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Lumos client code in your app and no per-customer branch in your codebase. Setup is 4 steps.

Do my customers each connect their own Lumos account?

Yes. Every connection is scoped to the individual customer, so each authorises their own Lumos account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.

Can AI agents use this Lumos integration?

Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent answers who has access to an application and how they got it, reading the customer's own tenant.

Who maintains the Lumos integration?

fastn does. When Lumos changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.

What permissions does the Lumos integration need?

Only the scopes required for the actions you enable. Each customer grants access to their own Lumos tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.

Can access changes be automated safely?

Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.

What can I build with the Lumos integration?

A common starting point: connect their own Lumos tenant so entitlements and who holds them are visible inside your product. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.

How much does the Lumos integration cost?

It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Lumos does not change your per-connector cost. You can start free with 3 connected accounts.

Add Lumos to your product

Start free with 3 connected accounts. No sales call required, and no per-customer integration code.

Start freeRead the docs
← All integrations