In section Releases

Lumos Targets Agent Security With Real-Time MCP Governance

A single employee might delete one Salesforce record by mistake, but an autonomous agent can delete a thousand in seconds. To address this risk, identity management firm Lumos is launching MCP Governance, a tool designed to intercept and validate AI agent permissions at the exact moment an action occurs.

Lumos Targets Agent Security With Real-Time MCP Governance

Enterprises are deploying AI coworkers at a pace that has outstripped traditional security oversight. Current methods often rely on inventory tracking, which merely identifies an agent without monitoring its specific capabilities or actual output. Lumos argues that because agents inherit the permissions of their human operators and execute tasks at machine speed, post-action reviews are no longer sufficient to prevent systemic damage.

Lumos CEO Andrej Safundzic noted that his company observed over 450,000 agent actions in a single week among fewer than 200 employees, highlighting the impossibility of manual tracking. By moving governance to the runtime layer, the platform aims to shift the security paradigm from retroactive auditing to proactive enforcement. Co-founder Leo Mehr emphasized that while identity management previously focused on what a user was permitted to do, the speed of AI necessitates intervention at the point of action rather than after the fact.

The new tool is currently available for teams utilizing Claude Code and Codex, with plans to expand support to additional agent frameworks. By integrating this control layer, Lumos intends to help security teams move away from blanket restrictions—which can hinder productivity—toward granular, real-time permissions that allow for safer AI adoption.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!