
22 Sep 2026
Lumos launches MCP Governance for Claude Code and Codex
Identity platform Lumos released MCP Governance, a runtime control that checks Claude Code and Codex tool calls—including MCP servers, bash, file operations, and browser use—against policy before they execute, and blocks the action when policy says no.
SOFTWARE desk — agent tool calls now move at machine speed. Runtime allow or deny at the hook is the practical control before a catalog of agents that never checks the action.
What the wire says the product does. MCP Governance checks an AI agent’s permissions at the moment it acts, and blocks the action if policy does not allow it. Policy, here, is the rule the company has written for that kind of action. The release says an agent inherits the permissions of the person who launched it, and then works at machine speed. The company’s example: one employee might delete one Salesforce record by mistake, but their agent can delete a thousand in seconds. That is an illustration on the page. It is not an incident this desk logged. File the check, the inherited-permissions line, and the example as Lumos’s.
A hook, not a gateway. The wire does not use those words. Lumos’s own blog, “Introducing MCP Governance: Control Agent Access at Runtime,” by Leo Mehr, co-founder and head of Lumos Labs, does. The page this desk read prints Sep 22, 2026 beside that byline, and it also prints Sep 21, 2026 above the summary line. It does not print a clock. Mehr writes that this is not an MCP gateway. Lumos is not proxying the organization’s tool calls through one chokepoint. It works through a tool-use hook, which does not reroute MCP traffic and does not require reconnecting servers. A hook, here, is a check the coding agent runs before a tool call, inside the session. A gateway would sit in the middle and forward the traffic. The same paragraph says the interface also covers other supported tool calls, including shell commands, browser use, and file operations. A shell command is a line at the computer’s command prompt. Bash is the name the product page uses for that prompt. File operations are reading, writing, or editing files. Browser use is the agent driving a web browser. The product page says the same split in shorter words: Lumos installs a hook that runs before every tool call, sends the call for a decision, and returns allow or deny. Nothing reroutes, and no MCP server has to be reconnected. It says decisions are in milliseconds. A millisecond is a thousandth of a second. The page also says each policy check is built to add under 50 milliseconds, and a later answer calls that a target latency under 50 milliseconds. Under 50 milliseconds is about a twentieth of a second. That figure is Lumos’s target. This desk did not time a call.
The scale line, and the inventory argument. Andrej Safundzic, chief executive and co-founder, said the company spent twenty years learning to govern humans and still has not finished, and that agents now do the same work ten times faster. He said that at Lumos, with fewer than 200 employees, the company measured over 450,000 agent actions in a single week, and that this scale is impossible to track with old methods. Over 450,000 actions in one week, at a company of fewer than 200 people, is his evidence that a person cannot review each action after it happens. The page does not say the actions were spread evenly, and it does not say what counted as an action. Do not invent either. The next paragraph is the company’s, not a study this desk ran: the industry has answered with inventory, but registering every agent only tells a security team that an agent exists. It does not say what that agent can reach, and it does not say what it did. Inventory, here, means a list of agents. Lumos’s position on the same page: permissions set the upper bound of what an agent is allowed to do. What the agent actually does happens at runtime, and until now identity teams have had no way to govern that moment. MCP Governance moves the decision to the point of action. Runtime means while the agent is acting, not in a review the next day. File the number, the headcount, and the inventory argument as the release’s.
How the company places the product next to identity work it already claims. The wire says MCP Governance extends Lumos’s work on non-human identity. A non-human identity, here, is an actor that is not a person: a machine account or an AI agent. Lumos says it maps every identity and permission across human, machine, and AI identities. MCP Governance covers the other half, which is control over what those identities do. The product page adds that the hook sees MCP servers an employee added locally, including ones no vendor list can enumerate, and that the same session also covers Bash commands and file operations. Locally added means the person installed that server on their own machine. Those lines are the product page’s. This desk did not list a company’s servers.
Availability. The wire says MCP Governance is available today for teams running Claude Code and Codex, with support for more agents to follow. Today, on this page, is 22 Sep 2026. The page does not name the next agents. Do not add them. It does not print a price. Do not add one.
Two more quotes, as color only. Safundzic said the teams he talks to are not trying to slow AI down. They are trying to say yes. He said one customer would not turn on an integration for a marketing team because too many people had access to the underlying tool, and that the decision cost them pipeline. Pipeline, here, is sales the team did not get. He said governance at the moment of action is how you turn that no into a yes. The customer is unnamed. Do not name one. Leo Mehr, named co-founder on the wire, said identity has always governed what someone is allowed to do, and has never governed what they actually did, because humans move slowly enough that review after the fact was good enough. He said that by the time you review an agent’s activity, it has already made a few thousand decisions, and that the only place left to govern is the moment before the action runs. File the names, the titles, and those sentences as the release’s. A quote is not a customer count, and it is not a measured delay.
What the product page says it keeps. Lumos stores the server, the tool name, who called it, the time, and the verdict. Tool-call arguments are stored by default and can be turned off with a setting. User prompts, model responses, and tool-call results are never sent to Lumos or stored. A prompt is what the person typed. A verdict is the allow or deny. Those sentences are the product page’s. This desk did not inspect a customer’s store. The blog also names Albus, which it says helps investigate activity and write a policy from plain language. That is the company’s description of its own assistant. This desk did not ask it to write a rule.
The about box, and where it stops. Lumos says it is the first identity platform built around autonomous agents, not manual workflows. First is the company’s word. This desk did not rank identity platforms. The box says teams at companies like Mars, Netskope, Assurant, and GitLab use Lumos. “Like” is the page’s. It does not say those companies bought MCP Governance on 22 Sep. Do not turn the list into launch customers. The contact on the pages is info@lumos.com. It stays in Sources.
Plain English for the rest of the card: MCP = Model Context Protocol, a way for an agent to call a tool on a server. Claude Code = Anthropic’s coding agent. Codex = OpenAI’s coding agent. hook = a check that runs before the tool call, inside the session. gateway = a middle box that would forward the traffic. Lumos says this product is the first and not the second. bash = the command prompt. file operations = reading, writing, or editing files. browser use = the agent driving a web browser. runtime = while the action is happening. inventory = a list of agents, which the company says is not the same as governing what they do. non-human identity = a machine account or an AI agent treated as an actor. 450,000 and fewer than 200 are Lumos’s figures for one week at Lumos. Under 50 milliseconds is the product page’s target for one policy check, not a stopwatch this desk ran. This filing is the 22 Sep launch.
PRIMARY here: Lumos’s 22 Sep 2026 PR Newswire release, “Lumos Launches MCP Governance to Provide Agent Runtime Security,” stamped 12:00 ET and datelined San Francisco — Tier A PRIMARY, the company’s own record. The Claude Code and Codex launch, more agents to follow, the permission check that blocks a disallowed action, the inherited-permissions line, the Salesforce illustration, the over-450,000 actions and fewer-than-200 employees, the inventory argument, the map of human, machine, and AI identities, the available-today line, the Safundzic and Mehr quotes, and the Mars, Netskope, Assurant, and GitLab “like” list are the wire’s. The hook-not-a-gateway wording, the no-reroute line, and the shell, browser, and file-operation coverage are the company’s 22 Sep blog, not the wire. The under-50-millisecond target, the Bash and file-edit line, the local-server line, and the storage limits are the product page’s. NOT claimed: that this desk installed the hook, timed a check, counted the 450,000 actions, named the unnamed customer, ranked “first,” or confirmed that Mars, Netskope, Assurant, or GitLab bought this product on 22 Sep, a stock tip, or investment advice. Distinct from the already-filed outerlimit-16m, secure-passage-truman-2, and cisco-talos-cairn.
RELATED
On 22 Sep 2026, Lumos issued a release on PR Newswire launching MCP Governance. The page stamp is Sep 22, 2026, 12:00 ET. The dateline is San Francisco. The subhead says security and IT teams get visibility and control over MCP usage and agent tool calls, starting with Claude Code and Codex. Lumos calls itself the identity management platform for the agentic era. Agentic, here, means software that takes steps with tools, not only a chat reply. Claude Code is Anthropic’s coding agent. Codex is OpenAI’s coding agent. MCP is the Model Context Protocol, a common way for an agent to call a tool on a server. These lines are the company’s. This desk did not install the product.