
Security and IT teams get visibility and control over MCP usage and agent tool calls, starting with Claude Code and Codex.
SAN FRANCISCO, Sept. 22, 2026 /PRNewswire/ -- Lumos, the identity management platform for the agentic era, is releasing MCP Governance for Claude Code and Codex. MCP Governance checks an AI agent's permissions at the moment it acts, and blocks the action if policy does not allow it.
Enterprises are rolling out AI coworkers faster than they can govern them. An agent inherits the permissions of the person who launched it, and then works at machine speed. A single employee might delete one Salesforce record by mistake, but their agent can delete a thousand in seconds.
"We spent twenty years learning to govern humans, and we still have not finished," said Andrej Safundzic, CEO and co-founder of Lumos. "Now we have agents doing the same work ten times faster. Just here at Lumos, with fewer than 200 employees, we measured over 450,000 agent actions in a single week. That kind of scale is impossible to track with old methods."
The industry has answered this problem with inventory, but registering every agent only tells a security team that an agent exists. It does not tell them what that agent can reach, and it does not tell them what it did.
Lumos is taking a different position. Permissions set the upper bound of what an agent is allowed to do. What the agent actually does happens at runtime, and until now identity teams have had no way to govern that moment. MCP Governance moves the decision to the point of action.
"The teams I talk to are not trying to slow AI down. They are trying to say yes," said Safundzic. "One customer would not turn on an integration for their marketing team because too many people had access to the underlying tool. That decision cost them pipeline. Governance at the moment of action is how you turn that no into a yes."
"Identity has always governed what someone is allowed to do," said Leo Mehr, co-founder of Lumos. "It has never governed what they actually did, because humans move slowly enough that review after the fact was good enough. Agents changed that. By the time you review an agent's activity, it has already made a few thousand decisions. The only place left to govern is the moment before the action runs."
MCP Governance extends the work Lumos has already done on non-human identity. Lumos maps every identity and permission across human, machine, and AI identities. MCP Governance covers the other half of the problem, which is control over what those identities do.
MCP Governance is available today for teams running Claude Code and Codex, with support for more agents to follow.
Learn more about MCP Governance by scheduling a demo today.
About Lumos
Lumos is the first identity platform built around autonomous agents, not manual workflows. Security teams use Lumos to give every human, machine, and AI agent a living control layer that watches and governs access in real time. Traditional identity governance was built for human workflows and periodic reviews. AI makes the problem bigger, messier, and faster: more identities to protect, more permissions to govern, and less time to catch abuse. Lumos helps teams at companies like Mars, Netskope, Assurant, and GitLab move faster, reduce risk, and prove compliance, all while keeping humans in control.
SOURCE Lumos
Share this article