
TL;DR
Lumos is built for enterprises already heavily invested in Okta who want a more modern identity governance layer on top of that environment. Potential buyers and customers run into these three recurring problems:
Lumos won't sell to you below a size floor: The right buyer for Lumos is a team with large enterprise IT leadership. Their own marketing pages state that companies below 200 employees are not a good fit.
Limited coverage of apps for automation: Most of Lumo's integration catalog relies on SCIM which comes with the SSO tax. That means the number of apps you can actually automate is limited to the SaaS apps you have on enterprise plans.
Lumos is heavily tied to Okta as the core: Lumos makes the most sense when Okta is already your core identity provider, with broad SCIM and SAML coverage behind it. Companies running on Google Workspace or Microsoft Entra end up fitting their environment to the product.
"Lumos advertises a lot of apps that they can integrate with. But when you dig into them, they're behind paywalls. It's not their fault, but… the SSO tax. It would only automate maybe five to ten percent of what I needed."
Shane Fritts, Sr. IT Manager, from Maxio's success story
AccessOwl as the alternative to Lumos for smaller enterprises
AccessOwl is built for growing companies that want access automation (onboarding, offboarding, approvals, access reviews) without needing a fully mature enterprise identity stack.
AccessOwl is viable for companies down to 30 employees and it keeps working as you grow to several hundred and beyond.
AccessOwl was a pioneer of automated provisioning without relying on SCIM. That's why our 500+ integrations don't depend on upgrading each tool to its enterprise tier.
AccessOwl fits companies on Google Workspace or Microsoft Entra, whether they haven't adopted Okta yet or want to put access automation in place before committing to a larger enterprise-grade identity stack.
"I was impressed that with AccessOwl I could grant users access and programmatically provision their accounts without having to upgrade to the enterprise tier of the company's applications. Other solutions I'd investigated worked only with specific APIs (SCIM and/or SAML), which would often require enterprise upgrades."
Ethan Yu, Cofounder & COO, from Motion's success story
Why teams look for a Lumos alternative

Lumos is open about who it wants to sell to: enterprise IT organizations with a CIO at the top. Lumos assumes a company already runs an enterprise identity stack and each of the problems below follows from that assumption.
Okta dependency
Lumos is built around Okta as the core identity provider. That works when Okta is already your source of truth, you're paying the SSO tax for broad SCIM and SAML coverage across your apps, every app has a clear owner, and IT has time to maintain governance workflows. Large enterprises usually meet all four.
Plenty of companies well past the startup stage don't. Their identity lives in Google Workspace or Microsoft Entra, their HR system is still catching up, and many of their tools were bought by individual teams.
Google Workspace support is a good example. One buyer we spoke to was told by Lumos sales rep that they were considering moving away from supporting Google Workspace. Later, Lumos came back to them to say it was supporting Google Workspace again. Lumos does support GWS today, and seems to have invested more there recently. But the back-and-forth shows that companies on Google Workspace as their identity provider aren't who Lumos builds for.
Large enterprise focus
In fact Lumos won't sell to you at all below a size floor. Their own Zluri alternatives page describes Lumos as "built for mid-market and enterprise teams (generally 200+ employees), so smaller teams may find it more capability than they need today."
A CISO at a 75-person AI security startup we spoke to was turned away by Lumos's website chatbot, going off nothing more than an email address:
"Lumos's chatbot literally told me to move along… they just saw my email address, and they're like, move along… you're not big enough."
CISO, 75-person AI security startup
Provisioning relies on SCIM
Lumos has historically built its provisioning on SCIM, the standard protocol that lets an identity system create and remove accounts inside an app. SCIM works well where it's available. The problem is it's not always available: most SaaS vendors only offer SCIM on their enterprise plan, usually bundled with SSO at a steep markup. That's the SSO tax.
So the number of apps Lumos can automate for you depends on how many of your apps you've upgraded to an enterprise tier. For an enterprise already paying for those tiers across the board, that's fine. For a company whose stack mostly runs on standard plans, a large share of the catalog can't be automated without buying upgrades first.
"For ConductorOne and Lumos, both only really work well if all of your tools are on the enterprise plan because of the SSO tax… It's not their fault. It's just a general problem in this field."
Philip Eller, Co-founder, AccessOwl
Comparing Lumos v.s. AccessOwl: Features and Pricing
Lumos | AccessOwl | |
|---|---|---|
Built for | Large enterprises on Okta ("generally 200+ employees," per Lumos) | Companies from around 30 employees to several hundred |
Primary identity provider | Built around Okta; also supports Google Workspace and Microsoft Entra | Built for Google Workspace and Microsoft Entra; also integrates with Okta |
How apps are provisioned | SCIM and direct API connectors, on-prem agent; browser agents marketed since 2026 | Service accounts and browser automation; APIs and SCIM where they fit |
SaaS apps in integration catalog | 101 | 496, each with provisioning and deprovisioning |
HR system integrations | 62 | |
Self-service access requests | AppStore, Slack, Teams, CLI, ITSM | Slack or web dashboard with app tiles |
Time-based access | Yes | Yes |
Non-human identity and AI agent governance | Yes | Not a current focus |
Pricing | Sales call required; AWS Marketplace listing starts at $27,000/yr | Public pricing; $250/month spend minimum; No seat or employee minimum; No SSO tax |
Integration counts from each vendor's integrations page, filtered to SaaS apps and HR systems, September 2026.
Provisioning and app coverage
Lumos
Provisioning is primarily reliant on SCIM or APIs. This limits the amount of integrations available...
The Lumos website claims that support for non SCIM connectors has been added (browser agents, on-prem agents) but their catalog does not specify
300+ marketed integrations, of which 101 are SaaS apps
"I find the current integrations lacking."
Cloud Security Engineer, mid-market company, G2 review of Lumos
AccessOwl
Provisioning is primarily done through browser RPA on service accounts. SCIM, APIs, and other connectors are still available for edge cases where those make more sense.
AccessOwl can cover apps that don't have SCIM or APIs available at all...
500+ marketed integrations, of which 496 are SaaS apps, each with provisioning and deprovisioning.
Integrations with IdP & HRIS systems
Lumos
Meant for teams on Okta
Supports Google Workspace and Microsoft Entra
AccessOwl
Is built for teams still on Google Workspace or Microsoft as the primary identity layer
Integrates with Okta
Layers on top of Google or Microsoft and can be live in one day. No rip and replace.
Integrates with 54 HRIS systems
Onboarding and Offboarding

Lumos
HRIS-triggered workflows: Lumos connects to HR systems, so start and end dates can trigger onboarding and offboarding. Access can be assigned automatically based on attributes like department or role.
Built around a mature HRIS: Lumos's workflows assume complete, well-kept HR data. A buyer we spoke to, whose identity lived in Google Workspace without a mature HRIS, found it a harder fit.
Automated where SCIM reaches: Accounts are created and removed automatically in apps Lumos can provision. For many SaaS tools, that means SCIM on the enterprise plan. Apps on standard plans may need manual steps.
AccessOwl
HRIS-triggered onboarding: A start date in your HRIS kicks off onboarding. Pick the employees access template and make small changes for the individual role if you need to.
Access ready on the first morning: AccessOwl creates the accounts and permissions inside each app, including Slack channels and team spaces.
HRIS-triggered offboarding: An end date in your HRIS triggers offboarding once the employee's last workday ends. AccessOwl revokes access inside each app and logs every action as audit evidence.
Shadow IT scan: Offboarding lists apps the employee signed up for on their own outside of IT's visibility. Such as password sign-ups or "Sign in With Google" accounts. These usually get missed and later turn into audit findings. Across our customer environments employees have usually signed up for 5x more apps than IT manages.
Self service access requests
Lumos
Request from where employees work: Employees request access through the Lumos AppStore, Slack, Teams, a command-line tool or the IT ticketing system. AI agents can request access too.
Policy-based approvals: Admins define who can request each app, who approves and how long access lasts. Lumos's Albus AI agent can approve routine requests automatically, and a human approves the rest.
Time-bound access: Just-in-time grants expire and are revoked automatically, so standing privileges don't build up over time.
Audit trail: Every grant, denial and expiration is logged, including approvals made automatically by the AI agent.
AccessOwl
Request from Slack or the web: Employees request apps and permission levels in a few clicks in Slack, or through a web portal. Managers can also request access on behalf of colleagues and contractors.
Approvals routed to the right person: Approvers get a 1 click task in Slack, email or the web dashboard. Usually that's the manager or IT admin. You can also add a multi-step chain or require stricter sign-off for admin roles.
Provisioned once approved: When the last approver signs off, AccessOwl creates the account at the requested permission level. Apps without an integration go to the tool owner as a tracked task.
Every request and action is recorded: Each request, approval and change is logged with who asked, who approved and when. The log is ready to hand to an auditor.
AccessOwl also supports time-based access. Grant it for a set period, such as a contractor engagement or a few days on a sensitive system, and AccessOwl removes it when the period ends.
An IT and InfoSec manager at a UK fintech we spoke to, who evaluated both Lumos and AccessOwl side by side, told us:
AccessOwl seemed like a better fit for our users. It was less enterprise-y and more friendly. Fundamentally, I need something where my users know how to use it and know how to easily get access to apps. Otherwise, there's no point. They're still just going to put a Jira ticket in. Then, what have we solved?
Access Reviews and Audit Evidence
Lumos
Entitlement-level visibility: Lumos pulls access data from your identity provider, HR system, IT ticketing, SaaS, cloud and on-prem systems, down to individual entitlements.
AI-assisted reviews: Reviewers get a Slack notification. Lumos's Albus agent recommends decisions based on usage and identity data, so reviewers can focus on flagged changes, anomalies and separation-of-duties conflicts.
Automatic remediation: Rejected access is revoked automatically, with guardrails for handling exceptions. Delta reviews show only what's changed since the last cycle.
Audit-ready reports: Evidence is stored automatically and formatted for SOC 2, SOX and ISO 27001, ready to hand to an auditor without extra assembly.
AccessOwl
User lists pulled automatically: AccessOwl pulls users and permissions from each connected app. It flags former employees and accounts that don't match anyone in your directory.
Context for every decision: Reviewers get a decision request showing how access was granted, who approved it, past review decisions and recent permission changes. They approve, change or revoke from the same screen.
Revoked in the same session: When a reviewer flags access, AccessOwl removes it right away. There's no separate cleanup ticket between finding the problem and fixing it.
Evidence ready for auditors: Every decision is logged with the reviewer's reason and exported automatically. Reports can be exported or pushed to Vanta for SOC 2 and ISO 27001 audits.
For AccessOwl customers, access reviews take about 10 minutes per app instead of the 2 hours a manual review usually takes.
Pricing
Lumos
Pricing behind a sales call: Lumos doesn't publish prices. Its pricing page is a contact form, so getting a quote means booking a sales call.
Listed starting price: Lumos's own AWS Marketplace listing prices the core platform at $27,000 for a 12-month contract, plus $180 a year for each additional user.
Enterprise app plans add costs: Where Lumos provisions over SCIM, each app needs the plan that includes SCIM, which is usually its enterprise tier. Those upgrades are paid to each app vendor on top of Lumos.
AccessOwl
Public pricing: AccessOwl publishes its pricing on its website, so you can estimate your cost before talking to anyone.
No seat minimum: There's no seat or employee minimum, only a minimum spend of $250 a month. Teams from around 30 employees use AccessOwl, and it scales as you grow.
No SSO tax: AccessOwl doesn't need SCIM or SAML, so you don't have to upgrade apps to their enterprise plans. That SSO tax can add tens of thousands of dollars a year in hidden costs.
Who Lumos is best for
Lumos is a better fit when you:
Are already fully committed to Okta as your core identity provider
Are a large enterprise (headcount in the thousands) with a dedicated identity or security team
Need a more modern governance layer than Okta alone provides
Already have broad SCIM and SAML coverage across your apps
Are looking for a modern replacement to legacy governance tools like SailPoint
Who AccessOwl is better for
AccessOwl is a better fit than Lumos when you:
Want access automation that works now, without first building a full enterprise identity program
Run on Google Workspace or Microsoft Entra as your primary identity layer
Don't want to become fully dependent on Okta
Want automation beyond SCIM and SAML limitations
Need a system that works even if your environment is messy
Teams as small as 30 employees up to several hundred. IT team is small team or one person.
Questions to decide between Lumos and AccessOwl
Are you already on Okta as your core identity provider?
Do you have at least 200 employees and operating like an enterprise IT organization?
Do you already have broad SCIM and SAML coverage across your SaaS stack?
Are you trying to solve an enterprise governance problem, or are you trying to automate access in the environment you actually have today?
FAQs
Does Lumos rely on SCIM provisioning?
Mostly. Lumos markets several ways to connect apps: SCIM connectors, direct API connectors, an on-premises agent and, since early 2026, browser agents. Its integration catalog lists 101 SaaS apps but doesn't say which method each one uses, so you can't tell how many provision over SCIM. SCIM and the on-prem agent have versioned public documentation. Browser agents appear on one marketing page, with no public technical documentation yet. Buyers we spoke to who passed on Lumos named limited automation coverage as a reason, and G2 reviewers mention limited integrations for custom and niche apps. AccessOwl pioneered non SCIM provisioning through browser automation. Its catalog lists 496 SaaS apps, each with automated provisioning and deprovisioning.
How much does Lumos cost?
Lumos doesn't publish pricing, so a quote requires a sales call. Its own AWS Marketplace listing prices the core platform at $27,000 for a 12-month contract, plus $180 a year per additional user. Procurement data from Vendr across 50 purchases puts it at roughly $13,000 to $129,000 a year, with a median of about $36,000. Where apps are provisioned over SCIM, you may also need to upgrade those apps to enterprise plans. If you are looking for a lower cost alternative, AccessOwl publishes its pricing, so you can estimate your cost before talking to anyone.
What are the best alternatives to Lumos?
For large enterprises, the closest alternatives are identity governance platforms like ConductorOne, SailPoint and Saviynt. These tools assume a mature identity stack and a dedicated team to run them. For companies from around 30 employees to several hundred, AccessOwl is the alternative built for the environment you already have.
Does AccessOwl support just-in-time access?
Yes, in both senses the term gets used. JIT provisioning, where an account is created the first time someone signs in through SSO, works through your identity provider, and AccessOwl supports it. Time-based access, where access expires after a set period, is handled by AccessOwl directly.
When is AccessOwl the right alternative to Lumos?
AccessOwl is the right alternative to Lumos when you meet these criteria: you want access automation that works now without first building a full enterprise identity program; run on Google Workspace or Microsoft Entra as your primary identity layer; don't want to become fully dependent on Okta; want automation beyond SCIM and SAML limitations; and need a system that works even if your environment is messy.
How do I know if Lumos is the right solution for me?
Ask yourself these questions. Are you already fully committed to Okta as your core identity provider? Are you a large enterprise with a dedicated identity or security team? Do you need a more modern governance layer than Okta provides on its own? Do you already have broad SCIM and SAML coverage across your apps? Are you looking to replace legacy governance tools like SailPoint? If most of the answers are yes, Lumos is likely a strong fit.
