Skip to main content

Lumos Launches MCP Governance to Block Rogue AI Agent Actions

Image
Lumos Launches MCP Governance to Block Rogue AI Agent Actions

San Francisco – September 22, 2026 -- Lumos has released MCP Governance, a new capability that checks an AI agent's permissions at the exact moment it attempts an action and blocks it if policy does not allow it, starting with support for Claude Code and Codex.

Lumos measured over 450,000 agent actions in a single week among its own staff of fewer than 200 employees

"We spent twenty years learning to govern humans, and we still have not finished," said Andrej Safundzic, CEO and co-founder of Lumos. "Now we have agents doing the same work ten times faster. That kind of scale is impossible to track with old methods."

An AI agent inherits the permissions of the employee who launched it but then operates at machine speed, meaning an error that might cause a human to delete one Salesforce record could see an agent delete a thousand records in seconds.

Lumos moves governance decisions to the point of action rather than after-the-fact review

The company argues that existing industry approaches, which focus on inventorying AI agents, only confirm that an agent exists without revealing what it can access or what it has done. Permissions define the upper limit of an agent's allowed actions, but Lumos contends that what an agent actually executes happens at runtime, a moment identity teams have previously had no mechanism to control.

"By the time you review an agent's activity, it has already made a few thousand decisions," said Leo Mehr, co-founder of Lumos. "The only place left to govern is the moment before the action runs."

One customer blocked a marketing integration over access concerns, a decision Lumos says cost them sales pipeline

Safundzic said governance at the point of action is designed to let enterprises approve AI tool usage they previously restricted due to over-broad access among too many users.

MCP Governance builds on Lumos's existing non-human identity mapping, which tracks identities and permissions across human, machine, and AI accounts. The new feature adds control over what those identities actually do once granted access.

MCP Governance is available now for teams running Claude Code and Codex, with the company stating support for additional agents will follow.

Published by
fairsonline_team
Company
Products
News Type