What happened
On Sept 22, 2026, Lumos (identity platform for the agentic era) released MCP Governance for Claude Code and Codex: instead of only inventorying agents, it evaluates an agent's permissions at the moment it acts and blocks the tool call if policy disallows it, governing what agents actually do at runtime.
Why it matters
Responds to the widely-flagged gap that agent inventory alone doesn't show what an agent can reach or did — Lumos measured 450,000+ agent actions/week at a <200-person company, which is impossible to review after the fact; this is a concrete runtime point-of-action control for MCP/tool authorization.
Applicability
Security/IAM and platform teams running Claude Code or Codex across the enterprise should evaluate Lumos MCP Governance to add runtime authorization on agent tool calls; relevant for near-term (30-60 day) agent governance rollouts.