What Lumia actually governs.
Lumia's design choice is to sit where AI traffic already flows and understand it there, rather than ask anything to be installed or enrolled. That choice is why it starts in minutes, and it also draws the line around what it can decide.
How the product is built
Lumia describes itself as AI usage control for employees and agents. Four connected pieces sit under that.
- A protocol analysis enginedeep packet inspection over browser, native-application and operating-system traffic, deployed inside the existing network or as a standalone proxy. No endpoint agent is required, and developer tools are left unmodified.
- Policy by content, context and intentrules can reference what was said or done, metadata such as the service account in use, and the intent of a conversation as classified by language models. Policies can be written in natural language.
- Three outcomesblock, redact or log, plus real-time feedback to the user explaining why an action was stopped. Redaction covers prompts, responses and network calls, and inspection extends to file, voice and visual content.
- Agent and MCP guardrailsagent actions evaluated before execution, MCP servers, tools and specific operations such as repository commits or database writes governed without a separate MCP gateway, and a log of every attempted, executed or blocked action with its origin, permissions and result.
Where Lumia is strongest
One of the sixteen rows below goes to Lumia and three are level. They follow from where the product sits: on the wire, with no client to deploy.
- Network-layer enforcementthe layer the whole product is built on. We govern the action rather than the packet, and run alongside whatever inspects traffic today rather than replacing it.
- Browser enforcement without an extensionbrowser AI traffic is read inline and a prompt, response or call can be blocked or redacted before it leaves, with nothing to roll out to the browser. Scored level with ours.
- Discovery, redaction and the audit logstandalone, embedded and agent AI tied to the person, team and device using it; sensitive values redacted in both directions; every attempted, executed and prevented action recorded. Each is complete for the traffic that crosses the inspection point, which is the one caveat in those cells.
- Getting starteda published five-minute start with no prerequisite product to buy first. Level with ours on both operating rows.
What the network can and cannot see
Inspecting traffic answers a precise question: what is this connection carrying, and should it go through? For a chat prompt that is the whole story. For an agent it is part of one. An agent running in a cloud workload, on a device off the corporate network, or inside a SaaS platform's own infrastructure acts on systems through paths that a corporate inspection point may never see.
Where the action does cross the path, Lumia can stop it before it executes, and the table scores that as real enforcement. Where it does not, there is no decision to make. That is why the moment-of-action row is a 3 rather than a 5: genuine inline control over a bounded set of actions. The same bound is the caveat on the redaction, audit, discovery and MCP rows, which are thorough for what passes the inspection point and silent on what does not.
Who answers for the agent
Lumia sees who is running an agent, which plugins it has, what it asks to do and the permissions it is using. For an agent an employee launches, that resolves the action to a person, and it scores accordingly.
What it does not hold is the agent as an identity with an owner of record. Policy context includes the service account an action used, which, for an unattended agent, is where the documented trail ends. A service account tells you which credential acted. An owner tells you who answers for it, including on the nights nobody launched anything.
Three questions to put to a deep-packet-inspection design
Lumia's packet inspection answers what an AI connection carries. Governing an agent asks three further questions, and the table's first three groups are built around them.
- Be at runtimeLumia judges an agent action before it executes when the action travels through its proxy or in-network sensor. The question is what happens to the action that travels some other way.
- Know the identityLumia's policy context names the user and the service account behind a connection. The question is whether an unattended agent's action resolves past that account to a person who owns the agent.
- Cover everythingLumia is scoped to AI used at work. The question is whether the same policy reaches agents in cloud workloads, on devices off the corporate network, and in front of your customers.
A buyer will also ask what it costs to run Lumia across a workforce. It publishes no price list or packaging tiers, so its two cost rows are left out rather than estimated; the operating rows that can be checked against its own pages, prerequisite licensing and time to start, are scored.