Comparison · agent governance · Lumia

Lumia, measured.

Lumia controls AI use by inspecting the traffic it generates. This page scores that approach across 16 capabilities against the same capabilities in Agen.co, with the sources, the scoring ladder, the ties, and the row Lumia wins all on the page.

The short answer

  • Lumia reads AI activity off the network with deep packet inspection, then blocks, redacts or logs it. Whatever an agent does that crosses that inspection point can be judged before it executes; whatever does not cross it is outside the decision.
  • Agents are recognised from their traffic and the permissions they use, not enrolled as identities with a standing owner. Agen gives every agent a first-class identity and a named accountable human, and resolves each action to that person.
  • Its discovery of AI use is broad: standalone chat services, AI embedded inside business applications, and agents, attributed by department, role, individual and device, for everything that crosses the inspection point.
  • No decision latency figure is published. Agen renders a verdict on every action, against any policy you write, in under 30ms.
  • The product is built for the workforce: employees and the agents working for them. Agen governs internal and customer-facing agents on the same policy plane.
  • Lumia is stronger at the network layer, which we deliberately do not operate, and that is what lets Agen govern agents whose actions never cross a corporate network. Browser enforcement, prerequisite licensing and time to start all score level.
The long read

What Lumia actually governs.

Lumia's design choice is to sit where AI traffic already flows and understand it there, rather than ask anything to be installed or enrolled. That choice is why it starts in minutes, and it also draws the line around what it can decide.


How the product is built

Lumia describes itself as AI usage control for employees and agents. Four connected pieces sit under that.

  • A protocol analysis enginedeep packet inspection over browser, native-application and operating-system traffic, deployed inside the existing network or as a standalone proxy. No endpoint agent is required, and developer tools are left unmodified.
  • Policy by content, context and intentrules can reference what was said or done, metadata such as the service account in use, and the intent of a conversation as classified by language models. Policies can be written in natural language.
  • Three outcomesblock, redact or log, plus real-time feedback to the user explaining why an action was stopped. Redaction covers prompts, responses and network calls, and inspection extends to file, voice and visual content.
  • Agent and MCP guardrailsagent actions evaluated before execution, MCP servers, tools and specific operations such as repository commits or database writes governed without a separate MCP gateway, and a log of every attempted, executed or blocked action with its origin, permissions and result.

Where Lumia is strongest

One of the sixteen rows below goes to Lumia and three are level. They follow from where the product sits: on the wire, with no client to deploy.

  • Network-layer enforcementthe layer the whole product is built on. We govern the action rather than the packet, and run alongside whatever inspects traffic today rather than replacing it.
  • Browser enforcement without an extensionbrowser AI traffic is read inline and a prompt, response or call can be blocked or redacted before it leaves, with nothing to roll out to the browser. Scored level with ours.
  • Discovery, redaction and the audit logstandalone, embedded and agent AI tied to the person, team and device using it; sensitive values redacted in both directions; every attempted, executed and prevented action recorded. Each is complete for the traffic that crosses the inspection point, which is the one caveat in those cells.
  • Getting starteda published five-minute start with no prerequisite product to buy first. Level with ours on both operating rows.

What the network can and cannot see

Inspecting traffic answers a precise question: what is this connection carrying, and should it go through? For a chat prompt that is the whole story. For an agent it is part of one. An agent running in a cloud workload, on a device off the corporate network, or inside a SaaS platform's own infrastructure acts on systems through paths that a corporate inspection point may never see.

Where the action does cross the path, Lumia can stop it before it executes, and the table scores that as real enforcement. Where it does not, there is no decision to make. That is why the moment-of-action row is a 3 rather than a 5: genuine inline control over a bounded set of actions. The same bound is the caveat on the redaction, audit, discovery and MCP rows, which are thorough for what passes the inspection point and silent on what does not.

Who answers for the agent

Lumia sees who is running an agent, which plugins it has, what it asks to do and the permissions it is using. For an agent an employee launches, that resolves the action to a person, and it scores accordingly.

What it does not hold is the agent as an identity with an owner of record. Policy context includes the service account an action used, which, for an unattended agent, is where the documented trail ends. A service account tells you which credential acted. An owner tells you who answers for it, including on the nights nobody launched anything.

Three questions to put to a deep-packet-inspection design

Lumia's packet inspection answers what an AI connection carries. Governing an agent asks three further questions, and the table's first three groups are built around them.

  • Be at runtimeLumia judges an agent action before it executes when the action travels through its proxy or in-network sensor. The question is what happens to the action that travels some other way.
  • Know the identityLumia's policy context names the user and the service account behind a connection. The question is whether an unattended agent's action resolves past that account to a person who owns the agent.
  • Cover everythingLumia is scoped to AI used at work. The question is whether the same policy reaches agents in cloud workloads, on devices off the corporate network, and in front of your customers.

A buyer will also ask what it costs to run Lumia across a workforce. It publishes no price list or packaging tiers, so its two cost rows are left out rather than estimated; the operating rows that can be checked against its own pages, prerequisite licensing and time to start, are scored.

The scored comparison

Sixteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it takes to operate — each scored 0–5 on capability depth against Lumia's own documentation, ties and the row Lumia wins included.

Capability depthNoneCompleteLumiaAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionLumiaBefore execution, on the network pathCapable3/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredLumiaNot publishedPartial2/5Agen.co<30ms, published, no samplingComplete5/5
Masking or redaction at action timeLumiaRedacts in transit, on-path onlyStrong4/5Agen.coMasking at action timeComplete5/5
Blocks a single action without disabling the agentLumiaSingle actions, on-path onlyStrong4/5Agen.coAction-level enforcementComplete5/5
02 · Identity & accountability
Agent has a first-class identity objectLumiaRecognised from traffic, not enrolledPartial2/5Agen.coFirst-class agent identityComplete5/5
A named human accountable for each agentLumiaSees who runs it; no ownerPartial2/5Agen.coNamed owner, every agentComplete5/5
Each individual action attributed to that humanLumiaAttributed to the running userCapable3/5Agen.coAttributed per actionComplete5/5
Audit record per actionLumiaEvery on-path action loggedStrong4/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementLumiaDevice traffic, no device clientPartial2/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementLumiaInline block and redact, no extensionCapable3/5Agen.coBrowserShield, early accessCapable3/5
Network-layer enforcementLumiaDeep packet inspection, its coreComplete5/5Agen.coNot our layer — works alongsidePartial2/5
Shadow-agent discoveryLumiaBroad, within inspected trafficStrong4/5Agen.coShadow AI surfacedComplete5/5
MCP tool governanceLumiaPer action, network path onlyStrong4/5Agen.coMCP tools governed per callComplete5/5
External customer-facing agentsLumiaWorkforce AI use onlyBasic1/5Agen.coCustomer-facing agents, same planeComplete5/5
04 · Operate & buy
Prerequisite licensingLumiaStandalone, no prerequisite tierComplete5/5Agen.coNo prerequisite tierComplete5/5
Time to first governed agentLumiaFive-minute start, publishedComplete5/5Agen.coDays to a first governed agentComplete5/5
12 rows Agen.co leads3 tied1 row Lumia leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation.
Get the walkthrough

Get the scored comparison walkthrough.

Thirty minutes, row by row, including the ones we lose to Lumia. You leave with the same table, scored for your environment. Tell us anything we should know in the comments.

length30 minutes
formatrow by row
commitmentnone
What the table shows

One boundary: Lumia's inspection point.

Lumia's controls are real and the scores reflect it: inline blocking before execution, single actions stopped without halting the agent, browser traffic governed with no extension, and the network layer itself, where it leads. Deep packet inspection is a strong place to stand.

Every gap in its column traces back to that same inspection point. Lumia decides on what crosses it, and what crosses it carries a user or a service account rather than an owner who answers for the agent. The cards below take Lumia's proxy-and-sensor design through runtime, identity, coverage and operations in turn.

Reading the table

What Lumia's network path means, group by group.

One card per table group, for an agent acting through Lumia's inspection point or around it.

01

Judged before execution, if it is on the path

Agent actions that cross the inspection point are evaluated before they execute and can be blocked one at a time. Actions taken on paths the network never sees have no decision point, and no latency figure is published for the ones that do.

published latencynone
02

An account in the log, not an owner on record

The log records origin, permissions and result for every action that crosses the inspection point, and an employee-launched agent resolves to that employee. For an unattended agent, the documented trail ends at the service account it used; no standing owner is described for the agent itself.

owner of record per agentno
03

Built for the workforce side

Discovery of AI use across employees, embedded AI and agents is broad, needs no client, and extends into the browser without an extension. The scope is AI used at work, so customer-facing agents sit outside it, as do agents whose traffic never reaches the inspection point.

customer-facing agentsout of scope
04

Fast to start, nothing to buy first

A published five-minute start, deployed inside the existing network or as a standalone proxy, with no prerequisite product. Both operating rows score level. Pricing is not published, so cost is not scored here.

published start5 minutes
Watch it happen

A verdict on the action, wherever the agent runs.

Not a decision tied to one inspection point: every action judged against your policy at the moment it happens, with allow, step-up, approval, masking and deny all available, and the verdict resolved to the human who owns the agent.

per-action policy · live product scene
What closes the gap

Keep the inspection. Govern the agent.

Your network inspection keeps classifying AI traffic. Agen governs above it: every agent discovered agentlessly whether or not it crosses your network, given an identity and a named owner, and every action judged against your policy at the moment it happens, internal agents and customer-facing ones on the same plane.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Thirty-one capabilities were scored against the ladder in our internal rubric; sixteen are published here. Eleven more rows in the standard set were not scored and are not published on any page: pricing and total cost because Lumia publishes no pricing or packaging, six because the only finding was an absence in public documentation, which is weaker evidence than a documented limit, and the rest because the two products count the underlying thing differently enough that the row would not be a fair like-for-like, or because the row is still being confirmed on our side. Each score reflects capability depth in the vendor's best available configuration.

Sources10 primary
Evidence ledger
  1. Lumia — overviewTier AAI usage control for work; modules for shadow AI detection, leakage prevention, compliance, agent guardrails, coding assistant security, MCP security and visibility, and AI cost control; operates at the network layer.
  2. Lumia — platformTier AProtocol analysis engine using deep packet inspection over browser, native-app and OS-level AI traffic; deployed within existing network infrastructure or as a standalone proxy; policy by content, context (including service account used) and intent; block, redact or log.
  3. Lumia — how it worksTier AThree-step start (integrate, assess risk, enforce policy) presented as getting started in five minutes; text, file, voice and visual modalities; block, redact or log outcomes.
  4. Lumia — agentsTier AEach agent action evaluated before execution as permitted, restricted, or requiring oversight; unauthorised or high-risk actions blocked; permissions used and systems affected identified; every attempted, executed or prevented action logged.
  5. Lumia — agent guardrailsTier AUnsafe or unauthorised actions blocked before execution; actions traced step by step; every attempted, executed or blocked action recorded with its origin, permissions and result.
  6. Lumia — MCP security and visibilityTier AMCP integrations identified without an MCP gateway; visibility into who runs agents, installed plugins, requested actions and permission scope; governs which servers and tools may be used, whether actions such as git commits or database writes are permitted, and when values are redacted.
  7. Lumia — shadow AI detectionTier ADiscovers standalone AI services, AI embedded in business applications, and agents; identifies users by department, role, individual, device and connection type; policies definable in natural language.
  8. Lumia — leakage preventionTier ABlocks prompts or responses beyond approved boundaries; automatically redacts personal identifiers, financial data and confidential IP; real-time user alerts and context.
  9. Lumia — coding assistant securityTier AGovernance without endpoint agents or modifications to developer tools; restricts unsafe actions, controls tool invocation, and redacts values such as API keys.
  10. Lumia — employeesTier ADetects standalone and embedded AI used by employees, by browser, application and endpoint; blocks or redacts a prompt, response or network call before it leaves the environment; explains to users in real time why an action was risky.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Lumia?
Lumia Security sells AI usage control for employees and agents. It deploys at the network layer, inside existing infrastructure or as a standalone proxy, and uses deep packet inspection to analyse browser, native-application and operating-system AI traffic. Policies can reference content, context such as the service account in use, and intent, and the outcomes are block, redact or log. Dedicated modules cover shadow AI detection, leakage prevention, compliance, agent guardrails, coding assistants, MCP and AI cost.
Does Lumia block agent actions at runtime?
Yes, for actions it can see. Lumia evaluates agent actions before execution and can block unauthorised or high-risk ones, including specific MCP operations such as repository commits or database writes. Because enforcement happens on the network path, an action an agent takes over a path that does not cross that inspection point has no decision point. No decision latency figure is published.
Can Agen.co run alongside Lumia?
Yes. Network-layer enforcement is a layer we deliberately do not operate, which is what lets one policy reach agents whose actions never cross a corporate network. Agen governs the action rather than the traffic: every agent discovered agentlessly across five surfaces, every action judged against your policy in under 30ms, and every verdict resolved to a named accountable human. Nothing in your network has to be removed.
How does Lumia tie an agent's action to a person?
Through the traffic. It identifies who is running agents, which plugins are installed, what actions are requested and the permissions in use, and records each action's origin, permissions and result. For an agent an employee launches, that resolves to the employee. Policy context includes the service account used, so for an agent running unattended the documented trail ends at its account; no standing owner is described for the agent itself.
Does Lumia govern MCP?
Yes. It identifies MCP integrations without requiring an MCP gateway and can govern which servers and tools may be used, whether specific actions are permitted, and when sensitive values must be redacted. It scores a 4 on MCP tool governance; the caveat is the network path, since an MCP call that does not cross Lumia's inspection point is not governed.
Where does Lumia score better than Agen.co?
One row of sixteen outright, network-layer enforcement, because that is the layer the product is built on and one we do not operate. Three more are level: browser enforcement, prerequisite licensing, and time to a first governed agent. Redaction, the per-action audit record and shadow AI discovery are close behind, each complete for the traffic its inspection point sees.
How current is this comparison?
It is scored against vendor public documentation and re-scored on a schedule we hold ourselves to. Every published row is backed by at least one primary vendor source, all listed on this page, so any row can be checked against the vendor's own documentation rather than taken on trust.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.