Adding Lumos Access Request Agent to Jira Service Management
Last updated: September 11, 2026
Background
The Lumos Agent appears in your Jira Service Management agent dropdown like any other agent. Assign an access request ticket to it and Lumos reads the ticket, builds the matching access request, and runs it through your approval and provisioning workflows. Lumos writes status back to the ticket when the request reaches a terminal state, so your team stays in Jira and no one has to re-enter the request in Lumos.
This article covers what the agent does, what has to be in place before it works, and how service desk agents interact with it. Setup requires the Jira integration and Organization Admin access in Lumos. See Connecting Jira Integration
When to use this
Ticket-first intake. Your employees are trained to file a Jira ticket for everything. Pointing them to the AppStore breaks that habit; assigning the ticket to Lumos does not.
Audit trail lives in Jira. The access request carries the ticket ID and URL, and the ticket carries the request ID. Either system leads an auditor to the other.
Triage volume. Your service desk fields a steady stream of access asks. The agent handles the well-formed ones end to end and comments on the ones it cannot.
Prerequisites
All of these must be true before the Forge app will install. Lumos refuses the install rather than binding to a site where it cannot resolve people.
The Jira integration is connected in your Lumos tenant, approved by an Organization Admin of your Atlassian site. This is what ties the Jira site to your Lumos tenant.
The user sync has run, so your Atlassian accounts appear in Lumos and are linked to Lumos users.
One Jira site per Lumos tenant. Two sites sharing a tenant make two-way ticket sync unreliable for the second site.
The person installing the App has a linked Atlassian account and the Organization Admin role in that Lumos tenant.
Setting up the Lumos Agent
In Lumos
Go to Settings → Integrations → Discover and connect Jira (ITSM).
Add connection information and approve the OAuth grant as an Organization Admin of your Atlassian site.
Confirm accounts sync after setup by visiting Apps → Jira (ITSM) → Accounts Users should show as matched, without the yellow Unmatched label.
In Jira
Install the Lumos Access Request Agent from the Atlassian Marketplace.
Open a service desk project and confirm "Lumos Agent" appears in the assignee dropdown.
Assign a test ticket with access request details, assign the "Lumos Access Request Agent" and confirm Lumos comments on the ticket.
How the agent handles a ticket
A service desk agent triages the ticket and sets the assignee to "Lumos Access Request Agent".
Lumos reads the ticket's reporter, summary, and description. It resolves them against your Lumos identities and your AppStore catalog.
Lumos submits the access request and comments on the ticket with a link to it.
The request runs through the approval and provisioning workflows configured for that app and permission.
Lumos writes each status change back to the ticket, then closes the ticket when the request reaches a terminal state.
What Lumos records on every request
Field | Source |
|---|---|
Origin, agent, agent version | Set by Lumos on the request |
Jira project | Ticket |
Jira issue ID and URL | Ticket |
Issue title and description | Ticket |
Originating actor | Ticket reporter |
Assigning service desk agent | The Jira user who set the assignee |
Terminal states
State | What it means |
|---|---|
Completed | Access was granted |
Denied | The request did not clear approvals |
Cancelled | Someone cancelled the request before completion |
Expired | No approver or admin acted within 14 days |
Error handling
Lumos fails loudly and says so on the ticket rather than guessing.
Situation | What happens |
|---|---|
Jira site not connected to any Lumos tenant | Lumos refuses the install |
Installer's Atlassian account not linked to a Lumos user | Lumos refuses the install |
Installer linked but not an Organization Admin | Lumos refuses the install |
Reporter's Atlassian account not linked | Lumos declines the ticket and asks an admin to link the account |
Reporter matches more than one Lumos user | Lumos declines the ticket and asks an admin to resolve the duplicate accounts |
Jira integration credentials have lapsed | Lumos declines the ticket and asks an admin to reconnect Jira |
App or permission missing from the catalog, inactive, or ineligible | Lumos comments with the conflict and a proposed alternative where one exists |
Duration or business justification missing and not inferable | Lumos comments naming exactly what it needs |
Target user already holds the access | Lumos comments and does not submit a request |
Fix the underlying issue, then assign the ticket to "Lumos Access Request Agent" again. The agent re-runs against the updated ticket.
FAQ
Do requesters need Lumos accounts?
Yes. Anyone who will be the reporter on a ticket needs a linked Lumos user. For most customers this happens automatically, since people arrive in Lumos from your HRIS or IdP.
Can we use the agent on more than one Jira site?
Connect each Jira site to its own Lumos tenant. Two sites sharing one tenant make two-way ticket sync unreliable for the second site.
Does this replace the existing Jira access request sync?
No. Two-way status sync between Lumos access requests and Jira tickets works as configured. The agent adds a way to create the request from the ticket.