Adding Lumos Access Request Agent to Jira Service Management

Last updated: September 11, 2026

Background

The Lumos Agent appears in your Jira Service Management agent dropdown like any other agent. Assign an access request ticket to it and Lumos reads the ticket, builds the matching access request, and runs it through your approval and provisioning workflows. Lumos writes status back to the ticket when the request reaches a terminal state, so your team stays in Jira and no one has to re-enter the request in Lumos.

This article covers what the agent does, what has to be in place before it works, and how service desk agents interact with it. Setup requires the Jira integration and Organization Admin access in Lumos. See Connecting Jira Integration

When to use this

  • Ticket-first intake. Your employees are trained to file a Jira ticket for everything. Pointing them to the AppStore breaks that habit; assigning the ticket to Lumos does not.

  • Audit trail lives in Jira. The access request carries the ticket ID and URL, and the ticket carries the request ID. Either system leads an auditor to the other.

  • Triage volume. Your service desk fields a steady stream of access asks. The agent handles the well-formed ones end to end and comments on the ones it cannot.

Prerequisites

All of these must be true before the Forge app will install. Lumos refuses the install rather than binding to a site where it cannot resolve people.

  • The Jira integration is connected in your Lumos tenant, approved by an Organization Admin of your Atlassian site. This is what ties the Jira site to your Lumos tenant.

  • The user sync has run, so your Atlassian accounts appear in Lumos and are linked to Lumos users.

  • One Jira site per Lumos tenant. Two sites sharing a tenant make two-way ticket sync unreliable for the second site.

  • The person installing the App has a linked Atlassian account and the Organization Admin role in that Lumos tenant.

Setting up the Lumos Agent

In Lumos

  1. Go to Settings → Integrations → Discover and connect Jira (ITSM).

  2. Add connection information and approve the OAuth grant as an Organization Admin of your Atlassian site.

  3. Confirm accounts sync after setup by visiting Apps → Jira (ITSM) → Accounts Users should show as matched, without the yellow Unmatched label.

In Jira

  1. Install the Lumos Access Request Agent from the Atlassian Marketplace.

  2. Open a service desk project and confirm "Lumos Agent" appears in the assignee dropdown.

  3. Assign a test ticket with access request details, assign the "Lumos Access Request Agent" and confirm Lumos comments on the ticket.

How the agent handles a ticket

  1. A service desk agent triages the ticket and sets the assignee to "Lumos Access Request Agent".

  2. Lumos reads the ticket's reporter, summary, and description. It resolves them against your Lumos identities and your AppStore catalog.

  3. Lumos submits the access request and comments on the ticket with a link to it.

  4. The request runs through the approval and provisioning workflows configured for that app and permission.

  5. Lumos writes each status change back to the ticket, then closes the ticket when the request reaches a terminal state.

What Lumos records on every request

Field

Source

Origin, agent, agent version

Set by Lumos on the request

Jira project

Ticket

Jira issue ID and URL

Ticket

Issue title and description

Ticket

Originating actor

Ticket reporter

Assigning service desk agent

The Jira user who set the assignee

Terminal states

State

What it means

Completed

Access was granted

Denied

The request did not clear approvals

Cancelled

Someone cancelled the request before completion

Expired

No approver or admin acted within 14 days

Error handling

Lumos fails loudly and says so on the ticket rather than guessing.

Situation

What happens

Jira site not connected to any Lumos tenant

Lumos refuses the install

Installer's Atlassian account not linked to a Lumos user

Lumos refuses the install

Installer linked but not an Organization Admin

Lumos refuses the install

Reporter's Atlassian account not linked

Lumos declines the ticket and asks an admin to link the account

Reporter matches more than one Lumos user

Lumos declines the ticket and asks an admin to resolve the duplicate accounts

Jira integration credentials have lapsed

Lumos declines the ticket and asks an admin to reconnect Jira

App or permission missing from the catalog, inactive, or ineligible

Lumos comments with the conflict and a proposed alternative where one exists

Duration or business justification missing and not inferable

Lumos comments naming exactly what it needs

Target user already holds the access

Lumos comments and does not submit a request

Fix the underlying issue, then assign the ticket to "Lumos Access Request Agent" again. The agent re-runs against the updated ticket.

FAQ

Do requesters need Lumos accounts?
Yes. Anyone who will be the reporter on a ticket needs a linked Lumos user. For most customers this happens automatically, since people arrive in Lumos from your HRIS or IdP.

Can we use the agent on more than one Jira site?
Connect each Jira site to its own Lumos tenant. Two sites sharing one tenant make two-way ticket sync unreliable for the second site.

Does this replace the existing Jira access request sync?
No. Two-way status sync between Lumos access requests and Jira tickets works as configured. The agent adds a way to create the request from the ticket.