Skip to main content

Agentic Access Management

Agents are increasingly capable, but our current security model is built on assumptions and playbooks from a previous generation that no longer hold. Human & service-centric access models cannot simply be grafted onto agents. A new approach is necessary.

Talk to our engineering team
A figure in a toga carries a tablet toward a marble arch bearing the Pomerium mark, its open archway glowing green.

The Problem

Agents have already shown that existing security models are insufficient.

At their core, agents are stochastic, non-deterministic, and operating at orders of magnitude faster than humans ever can. As agents begin to collaborate with each other the complexity of identity, access, and security requires an entirely new security paradigm. The operating primitives remain the same, but the secure execution layer needs to change.

Which security primitives need to be re-examined for agentic access?

Authentication + Identity
Authentication is not a one-time, static event anymore. For agents identity is constantly shifting based on any number of factors such as tools, context windows, chain of thought, task, etc.
Authorization + Policy Enforcement
Static OAuth scopes are ineffective when governing an untrustworthy, dynamic agent where intent unknowingly drifts from benign to malicious during a session. Simply put, agents can't be trusted with coarse grained access.
Trusted execution environment
While useful, sandboxes aren't a security panacea. Agents have shown in multiple breakouts that they need to be controlled with strong ingress and egress. It doesn't do much good to not be able to write to disk if you can still write to the internet.
Secure I/O
You can't give agents a blind Layer 4 pipe and hope for the best. Agents want to interact with all your data, across protocols, tools, and platforms. They're also non-deterministic, fast, and autonomous. The scope of securing this attack surface is enormous if left unchecked.
Governance, Auditability & Observability
Agents shouldn't get a pass from governance. They need to be as auditable as anything or anyone else in your organization. However, the architecture of agents does not make this easy. The context that we need to govern these agents isn't being streamed today.

The Solution

How Pomerium secures agentic access.

Pomerium combines declarative access controls, dynamic policy enforcement, secure and credential-free agentic sandboxing with per-tool-call logging to effectively contain agents.

Agentic AI

Securing Agentic Runtime

A user's request enters Pomerium at Ingress. The agent runs in AgentRun, in the harness you bring. Its tool calls leave through Pomerium at Egress to reach MCP tools. Above them, Pomerium's control plane connects in both directions to Ingress for policy, to AgentRun for observability and evidence, and to Egress for identity and credentials.

Builds on existing security primitives to support agents:

  • Authentication + Identity

    Pomerium supports continuous identity verification based on dynamic characteristics, from multiple sources including user identity, user state, device state, and agent state in any environment. You aren't forced to shoehorn a rigid sense of identity onto agents. Pomerium is able to account for the nuance of identity regardless of if the agent is acting on behalf of one user, multiple users or on behalf of other agents, in a holistic way.

  • Authorization + Policy Enforcement

    Pomerium supports continuous policy enforcement on a per-action basis at the speed of agentic tool calls. Because of the scale and non-determinism of agentic actors, static OAuth scopes are insufficient in constraining an agent's reach. Pomerium's authorization framework allows you to evaluate a wide range of contextual data and respond in real time with dynamic policies via Rego or Pomerium's YAML-based policy language.

  • Trusted execution environment

    Pomerium is agnostic to whichever run environment you want to use, and operates above and isolated from your sandbox. Attack surface areas are not co-mingled, so security controls remain outside of the reach of the model.

  • Secure I/O

    Pomerium sits above your harness and acts as a context aware ingress and egress proxy for all input/output. Because the channels in which your agent is able to communicate with the world are the most important to keep secure, Pomerium protects what your agent is able to receive and send to the world.

  • Auditability & Observability

    Pomerium acts as an ingress and egress proxy, establishing an auditable chain of custody from prompt to action. With end to end tracing, you get a comprehensive, cryptographically attested audit trail, as well as telemetry and observability details relevant to how and what your agents are doing.

Agentic Access Management

Interested in using Pomerium to secure agents?

Talk to our engineering team