Skip to main content

Context-aware access

Make access decisions from verified context

Pomerium evaluates configured identity, device, request, and external data before it forwards a protected HTTP request.

What this pattern controls

Identity context

Match verified user and service identity claims.

Request context

Use current device and HTTP request facts where supported.

External context

Import reviewed external records with Enterprise.

Policy inputs

Build policy from the context that you trust

Pomerium Policy Language combines identity and request facts into explicit allow and deny decisions.

  • Match user ID, email, domain, groups, or reviewed token claims.
  • Match source IP, HTTP method, HTTP path, device identity, date, or schedule where supported.
  • Use deny rules to override matching allow rules.

Data boundary

Know where each policy signal comes from

Device posture and external data require a defined source, refresh path, and edition. Pomerium does not infer missing context.

  • Use WebAuthn for Pomerium device identity.
  • Use FleetDM host and vulnerability data with Pomerium Enterprise.
  • Use imported external records and Rego with Pomerium Enterprise.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo