Identity context
Match verified user and service identity claims.
Context-aware access
Pomerium evaluates configured identity, device, request, and external data before it forwards a protected HTTP request.
Match verified user and service identity claims.
Use current device and HTTP request facts where supported.
Import reviewed external records with Enterprise.
Policy inputs
Pomerium Policy Language combines identity and request facts into explicit allow and deny decisions.
Data boundary
Device posture and external data require a defined source, refresh path, and edition. Pomerium does not infer missing context.
PPL operators, criteria, and edition availability.
Route, namespace, and cluster policy behavior.
Enterprise device posture from FleetDM.