Tanium Platform
Use selected Tanium Platform records in Pomerium policy through a customer-owned external data source.
Overview
Tanium Platform provides endpoint management and security data. Tanium API Gateway uses GraphQL for current queried integrations, while Tanium Connect can deliver scheduled output. A customer-owned adapter can map selected data to Pomerium Enterprise external data.
Selected Tanium Platform data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected Tanium Platform records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Use Tanium API Gateway for new queried integrations when it exposes the required data. Use a scheduled Tanium Connect output when that delivery model fits better. Request only the module data that the access policy needs.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter reads a narrow endpoint inventory result and maps an approved organization state to a supported user key. Pomerium evaluates that imported state. A Tanium endpoint identifier is not treated as proof of the current requester device.
Considerations
- Tanium module entitlements and available fields vary by deployment.
- Tanium is phasing out the broad Platform REST API where newer interfaces exist. Use current product guidance.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A vendor device or asset ID does not prove which device made the current Pomerium request.
