System and boundaries
Access control restricts actions by subjects on protected resources according to policy. A complete system includes policy administration, information sources, decision, enforcement, and evidence. Authentication can identify a principal, but it does not decide the principal's allowed actions.
Request and decision flow
The enforcement point intercepts an attempted action and forms or forwards an authorization request. The decision point evaluates policy with trusted subject, resource, action, and context facts. The enforcement point applies the result to the same action and records relevant evidence.
Models and placement
Role-based, attribute-based, relationship-based, mandatory, discretionary, and capability-based systems express authority differently. Central decisions can improve consistency. Distributed enforcement remains necessary near resources. Choose the model and placement from the resource, threat, latency, and ownership needs.
Failure domains and residual risk
An access rule can be correct while a bypass path avoids it. Inputs can be stale. Distributed policy versions can drift. An application can accept an object identifier that the gateway did not evaluate. Emergency access can create a second unreviewed system.
Pomerium boundary
Pomerium provides route-level policy decision and enforcement for protected traffic. Network design must prevent direct upstream access. Applications still control object and action permissions based on application state.
Evaluation checklist
- Which resources and actions does each control own?
- Where are policy, information, decision, and enforcement functions placed?
- Does every path to the resource cross effective enforcement?
- Are inputs authentic and fresh enough for the decision?
- Can evidence connect the decision to the final action?
