Inventory scope
An access system inventory is the authoritative relationship map for protected applications, APIs, infrastructure endpoints, data, human and workload identities, routes, policy, credentials, enforcement points, decision services, identity providers, context sources, logs, owners, and recovery paths.
An asset list is not enough. The inventory must show which identity can reach which named resource through which route and control.
Required relationships
For each protected resource, record the business owner, technical owner, public and private addresses, protocol, data class, normal clients, route, enforcement point, policy, upstream identity mechanism, object-authorization owner, credentials, dependencies, evidence, last verified request, and retirement state.
For each identity source and credential, record issuer, subject namespace, audience, lifetime, rotation, revocation, and consumers. Include emergency and disaster-recovery paths. Derive data from deployment, DNS, cloud, Kubernetes, identity, certificate, and traffic systems where possible. Reconcile it with observed runtime use.
Failure and residual risk
An inventory can be complete in one control plane and miss a direct origin, old DNS name, shadow API, secondary cloud account, service token, local MCP server, or break-glass route. Stale ownership makes alerts and revocation unactionable. Observed traffic alone misses dormant recovery paths.
Inventory is evidence of known state. It is not proof that no unknown path exists. Use active discovery and negative tests.
Pomerium boundary
Pomerium can expose configured routes, policy, access logs, and deployment state. It cannot inventory applications or paths that do not use it. Operators must correlate Pomerium routes with DNS, upstream listeners, cloud networking, application ownership, and direct-origin tests.
Evaluation checklist
- Does every resource have a business owner, technical owner, route, policy, and retirement state?
- Are human, workload, agent, service, and emergency identities included?
- Are direct, internal, secondary, and recovery paths represented?
- Can observed traffic and deployed state be reconciled with the inventory?
- Does removal delete routes, credentials, policy, DNS, trust, evidence retention, and exceptions?
