What is Agentic Access Management (AAM)?
Agentic Access Management is an architecture pattern for controlling agent actions with originating identity, explicit delegation, per-request policy, application-level enforcement, and audit records. In this Academy, the term names the combined pattern. It is not a formal IETF, NIST, or Model Context Protocol standard.
Why it matters
A one-time sign-in or shared service identity can hide who authorized an agent and can give the agent more authority than the current task needs.
How it works
- Establish the identity that the human, workload, or agent application presents and record any delegation relationship.
- Authorize the exact resource and tool action with current context for each request.
- Record the principal, actor, resource, action, and result, then evaluate the next request again.
Example
A release agent can read deployment status for its user team. A production deployment call requires the configured production role and the specific allowed deployment tool.
Pomerium boundary
On Streamable HTTP routes, Pomerium Model Context Protocol support can combine per-user upstream connections, identity-based policy, tool rules, External Tokens for documented on-behalf-of calls, and configurable Model Context Protocol authorization log fields. These features can implement parts of an Agentic Access Management architecture.
Limits and non-claims
- Agentic Access Management is an architecture label, not one protocol or certification.
- No gateway replaces model controls, safe tool implementation, workload isolation, and downstream policy.
- Traceability depends on accurate identity context and correct use of logs at every relevant boundary.
- Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.
Evaluation checklist
- Are the human, agent, host, tool, credential, and target identities distinct?
- Does each tool call bind delegated authority to one resource, action, audience, and time limit?
- Can a direct route, hidden credential path, or downstream permission bypass the recorded decision?
Sources and further reading
- Agentic Access Management for Model Context ProtocolPomerium documentation
- Pomerium Model Context Protocol supportPomerium documentation
- Delegate MCP access to an LLMPomerium documentation
- Pomerium MCP observabilityPomerium documentation
- Pomerium MCP referencePomerium documentation
- NIST SP 800-207Standard
- RFC 8693 OAuth 2.0 Token ExchangeStandard
- Model Context Protocol authorizationStandard
