Skip to main content

Agentic Access Management (AAM)

Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.

What is Agentic Access Management (AAM)?

Agentic Access Management is an architecture pattern for controlling agent actions with originating identity, explicit delegation, per-request policy, application-level enforcement, and audit records. In this Academy, the term names the combined pattern. It is not a formal IETF, NIST, or Model Context Protocol standard.

Why it matters

A one-time sign-in or shared service identity can hide who authorized an agent and can give the agent more authority than the current task needs.

How it works

  1. Establish the identity that the human, workload, or agent application presents and record any delegation relationship.
  2. Authorize the exact resource and tool action with current context for each request.
  3. Record the principal, actor, resource, action, and result, then evaluate the next request again.

Example

A release agent can read deployment status for its user team. A production deployment call requires the configured production role and the specific allowed deployment tool.

Pomerium boundary

On Streamable HTTP routes, Pomerium Model Context Protocol support can combine per-user upstream connections, identity-based policy, tool rules, External Tokens for documented on-behalf-of calls, and configurable Model Context Protocol authorization log fields. These features can implement parts of an Agentic Access Management architecture.

Limits and non-claims

  • Agentic Access Management is an architecture label, not one protocol or certification.
  • No gateway replaces model controls, safe tool implementation, workload isolation, and downstream policy.
  • Traceability depends on accurate identity context and correct use of logs at every relevant boundary.
  • Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.

Evaluation checklist

  • Are the human, agent, host, tool, credential, and target identities distinct?
  • Does each tool call bind delegated authority to one resource, action, audience, and time limit?
  • Can a direct route, hidden credential path, or downstream permission bypass the recorded decision?

Sources and further reading

Keep learning

Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo