Skip to main content

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

What is Authorization?

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication. Firewalls can enforce some network authorization rules. Intrusion detection reports activity, and encryption protects data. Neither control replaces an authorization decision.

Why it matters

Authentication answers who the requester is. Authorization limits what that requester can do with the specific resource now.

How it works

  1. The requester asks to perform a defined operation on a resource.
  2. A decision point evaluates identity, policy, and current context for that operation.
  3. An enforcement point allows or denies the operation and records the result.

Example

An authenticated engineer can read staging logs. A production restart request is denied because the engineer does not have the required production role.

Pomerium boundary

For HTTP routes, Pomerium applies route and inherited policy to each protected request. For TCP and WebSocket routes, it validates access policy when the connection starts. The decision can use identity-provider claims, device identity, request data, and external context.

Limits and non-claims

  • A route decision cannot control a later application operation that the route does not identify.
  • Direct access to an upstream service can bypass Pomerium policy if the deployment permits it.
  • Authorization can fail when policy or context data is incorrect, stale, or too broad.

Evaluation checklist

  • Which subject requests which action on which exact resource?
  • Where do policy evaluation and enforcement occur, and do they use the same request context?
  • Can stale identity, broad routes, cached decisions, or missing object permission produce excess access?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo