What is Authorization?
Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication. Firewalls can enforce some network authorization rules. Intrusion detection reports activity, and encryption protects data. Neither control replaces an authorization decision.
Why it matters
Authentication answers who the requester is. Authorization limits what that requester can do with the specific resource now.
How it works
- The requester asks to perform a defined operation on a resource.
- A decision point evaluates identity, policy, and current context for that operation.
- An enforcement point allows or denies the operation and records the result.
Example
An authenticated engineer can read staging logs. A production restart request is denied because the engineer does not have the required production role.
Pomerium boundary
For HTTP routes, Pomerium applies route and inherited policy to each protected request. For TCP and WebSocket routes, it validates access policy when the connection starts. The decision can use identity-provider claims, device identity, request data, and external context.
Limits and non-claims
- A route decision cannot control a later application operation that the route does not identify.
- Direct access to an upstream service can bypass Pomerium policy if the deployment permits it.
- Authorization can fail when policy or context data is incorrect, stale, or too broad.
Evaluation checklist
- Which subject requests which action on which exact resource?
- Where do policy evaluation and enforcement occur, and do they use the same request context?
- Can stale identity, broad routes, cached decisions, or missing object permission produce excess access?
