User decision
Consent records that a user approved a stated client, resource, and set of delegated actions. Useful consent is specific, informed, current, revocable, and bound to the actual client and resource. It answers what the user chose. It does not prove that the administrator permits the action or that the resource server should honor it.
Three independent gates
The authorization server verifies the client and requested delegation. The user grants or refuses the presented access. The resource owner or administrator policy limits what can be granted. The resource server then enforces permission on the exact resource and action. Each gate can deny a request that passed the others.
Preserve binding
Bind consent to the user, client identifier, redirect destination, target resource or audience, scope, time, and policy context. Show changes before approval. Require fresh consent when a new client, resource, or material capability is added. Give the user and administrator a way to inspect and revoke grants.
Failure and residual risk
Broad or misleading prompts create approval fatigue. A proxy can request authority for a different resource, reuse another client's consent, or pass a token to the wrong service. Consent can remain after the user's role, the client, or the resource policy changes. A valid grant can still be abused by a compromised client.
Pomerium boundary
Pomerium authenticates users and enforces route policy. It does not turn an upstream application's OAuth or agent consent into application permission. The authorization server and resource server must bind and enforce delegated authority for their own clients, resources, and actions.
Evaluation checklist
- Does the user see the real client, resource, and material actions?
- Is consent limited by administrator and resource-owner policy?
- Is the grant bound to the exact client and resource audience?
- Do changed authority and revoked consent stop future use within a measured time?
- Can a resource server reject a valid token that lacks local permission?
