Skip to main content

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

What is Authorization Drift?

Authorization drift is the gap that develops when effective access no longer matches intended access. It can result from stale sessions, accumulated scopes, changed roles, copied policy, or tools and resources that change without a new decision.

Why it matters

A valid old credential can retain access after the user role or task changes. Broad permissions can also become normal when no current workflow needs them.

How it works

  1. A system grants access from identity, scope, and policy at one point in time.
  2. Identity, policy, tools, or resource state changes while the old grant remains effective.
  3. Per-request checks, short-lived credentials, scope minimization, revocation, and access review bring effective access back to intended access.

Example

An engineer leaves the production team, but a long-lived agent credential still has production write scope. The agent can continue to deploy until the token expires or the resource rejects it.

Pomerium boundary

Pomerium evaluates configured identity and context policy on each protected HTTP request. This can reduce stale session trust on that path, but it does not repair direct upstream permissions or incorrect directory data.

Limits and non-claims

  • Authorization drift is a descriptive term, not a formal NIST or Model Context Protocol control.
  • Per-request evaluation cannot infer the organization's intended access model.
  • Control also needs identity lifecycle, credential revocation, policy review, and narrow scopes.

Evaluation checklist

  • What is the intended permission set, and which policies, groups, caches, exceptions, and application grants create the effective set?
  • Which lifecycle or deployment event can leave stale or excess access?
  • Can the operator detect the difference, revoke it, and prove the new effective state?

Sources and further reading

Keep learning

Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo