Skip to main content

Capability-Based Security

A capability is an unforgeable reference that carries authority to perform defined operations on a resource.

Control objective

A capability is an unforgeable reference that designates a resource and conveys authority to perform defined operations. Possession, not a separate lookup by global subject name, is the basis for use. Capability security aims to make authority explicit, delegable, and attenuable.

Delegation and attenuation

A holder can pass a capability when delegation is allowed. Attenuation derives a capability with less authority, such as read-only access, one object, a short lifetime, or one downstream service. The recipient must not be able to amplify it.

Revocation and evidence

Revocation can use expiry, indirection, a revocable proxy, versioned resource state, or replacement of a reference. Direct distributed capabilities can be difficult to enumerate and revoke. Record issuance, delegation, attenuation, use, and invalidation without exposing the capability value.

Failure and residual risk

A bearer capability can be copied and replayed by any holder. Ambient access to a capability store defeats explicit authority. Delegation chains can lose the original actor. Revocation may be slow or incomplete. A capability for a route may still be broader than an application object action.

Pomerium boundary

Pomerium normally evaluates identity and context policy rather than acting as a general object-capability system. Tokens or credentials used on Pomerium routes can carry bounded authority, but operators must not assume that possession alone preserves user identity, delegation, or application permission.

Evaluation checklist

  • Which resource and operations does the capability designate?
  • Can a holder delegate or attenuate it without amplifying authority?
  • Is it bound to a holder, audience, time, or channel when required?
  • How are copies, delegation, revocation, and last use observed?
  • Does downstream authorization remain narrower than route possession?

Sources and further reading

Keep learning

Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo