Control objective
A capability is an unforgeable reference that designates a resource and conveys authority to perform defined operations. Possession, not a separate lookup by global subject name, is the basis for use. Capability security aims to make authority explicit, delegable, and attenuable.
Delegation and attenuation
A holder can pass a capability when delegation is allowed. Attenuation derives a capability with less authority, such as read-only access, one object, a short lifetime, or one downstream service. The recipient must not be able to amplify it.
Revocation and evidence
Revocation can use expiry, indirection, a revocable proxy, versioned resource state, or replacement of a reference. Direct distributed capabilities can be difficult to enumerate and revoke. Record issuance, delegation, attenuation, use, and invalidation without exposing the capability value.
Failure and residual risk
A bearer capability can be copied and replayed by any holder. Ambient access to a capability store defeats explicit authority. Delegation chains can lose the original actor. Revocation may be slow or incomplete. A capability for a route may still be broader than an application object action.
Pomerium boundary
Pomerium normally evaluates identity and context policy rather than acting as a general object-capability system. Tokens or credentials used on Pomerium routes can carry bounded authority, but operators must not assume that possession alone preserves user identity, delegation, or application permission.
Evaluation checklist
- Which resource and operations does the capability designate?
- Can a holder delegate or attenuate it without amplifying authority?
- Is it bound to a holder, audience, time, or channel when required?
- How are copies, delegation, revocation, and last use observed?
- Does downstream authorization remain narrower than route possession?
