Three information forms
An attribute is a property associated with an entity in a source system, such as a directory group or department. A claim is a statement about a subject, often selected and formatted for a transaction. An assertion is a protected set of claims issued for a relying party. Protocols use specific forms, such as an OpenID Connect ID Token or a SAML assertion.
Provenance and meaning
Record where each attribute originates, who can change it, what it means, and how fresh it is. The issuer decides which claims to release. The relying party must interpret them only within the issuer, audience, schema, assurance, and time context.
Validation and use
Validate the assertion before trusting claims. Check issuer, audience, signature, time, and protocol-specific request binding. Use stable issuer and subject identifiers for account mapping. Do not use a display name or email address as a global identity key unless the system explicitly guarantees the required uniqueness and lifecycle.
Failure and residual risk
A correctly signed assertion can contain an inaccurate or stale source attribute. Two issuers can use the same subject string for different people. Excess claims increase privacy and authorization exposure. A caller-supplied header can look like a claim without being a verified assertion.
Pomerium boundary
Pomerium consumes claims from the configured identity provider and can send a signed identity assertion to an upstream. The upstream must validate the Pomerium assertion before trusting it. The application decides which verified claims are suitable for its permissions.
Evaluation checklist
- What source owns each attribute, and who can change it?
- Which issuer, subject, audience, and schema give the claim meaning?
- Is the assertion validated before any claim is used?
- Is freshness suitable for the access decision?
- Are only necessary claims released, logged, and forwarded?
