Skip to main content

Complete Mediation

Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.

Protection objective

Every relevant access to a protected resource must receive the required authorization check. The check must use current enough policy and context for the security objective. A successful check on one path or at one time does not authorize other paths or later actions automatically.

The principle

Complete mediation means the system validates each access against the policy that applies to that access. The design must account for alternate routes, direct network access, cached decisions, long-lived sessions, reused capabilities, internal calls, and application operations after gateway entry.

Apply it to a request

Enumerate all paths to the resource. Mark the enforcement point on each path. State when a prior decision can be reused, which facts it binds, how long it remains valid, and what event revokes it. Test direct access and stale-context cases.

Failure and limits

Checking every HTTP request does not recheck every action inside the application. A long-lived TCP or WebSocket connection can outlive a policy change. Strong mediation can also depend on identity, policy, or context services whose failure behavior must be designed.

Pomerium boundary

Pomerium evaluates configured HTTP access at the protected route. Its documentation states that TCP and WebSocket policy applies when the connection starts, so later policy change does not terminate an established connection by itself. Applications must mediate their own object and action permissions.

Evaluation checklist

  • Have all public, private, internal, and administrative paths been enumerated?
  • Does each path cross the intended enforcement point?
  • Is decision reuse bound to the correct subject, resource, action, and context?
  • Is the maximum stale interval known and tested?
  • Which application actions need a separate authorization check?

Sources and further reading

Keep learning

Security Engineering FoundationsAuthorization and Policy

Reference Monitor

Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Agentic AccessSecurity Operations and Risk

Hidden Trust Boundary

A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo