What is Context-Aware Proxy?
A context-aware proxy is a policy enforcement point placed between a requester and a protected service. It uses identity, device, request, and external context to allow or deny access, then forwards only approved traffic. It can complement firewalls, VPNs, and detection tools, but it does not have to combine those tools into one product. Identity-aware access identifies the requester and makes a policy decision from verified identity attributes instead of network location alone. Context-aware access adds device, request, and external facts to that identity decision.
Why it matters
Network location alone gives little information about the current requester and device. A context-aware proxy can make a narrow decision at the protected service path.
How it works
- The proxy receives a request for a configured protected route.
- It authenticates the requester as required and gathers identity, device, request, and external context.
- It evaluates policy, forwards an approved request to the service, or denies the request and records the result.
Example
An employee can open an internal source-control service only when the employee is in the engineering group and uses an approved device.
Pomerium boundary
Pomerium is an identity-aware proxy and policy enforcement point. A Pomerium route maps an external URL to an upstream service and applies context-aware authorization before it forwards the request.
Limits and non-claims
- The proxy cannot protect a service that accepts traffic around the proxy.
- A decision can be wrong when identity, device, or external context is stale or incorrect.
- Proxy policy does not replace endpoint security or authorization for operations inside the application.
Evaluation checklist
- Which identity, device, route, time, and risk signals are authoritative and fresh?
- Does policy evaluate the current protected resource and action at the required frequency?
- What happens when context is stale, a provider fails, or a direct upstream path exists?
