Skip to main content

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

What is Continuous Verification?

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust. It can reevaluate identity, device state, route policy, and external context when a request is made or when relevant state changes. It does not require the user to complete MFA for every action. Pomerium enforces context-aware authorization on each proxied HTTP request.

Why it matters

Identity, device state, policy, and external risk can change after sign-in. A new decision can stop later access without waiting for the original session to end.

How it works

  1. The system authenticates the requester and establishes the initial session context.
  2. For each protected request, it reads the current available context and evaluates the applicable policy again.
  3. It denies and records a later request when the context no longer meets policy.

Example

A laptop loses its approved device status while its user session is still active. The next protected request is denied because current device context no longer meets policy.

Pomerium boundary

Pomerium reevaluates identity-provider claims, device posture, location, and other configured context on every proxied HTTP request. It applies the current route or inherited policy to that request. For TCP and WebSocket connections, Pomerium validates access policy when the connection starts and does not terminate an established connection if policy later becomes invalid.

Limits and non-claims

  • A per-request check does not inspect an idle session or every action inside a long-lived connection.
  • The result can use stale facts when an identity or context source has not updated yet.
  • Continuous verification does not repair an incorrect policy or a vulnerable upstream service.

Evaluation checklist

  • Which requests and long-lived connections receive a new decision after sign-in?
  • Which identity, device, resource, action, policy, and risk facts are reevaluated?
  • How fresh is each fact, and what happens when its source is unavailable?
  • How long can a revoked subject or changed policy still produce an accepted action?
  • Which direct path or application session can outlive the gateway decision?

Sources and further reading

Keep learning

Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo