Authorization from request to enforcement
Model the subject, resource, action, context, policy, decision, enforcement, and application authorization chain.
Courses and learning paths
Use the Academy paths for security engineering decisions. Use the Pomerium Zero Fundamentals course for guided product work.
Guided product work
Pomerium Zero Fundamentals starts with the quickstart, then covers routes, policies, single sign-on, TCP and SSH connections, and custom identity providers.
Audience: For evaluators and operators who want guided practice with Pomerium Zero.
Outcome: Finish with a working protected route and a clear model for identity, policy, TLS, and upstream verification.
Academy curriculum
Model the subject, resource, action, context, policy, decision, enforcement, and application authorization chain.
Protect named resources through explicit verification, least privilege, complete mediation, and assumed breach.
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
Preserve identity, delegation, consent, policy, credential custody, approval, evidence, and revocation through agent actions.
Combine named application access, segmentation, workload identity, Kubernetes authorization, and multi-cloud trust.
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Control personal data, metadata, identifiers, correlation, telemetry, inference, release, retention, and deletion across access systems.
Design proofing, enrollment, authenticators, sessions, recovery, federation, and non-human identity as one system.
Govern, observe, detect, investigate, preserve evidence, contain, recover, and assure an identity-aware access system.
Design browser, API, service, SSH, TCP, and UDP access without losing identity or creating a direct bypass.
Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.
Build justified trust from small enforcement components, hardened runtimes, boot evidence, isolation, and controlled information flow.
Turn a protection need into boundaries, requirements, controls, evidence, failure behavior, and recovery.
Validate TLS, X.509, OAuth, OpenID Connect, JOSE, WebAuthn, metadata, token, and version boundaries.