Skip to main content

Digital Identity Assurance Levels

Select and distinguish identity, authentication, and federation assurance levels for a digital service.

Three separate decisions

Identity Assurance Level (IAL) describes confidence in the identity-proofing and enrollment process. Authentication Assurance Level (AAL) describes confidence that the claimant controls authenticators bound to the subscriber account. Federation Assurance Level (FAL) describes protection of assertions that carry authentication and identity results between parties.

Select from impact

Choose each level from the harm caused by an incorrect identity, account takeover, or forged or replayed federation result. A service can need no proofed real-world identity but still require strong authentication. It can also require high identity confidence while receiving a weakly protected assertion, which leaves the complete transaction weak.

Keep the levels through the flow

Document which party performs proofing, which authenticator and verifier satisfy the selected AAL, and which federation protocol and protections satisfy the FAL. Preserve the result and relevant method in a form that the relying party can evaluate. Reassess when the transaction or impact changes.

Failure and residual risk

An assurance label can become empty when the deployment does not meet every requirement or when recovery uses a weaker path. A high level in one part does not compensate for a weak account-linking, session, or authorization design. Organizations can also use terms that resemble NIST levels without applying the NIST requirements.

Pomerium boundary

Pomerium consumes the identity provider's federated result and creates its own access session. The operator must select and configure the provider, protocol, claims, and authentication behavior that meet the service need. Pomerium route policy is a later authorization decision, not another assurance level.

Evaluation checklist

  • Is IAL needed for the transaction, and who performs proofing?
  • Which authenticators and verifier controls support the required AAL?
  • How is the federated assertion protected and bound to the relying party?
  • Does recovery preserve the selected assurance?
  • Can the relying party verify the level and method it depends on?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo