What is the distinction?
An identifier is a value used to refer to an entity in one namespace. An account is a system object that can receive authentication, authority, state, or settings. A directory record stores attributes. A person is the human outside those systems. These can correspond, but they are not interchangeable.
Why it matters
Email addresses change, names collide, accounts are reused or linked, and one person can have several accounts. Joining identity only by a display value can give one subject another subject's authority.
How it works
Use an issuer-scoped stable subject identifier for security joins. Record account lifecycle and provenance. Treat email, name, and group as attributes with their own authority and freshness. Link accounts only through an explicit verified process.
Example
Two identity providers both issue alex@example.com. The application keys users by issuer plus subject, not by email, and requires approved account linking before it combines records.
Failure and residual risk
Stable identifiers can still be reassigned by an upstream authority or copied into the wrong tenant. Account linking, migration, merge, and recovery are high-risk transitions. Residual risk includes source compromise and stale mappings.
Pomerium boundary
Pomerium uses identity-provider claims according to configuration and policy. Operators and applications own namespace selection, account linking, lifecycle, and object ownership. A matching email claim alone does not prove two accounts are the same subject.
Evaluation checklist
- Which issuer and namespace make each identifier unique?
- Which account or record can receive authority and lifecycle changes?
- Which attributes can change or collide?
- How are links, merges, migrations, and recovery verified?
- Does the application preserve issuer-scoped subject identity?
