Skip to main content

Identifier, Account, Record, and Person

Separate a label, system account, directory record, and real person before joining identity across systems.

What is the distinction?

An identifier is a value used to refer to an entity in one namespace. An account is a system object that can receive authentication, authority, state, or settings. A directory record stores attributes. A person is the human outside those systems. These can correspond, but they are not interchangeable.

Why it matters

Email addresses change, names collide, accounts are reused or linked, and one person can have several accounts. Joining identity only by a display value can give one subject another subject's authority.

How it works

Use an issuer-scoped stable subject identifier for security joins. Record account lifecycle and provenance. Treat email, name, and group as attributes with their own authority and freshness. Link accounts only through an explicit verified process.

Example

Two identity providers both issue alex@example.com. The application keys users by issuer plus subject, not by email, and requires approved account linking before it combines records.

Failure and residual risk

Stable identifiers can still be reassigned by an upstream authority or copied into the wrong tenant. Account linking, migration, merge, and recovery are high-risk transitions. Residual risk includes source compromise and stale mappings.

Pomerium boundary

Pomerium uses identity-provider claims according to configuration and policy. Operators and applications own namespace selection, account linking, lifecycle, and object ownership. A matching email claim alone does not prove two accounts are the same subject.

Evaluation checklist

  • Which issuer and namespace make each identifier unique?
  • Which account or record can receive authority and lifecycle changes?
  • Which attributes can change or collide?
  • How are links, merges, migrations, and recovery verified?
  • Does the application preserve issuer-scoped subject identity?

Sources and further reading

Keep learning

Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term
Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo