Skip to main content

Identity and Access Management (IAM)

Identity and access management uses governance, processes, and technology to establish digital identities and control their access to resources.

What is Identity and Access Management (IAM)?

Identity and access management (IAM) is the set of governance rules, processes, and technologies used to establish digital identities and control their access to resources. It covers account and authenticator lifecycle, authentication, authorization, provisioning, access review, revocation, and audit. IAM applies to people, services, workloads, and devices. Authentication establishes confidence in an identity; authorization decides what that identity can do.

Why it matters

An organization must change access when a person joins, changes roles, or leaves, and when a workload or device changes state. A managed identity lifecycle reduces stale accounts, excessive access, and weak audit records.

How it works

  1. Establish an identity record, bind approved authenticators, and maintain the attributes needed for access decisions.
  2. Authenticate the principal, then evaluate authorization policy for the requested resource and action.
  3. Update, review, suspend, and remove access as identity state changes, and retain useful audit records.

Example

An engineer moves from the support team to the platform team. The identity system removes the old group, adds the new group, and the access layer uses the current group data for the next request.

Pomerium boundary

Pomerium is an identity-aware access proxy, not a complete IAM system or identity provider. It authenticates users through an OIDC-compatible identity provider and applies identity and context policy to protected routes. The external identity system remains responsible for account, group, and authenticator lifecycle.

Limits and non-claims

  • IAM does not make identity data accurate or current without a controlled lifecycle and trusted data sources.
  • Successful authentication does not authorize every resource or action.
  • A central identity service can affect many applications, so its administration, recovery, and availability need strong controls.

Evaluation checklist

  • Which people, services, workloads, devices, agents, accounts, and authenticators are in scope?
  • How do authentication, authorization, provisioning, sessions, and evidence protect each resource action?
  • Do joiner, mover, leaver, recovery, and emergency processes remove obsolete authority?

Sources and further reading

Keep learning

Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term
Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo