Skip to main content

Identity Proofing and Enrollment

Resolve a claimed real-world identity, validate evidence, verify the applicant, and bind the result to an account.

The lifecycle stage

Identity proofing establishes evidence about a person or entity before an account receives a verified identity. Enrollment records the result and binds one or more authenticators to the subscriber account. Authentication later proves control of those bound authenticators. It does not repeat proofing.

Core proofing steps

Resolve the claimed identity to a unique subject in the required population. Validate evidence as genuine and accurate. Verify that the applicant is the rightful subject of the evidence. Record the proofing result, assurance level, exceptions, and enrollment event. Protect collected evidence and remove it when retention is no longer justified.

Choose assurance from risk

Not every account needs the same proofing. Select the process from the harm caused by a wrong identity binding. Consider remote and attended methods, evidence strength, authoritative sources, fraud checks, accessibility, privacy, and redress for failed or disputed results.

Failure and residual risk

Valid evidence can belong to another person. A strong authentication ceremony can then protect the wrong binding. Help-desk enrollment, imported directories, duplicate records, name changes, and account linking can undercut the initial process. Proofing also collects sensitive data that creates privacy and breach risk.

Pomerium boundary

Pomerium relies on the configured identity provider's authentication result. It does not perform the identity provider's proofing and enrollment process. Route policy can use released identity claims, but the operator must know how the provider established and maintains them.

Evaluation checklist

  • What real-world identity must be resolved, and why?
  • Which evidence is validated, and how is applicant ownership verified?
  • What assurance level does the risk require?
  • How are duplicate, disputed, changed, and terminated identities handled?
  • What proofing data is retained, protected, and deleted?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo