The lifecycle stage
Identity proofing establishes evidence about a person or entity before an account receives a verified identity. Enrollment records the result and binds one or more authenticators to the subscriber account. Authentication later proves control of those bound authenticators. It does not repeat proofing.
Core proofing steps
Resolve the claimed identity to a unique subject in the required population. Validate evidence as genuine and accurate. Verify that the applicant is the rightful subject of the evidence. Record the proofing result, assurance level, exceptions, and enrollment event. Protect collected evidence and remove it when retention is no longer justified.
Choose assurance from risk
Not every account needs the same proofing. Select the process from the harm caused by a wrong identity binding. Consider remote and attended methods, evidence strength, authoritative sources, fraud checks, accessibility, privacy, and redress for failed or disputed results.
Failure and residual risk
Valid evidence can belong to another person. A strong authentication ceremony can then protect the wrong binding. Help-desk enrollment, imported directories, duplicate records, name changes, and account linking can undercut the initial process. Proofing also collects sensitive data that creates privacy and breach risk.
Pomerium boundary
Pomerium relies on the configured identity provider's authentication result. It does not perform the identity provider's proofing and enrollment process. Route policy can use released identity claims, but the operator must know how the provider established and maintains them.
Evaluation checklist
- What real-world identity must be resolved, and why?
- Which evidence is validated, and how is applicant ownership verified?
- What assurance level does the risk require?
- How are duplicate, disputed, changed, and terminated identities handled?
- What proofing data is retained, protected, and deleted?
