Skip to main content

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

What is Layer-7 Enforcement?

Layer 7 enforcement makes access decisions from application-protocol facts, such as the HTTP host, route, method, Model Context Protocol tool name, and verified identity context. It is more specific than a network rule that sees only an address, port, or connection.

Why it matters

One permitted network connection can carry many application actions. Application-aware policy can allow a low-risk operation and deny a high-risk operation on the same service.

How it works

  1. A proxy or gateway receives and understands the application request.
  2. It combines the operation with verified identity and current context.
  3. It enforces policy before it forwards the request to the protected service.

Example

Two tool calls use the same HTTPS endpoint. Policy allows list_incidents but denies delete_incident for the same caller.

Pomerium boundary

Pomerium operates as an identity-aware application proxy and checks policy before it routes a protected request. Its Model Context Protocol tool criterion adds tool-name policy for that traffic.

Limits and non-claims

  • The enforcement point needs usable application semantics. Opaque end-to-end payloads limit what it can decide.
  • Layer 7 access policy does not replace input validation, safe tool code, or a web application firewall.
  • Pomerium documents non-HTTP TCP authorization as per session.
  • Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.

Evaluation checklist

  • Which application protocol, message, resource, and action does the enforcement point understand?
  • Are authority, path, method, headers, and message fields normalized before policy evaluation?
  • Can encryption, tunneling, parser disagreement, or a direct endpoint bypass layer 7 checks?

Sources and further reading

Keep learning

Network and InfrastructureStandards and Protocols

OSI Layers

The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo