Skip to main content

Multilevel Security

Enforce mandatory policy when one system processes information and users at different sensitivity and clearance levels.

Several protection levels in one system

A multilevel secure system processes information with different sensitivity labels and serves subjects with different authorizations while enforcing one mandatory security policy. A data owner or ordinary user cannot override the central constraints.

The model is useful beyond government classification. Tenant, legal hold, export region, environment, and regulated-data boundaries can require centrally enforced non-discretionary policy, though not every such design is a formal MLS system.

Labels and dominance

Define labels with levels and compartments or another partial order. Define when one label dominates another and how labels combine. Bind subject authorization and object labels through creation, import, transformation, export, and deletion.

Confidentiality models commonly prevent a lower-authorized subject from reading higher data and prevent a higher subject from writing protected data to a lower object. Integrity models can reverse the ordering to prevent less trustworthy data from contaminating higher-integrity decisions. Real systems may need both.

Trusted operations and release

Some functions must downgrade, sanitize, relabel, aggregate, or bridge domains. Treat each as a trusted subject with narrow authority, explicit transformation, independent review where needed, and complete evidence. A cross-domain transfer should validate both data content and metadata.

Policy administration, label assignment, import, and recovery are part of the TCB. An ordinary owner must not be able to relabel an object to bypass the mandatory rule.

Failure and residual risk

Wrong labels, missing labels, broad trusted subjects, composition across services, and unmodeled outputs can break the policy. Aggregates and query results can reveal high-level facts. Covert channels can signal through shared resources even when direct information flow is blocked.

Strict policy can reduce usability and availability. Teams can create unapproved side systems when legitimate release is too slow. The design needs controlled declassification and operational paths, not only denial rules.

Pomerium boundary

Pomerium can enforce route policy with identity and context. It is not a general MLS kernel and does not attach mandatory labels to every application object or control later reads, writes, derivations, and releases. A route can represent one security domain, but the application must enforce object labels and trusted transformations within and across routes.

Evaluation checklist

  • What are the levels, compartments, dominance rule, and integrity or confidentiality objective?
  • Who assigns subject and object labels, and can an ordinary owner change them?
  • Which trusted subject can declassify, relabel, sanitize, or bridge domains?
  • Can query results, aggregates, metadata, logs, caches, recovery, or shared resources leak higher-level information?
  • Does the operational release path work well enough to prevent unsafe side systems and manual bypass?

Sources and further reading

Keep learning

Platform and Component SecurityAuthorization and Policy

Information Flow Control

Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.

Learn this term
Cryptography and Data Protection

Data Classification

Assign data sensitivity, criticality, ownership, use, sharing, retention, and recovery requirements that drive technical controls.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Platform and Component Security

Security Kernel

Understand the small privileged mechanism that implements a reference monitor and controls access to system resources.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo