Skip to main content

Object and Action Authorization

Authorize every application action against the exact object instead of trusting route access, a role, or an object ID.

Two dimensions

Object authorization asks whether this subject may act on this exact record, tenant, document, project, or account. Action authorization asks whether the subject may perform this operation, such as read, update, approve, export, or delete. A correct check binds both dimensions to the current request.

Enforce near the object

The application usually owns the object identifiers, relationships, state, and business actions. Resolve the requested object through an authorized tenant or parent. Derive the action from the server-side operation. Evaluate the current subject and trusted context. Do not accept a client-provided owner, role, tenant, or permission result as authority.

Cover every path

Apply the same check to list, detail, search, batch, export, background, administrative, and indirect object paths. Check before disclosing whether a protected object exists. For state-changing operations, bind the decision to the object version or recheck before the commit.

Failure and residual risk

Opaque identifiers do not provide authorization. A route-level allow can expose every object behind that route. A user can change an object ID, call an administrative function directly, exploit a bulk endpoint, or race a permission change after the check. Cached relationship data can preserve access after removal.

Pomerium boundary

Pomerium can authenticate the requester, enforce route policy, and pass verified identity context to an upstream. The upstream application must authorize each of its objects and actions. A Pomerium route allow is not permission to read every record or invoke every function in that application.

Evaluation checklist

  • Does every object lookup include the authorized tenant, owner, or relationship boundary?
  • Does every operation map to a server-defined action?
  • Do list, batch, export, and administrative paths use the same authorization model?
  • Are negative tests run with another user's identifier and a lower-privilege action?
  • Can a state or permission change invalidate the decision before the action completes?

Sources and further reading

Keep learning

Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Complete Mediation

Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo