Skip to main content

Policy Administration Point (PAP)

In an XACML-style access control system, the Policy Administration Point creates and manages policy. It does not supply live request context to the PDP.

What is Policy Administration Point (PAP)?

In an XACML-style access control system, the Policy Administration Point creates and manages policy. It does not supply live request context to the PDP. A Policy Information Point supplies attributes. NIST SP 800-207 uses a different term, Policy Administrator, for the component that establishes or closes the communication path after the Policy Engine decides. State which model applies before mapping Pomerium components to it.

Why it matters

Authorization policy needs a controlled source, clear ownership, and a safe publication process. Separating policy administration from runtime evaluation also makes each responsibility easier to review.

How it works

  1. An authorized administrator creates, reviews, changes, or removes policy at the Policy Administration Point.
  2. The system validates and publishes the policy in a form that the Policy Decision Point can evaluate.
  3. Change control, version records, and review processes track which policy was active and who changed it.

Example

A security administrator creates a policy that allows the production operations group to reach a deployment service, reviews the change, and publishes it to the authorization system.

Pomerium boundary

Pomerium Core configuration and the Pomerium policy management interfaces perform PAP-like work because administrators define and apply policy there. This is an XACML-style comparison. It is not the NIST SP 800-207 Policy Administrator component.

Limits and non-claims

  • PAP and Policy Administrator name different roles in different access-control models.
  • A PAP manages policy; it does not supply live subject, resource, or environment attributes for each decision.
  • A controlled publication process cannot make an incorrect or overly broad policy safe.

Evaluation checklist

  • Who can create, approve, test, version, publish, and retire policy?
  • How do decision points verify the integrity, identity, and freshness of a policy bundle?
  • Can a compromised administrator, rollback, partial distribution, or outage leave unintended access?

Sources and further reading

Keep learning

Authorization and Policy

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo