What is Policy Administration Point (PAP)?
In an XACML-style access control system, the Policy Administration Point creates and manages policy. It does not supply live request context to the PDP. A Policy Information Point supplies attributes. NIST SP 800-207 uses a different term, Policy Administrator, for the component that establishes or closes the communication path after the Policy Engine decides. State which model applies before mapping Pomerium components to it.
Why it matters
Authorization policy needs a controlled source, clear ownership, and a safe publication process. Separating policy administration from runtime evaluation also makes each responsibility easier to review.
How it works
- An authorized administrator creates, reviews, changes, or removes policy at the Policy Administration Point.
- The system validates and publishes the policy in a form that the Policy Decision Point can evaluate.
- Change control, version records, and review processes track which policy was active and who changed it.
Example
A security administrator creates a policy that allows the production operations group to reach a deployment service, reviews the change, and publishes it to the authorization system.
Pomerium boundary
Pomerium Core configuration and the Pomerium policy management interfaces perform PAP-like work because administrators define and apply policy there. This is an XACML-style comparison. It is not the NIST SP 800-207 Policy Administrator component.
Limits and non-claims
- PAP and Policy Administrator name different roles in different access-control models.
- A PAP manages policy; it does not supply live subject, resource, or environment attributes for each decision.
- A controlled publication process cannot make an incorrect or overly broad policy safe.
Evaluation checklist
- Who can create, approve, test, version, publish, and retire policy?
- How do decision points verify the integrity, identity, and freshness of a policy bundle?
- Can a compromised administrator, rollback, partial distribution, or outage leave unintended access?
