Skip to main content

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

What is Policy Decision Point (PDP)?

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed. In NIST's zero trust model, the PDP is split into the Policy Engine and Policy Administrator. A Policy Information Point, not the PAP, supplies attributes and other context used in the decision.

Why it matters

A PDP gives the system a defined place to make an authorization decision from policy and current request facts. This supports consistent decisions across protected resources.

How it works

  1. A Policy Enforcement Point sends the requested action and available subject, resource, and environment attributes for evaluation.
  2. The PDP gets any required context from Policy Information Points and evaluates the applicable policy.
  3. The PDP returns a permit, deny, or other defined decision for the enforcement point to apply.

Example

Pomerium's Authorization service evaluates the requested route, user claims, device context, and configured policy, then returns a decision to the Proxy service.

Pomerium boundary

The Pomerium Authorization service is PDP-like because it evaluates route policy and session context for a request. Pomerium's documented architecture keeps this decision role separate from the Proxy service that handles and routes the request.

Limits and non-claims

  • A decision is only as accurate as the policy and attributes used in the evaluation.
  • Stale, missing, or incorrectly mapped context can produce the wrong result.
  • A PDP returns a decision, but a correctly placed enforcement point must apply it.

Evaluation checklist

  • Which subject, resource, action, context, and policy version enter each decision?
  • What decision follows missing input, stale data, conflict, timeout, cache use, or evaluator failure?
  • How does the enforcement point bind the returned decision to the request that was evaluated?

Sources and further reading

Keep learning

Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo