What is Policy Enforcement Point (PEP)?
A Policy Enforcement Point guards a resource and enforces the decision returned by a PDP. It permits, denies, or ends access at the enforcement location. The PDP evaluates policy and context. The PAP manages policy and does not evaluate each request. Pomerium can act as a PEP because it intercepts protected requests and enforces authorization before forwarding approved traffic.
Why it matters
An authorization decision has no effect until a control enforces it on the resource path. A PEP gives each protected request a clear permit or deny boundary.
How it works
- The PEP intercepts a request before it reaches the protected resource.
- It sends the request facts to a PDP or uses a valid decision that the PDP returned.
- It permits, denies, or ends access as directed and records the enforcement result.
Example
The Pomerium Proxy service receives a request for Grafana, gets a deny decision from the Authorization service, and does not forward the request upstream.
Pomerium boundary
For HTTP routes, Pomerium's Proxy and Authorization services form an enforcement path. The Proxy receives the request, the Authorization service evaluates policy, and the Proxy forwards only an approved request to the upstream service.
Limits and non-claims
- A PEP protects only traffic that cannot bypass its enforcement path.
- It cannot repair missing authorization inside the upstream application.
- Incorrect identity, route, or context data can make a correctly enforced decision unsafe.
Evaluation checklist
- Does the enforcement point intercept every path to the protected resource?
- How does it bind the authenticated request, policy decision, and final action?
- What happens during decision-service failure, stale policy, retry, or direct target access?
