Skip to main content

Policy Enforcement Point (PEP)

A Policy Enforcement Point guards a resource and enforces the decision returned by a PDP. It permits, denies, or ends access at the enforcement location.

What is Policy Enforcement Point (PEP)?

A Policy Enforcement Point guards a resource and enforces the decision returned by a PDP. It permits, denies, or ends access at the enforcement location. The PDP evaluates policy and context. The PAP manages policy and does not evaluate each request. Pomerium can act as a PEP because it intercepts protected requests and enforces authorization before forwarding approved traffic.

Why it matters

An authorization decision has no effect until a control enforces it on the resource path. A PEP gives each protected request a clear permit or deny boundary.

How it works

  1. The PEP intercepts a request before it reaches the protected resource.
  2. It sends the request facts to a PDP or uses a valid decision that the PDP returned.
  3. It permits, denies, or ends access as directed and records the enforcement result.

Example

The Pomerium Proxy service receives a request for Grafana, gets a deny decision from the Authorization service, and does not forward the request upstream.

Pomerium boundary

For HTTP routes, Pomerium's Proxy and Authorization services form an enforcement path. The Proxy receives the request, the Authorization service evaluates policy, and the Proxy forwards only an approved request to the upstream service.

Limits and non-claims

  • A PEP protects only traffic that cannot bypass its enforcement path.
  • It cannot repair missing authorization inside the upstream application.
  • Incorrect identity, route, or context data can make a correctly enforced decision unsafe.

Evaluation checklist

  • Does the enforcement point intercept every path to the protected resource?
  • How does it bind the authenticated request, policy decision, and final action?
  • What happens during decision-service failure, stale policy, retry, or direct target access?

Sources and further reading

Keep learning

Authorization and Policy

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo