Skip to main content

Separation of Privilege

Require independent conditions, authorities, or actors before the system permits a sensitive action.

Protection objective

A sensitive action should not depend on one condition, credential, component, or person when one compromise could cause unacceptable harm. Require independent conditions or authorities so that one failure is insufficient.

The principle

Separation of privilege can require two people, two keys, two systems, or two independent facts. Multi-factor authentication is one example, but the principle also applies to approvals, deployment, key recovery, policy changes, and financial actions. Independence is the important property.

Design independent conditions

State the action and harm. Choose conditions controlled through different failure paths. Ensure one actor cannot silently satisfy both roles. Bind each approval to the exact operation, resource, parameters, and time. Record who approved and what was executed.

Failure and limits

Two checks that depend on the same account, device, administrator, or identity provider may fail together. Approval fatigue can turn a second actor into a rubber stamp. Separation adds delay and availability dependencies, so recovery needs its own controlled process.

Pomerium boundary

Pomerium can require multiple independent policy criteria for route access. A business action that needs dual approval must usually be enforced by the application because it owns the action and workflow state. Route access alone does not prove application approval.

Evaluation checklist

  • Is the sensitive action and unacceptable harm explicit?
  • Are the required conditions independent in control and failure mode?
  • Can one actor or compromised system satisfy all conditions?
  • Are approvals bound to the exact action and time?
  • Does recovery preserve separation or add a reviewed exception?

Sources and further reading

Keep learning

Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo