Control objective
Shared responsibility assigns accountable owners across the user, identity provider, device, network, Pomerium deployment, cloud, workload, application, evidence, and recovery path. Shared does not mean ambiguous or duplicated.
Responsibility model
For each protection claim, name who defines requirements, implements the control, operates it, supplies inputs, reviews evidence, responds to failure, accepts residual risk, and verifies recovery. Record interfaces and escalation between owners.
Evidence
Use a control matrix tied to real resources and actions. Show configuration owner, identity authority, policy owner, enforcement owner, application authorization owner, log destination, containment authority, and recovery tester. Revisit it after system or organization change.
Failure and residual risk
Cloud or product responsibility diagrams can omit customer configuration and application action. Two teams can assume the other owns revocation or direct-path isolation. One owner can exist on paper and lack authority or evidence.
Pomerium boundary
Pomerium provides documented access functions. Operators own deployment, identity integration, policy intent, configuration, upstream isolation, application authorization, evidence retention, response, and recovery. Product capability does not transfer those decisions to Pomerium.
Evaluation checklist
- Who owns each requirement, input, policy, enforcement point, and target action?
- Who can change and who independently reviews the control?
- Who receives evidence and can contain failure?
- Who tests recovery and accepts residual risk?
- Do handoffs have explicit data, timing, and escalation contracts?
