Distinct roles
An actor is the person, organization, service, or adversary that causes an action. A subject is the active process or session that requests access. A principal is the entity whose authority the system uses for the decision. A digital identity is a set of attributes about an entity in a given context. An account is a local record that a system uses to manage access and state.
One request can involve several of these. A person can use a browser subject that acts for a user principal. A service can then call another service with its own identity while retaining evidence of the originating user.
Preserve the chain
For each hop, record who initiated the action, which subject sent the request, whose authority was used, and which service acted. Do not replace the originating actor with the last service identity. Do not treat an email address or account name as proof of a person without the relevant authentication and binding.
Authorization consequences
Policy must select the correct principal and context. A service account can authenticate correctly but have authority that is too broad for the originating user. Impersonation, delegation, and ordinary service-to-service calls have different evidence and policy requirements.
Failure and residual risk
Identity propagation can lose the actor, accept a caller-supplied header, confuse two issuers, or map several identities to one account. Logs that show only the final service make investigation and authorization review incomplete.
Pomerium boundary
Pomerium can authenticate a user session and send a signed identity assertion to an upstream. The upstream must validate that assertion and decide how it maps to its own accounts and permissions. Calls made after that point need a separate design for service identity, delegation, and actor evidence.
Evaluation checklist
- Can you name the actor, subject, and principal at every hop?
- Is each identity bound to a trusted issuer and intended audience?
- Does delegation preserve the originating actor and delegated authority?
- Can a caller inject or replace the identity signal?
- Do audit records preserve both user and service identities where needed?
