Skip to main content

Actor, Subject, and Principal

Separate the real-world actor, active subject, represented principal, digital identity, and account.

Distinct roles

An actor is the person, organization, service, or adversary that causes an action. A subject is the active process or session that requests access. A principal is the entity whose authority the system uses for the decision. A digital identity is a set of attributes about an entity in a given context. An account is a local record that a system uses to manage access and state.

One request can involve several of these. A person can use a browser subject that acts for a user principal. A service can then call another service with its own identity while retaining evidence of the originating user.

Preserve the chain

For each hop, record who initiated the action, which subject sent the request, whose authority was used, and which service acted. Do not replace the originating actor with the last service identity. Do not treat an email address or account name as proof of a person without the relevant authentication and binding.

Authorization consequences

Policy must select the correct principal and context. A service account can authenticate correctly but have authority that is too broad for the originating user. Impersonation, delegation, and ordinary service-to-service calls have different evidence and policy requirements.

Failure and residual risk

Identity propagation can lose the actor, accept a caller-supplied header, confuse two issuers, or map several identities to one account. Logs that show only the final service make investigation and authorization review incomplete.

Pomerium boundary

Pomerium can authenticate a user session and send a signed identity assertion to an upstream. The upstream must validate that assertion and decide how it maps to its own accounts and permissions. Calls made after that point need a separate design for service identity, delegation, and actor evidence.

Evaluation checklist

  • Can you name the actor, subject, and principal at every hop?
  • Is each identity bound to a trusted issuer and intended audience?
  • Does delegation preserve the originating actor and delegated authority?
  • Can a caller inject or replace the identity signal?
  • Do audit records preserve both user and service identities where needed?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo