Skip to main content

Topic index

Authorization and Policy

Learn how policy decides who can do what, under which conditions, and for how long.

Topic index

Understand this domain

Pomerium coverage

Pomerium route and inherited policy can use identity-provider claims, device identity, request facts, and external records. Pomerium Policy Language defines reusable criteria. The Proxy and Authorization services enforce the route decision before approved traffic reaches the upstream.

Limits

  • A correct policy at the gateway does not replace authorization inside the application.
  • Frequent evaluation cannot correct false identity data or stale context.
  • A later denial cannot undo an action that already completed.

Primary sources

2 learning paths

Paths for this topic

21 related guides

Guides in this topic

50 related terms

Concepts in this topic

Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Agentic AccessAuthorization and Policy

Agentic Access Management (AAM)

Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.

Learn this term
Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term
Authorization and PolicyStandards and Protocols

Authorization Consent

Use consent to record a user's informed grant without treating it as proof that an action is safe or permitted.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Decision Log

Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Complete Mediation

Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.

Learn this term
Authorization and PolicyAgentic Access

Confused Deputy

Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.

Learn this term
Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term
Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Agentic AccessAuthorization and Policy

Delegation Chain

Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.

Learn this term
Authorization and PolicySecurity Operations and Risk

Distributed Security State

Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.

Learn this term
Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Fail-Safe Defaults

Start from explicit denial and define safe behavior for missing policy, invalid input, dependency failure, and recovery.

Learn this term
Platform and Component SecurityAuthorization and Policy

Information Flow Control

Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.

Learn this term
Network and InfrastructureAuthorization and Policy

Kubernetes RBAC

Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.

Learn this term
Agentic AccessAuthorization and Policy

MCP Authorization

Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.

Learn this term
Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term
Platform and Component SecurityAuthorization and Policy

Multilevel Security

Enforce mandatory policy when one system processes information and users at different sensitivity and clearance levels.

Learn this term
Identity and AuthenticationAuthorization and Policy

OAuth 2.0

Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term
Authorization and Policy

Policy as Code

Treat access policy as a versioned, reviewed, tested, and observable decision artifact with controlled deployment.

Learn this term
Authorization and Policy

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

Learn this term
Agentic AccessAuthorization and Policy

Prompt Injection

Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Reference Monitor

Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.

Learn this term
Standards and ProtocolsAuthorization and Policy

Security Time and Freshness

Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.

Learn this term
Authorization and Policy

Separation of Duties

Split incompatible authority across independent people or roles so one actor cannot complete a sensitive process alone.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Separation of Privilege

Require independent conditions, authorities, or actors before the system permits a sensitive action.

Learn this term
Application and Service AccessStandards and Protocols

Token Exchange

Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.

Learn this term
Agentic AccessAuthorization and Policy

Tool Misuse

Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo