Authorization from request to enforcement
Model the subject, resource, action, context, policy, decision, enforcement, and application authorization chain.
Topic index
Learn how policy decides who can do what, under which conditions, and for how long.
Topic index
Pomerium route and inherited policy can use identity-provider claims, device identity, request facts, and external records. Pomerium Policy Language defines reusable criteria. The Proxy and Authorization services enforce the route decision before approved traffic reaches the upstream.
2 learning paths
Model the subject, resource, action, context, policy, decision, enforcement, and application authorization chain.
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
21 related guides
Join authentication, authorization, proxy, and application evidence without confusing one event for another.
Compare owner-controlled, centrally mandated, role-based, and attribute-based authorization for one resource.
Compare central and local authorization while preserving complete enforcement, current context, and safe failure behavior.
Preserve subject, actor, audience, action, and authority limits when a service or agent acts for another principal.
Present the real target, arguments, authority, effect, and uncertainty so human approval gates a concrete agent action.
Protect API inventory, clients, routes, versions, objects, actions, credentials, quotas, and evidence with explicit owners.
Define labels, allowed flows, trusted transformations, release policy, evidence, and residual channels across an application and its data systems.
Separate OAuth scopes, roles, entitlements, consent, and application permissions before a resource server authorizes an action.
Assign owners and review, approve, deploy, observe, expire, and retire access policy with evidence and rollback.
Turn one access protection need into a precise state model, analyze adverse transitions, and connect the result to deployed evidence.
Review, test, deploy, attest, observe, and reconcile access configuration without allowing hidden runtime drift.
Grant short-lived and emergency authority with explicit scope, expiry, approval, monitoring, revocation, and review.
Move access policy from protection need through review, testing, staged deployment, observation, rollback, and retirement.
Place policy administration, information, decision, enforcement, distribution, and evidence components in one access system.
Trace authentication, gateway route authorization, and application permission as separate decisions with separate evidence.
Verify object, property, action, workflow, tenant, and administrative authorization with a systematic identity and state matrix.
Build deterministic authorization tests for allow, deny, boundaries, conflicts, failures, stale context, and bypass paths.
Trace one protected request, find trust boundaries and bypass paths, and test which access decisions belong at the gateway and application.
Trace Kubernetes API transport, authentication, authorization, admission, persistence, and audit for human and workload requests.
Trace one agent action from human intent through agent, client, server, tool, credential, target resource, and evidence.
Derive testable security objectives, requirements, invariants, controls, and evidence for one protected action.
50 related terms
Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.
Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.
Evaluate subject, resource, action, and environment attributes with explicit provenance, freshness, and policy behavior.
Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.
Use consent to record a user's informed grant without treating it as proof that an action is safe or permitted.
Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.
Authorization drift is the gap that develops when effective access no longer matches intended access.
Model each decision with a subject, resource, action, context, policy, and evidence instead of a user role alone.
A capability is an unforgeable reference that carries authority to perform defined operations on a resource.
Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.
Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.
Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.
Deny unmatched and indeterminate requests, then add explicit narrow grants with tested conflict and failure behavior.
Delegation gives an actor limited authority to act for another principal, called the subject.
Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.
Device posture is the current security state of a device.
Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.
Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.
Start from explicit denial and define safe behavior for missing policy, invalid input, dependency failure, and recovery.
Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.
Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.
Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.
Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.
Enforce mandatory policy when one system processes information and users at different sensitivity and clearance levels.
Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.
An OAuth resource indicator identifies the protected resource for which a client requests an access token.
Authorize every application action against the exact object instead of trusting route access, a role, or an object ID.
Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.
In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.
In an XACML-style access control system, the Policy Administration Point creates and manages policy. It does not supply live request context to the PDP.
Treat access policy as a versioned, reviewed, tested, and observable decision artifact with controlled deployment.
Policy combining defines how allow, deny, not-applicable, indeterminate, inherited, and local results become one decision.
A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.
A Policy Enforcement Point guards a resource and enforces the decision returned by a PDP. It permits, denies, or ends access at the enforcement location.
Limit authority by resource, action, context, and time, then remove access when the assigned function ends.
PAM is the set of controls used to protect, monitor, and audit privileged accounts and privileged sessions.
Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.
Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.
Derive permission from typed relationships between subjects, groups, resources, and organizations in an authorization graph.
Assign permissions to reviewed job or system roles, then assign subjects to roles with constraints and lifecycle controls.
Separate the rule that states allowed behavior from the components that decide, enforce, and record it.
Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.
Split incompatible authority across independent people or roles so one actor cannot complete a sensitive process alone.
Require independent conditions, authorities, or actors before the system permits a sensitive action.
Find authorization decisions that outlive the identity, relationship, policy, resource state, or request they evaluated.
Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.
Accept a token only from a trusted issuer and only at the resource audience for which the token was issued.
Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.
Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.
A zero trust trust algorithm combines subject, resource, action, context, policy, and confidence into an access decision.