Skip to main content

Topic index

Zero Trust

Learn the principles, trust boundaries, and request checks that define a zero trust architecture.

Topic index

Understand this domain

Pomerium coverage

Pomerium attaches identity-aware policy to named routes. It evaluates each protected HTTP request. It validates TCP and WebSocket policy when the connection starts. The upstream service still owns its resource and action permissions.

Limits

  • Zero trust does not replace endpoint, application, data, or network security.
  • A policy decision is only as reliable as its identity, context, and enforcement path.
  • An established TCP or WebSocket connection does not end only because policy later changes.

Primary sources

1 learning path

Paths for this topic

13 related guides

Guides in this topic

19 related terms

Concepts in this topic

Agentic AccessAuthorization and Policy

Agentic Access Management (AAM)

Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.

Learn this term
Zero TrustSecurity Engineering Foundations

Assume Breach

Design as if one identity, credential, workload, route, or control will fail, then limit movement and impact.

Learn this term
Application and Service AccessNetwork and Infrastructure

Clientless Zero Trust Access

Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.

Learn this term
Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term
Agentic AccessSecurity Operations and Risk

Hidden Trust Boundary

A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.

Learn this term
Zero TrustNetwork and Infrastructure

Implicit Trust Zone

An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.

Learn this term
Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term
Application and Service AccessZero Trust

Named Resource Access

Grant access to one named application or service without extending general reachability to its network or neighboring systems.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo