Repetition changes behavior
Habituation reduces attention to a repeated stimulus. Warning fatigue occurs when people receive too many low-value, unclear, or unactionable prompts and alerts. They learn that dismissal is the normal path. Attackers can exploit that learned response through push bombing, consent prompts, certificate warnings, approval queues, or noisy security alerts.
Measure the decision burden
Count prompts and alerts per person, role, task, and time. Record how often each requires a different action, contains enough context, represents real harm, and leads to useful response. Include repeated reauthentication, device notices, permission consent, policy denials, browser warnings, and operator alerts.
Find prompts where approval is required to continue routine work. They do not provide meaningful consent if denial is not practical or the person cannot evaluate the risk.
Design for signal and action
Remove prompts that can be replaced by safe defaults or automatic policy. Group related low-risk information. Reserve interruption for high-impact decisions the person can understand and control. Show trusted resource, action, requester, destination, scope, duration, anomaly, and consequence.
Provide a safe denial, report, and recovery path. Rate-limit repeated approval requests. For operators, tune detections against known response capacity and attach an owner and playbook.
Failure and residual risk
Reducing prompts can hide important state. Risk-based prompting depends on accurate context and can be manipulated. A rare prompt can still be confusing. An attacker can imitate the real interface or wait for a high-workload period.
Training people to inspect every detail does not scale when the system creates hundreds of indistinguishable decisions. Fix prompt volume and technical binding.
Pomerium boundary
Pomerium can apply route policy and delegate authentication to an identity provider. Provider MFA prompts, application consent, approval queues, and security-alert volume remain separate systems. Operators should avoid redundant access prompts and ensure each remaining decision shows the actual protected route and action.
Evaluation checklist
- How many prompts or alerts does each role receive, and how often is dismissal the normal successful action?
- Can the person distinguish resource, action, requester, destination, scope, duration, and consequence?
- Which prompt can become a safe default, bounded policy, grouped notice, or automatic denial?
- Can an attacker generate repeated requests, choose timing, or imitate the expected interface?
- Do denial and reporting stop the request without forcing the person into an unofficial bypass?
