Skip to main content

Continuous verification and auditing

Reevaluate HTTP access and record the decision

Pomerium applies current policy to each protected HTTP request and emits documented authorization and access log fields for later review.

What this pattern controls

Current decision

Apply the current policy to every protected HTTP request.

Protocol boundary

Validate a tunneled connection when it starts.

Reviewable evidence

Record documented decision and request fields.

Verification boundary

Reevaluate each HTTP request

Pomerium continuously authorizes protected HTTP requests. It does not retroactively close an established tunneled connection when policy later changes.

  • Use current identity-provider claims, device identity, request facts, and external data in route policy.
  • Apply the current route or inherited policy to each HTTP request.
  • Treat TCP and WebSocket connections as connection-start decisions.

Audit evidence

Record the decision and the request path

Authorization and access logs provide different evidence. Keep their fields and retention responsibilities separate.

  • Record allow or deny outcomes and policy reasons in authorization logs.
  • Use access logs for request, response, and upstream fields.
  • Configure retention and downstream analysis in your logging system.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo