Current decision
Apply the current policy to every protected HTTP request.
Continuous verification and auditing
Pomerium applies current policy to each protected HTTP request and emits documented authorization and access log fields for later review.
Apply the current policy to every protected HTTP request.
Validate a tunneled connection when it starts.
Record documented decision and request fields.
Verification boundary
Pomerium continuously authorizes protected HTTP requests. It does not retroactively close an established tunneled connection when policy later changes.
Audit evidence
Authorization and access logs provide different evidence. Keep their fields and retention responsibilities separate.
Per-request HTTP authorization behavior.
Allow, deny, identity, and policy reason fields.
HTTP request, response, and upstream access fields.