Skip to main content

Continuous authorization

Per-request policy for multi-request agent workflows

Send each MCP or HTTP request through Pomerium. Pomerium reevaluates current identity context and policy, including named MCP tool rules.

What this pattern controls

Current policy

Reevaluate identity and policy for each request.

Named tools

Control exact MCP tool names or patterns.

Exact scope

Keep prompt meaning outside the claim boundary.

Continuous authorization

Apply documented policy context on each request

Route each MCP or HTTP request through Pomerium. Pomerium reevaluates current identity context and policy on every request.

  • Use identity claims, email, domain, device, source IP, HTTP method, or path.
  • Use time criteria with Pomerium Zero or Enterprise.
  • Use groups, external records, or Rego with Pomerium Enterprise.

Tool-call boundary

Control named MCP tools without claiming prompt inspection

Use mcp_tool rules for named tool calls. Pomerium controls requests and tool names, not prompt meaning or an LLM decision chain.

  • Match the tool name in an MCP tools/call request.
  • Put mcp_tool under deny so non-tool MCP methods continue to work.
  • Record the allow or deny result and matching policy reason.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo