Skip to main content

Scoped contractor access

Contractor access for the required route and time only

Attach route policy to the contractor identity and required context. Add a date window with Pomerium Zero or Enterprise when the assignment has a fixed end.

What this pattern controls

Selected route

Expose only the application or endpoint required.

Named identity

Match the contractor's verified identity.

Explicit end time

Enforce the assignment window in policy.

Contractor boundary

Scope the contractor to selected routes

Publish only the application or endpoint that the contractor needs. The deployment must prevent a direct path around Pomerium.

  • Use separate routes for applications with different policy.
  • Match a verified user ID, email, domain, or reviewed token claim.
  • Use Enterprise directory groups only when that edition and data source are configured.

Offboarding

Set the end time and verify later requests

Combine the contractor identity with a time condition. Later protected HTTP requests fail after the window closes.

  • Use date.before with Pomerium Zero or Enterprise.
  • Remove the identity rule to revoke access early.
  • An already-open tunneled TCP connection does not close when policy changes.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo