Skip to main content

Time-bound access

Route access with an explicit start, end, or schedule

Use PPL time criteria to define when a verified identity can use a route. This feature requires Pomerium Zero or Enterprise.

What this pattern controls

Absolute window

Set exact ISO 8601 start and end times.

Recurring schedule

Set days, hours, and a timezone.

Identity condition

Combine the schedule with a verified identity.

PPL time criteria

Set an absolute window or recurring schedule

Pomerium Zero and Enterprise provide date, day-of-week, and time-of-day PPL criteria. Combine time with a user or another identity condition.

  • Use date.after and date.before for an absolute window.
  • Use day_of_week for selected days.
  • Use time_of_day with an explicit timezone for recurring hours.

Enforcement timing

Know when the policy check takes effect

A time criterion is a policy constraint. It does not create an approval workflow, count request uses, or terminate an already-open tunneled connection.

  • Later HTTP requests fail after the window closes.
  • TCP and WebSocket tunnels are checked when the connection starts.
  • Use a separate JIT workflow when a person must approve the request.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo