Correct caller model
Select a service or user-driven identity flow.
Federated access for third-party tools
Create a separate service account for each external CI job, monitoring process, or automation tool. Limit that identity to the required route.
Select a service or user-driven identity flow.
Create one identity for one external tool.
Permit only the selected internal service route.
Caller model
Choose the caller model before you configure policy. Service accounts are available with Pomerium Zero and Enterprise.
Credential boundary
Match the service account user ID in only the required route policy. The protected service must still enforce its own roles and operations.
Autonomous machine identity and authorization headers.
User-driven command and application sign-in.
Attach policy to a specific route.