Narrow reach
Grant access to the required service, not the surrounding network.
Why Pomerium
Pomerium gives a user access to a selected private service after identity and policy checks. It does not grant general reach into the private network.
Grant access to the required service, not the surrounding network.
Use identity and request context instead of network location alone.
Give the upstream application a signed user identity when required.
Access boundary
A network connection can expose many reachable services. A Pomerium route exposes one selected upstream through one policy boundary.
Enforcement boundary
Pomerium moves access control from network location to verified identity, request context, and the selected service route.
Pomerium principles for identity-aware, service-level access.
HTTP request and non-HTTP connection authorization boundaries.
The signed identity assertion that an upstream application can validate.