ProofGrid and Pomerium: route and action control

Pomerium documents continuous context-aware authorization on proxied routes using identity and policy. Ask how an agent’s task, grant and exact mutation parameters reach the final executor and how outcome evidence is correlated.

01 / What each boundary answers

Compare the decision, not the label.

Pomerium documented boundary

Pomerium documents continuous context-aware authorization on proxied routes using identity and policy.

ProofGrid evaluation lens

Ask how an agent’s task, grant and exact mutation parameters reach the final executor and how outcome evidence is correlated.

02 / Same operating case

Which request must be stopped?

An agent passes a protected route but asks the upstream API to delete a production workload.

Evaluation exercise

Send a protected-route request for a read and a destructive DELETE. Examine the Pomerium policy inputs and the upstream API’s action check, including any alternate route.

03 / Architecture fit

How the controls can compose

A proxied route can be a strong first boundary; the upstream service can enforce effect-specific policy when it has richer context.

No claim is made that Pomerium lacks fine-grained policies; coverage depends on request attributes and topology.

04 / Evidence

Prove the decision and the effect separately.

Keep route decision, agent/task identity, upstream delete request, executor decision and workload state.

Primary sources

Check the documented controls

Architecture evaluation

Bring a consequential action to the discussion.

Request a Conversation