By NHI Mgmt Group Editorial TeamBased on StrongDM: “Alternatives to Pomerium” (September 29, 2025)

TL;DR: Identity-aware proxies can simplify application access, but teams still need deeper controls for databases, servers, Kubernetes, audit logging, and offboarding across hybrid environments, according to StrongDM. The issue is not access convenience alone, but whether access layers actually hide credentials, enforce least privilege, and preserve revocation control.


At a glance

What this is: This comparison piece argues that identity-aware proxy models are useful for application access, but leave gaps when teams need governed access to databases, servers, Kubernetes, logging, and offboarding.

Why it matters: It matters because IAM and PAM teams need access layers that control credentials, sessions, and revocation consistently across human and non-human access paths, not just front-door sign-in.


Context

Pomerium-style identity-aware proxies simplify sign-in and application access, but they do not automatically solve the broader access governance problem. In practice, teams still need to decide whether the control layer merely brokers login, or whether it also governs credentials, session visibility, and removal of access when users leave or roles change.

That distinction matters in hybrid environments where databases, servers, and Kubernetes clusters sit behind different access patterns. A proxy can centralize authentication, but if underlying credentials remain exposed or revocation remains fragmented, the access model still carries operational risk for IAM, PAM, and NHI governance programmes.


Key questions

Q: What breaks when proxy-based access is used for infrastructure resources?

A: Proxy-based access often breaks down when teams need consistent control over databases, servers, and Kubernetes rather than just application sign-in. The main failure mode is partial governance: users authenticate through one layer, but downstream credentials, revocation, and logging remain fragmented. That leaves PAM and IAM teams with a front door that looks controlled while the actual resource path still leaks privilege.

Q: Why do identity-aware proxies not remove the need for PAM?

A: Identity-aware proxies reduce exposure at the access edge, but PAM is still needed when the underlying resources require privileged actions, session evidence, and strong offboarding. The proxy changes how users arrive at the resource, not the need to govern what they can do once inside. If credentials, session controls, or revocation are inconsistent, PAM remains the control that closes the gap.

Q: How do teams know whether an access platform is actually auditable?

A: Teams should look for session-level evidence that can be tied to a specific user, resource, and action. If the platform cannot show queries, commands, or cluster activity in a reviewable form, it is only partially auditable. A real control leaves a durable record that supports investigation, certification, and compliance, not just authentication success.

Q: When should organisations choose a proxy model over a full access control plane?

A: A proxy model fits when the main requirement is simpler sign-in to applications and the risk surface does not depend on hidden downstream credentials. A fuller access control plane is better when the organisation needs governance over infrastructure resources, offboarding, and audit trails. The choice should follow the resource type and the revocation model, not the appeal of a simpler access experience.


Technical breakdown

Identity-aware proxy versus access control plane

An identity-aware proxy sits in front of applications and brokers access based on identity, usually reducing direct exposure of endpoints. An access control plane goes further by governing how access is granted, monitored, and revoked across infrastructure resources such as databases, servers, and clusters. The difference is not just transport or login flow. It is whether the control layer removes dependency on distributed credentials and creates a single point for policy enforcement, logging, and lifecycle control across multiple resource types.

Practical implication: evaluate whether the access layer governs infrastructure resources or only brokers application sign-in.

Why hidden credentials matter in hybrid access

When access depends on VPN passwords, SSH keys, or database credentials scattered across environments, identity control becomes harder to enforce and harder to revoke. Hiding the underlying credential from the end user reduces one common blast radius, because users do not need direct possession of the secrets used to reach the resource. That matters in both human IAM and NHI governance, because the security outcome depends on who can authenticate, who can see the secret, and whether revocation is centralized enough to work across the full path.

Practical implication: remove direct end-user exposure to infrastructure credentials wherever a control plane can mediate access.

Audit logging and session replay are governance controls, not extras

Proxy-based access is often presented as a convenience layer, but its deeper value is control visibility. Logging every query, SSH session, or kubectl action creates evidence for access review, incident investigation, and compliance reporting. Session replay and standardized logs matter because identity governance fails when teams cannot reconstruct what was done under a given entitlement. In environments that span cloud, on-prem, and Kubernetes, unified audit trails are the difference between partial access awareness and a defensible control record.

Practical implication: require session-level evidence before treating any access platform as a governance control.


NHI Mgmt Group analysis

Proxy-based access is not the same thing as governed access. Identity-aware proxies can simplify authentication, but they do not automatically solve credential ownership, entitlement scope, or offboarding across the wider estate. The governance question is whether the access layer merely front-ends applications or actually controls the full lifecycle of access to infrastructure. Practitioners should treat access convenience and access governance as separate problems.

The real gap is credential displacement, not login centralization. A proxy can unify sign-in while leaving databases, SSH access, or cluster controls dependent on hidden but still real downstream privileges. That means the control surface has moved, not disappeared. The practical implication is that IAM teams must validate whether secrets, sessions, and revocation remain governed after the proxy decision point.

Access logging becomes the proof point for modern PAM. If a platform cannot provide query-level, command-level, or session-level evidence, it cannot support credible review or investigation for hybrid infrastructure. This is especially relevant where human and non-human access share the same resources. Auditability is not a reporting add-on; it is part of the control itself.

Offboarding is the clearest test of whether an access model is mature. A system that can suspend one SSO session but leave resource-level access intact creates a false sense of control. Strong offboarding requires revocation to reach the actual resource path, not just the entry portal. Practitioners should use leaver testing to expose where proxy-based access stops and true lifecycle governance begins.

What this signals

Proxy-layer convenience can mask governance gaps: the presence of centralized sign-in does not prove that resource-level access is governed, logged, or revocable in the same way. For IAM and PAM teams, the next question is whether the control reaches the database, server, or cluster itself.

Identity-aware proxies are best understood as one layer in a broader access architecture, not a substitute for lifecycle governance. Where human access, vendor access, and workload access overlap, the programme needs a way to prove that privileges disappear at the resource path, not only at the authentication gateway.


For practitioners

  • Test offboarding at the resource layer Suspend a user once and verify that database, server, and cluster access actually disappears, not just the front-door session.
  • Map hidden credential paths Inventory where VPN passwords, SSH keys, and database credentials still exist outside the proxy layer and document who can reach them.
  • Require session evidence for privileged access Set a minimum standard for query logs, shell command capture, and kubectl activity before treating an access model as auditable.
  • Differentiate application access from infrastructure access Classify which resources can live behind identity-aware proxies and which require a dedicated control plane for governance and monitoring.
  • Validate third-party vendor access expiry Confirm that project-based vendor access actually expires on schedule across every backend resource, not only at the application entry point.

Key takeaways

  • Proxy-based access can simplify sign-in, but it does not automatically solve governance for infrastructure resources.
  • The key control question is whether underlying credentials, sessions, and logs remain under policy after authentication is centralized.
  • Offboarding and auditability expose the limits of proxy-only models more clearly than day-to-day login convenience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIProxy-only access can leave downstream privileges broader than the front-door control suggests.
NHI-01 — Improper OffboardingThe article centres on whether access can be revoked cleanly across databases, servers, and clusters.
Recommendation — Map infrastructure access paths to NHI-05 and remove standing privileges that remain outside the proxy layer. Test offboarding against NHI-01 by revoking access at the resource path, not only at sign-in.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe post discusses hidden credentials and whether they remain governed after authentication.
Recommendation — Apply IA-5 to manage credential lifecycle and eliminate unmanaged downstream authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe key issue is whether access permissions stay controlled beyond the proxy entry point.
Recommendation — Use PR.AA-05 to validate that entitlements remain least-privilege across every resource layer.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementCredential hiding and session logging reduce the chance of credential abuse and movement across resources.
Recommendation — Hunt for credential access and lateral movement paths that bypass the proxy layer.

Key terms

  • Identity-aware Proxy: An identity-aware proxy combines routing with authentication and authorization logic. It checks tokens or certificates, applies policy at the edge, and forwards verified identity context to the backend so applications do not have to re-implement security decisions inconsistently.
  • Access Control Plane: The layer that coordinates identity, policy, approvals, enforcement, and logging across multiple systems. It matters because modern access decisions are rarely made in one place, and fragmentation across tools can turn governance into disconnected evidence.
  • Session Replay: A technique where an attacker reuses a captured authenticated session token to act as the victim without knowing the password. In modern cloud environments, replay can bypass traditional login controls and persist until the token is revoked or naturally expires.
  • Credential Displacement: Credential displacement describes a control model that moves sensitive credentials away from the end user while still allowing access to the underlying resource. It reduces exposure, but only works as intended when the replacement control also preserves visibility, revocation, and policy enforcement across the full path.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org