TL;DR: Session storage and directory sync need simpler operational patterns than Postgres can always deliver at scale, according to Pomerium. The deeper lesson is that identity enforcement depends on durable, quickly recoverable state, not just a familiar database choice.
At a glance
What this is: Pomerium’s article explains why its Databroker moved from Postgres to local file storage plus Raft clustering, highlighting operational limits around session persistence, directory sync, and replicated state.
Why it matters: IAM and access-proxy teams need to treat state durability and recoverability as part of authorization design, because stale or lost session data changes access decisions and user experience.
Context
Pomerium’s Databroker is the state layer behind an identity-aware access proxy, storing sessions and external context so authorization can reflect current identity and directory conditions. The article argues that the control problem is not simply where to keep data, but how to keep it available, current, and recoverable when access decisions depend on it.
The governance gap is operational rather than conceptual. Cookies can be too limited and too static for large claims and directory sync, while a shared Postgres backend can become difficult to tune, replicate, and operate consistently across environments. In this design, storage resilience directly shapes how quickly identity changes take effect.
The result is a shift from database centralisation to simpler local persistence with clustered recovery, framed as a trade-off between operational ease and strict consistency. That makes the article relevant to teams running access proxies, directory sync, or any policy engine that depends on fresh non-human or human identity state.
Key questions
Q: What breaks when identity is treated as a login layer only?
A: When identity is treated as a login layer only, teams miss the fact that many high-risk decisions happen after authentication, inside delegated workflows and tool chains. That leaves privilege use, session behaviour, and agent action paths outside the governance model. The result is weak accountability and poor visibility into how access is actually consumed.
Q: When does Postgres become the wrong choice for access-proxy state?
A: Postgres becomes a poor fit when the real problem is not data storage alone but low-latency replication, simple recoverability, and easy day-two operations at scale. If teams cannot tune, support, and isolate the database reliably, the access control plane inherits that instability.
Q: How can teams tell whether authorization state is actually recoverable?
A: A useful test is whether sessions and directory context can be rebuilt quickly after a restart without manual repair. If access decisions depend on hidden state that cannot be re-synced or rehydrated cleanly, the identity plane is more fragile than it appears.
Q: Should IAM teams centralize all policy data in one datastore?
A: Not always. Centralization only helps when the datastore can sustain the read-write pattern, replication needs, and operational support model of the access system. For some identity workloads, simpler local persistence with controlled clustering is easier to govern than a shared database that becomes the bottleneck.
Technical breakdown
Why session state cannot always stay in cookies
An identity-aware access proxy needs durable state for sessions, claims, and external context that cannot reliably live only in a browser cookie. Cookies are constrained in size and are poor at representing large group memberships or rich directory attributes. More importantly, directory-derived authorization data changes after login, so a login-time snapshot can become stale even when authentication is valid. That creates a mismatch between identity proof and policy truth. The databroker exists to hold state that policy evaluation can query independently of the next login event.
Practical implication: move any authorization input that must change independently of login out of the session cookie and into governed backend state.
What Postgres solves, and what it complicates
Postgres can provide indexing, JSON support, and publish/subscribe style updates, which makes it attractive for replicated session and directory data. The problem is operational fit at scale, especially when many reads and writes must be propagated across instances and managed environments are underprovisioned or poorly isolated. In this article, the issue is not database capability but operating burden: backups, latency, scaling, support knowledge, and cross-application contention all become part of the identity plane. When a control depends on fresh state, infrastructure drift becomes an access-control risk.
Practical implication: evaluate storage not only for feature fit, but for the operational consistency required by policy enforcement latency.
Why Raft clustering changes the failure model
Raft gives the Databroker a way to maintain a leader and recover from node loss without requiring every replica to behave as a fully consistent database. That is a deliberate relaxation of guarantees. The article makes clear that losing a write may mean a user is logged out or directory data goes stale, but the system can recover because the state can be rebuilt from login and directory sync. This is a recovery-oriented design, not a perfect-history design, and it works because the underlying identity state is recomputable.
Practical implication: design clustered identity state around recoverability and re-synchronization, not around the assumption that every write must be durably perfect.
Threat narrative
Attacker objective: The operational objective is to disrupt trustworthy authorization by making access state unreliable, stale, or unavailable.
- Entry occurs when a weakly managed backend or volatile datastore cannot reliably hold session and directory state for the access proxy.
- Credential and session data become inconsistent when reads, writes, or replication fall behind the pace of policy enforcement.
- Impact appears as stale authorization decisions, forced logouts, or temporary loss of directory context until state is rebuilt.
Breaches seen in the wild
- iOS apps leaking hard-coded secrets: Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, with open cloud storage and Firebase databases exposing user data.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity enforcement fails when policy state is treated like ordinary application data. This article shows that access decisions depend on state freshness, recoverability, and operational accessibility, not simply on choosing a familiar database. When directory data changes faster than the storage pattern can absorb, authorization drifts away from the identity source of truth. Practitioners should treat state design as part of the access-control model, not just platform plumbing.
Durable session state is a governance requirement, not a storage preference. Cookies can carry identity at login, but they cannot represent dynamic directory changes, active-session visibility, or revocation at scale. That leaves access control exposed to timing gaps between authentication and policy enforcement. The practical conclusion is that the authorization plane needs managed state that can be queried, refreshed, and operationally recovered without manual intervention.
Postgres is not failing as a database, but it can fail as an identity-state operating model. The article’s core lesson is that the right backend is the one teams can reliably run for the access patterns they actually have, including replication, latency, and directory sync pressure. Large-scale IAM programmes should measure the operational cost of their state layer, not just its feature list. The decision point is whether identity state can be sustained by the team that must govern it.
Recovery-oriented identity design is becoming a first-class architecture pattern. Pomerium’s shift to local persistence and clustered recovery reflects a broader reality across human IAM, NHI governance, and agentic control planes: some state is important, but not all state needs perfect consistency if it can be rebuilt quickly. That changes how practitioners think about durability, failover, and trust boundaries. The programme implication is to distinguish recomputable context from irreplaceable authority.
Identity-aware proxies now expose a storage-governance layer that many teams have ignored. The more an access control plane depends on directory sync, session replication, and distributed leases, the more storage behavior becomes security behavior. That creates a named pattern worth tracking: identity state recoverability gap. When the gap widens, access policy lags behind identity reality. Practitioners should review their access proxies for the point where operational convenience starts to weaken governance fidelity.
What this signals
Identity state recoverability gap: access control systems increasingly fail at the point where they assume the state layer behaves like a static database. Once session data, directory sync, and replicated context become part of the authorization decision, the storage model is part of the control model. Teams should assess whether their access proxy can rebuild trust after restart without manual intervention.
The broader signal is that IAM and proxy architectures are moving toward recovery-oriented designs, where some state can be recomputed and some authority cannot. That distinction matters for both human access and NHI-style machine access, because freshness and recoverability determine whether policy reflects reality or lags behind it.
For practitioners
- Audit identity-state dependencies Map which authorization decisions depend on session data, directory sync, and external context that must remain current between logins.
- Separate recomputable context from authoritative state Classify which access inputs can be rebuilt after restart and which ones must remain continuously durable for policy enforcement.
- Measure state replication latency Test how quickly a membership change, session update, or policy-relevant record reaches every proxy or databroker instance.
- Review backend operability at scale Check whether the team can actually run the chosen datastore under the real read-write load, failure pattern, and support model.
Key takeaways
- Identity-aware access proxies can lose policy fidelity when session and directory state are tied to storage patterns that do not match real operational load.
- The article shows that recoverability and replication behavior are now security-relevant design choices, not only infrastructure decisions.
- Practitioners should test whether access state can be rebuilt, resynced, and governed fast enough for the decisions their programmes depend on.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Stale sessions and directory state create lingering access after identity changes. |
| NHI-07 — Long-Lived Secrets | Persistent access state needs controlled lifetime and rebuildability, not indefinite retention. | |
| Recommendation — Review session and directory lifecycle handling so access disappears when the source identity changes. Limit the lifetime of stored access state and validate how quickly it can be re-established. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Authorization depends on current entitlements and timely propagation of directory changes. |
| PR.DS-11 — Data-at-rest is protected | Databroker state contains sensitive session and directory data that must be protected at rest. | |
| Recommendation — Align entitlement propagation and authorization checks so access reflects current identity state. Protect stored session and directory data with strong controls wherever it is persisted. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential and session lifecycle management underpins the Databroker’s trust model. |
| Recommendation — Apply authenticator lifecycle controls to the session data and recovery paths that support access decisions. | ||
Key terms
- Databroker: A Databroker is the storage and coordination layer that holds session data, directory context, and other identity state used for access decisions. In this design, it is part of the authorization path, so persistence, freshness, and cluster behavior directly affect whether policy enforcement stays current.
- Directory Sync: Directory sync is the operational process of moving identity changes from a source directory into downstream applications. The important distinction is that sync must preserve both data quality and governance scope, otherwise the application receives incomplete or mis-scoped lifecycle events that create access drift.
- Recovery-Oriented Storage: Recovery-oriented storage is a design approach that prioritises fast restoration of state after failure over perfect durability or full transactional consistency. For identity systems, that is acceptable only when the lost state can be safely rebuilt from authoritative sources without weakening access decisions.
- Raft Leader Election: Raft leader election is the process a clustered system uses to choose which node becomes the active leader when the current one fails. It helps distributed state stay consistent and available by ensuring only one node writes at a time while others keep a synchronized copy ready for takeover.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org