POMERION

Infrastructure for autonomous systems

Autonomy needs
authority.

Pomerion provides identity, policy and authorization infrastructure for autonomous machines — controlling which machines, models and physical actions are allowed to operate.

Authorization flowscenario 1/2 · req_3a07

AI intent

Machine
AMR-042
Model
navigation-v18
Action
enter_zone
Resource
warehouse-b

POMERION

  • IdentityPending
  • ModelPending
  • PolicyPending
  • EnvironmentPending
Decision—

Physical action

awaiting authorization

AI decides what it wants to do.

Pomerion decides what it is allowed to do.

Traditional security infrastructure controls access to software and data.

Autonomous systems introduce something fundamentally different: software can now create physical consequences.

Pomerion creates the authorization boundary between intelligence and execution.

01The trust model

Trust the machine.
Trust the model.
Authorize the action.

01

Machine

Who is acting?

  • Machine Identity
  • Hardware Identity
  • Device Attestation

02

Model

What intelligence controls it?

  • Model Identity
  • Software Version
  • Model Provenance

03

Action

What is being attempted?

  • Capability
  • Resource
  • Environment
  • Risk

POMERION AUTHORIZATION ENGINE

ALLOWorDENY
02Product

One control plane for machine authority.

01

Identity

Give every machine a cryptographically verifiable identity.

id: mch_amr-042

02

Attestation

Verify hardware, firmware, software and model state before granting authority.

hw ✓ fw ✓ sw ✓ model ✓

03

Authorization

Evaluate whether physical actions are permitted before execution.

intent → [ ] → act

04

Policy

Define what machines and models can do, where and under which conditions.

allow … when { … }

05

Deployment

Roll out models and policies through controlled deployments, canaries and rollback.

1 → 10 → 100 → fleet

06

Audit

Record the identity, model, policy and context behind every authorization decision.

decision.log ▸ append-only

03Architecture

Between intelligence and execution.

L1

Autonomy Layer

Decides what it wants to do

  • VLA Models
  • Planning
  • Navigation
  • Perception
  • Agents
▾

L2

Pomerion

Decides whether it can

  • Machine Identity
  • Model Identity
  • Attestation
  • Policy Engine
  • Authorization Runtime
  • Deployment Control
  • Audit
▾

L3

Machine Runtime

Executes authorized commands

  • ROS / ROS 2
  • Robot Controller
  • Vehicle Controller
  • Flight Controller
  • Edge Runtime
▾

L4

Physical World

Consequences

  • Motors
  • Actuators
  • Movement
  • Manipulation
  • Vehicles
  • Machines

Your autonomy stack decides what it wants to do.

Pomerion decides whether it can.

04 — Developer experience

Built like infrastructure.

authorize.ts
1const decision = await pomerion.authorize({
2 machine: "amr-042",
3 model: "navigation-v18",
4 action: "enter_zone",
5 resource: "warehouse-b"
6});
7
8if (decision.allowed) {
9 execute();
10}

Authorization decision

ALLOW

Machine
Verified
Model
Approved
Policy
Matched
Environment
Valid

Designed to integrate with existing autonomy stacks rather than replace them.

05Policy as code

Define where autonomy ends.

policies/restricted_zone.pomv3 · active
1policy restricted_zone {
2 require machine.attested
3 require model.approved
4 allow action.enter_zone
5 when {
6 zone.classification != "restricted"
7 }
8}
site: warehouse-bevaluating…
ZONE A
RESTRICTED
AMR-042
06Controlled deployment

Update autonomy without surrendering control.

model navigation-v18Rolling out
  1. 1 machine
  2. 10 machines
  3. 100 machines
  4. Fleet

Control operations

  • Canary_
  • Observe
  • Expand
  • Rollback
  • Revoke

Autonomous systems will increasingly receive continuous model and software updates. Physical systems require deployment infrastructure where failed updates can be contained before they become real-world incidents.

07Revocation

Authority should be reversible.

Machine

ROBOT-1092

Active

authority: active · operating normally

Propagation

  • Credentials revoked—
  • Model authorization removed—
  • Remote access disabled—
  • Action permissions denied—

Conceptual illustration of the intended revocation model.

08Why now

Software is entering the physical world.

01

AI is becoming capable of physical decision-making.

Models increasingly control movement, manipulation and navigation.

02

Machines are becoming continuously updated.

Robots are turning into software-defined platforms.

03

Existing IAM was not built for physical actions.

Users and cloud workloads are not the same as autonomous machines.

A new authorization boundary is emerging.

POMERION

The name

A boundary of authority.

The pomerium of ancient Rome marked more than a physical boundary. It represented a limit of authority.

Power could not simply cross it unchanged.

Pomerion applies the same principle to autonomous systems.

Capability does not equal permission.

Every autonomous system needs a boundary.

09Use cases

Built for machines that act.

  • 01RoboticsBound what manipulators and mobile robots can do around people and property.
  • 02Industrial AutomationGate machine actions on attested state and plant conditions.
  • 03Autonomous MobilityAuthorize vehicle behaviors by zone, model version and context.
  • 04DronesEnforce airspace, payload and mission permissions before flight actions.
  • 05DefenseKeep human-defined authority over autonomous capability.
  • 06Critical InfrastructureEnsure autonomous systems act only within sanctioned limits.

Humans authenticate before accessing critical systems.

Machines will too.

POMERIONPomerion is building the authority layer for the autonomous world.

Give autonomy
boundaries.

Bring identity, authorization and policy infrastructure to your autonomous systems.