Zero Trust Is Not a Product. It Is a Commitment to Identity Discipline

The zero trust market is worth billions of dollars. Vendors offer zero trust platforms, zero trust network access, zero trust architecture solutions.

RCDr. Richard Chingombe · Founder, Verisq·5 min read·Practitioner perspective, not legal advice

Organizations purchase them, deploy them, and report to their boards that they have implemented zero trust. What most of them have implemented is a set of technologies that support zero trust principles. Whether they have implemented zero trust depends on something the technology cannot provide: the organizational discipline to govern identity, access, and authorization with the rigor the model requires.

What Zero Trust Actually Means

Zero trust is an architectural philosophy built on a single foundational assumption: no user, device, or system should be trusted by default, regardless of its location in the network. Every access request should be authenticated, authorized against defined policies, and continuously validated. Trust is granted explicitly, for specific resources, for specific periods, based on verified context. It is never assumed because a request comes from inside the network perimeter.

This sounds like a technology problem. It is not primarily a technology problem. The technologies that support zero trust — multi-factor authentication, device health verification, microsegmentation, continuous access evaluation — are available, mature, and deployable. The hard part is the governance discipline that the model requires: knowing who your users are with enough precision to authenticate them correctly, knowing what they should have access to with enough precision to authorize them correctly, and maintaining both of those things accurately as users, roles, and systems change continuously.

Organizations that have deployed zero trust technologies without building the underlying identity governance discipline have built the enforcement mechanism without the policy it is supposed to enforce. The access evaluation engine is running. The policies it is evaluating against are incomplete, inaccurate, or outdated. The zero trust architecture is enforcing a version of the access model that does not reflect the organization's actual access intent.

Zero trust moves the trust decision from the network perimeter to the identity layer. If the identity layer is poorly governed, zero trust moves the problem rather than solving it. The enforcement is as good as the access policies it enforces.

The Identity Governance Foundation

Identity Accuracy at Scale

Zero trust access decisions are only as accurate as the identity data that underlies them. The model requires that every user's identity is verified with high confidence, that every user's role and access entitlements are accurate and current, and that every device's health status is verified before access is granted. In organizations with thousands of users, hundreds of roles, and continuous change in both, maintaining that accuracy is an operational discipline that most organizations have not achieved.

The specific failures are predictable. Users who have changed roles still have entitlements from previous roles — the joiner-mover-leaver process did not remove the old access when the new access was provisioned. Service accounts created for specific projects still have access after the projects ended — deprovisioning was not triggered because service accounts are not included in the standard HR-driven offboarding process. Contractor and vendor identities are managed in a separate directory with different governance standards — the zero trust policy applies to them inconsistently.

Authorization Policy Depth

Authentication verifies who you are. Authorization verifies what you are allowed to do. Zero trust requires that authorization be granular, contextual, and continuously evaluated. Most authorization policies in enterprise environments are neither granular nor contextual. They are role-based access control policies that assign broad permission sets to roles, and those roles are assigned to users based on their department and title.

Role-based access in a zero trust environment means that the enforcement mechanism is enforcing role assignments. If the role assignments are too broad, the zero trust architecture enforces broad access. The microsegmentation and continuous evaluation add friction to the access path. They do not reduce the scope of what is accessible to an authenticated user whose role assignment gives them broad permissions.

Zero trust without granular authorization policies enforces coarse access with sophisticated technology. The sophistication of the enforcement does not compensate for the coarseness of the policy.

Continuous Validation That Actually Runs

Continuous access evaluation is a core zero trust principle: access that was granted under one set of conditions should be re-evaluated when conditions change. A user's access to a sensitive resource should be re-evaluated if their device health drops below the required threshold, if they authenticate from an unusual location, or if their behavior deviates from established patterns. In practice, continuous evaluation in most implementations means periodic re-authentication with a defined session duration. It does not mean real-time behavioral monitoring that responds to context changes within a session.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What Mature Implementation Looks Like

Organizations that have implemented zero trust in a way that reflects the model's intent rather than its marketing definition share specific operational characteristics. Identity is governed as a continuous discipline, not as an onboarding activity — role assignments are reviewed regularly, orphaned accounts are detected and addressed systematically, and service account access is governed with the same rigor as user access.

Authorization policies have been designed around the principle of minimum necessary access for specific tasks rather than around role categories that map to organizational hierarchy. The policy design process started from what each role actually needs to do — not from what permissions were previously held and need to be replicated in the new system.

The technology stack is instrumented to detect and respond to access anomalies in real time. The detection capability is connected to the identity governance program so that detected anomalies can inform access policy adjustments, not only trigger security alerts that are investigated independently.

The Governance Commitment

Implementing zero trust as an architectural discipline rather than a technology deployment requires a governance commitment that most organizations underestimate when they begin the journey. It requires that identity governance become a sustained operational discipline with dedicated ownership, regular audit cycles, and the organizational authority to enforce access policy decisions against business unit preferences for operational convenience.

It requires that access policy design be an ongoing program, not a one-time migration activity. The access policies that reflect the organization's intent today will not reflect its intent in two years if the policies are not maintained as the organization changes. Zero trust enforcement of outdated policies is zero trust enforcement of the wrong thing.

Zero trust is the right model. Building it requires starting with the identity governance that makes the model meaningful, not with the technology that enforces it.

Deploy the zero trust technology when the identity governance discipline can support it. In the reverse order, you are enforcing a policy that does not reflect reality with sophisticated technology. That is not zero trust. It is zero trust theater.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.