Published 2 October 2026 · Online guide
Inventory resources and access
List the services, data and identities involved in a business workflow. Include service accounts and machine identities, not just employees. Establish who authorizes access and how that access is changed or removed. Network location alone should not substitute for an explicit authorization decision.
Map dependencies and introduce controls
Identify legacy assumptions, shared credentials and integrations before tightening policies. Select a bounded service with clear ownership for the initial rollout. Test allowed and denied access, expired credentials and identity-provider failures. Keep emergency access time-limited and observable. Define rollback criteria before a policy change can interrupt a critical workflow.
Sustain the architecture
Review policy coverage, privileged access, unmanaged identities and documented exceptions. Give exceptions owners and expiry dates. Reassess policies when applications, devices or data flows change. Coordinate security, infrastructure and application teams so the controls remain usable.
Working checklist
Create a resource inventory; map identities and dependencies; define access policy; validate enforcement; test emergency access; establish decision logging; review exceptions; agree expansion criteria. A successful pilot should show that required work remains possible while access decisions are explicit. Zero trust is an architectural approach, not a certificate or a guarantee that incidents cannot occur. Applicable industry obligations still need to be assessed separately.
General planning guidance. Adapt the framework to your systems, business requirements and applicable obligations.
Explore related technology insights