Zero trust
Quick answer
Zero trust assumes no implicit trust, every access is verified continuously. Identity becomes the primary control point, and IGA supplies the access decisions zero trust enforces.
Key takeaways
- Zero trust = never trust, always verify
- Identity is the new perimeter
- Requires least privilege and continuous verification
- SailPoint supplies governed, minimal access
Zero trust is a security model built on one uncompromising principle: never trust, always verify. It discards the old assumption that anything inside the corporate network is safe, and instead treats every access request, from anywhere, by anyone, as untrusted until it is authenticated, authorized and validated. Because access is always granted to an identity, identity becomes the new security perimeter, and identity governance becomes foundational to making zero trust real rather than aspirational.
The shift zero trust represents
The traditional "castle and moat" model authenticated users at the network edge and then largely trusted them inside. That collapses in a world of cloud applications, remote work, contractors and mobile devices, where there is no meaningful edge and a single compromised device inside the perimeter has free rein. Zero trust removes the implicit trust entirely: location no longer confers privilege, and every request is evaluated on its own merits.
The core tenets
- Verify explicitly: authenticate and authorize every request using all available signals (identity, device, location, behaviour).
- Use least-privilege access: grant the minimum access needed, just in time where possible.
- Assume breach: design as though an attacker is already inside, minimising blast-radius through segmentation and minimal standing privilege.
Why identity is the new perimeter
In a zero-trust architecture, the consistent thing every request has is an identity making it. You cannot trust the network, so you must trust, and continuously re-verify, the identity and its entitlements. That places identity governance at the centre: the quality of your access data and the tightness of least privilege directly determine how much a verified-but-malicious or compromised identity can reach.
Where SailPoint fits
Zero trust needs two things from the identity layer that SailPoint provides:
- Accurate, minimal access. Enforcement points (IdP, network, applications) can only make good decisions if the underlying entitlements are correct and least-privileged. SailPoint models roles, removes access on movement and departure, and certifies the rest, so the access data zero trust relies on is trustworthy.
- Continuous verification of appropriateness. Zero trust verifies each session; governance verifies that the access itself should still exist. Certifications, SoD policy and outlier analytics keep the entitlement set honest over time.
Put simply: authentication tools and network controls enforce zero trust in the moment; SailPoint ensures the access being enforced is the right access. Without governed least privilege, "verify every request" just faithfully grants an over-privileged identity everything it was wrongly given.
A pragmatic path
- Get authoritative identity data and correlation clean, this is the foundation.
- Drive least privilege through roles, lifecycle revocation and certifications.
- Integrate governance with your IdP so enforcement acts on accurate entitlements.
- Add risk signals and outlier analytics to prioritise where to tighten first.
Common pitfalls
- Treating zero trust as a product to buy rather than an architecture spanning identity, device and network.
- Enforcing sessions over stale access: verifying every request is worthless if the entitlements themselves are wrong.
- Neglecting non-human identities, which often carry the broadest standing privilege of all.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What is the zero-trust principle?
- A. By enforcing least privilege and keeping access data accurate and continuously reviewed.
- B. Because access is granted to identities, identity becomes the primary control point and perimeter.
- C. Never trust, always verify, no access is implicitly trusted based on network location.
Show answer
C. Never trust, always verify, no access is implicitly trusted based on network location.
Never trust, always verify, no access is implicitly trusted based on network location.
Why is identity central to zero trust?
- A. Because access is granted to identities, identity becomes the primary control point and perimeter.
- B. Never trust, always verify, no access is implicitly trusted based on network location.
- C. By enforcing least privilege and keeping access data accurate and continuously reviewed.
Show answer
A. Because access is granted to identities, identity becomes the primary control point and perimeter.
Because access is granted to identities, identity becomes the primary control point and perimeter.
How does SailPoint support zero trust?
- A. By enforcing least privilege and keeping access data accurate and continuously reviewed.
- B. Never trust, always verify, no access is implicitly trusted based on network location.
- C. Because access is granted to identities, identity becomes the primary control point and perimeter.
Show answer
A. By enforcing least privilege and keeping access data accurate and continuously reviewed.
By enforcing least privilege and keeping access data accurate and continuously reviewed.