IT CanvassTalk to an advisor
Core concepts · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Zero trust

Zero trust and identity: why "never trust, always verify" makes identity the new security perimeter, and where SailPoint fits.

Quick answer

Zero trust assumes no implicit trust, every access is verified continuously. Identity becomes the primary control point, and IGA supplies the access decisions zero trust enforces.

Key takeaways
  • Zero trust = never trust, always verify
  • Identity is the new perimeter
  • Requires least privilege and continuous verification
  • SailPoint supplies governed, minimal access

Zero trust is a security model built on one uncompromising principle: never trust, always verify. It discards the old assumption that anything inside the corporate network is safe, and instead treats every access request, from anywhere, by anyone, as untrusted until it is authenticated, authorized and validated. Because access is always granted to an identity, identity becomes the new security perimeter, and identity governance becomes foundational to making zero trust real rather than aspirational.

The shift zero trust represents

The traditional "castle and moat" model authenticated users at the network edge and then largely trusted them inside. That collapses in a world of cloud applications, remote work, contractors and mobile devices, where there is no meaningful edge and a single compromised device inside the perimeter has free rein. Zero trust removes the implicit trust entirely: location no longer confers privilege, and every request is evaluated on its own merits.

The core tenets

  • Verify explicitly: authenticate and authorize every request using all available signals (identity, device, location, behaviour).
  • Use least-privilege access: grant the minimum access needed, just in time where possible.
  • Assume breach: design as though an attacker is already inside, minimising blast-radius through segmentation and minimal standing privilege.

Why identity is the new perimeter

In a zero-trust architecture, the consistent thing every request has is an identity making it. You cannot trust the network, so you must trust, and continuously re-verify, the identity and its entitlements. That places identity governance at the centre: the quality of your access data and the tightness of least privilege directly determine how much a verified-but-malicious or compromised identity can reach.

Where SailPoint fits

Zero trust needs two things from the identity layer that SailPoint provides:

  • Accurate, minimal access. Enforcement points (IdP, network, applications) can only make good decisions if the underlying entitlements are correct and least-privileged. SailPoint models roles, removes access on movement and departure, and certifies the rest, so the access data zero trust relies on is trustworthy.
  • Continuous verification of appropriateness. Zero trust verifies each session; governance verifies that the access itself should still exist. Certifications, SoD policy and outlier analytics keep the entitlement set honest over time.

Put simply: authentication tools and network controls enforce zero trust in the moment; SailPoint ensures the access being enforced is the right access. Without governed least privilege, "verify every request" just faithfully grants an over-privileged identity everything it was wrongly given.

A pragmatic path

  • Get authoritative identity data and correlation clean, this is the foundation.
  • Drive least privilege through roles, lifecycle revocation and certifications.
  • Integrate governance with your IdP so enforcement acts on accurate entitlements.
  • Add risk signals and outlier analytics to prioritise where to tighten first.

Common pitfalls

  • Treating zero trust as a product to buy rather than an architecture spanning identity, device and network.
  • Enforcing sessions over stale access: verifying every request is worthless if the entitlements themselves are wrong.
  • Neglecting non-human identities, which often carry the broadest standing privilege of all.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What is the zero-trust principle?

Frequently asked questions

What does the term Zero trust refer to in SailPoint?
Zero trust is a security model built on one uncompromising principle: never trust, always verify.
How is access to Zero trust controlled?
Verify explicitly: authenticate and authorize every request using all available signals (identity, device, location, behaviour). Use least-privilege access: grant the minimum access needed, just in time where possible.
What is worth remembering about Zero trust in practice?
The traditional "castle and moat" model authenticated users at the network edge and then largely trusted them inside.
What tends to go wrong with Zero trust?
Treating zero trust as a product to buy rather than an architecture spanning identity, device and network. Enforcing sessions over stale access: verifying every request is worthless if the entitlements themselves are wrong.
Want this with a live instructor and a lab tenant?
SailPoint IGA training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support