Access models: a primer

The old model grants trust by location — if you are on the network, you are trusted. The modern model grants trust per request, based on who and what is asking.

Why location fails

Once a device connects to the network, it can reach everything. Compromise one laptop, phish one credential, and the attacker inherits the whole perimeter. Location is not identity.

What identity-based access looks like

Every request carries identity, device posture and context. Access is granted per application, per moment. Breaching one endpoint exposes one session — not a network.

Frequently asked questions

Is this the same as Zero Trust?

Identity-aware access is the core of Zero Trust architecture, applied per application rather than per network.