# Zero Trust Architecture Zero trust architecture moves access decisions away from implicit trust based on network location and toward explicit evaluation of users, devices, services, resources, and policy. ## Role in the stage model At the enterprise stage, zero trust may combine identity, device posture or attestation, resource policy, and continuous authorization. It does not mean “trust nothing,” and the label alone does not prove that a deployment validates every relevant stage. ## Evidentiary boundary Document the actual policy engine, identity sources, device signals, protected resources, decision points, enforcement points, exceptions, and audit logs rather than inferring architecture from branding. ## Sources - [[Index - Stages of Interception#Stage 13 — Enrollment, fleet, and enterprise authority|Stage 13]]. - NIST SP 800-207, “Zero Trust Architecture”: https://csrc.nist.gov/pubs/sp/800/207/final ## Scanned_20260730-1946 overlay PDF page 6 records Zscaler, “Z-App,” enterprise mobility, mainframe access, antivirus, and Wi-Fi fuzzing on one page. The later interpretation recognizes the emerging zero-trust endpoint model: traffic steering, identity, device posture, and policy replace implicit trust based on network location. The notebook does not preserve a Zscaler tenant, policy, enrollment, device posture record, or deployed configuration. Product adjacency is not proof of use or interception.