Skip to content

Glossary

Zero trust

Treating every request as unproven wherever it comes from, rather than granting anything on the basis of where it originated.

In plain terms

Being asked for identification at every door rather than only at the front entrance. The old arrangement assumed anybody already inside the building belonged there. This one stops assuming that, which is inconvenient and is the entire point.

01

Why it matters

Because the older assumption stopped matching how organisations work. When staff are remote, systems are hosted elsewhere and contractors need access to some things and not others, there is no inside to be inside of, and a boundary that grants access on the basis of location is granting it on the basis of something that no longer means anything.

02

How it works

It removes an assumption rather than adding a product, which is why the phrase resists a simple definition. The assumption being removed is that position implies permission, and every part of the change follows from that single deletion.

Each request is judged on its own rather than on the session that preceded it. Who is asking, from what device, for what, and does that still make sense: these are asked repeatedly rather than settled once at sign-in, which is what makes a stolen session less valuable than it used to be.

It is a direction of travel rather than a state to reach, and organisations describing themselves as having completed it are usually describing a project rather than an architecture. The work touches identity, devices, networks and applications, and most organisations do a subset and live with the remainder indefinitely.

The commercial version is much narrower than the architectural one. A great many products carry the phrase while implementing one part of it, most often access to applications, and a buyer reading the label rather than the description will conclude they have bought something considerably larger than they have.

It suits AI tools awkwardly and interestingly. A search deployment or an assistant frequently holds a broad standing connection to source systems, which is precisely the kind of permanent, location-shaped grant this approach exists to remove, and the tool's usefulness partly depends on having it.

What changed, in one line each

What changed, in one line eachReducing it to these three rows is worth doing because the phrase has been stretched to the point of being unhelpful, and underneath the stretching there is a single clear idea. Once position stops implying permission, judging each request individually is not a separate initiative but the only thing left to do, and the boundary becomes an identity because there is nowhere else for it to be. That also explains the gap between what the phrase promises and what a purchase delivers. A product can implement the middle row for its own traffic while everything around it continues to grant access on the basis of being inside, and the label is accurate about the product and misleading about the organisation. For anyone assessing AI tools the useful move is to apply the left-hand column as a test rather than the right-hand one as an aspiration: ask what the deployment can reach purely by virtue of having been installed. Where the answer is a great deal, the older assumption is alive inside the newest tool in the estate, whatever the surrounding architecture is called.The older assumptionInside the network impliesallowed.Sign-in settles it for thesession.The boundary is a place.What replaces itLocation implies nothing atall.Each request is judged on itsown.The boundary is an identity.Only the first line genuinelychanged; the other two followfrom it. That is why theapproach is hard to buy and easyto claim, because a product canimplement one row while theassumption survives everywhereelse.
Reducing it to these three rows is worth doing because the phrase has been stretched to the point of being unhelpful, and underneath the stretching there is a single clear idea. Once position stops implying permission, judging each request individually is not a separate initiative but the only thing left to do, and the boundary becomes an identity because there is nowhere else for it to be. That also explains the gap between what the phrase promises and what a purchase delivers. A product can implement the middle row for its own traffic while everything around it continues to grant access on the basis of being inside, and the label is accurate about the product and misleading about the organisation. For anyone assessing AI tools the useful move is to apply the left-hand column as a test rather than the right-hand one as an aspiration: ask what the deployment can reach purely by virtue of having been installed. Where the answer is a great deal, the older assumption is alive inside the newest tool in the estate, whatever the surrounding architecture is called.
03

Seen in the wild

  • A search deployment holding a standing connection across systems, which is the arrangement the approach is meant to avoid.

    Glean
  • Judging each request from an assistant on what is being asked for, rather than on the connection being already open.

    ChatGPT
  • An automation platform whose stored credentials are a permanent grant nothing re-evaluates.

    Make
04

Common misconceptions

People assume

It is a product you can buy.

In fact

It is the removal of an assumption, which shows up across identity, devices, networks and applications. Products implement parts of it, and a label on one product is a claim about that part rather than about the organisation.

People assume

It means trusting nothing.

In fact

It means granting nothing on the basis of location. Trust is still extended constantly, to verified identities, known devices and specific requests; what stops being sufficient is the fact that something is already inside.

05

Questions

Is this relevant to a small organisation?
The underlying change usually already happened to them without the label. A small team using hosted tools from wherever they are has no internal network to defend, so they arrived at the position by circumstance rather than by design and mostly need to avoid reintroducing the old assumption.
How does it apply to AI tools specifically?
Awkwardly, because a useful deployment often needs a broad standing connection to source systems, and that is exactly the kind of permanent grant the approach exists to remove. The practical version is narrowing what the connection reaches rather than re-evaluating each request.
What does a vendor claiming it actually mean?
Usually that their product handles one part, most often access to applications. That can be genuinely valuable and is a much smaller claim than the phrase implies, so the useful follow-up is which part they implement and what remains yours.
06

Key takeaways

  • It removes one assumption: that position implies permission.
  • It is a direction rather than a state, and mostly done in parts.
  • A product carrying the label implements a slice of it.
  • AI deployments often depend on exactly the standing grant it removes.
08

Tools that use this

  • Glean

    A standing cross-system connection is the shape it exists to remove.

  • ChatGPT

    Judging each request rather than the connection already being open.

  • Make

    Stored credentials as a permanent grant nothing re-evaluates.

Last checked August 2026

All glossary terms