By NHI Mgmt Group Editorial TeamBased on SGNL: “Exceed NIST 1800-35’s Zero Trust demonstrations with continuous, context-aware identity” (January 22, 2026)

TL;DR: NIST SP 1800-35 shows that Zero Trust can be implemented in practice, but its example architectures still depend on periodic checks, provisioned access, and fragmented policy decisions, according to SGNL’s analysis of the guide. The real governance gap is not proving ZTA works, but making identity decisions continuous, contextual, and ephemeral enough for NHI and agentic environments.


At a glance

What this is: This is SGNL’s analysis of NIST SP 1800-35, arguing that demonstrated Zero Trust architectures still rely on periodic checks, temporary but standing access, and fragmented policy inputs.

Why it matters: For IAM, NHI, and Zero Trust practitioners, the gap matters because access decisions that are not continuous create latency windows that undermine least privilege across both human and non-human identities.

By the numbers:

  • NIST SP 1800-35 includes 19 distinct Zero Trust Architecture implementation examples.
  • The guide was built with 24 technology collaborators.

Context

NIST SP 1800-35 is a practical Zero Trust implementation guide, but its examples also expose a structural gap in how many organisations still make identity decisions. The problem is not whether Zero Trust can be built. The problem is whether access is governed continuously enough for the control to stay valid while the session is active.

In SGNL’s reading, the weak point is the persistence of periodic verification and provisioned access. That model can satisfy a checklist, yet it still leaves a window between decision and enforcement. For NHI, human IAM, and agentic environments, that window is where governance drift becomes exposure.


Key questions

Q: What breaks when Zero Trust still depends on periodic identity checks?

A: Periodic checks create a delay between context change and enforcement, so access can remain valid after the risk signal has changed. That gap is especially dangerous when business, device, and identity posture are all moving during the same session. The control fails not because it is absent, but because it reacts too slowly for modern access decisions.

Q: Why can JIT provisioning create governance gaps?

A: JIT can create governance gaps because it only provisions access at the moment of login and does not manage later updates or removal. If offboarding and entitlement maintenance are not handled by another process, accounts can remain active longer than intended and drift away from the source of truth.

Q: What are the signs that fragmented policy data is weakening access decisions?

A: Common signs include different systems approving or denying the same user based on different context, delayed revocation after a posture change, and audit trails that cannot explain why a session was allowed to continue. Those symptoms usually mean the organisation has multiple policy views instead of one authoritative decision model.

Q: How should security teams implement identity controls as they move toward zero trust in cloud environments?

A: They should start with identity as the control plane, then layer in access provisioning, deprovisioning, recertification, role mining, segregation of duties, MFA, and passwordless authentication. The goal is to make access decisions continuously, based on risk and business need, while keeping workflows simple enough for users and admins to follow consistently.


Technical breakdown

Why periodic checks leave Zero Trust latency gaps

Zero Trust is often described as continuous verification, but many deployments still rely on polling, scheduled checks, or event-triggered revalidation. That creates a latency gap between a change in risk posture and the enforcement response. If device state, user context, or business conditions change after the last check, the access decision remains stale until the next cycle or API poll. NIST SP 1800-35 illustrates this problem indirectly by showing how much implementation still depends on staged policy points and temporary privileges rather than session-native enforcement.

Practical implication: move enforcement closer to the session so risk changes can revoke access before the next polling cycle.

Why just-in-time provisioning is not the same as zero standing privilege

Just-in-time provisioning creates access on demand, but it still creates an account, entitlement, or role that exists for some period of time. Zero standing privilege is narrower and stronger because the actor never retains persistent privilege outside the active need. That distinction matters because temporary access can still be abused while it exists, especially when the workflow grants more privilege than the task requires. In practice, many teams call JIT provisioning a control success when it is actually only a reduction in exposure duration.

Practical implication: treat JIT provisioning as a transition state, not the end-state control, when designing access governance.

How fragmented policy decision points weaken access governance

NIST’s implementation examples show a common problem in multi-vendor Zero Trust architectures: policy information is spread across multiple systems that do not share a consistent view of user, device, and business context. When those inputs are not unified, one control point may approve access while another already knows the risk has changed. This is not just an integration inconvenience. It means the authorisation decision is being made against partial truth, which weakens both least privilege and accountability.

Practical implication: consolidate policy inputs into a single contextual decision layer before tuning enforcement rules.


NHI Mgmt Group analysis

Continuous identity is the real control boundary for Zero Trust. The tested architectures in NIST SP 1800-35 show that Zero Trust can be demonstrated with today’s tools, but demonstration is not the same as durable governance. When policy decisions are periodic, access remains valid longer than the risk signal that justified it. The implication is that identity governance has to move from scheduled review logic to session-bound control logic.

Zero standing privilege is not equivalent to temporary provisioning. The guide’s JIT examples prove that access can be issued on demand, but they also show that issuance and persistence are still separated in time. That is a governance compromise, not a final state. Practitioners should stop treating time-limited entitlements as proof that standing privilege has been eliminated.

Fragmented policy data is an identity governance failure, not a tooling inconvenience. NIST’s multi-point policy model reflects how many enterprises actually operate, but it also explains why access decisions drift out of sync across systems. When EDR, IdP, and business context do not share a unified view, authorisation becomes partial and delayed. The practitioner conclusion is simple: if the policy inputs are fragmented, the trust decision is fragmented too.

Continuous enforcement is now a prerequisite for human, NHI, and agentic access alike. The same control weakness appears whether the subject is a person, a service account, or a software agent acting at runtime. Static governance models assume the access object is stable long enough to be reviewed later. That assumption no longer holds in modern environments, so the programme has to govern trust at the moment of use, not after the fact.

Identity blast radius is the right lens for mature Zero Trust. Once access is issued, the question is no longer only whether it was approved, but how far it can travel before the system notices risk has changed. Continuous identity reduces that blast radius by shortening the useful life of privilege. Practitioners should measure whether their architecture can still limit damage after a context change, not only whether it can grant access cleanly.

From our research library:

What this signals

Continuous identity becomes the differentiator once Zero Trust reaches production. Organisations that still rely on periodic authentication or scheduled posture checks will keep creating short but real exposure windows. The programme shift is toward session-native governance, where policy changes can terminate access while the work is still in progress.

Zero standing privilege should be measured by persistence, not by provisioning style. A JIT workflow that still leaves a reusable entitlement in place is not the same as ephemeral access. Teams should test whether access disappears with the task, because anything else leaves governance debt behind.

90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs. That matters here because continuous identity controls are now part of the same governance problem across humans, workloads, and autonomous systems.


For practitioners

  • Replace polling with event-driven access revocation Wire risk signals from device, identity, and business systems into enforcement so a context change can end the session before the next scheduled check.
  • Distinguish JIT provisioning from zero standing privilege Review whether your current JIT model still leaves a persistent entitlement or account behind, then reclassify it as temporary access rather than true zero standing privilege.
  • Unify policy inputs before tuning access rules Map every policy decision point that contributes to authorisation, then remove duplicated or conflicting context sources that make the decision inconsistent across systems.
  • Set explicit session-bound revocation triggers Define the signals that should terminate access mid-session, including compliance failure, device drift, and assignment changes in the supporting workflow.

Key takeaways

  • Zero Trust can be demonstrated with current architectures, but periodic checks and fragmented policy points still leave gaps in enforcement.
  • Temporary access is not the same as zero standing privilege, because the privilege still exists long enough to be misused.
  • The control problem is shifting from granting access correctly to revoking it continuously and in context.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureThe article centres on NIST SP 1800-35 and its relationship to Zero Trust Architecture.
Recommendation — Use NIST SP 800-207 to evaluate whether access decisions are truly continuous and context-aware.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on how permissions and entitlements are granted, retained, and revoked.
Recommendation — Apply PR.AA-05 to ensure entitlements are enforced and revoked in line with live risk signals.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe post explicitly extends Zero Trust concerns to non-human identities and standing privilege.
NHI-07 — Long-Lived SecretsThe article’s emphasis on temporary but still-standing access aligns with secret lifetime risk.
Recommendation — Map privileged NHI access to NHI-05 and eliminate persistent access that outlives the task. Review NHI secret lifetime and reduce any credential that remains valid beyond the active session.
CIS Controls v8CIS-5 — Account ManagementThe article is about continuous control of access lifecycle and revocation.
Recommendation — Use CIS-5 to tighten account lifecycle controls and remove access that should not persist.

Key terms

  • Continuous Identity: A governance model that turns identity data into live access decisions. Instead of relying on static approvals and periodic reviews, continuous identity reevaluates whether access should still exist based on current context such as risk, device state, ticket status, or business need.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
  • Policy decision point: A policy decision point evaluates contextual rules and returns an access decision that enforcement points can act on. It separates authorization logic from application code, which helps teams manage tenant rules, resource ownership, and risk signals consistently.
  • Just-in-Time Provisioning: Just-in-time provisioning creates an account or entitlement at the moment it is needed, then removes it later. It reduces standing access duration, but it still relies on a static identity or role existing during the access window, which leaves room for misuse if revocation lags.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on May 27, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org