TL;DR: Zero trust means nothing is automatically trusted, yet implementation still fails when organisations overextend access, rely on perimeter-era assumptions, and leave permission creep unchecked, according to Axiad's guidance. The real test is whether identity, device posture, and least privilege are enforced continuously across human and non-human access paths.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “How to Implement Zero Trust in Your Business”.
Key questions
Q: What breaks when permission creep is not controlled in a zero-trust programme?
A: The model stops being dynamic and becomes a new wrapper for old standing access.
Q: Why do MFA and device checks not prevent overprivileged access?
A: MFA and device verification strengthen the decision to let someone in, but they do not automatically limit what that identity can do after entry.
Q: How do organisations know if zero trust controls are actually working?
A: They know the controls are working when they can inventory privileged identities, prove access is time-bound, and show that rotation and revocation happen on schedule.
Practitioner guidance
- Audit entitlement growth paths Map where access expands over time through role change, group inheritance, temporary elevation, and manual exceptions.
- Tie access reviews to access drift Schedule recertification around entitlement changes rather than fixed calendar habits alone.
- Separate authentication from authorisation Treat MFA and device checks as entry controls, then assess whether authorization boundaries still match least privilege after sign-in.
Bottom line: Permission creep is the quiet failure mode that can make a zero trust programme look healthy at the front door while leaving excessive access in place.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Permission creep is the point where zero trust becomes procedural instead of real: A programme can authenticate users and devices correctly while still leaving stale entitlements in place. That is a governance defect, because zero trust is only meaningful when access is continuously re-justified, not merely initially approved. The practitioner conclusion is simple: if privilege growth is not monitored, zero trust degrades into perimeter thinking with better login screens.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- By 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions.
A question worth separating out:
Q: Should organisations review human and non-human access with the same zero trust discipline?
A: Yes. The governance question is not whether the subject is a person or a machine, but whether access still matches current business need. Service accounts, API keys, and human users all create risk when entitlement drift is ignored. The review model should be adapted to the actor type, but the control objective is the same.
👉 Read our full editorial: Zero trust implementation is still undermined by permission creep