TL;DR: Zero trust only works when the underlying access model is correct, because continuous verification can reliably approve over-provisioned access as easily as legitimate access, according to Nexis. The real governance problem is sustaining least privilege across role changes, policy drift, and adaptive access decisions.
NHIMG editorial — based on content published by Nexis: Zero Trust Depends on the Access Beneath It
By the numbers:
- 2026., er named Nexis in the AI for Access Administration category of the Gartner Hype Cycle for Zero-Trust Technology, 2026.
Questions worth separating out
Q: How should security teams implement zero trust when access roles change frequently?
A: They should treat entitlement accuracy as a living control.
Q: Why do adaptive access controls fail when the entitlement model is weak?
A: Adaptive access can only adjust decisions around the baseline it inherits.
Q: What breaks when least privilege is applied only at review time?
A: Least privilege becomes a snapshot rather than a control.
Practitioner guidance
- Audit entitlement correctness before expanding verification layers Map the current access model across users, privileged accounts, service accounts, and application identities, then compare it to actual business need and policy intent.
- Run continuous right-sizing on stale and excessive access Use recurring reviews and automated analysis to remove unused permissions, not just to revalidate them, so least privilege stays current as roles change.
- Tie adaptive access to a verified baseline Allow context-based decisions only after roles, policies, and segregation-of-duties checks have been validated for the target identity.
What's in the full article
Nexis's full analysis covers the operational detail this post intentionally leaves for the source:
- The article's discussion of AI for access administration in the Gartner Hype Cycle for Zero-Trust Technology, 2026, and what that placement implies for programme planning
- The vendor's breakdown of how dynamic authorization combines role-, attribute-, and policy-based rules with context and risk signals
- The post's explanation of how Nexis models roles and policies across systems, including its ISPM and segregation-of-duties checks
- The article's reasoning for why continuous right-sizing is the operational mechanism behind least privilege
👉 Read Nexis's analysis of why zero trust depends on the access model beneath it →
Zero trust and access right-sizing: what are teams missing?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Zero trust is an access governance model before it is a verification model. Continuous verification cannot create correct entitlement decisions if the underlying role and policy structure is already wrong. That means the programme failure is often upstream of the control everyone points to, and practitioners need to treat entitlement correctness as the primary dependency.
A question worth separating out:
Q: How do IAM and NHI teams share responsibility for zero trust governance?
A: They should operate from one access model. Human accounts, privileged users, service accounts, and other non-human identities all contribute to the same entitlement landscape, so separate governance streams miss cross-cutting privilege drift and hidden policy conflicts.
👉 Read our full editorial: Zero trust depends on the access model beneath it