TL;DR: Zero Trust breaks down when access data is fragmented across SaaS, cloud, and directories, making least privilege, JIT access, and reviews hard to enforce consistently, according to Veza. The core problem is identity debt: access accumulates faster than manual governance can remove it, leaving blind spots for both human and non-human identities.
NHIMG editorial — based on content published by Veza: Zero Trust begins with a single question about access
Questions worth separating out
Q: How should security teams implement Zero Trust when access data is fragmented?
A: Start by consolidating identity-to-access data across cloud, SaaS, and on-prem systems so entitlement decisions are based on current state rather than partial evidence.
Q: Why do stale permissions weaken Zero Trust programmes?
A: Stale permissions create identity debt, which means the access a person or workload had last month still exists even when the business need has gone.
Q: What breaks when least privilege is missing?
A: When least privilege is missing, a single compromised identity can reach far more systems and data than the task requires.
Practitioner guidance
- Unify access lineage across all identity stores Create a single view of human and non-human entitlements across SaaS, cloud, data platforms, and directories so review teams can see inherited and object-level access paths.
- Automate revocation for time-bound access Use workflow enforcement to grant privileged access only for the approved task window and revoke it automatically when the window closes.
- Prioritise cleanup of stale and orphaned access Identify dormant accounts, unused entitlements, and over-permissioned identities, then remove them before expanding Zero Trust controls elsewhere.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- Identity attack surface analysis workflow for mapping who has access to what across hybrid estates
- Practical examples of least-privilege remediation and time-bound access enforcement
- Buyer guidance for evaluating identity security posture management capabilities in Zero Trust programmes
- Operational framing for tying access visibility to risk reduction across SaaS, cloud, and on-prem environments
👉 Read Veza's analysis of Zero Trust, access visibility, and identity debt →
Zero Trust and identity data fragmentation: are your controls keeping up?
Explore further
Identity debt is the hidden control failure behind most Zero Trust programmes. Zero Trust is often framed as a network or endpoint strategy, but this article shows that access accumulation is the real weak point. When permissions outlive the task, role, or business need that justified them, the programme inherits risk it cannot see. For practitioners, the conclusion is simple: Zero Trust fails first at entitlement governance, not at the firewall.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Which frameworks should teams use to align zero trust with identity controls?
A: NIST SP 800-207 is the best anchor for the architecture, while IAM, PAM, and IGA programmes provide the operational controls. Teams should use the framework to standardise identity-led access decisions across environments rather than treating zero trust as a network project.
👉 Read our full editorial: Zero Trust fails when access review and privilege data stay fragmented