Core Concepts

    Understand identity, trust posture, signals, enforcement, segmentation, and immutable evidence.

    Concepts
    ZTA
    Identity
    Evidence
    9 min
    Last updated: 2026-01-22

    Identity

    QuantLayer treats every subject as an identity: workforce users, machines, workloads, gateways, and OT/IoT assets.

    • Identity assurance increases with stronger signals (e.g., passkey, device-bound).
    • Identity is continuously re-verified—trust is not permanent.

    Trust posture

    Posture is the current security state of an identity or asset.

    • Integrity state (secure boot, tamper events, configuration baseline).
    • Patch posture and vulnerability exposure.
    • Behavioral drift (new connections, unusual commands).

    Risk signals

    • Authentication anomalies, failed verification attempts.
    • New device enrollments, location changes, unusual access paths.
    • OT safety constraints and change windows.

    Policy & enforcement

    Policies define least privilege using Subject → Resource → Action → Context. Enforcement can be staged: Observe → Warn → Enforce with allow/deny and step-up.

    Segmentation

    • IT: applications/services and east-west access.
    • OT: zones and conduits aligned to IEC 62443.
    • IoT: fleet grouping and gateway mediation.

    Evidence & audit

    Every decision and action produces traceable evidence suitable for compliance and incident response.

    Key promise
    You can answer “what was verified, what was enforced, and what changed?”
    Glossary mini
    PE/PA/PEP: policy engine/administrator/enforcement point. Trust drift: posture changes that degrade assurance. Break-glass: controlled emergency access with strict logging.