Core Concepts
Understand identity, trust posture, signals, enforcement, segmentation, and immutable evidence.
Concepts
ZTA
Identity
Evidence
9 min
Last updated: 2026-01-22Identity
QuantLayer treats every subject as an identity: workforce users, machines, workloads, gateways, and OT/IoT assets.
- Identity assurance increases with stronger signals (e.g., passkey, device-bound).
- Identity is continuously re-verified—trust is not permanent.
Trust posture
Posture is the current security state of an identity or asset.
- Integrity state (secure boot, tamper events, configuration baseline).
- Patch posture and vulnerability exposure.
- Behavioral drift (new connections, unusual commands).
Risk signals
- Authentication anomalies, failed verification attempts.
- New device enrollments, location changes, unusual access paths.
- OT safety constraints and change windows.
Policy & enforcement
Policies define least privilege using Subject → Resource → Action → Context. Enforcement can be staged: Observe → Warn → Enforce with allow/deny and step-up.
Segmentation
- IT: applications/services and east-west access.
- OT: zones and conduits aligned to IEC 62443.
- IoT: fleet grouping and gateway mediation.
Evidence & audit
Every decision and action produces traceable evidence suitable for compliance and incident response.
Key promise
You can answer “what was verified, what was enforced, and what changed?”
Glossary mini
PE/PA/PEP: policy engine/administrator/enforcement point. Trust drift: posture changes that degrade assurance. Break-glass: controlled emergency access with strict logging.