Access decisions that do not depend on where you are
Network location stopped predicting who you were, and an entire generation of access control quietly lost its input. These essays are about what replaced it: identity as the thing policy is written against, segmentation that survives contact with a real estate, workload credentials that expire faster than they can be stolen — and the parts of the model that no amount of architecture repairs.
All essays
- What Zero Trust Does Not Fix
The model relocates trust rather than eliminating it. Knowing precisely where it was relocated to — the issuer, the policy, the enforcement points, the administrators — is the difference between architecture and belief.
- Workload Identity Without Shared Secrets
Service-to-service authentication is where most estates still run on long-lived credentials that nobody can rotate. Replacing them means giving workloads identities they cannot copy and did not have to be told.
- Device Posture, and the Cost of Checking Again
Posture is a claim made by software running on the machine being assessed. Re-checking it continuously is the expensive part of zero trust, and the expense is where most implementations quietly compromise.
- Microsegmentation on the Diagram and in Production
Segmentation is easy to draw and hard to keep. The difficulty is never the enforcement technology — it is that nobody has an accurate description of which systems legitimately talk to which.
- Identity as the Control Plane
If policy is written against identity, then the identity system is not one control among many — it is where authority is manufactured, and the estate inherits every weakness it has.
- What the Perimeter Was Actually For
The network perimeter was not a mistake. It was an amortisation strategy for the cost of authorisation, and it worked until network location stopped predicting anything useful about the requester.