Zero-Trust Policy Simulator

Implement Zero-Trust Security

Zero Trust Policy Lab

Evaluate access requests against ordered zero-trust policies. Inspect identity, device health, location, network context, resource sensitivity, and least-privilege outcomes before deciding allow, deny, MFA, or limited access.

Goal
Make every access decision explicit, contextual, and explainable.
Try
Load a scenario, evaluate it, then add or remove one higher-priority policy.
Watch
Compare matched policy, request risk, skipped rules, and principle checks.
Reflect
Why can a broad allow rule weaken zero trust even when it improves convenience?

Guided Investigation

  1. Start with Employee SaaS Login and evaluate the default policy set.
  2. Switch to Compromised Laptop and confirm the high-priority deny wins.
  3. Add a broad allow policy at priority 2 and use Policy Checks to see the risk.

Scenario Focus

Employee SaaS Login tests whether a managed, compliant employee device can reach an internal app from home through a VPN with MFA.

Access Scenarios
Ready: Employee SaaS Login loaded

Access Request

Policy Composer

Specific policies should appear before broad catch-all rules. Deny compromised devices early, then require stronger verification for critical resources.

Security Metrics

--
Policies
--
Last Decision
--
Request Risk
--
Policy Health

Request Context

Not evaluated yet
Choose a scenario or edit the request, then evaluate access.

Decision Path

Active Policies

Diagnosis

Evaluate the request to inspect the decision and policy quality.

    Evaluation Trace

    Step Evidence Result

    Policy Checks

    Check Evidence Status

    Zero Trust Principles

    Principle What to Inspect Current Evidence