Zero-Trust Policy Simulator
Implement Zero-Trust Security
Zero Trust Policy Lab
Evaluate access requests against ordered zero-trust policies. Inspect identity, device health, location, network context, resource sensitivity, and least-privilege outcomes before deciding allow, deny, MFA, or limited access.
Goal
Make every access decision explicit, contextual, and explainable.
Try
Load a scenario, evaluate it, then add or remove one higher-priority policy.
Watch
Compare matched policy, request risk, skipped rules, and principle checks.
Reflect
Why can a broad allow rule weaken zero trust even when it improves convenience?
Guided Investigation
- Start with Employee SaaS Login and evaluate the default policy set.
- Switch to Compromised Laptop and confirm the high-priority deny wins.
- Add a broad allow policy at priority 2 and use Policy Checks to see the risk.
Scenario Focus
Employee SaaS Login tests whether a managed, compliant employee device can reach an internal app from home through a VPN with MFA.
Access Request
Policy Composer
Specific policies should appear before broad catch-all rules. Deny compromised devices early, then require stronger verification for critical resources.
Security Metrics
--
Policies
--
Last Decision
--
Request Risk
--
Policy Health
Request Context
Not evaluated yet
Choose a scenario or edit the request, then evaluate access.
Decision Path
Active Policies
Diagnosis
Evaluate the request to inspect the decision and policy quality.
Evaluation Trace
| Step | Evidence | Result |
|---|
Policy Checks
| Check | Evidence | Status |
|---|
Zero Trust Principles
| Principle | What to Inspect | Current Evidence |
|---|