Zero-Trust Network Access
No network perimeter: identity, device posture, risk and context feed a policy decision point, and an identity-aware proxy enforces per-request access to micro-segmented resources, logging every decision.
Rendering…
Make it your own.
{
"nodes": [
{ "id": "trust", "type": "container", "label": "Continuous trust evaluation", "x": 260, "y": 40, "width": 420, "height": 460, "fill": "rgba(237,233,254,0.26)", "stroke": "#6d28d9" },
{ "id": "res", "type": "container", "label": "Micro-segmented resources", "x": 1000, "y": 40, "width": 380, "height": 580, "fill": "rgba(219,234,254,0.26)", "stroke": "#1d4ed8" },
{ "id": "usr", "type": "user-circle", "label": "Employee — café Wi-Fi", "x": 40, "y": 60, "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
{ "id": "dev", "type": "laptop", "label": "Managed laptop (MDM)", "x": 40, "y": 210, "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
{ "id": "phn", "type": "mobile-device", "label": "Phone — push MFA", "x": 40, "y": 360, "width": 150, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
{ "id": "idp", "type": "fingerprint", "label": "Identity provider + MFA", "x": 290, "y": 90, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "post", "type": "shield-check", "label": "Device posture — patch, disk", "x": 290, "y": 230, "width": 190, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "pdp", "type": "gear", "label": "Policy decision point (OPA)","x": 290, "y": 370, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9", "bold": true },
{ "id": "risk", "type": "gauge-chart", "label": "Risk — impossible travel", "x": 490, "y": 90, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "ctx", "type": "clock", "label": "Context — time, geo, ASN", "x": 490, "y": 230, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "cert", "type": "certificate", "label": "Short-lived mTLS cert", "x": 490, "y": 370, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
{ "id": "deny", "type": "octagon", "label": "Deny by default", "x": 740, "y": 60, "width": 150, "height": 80, "fill": "#fecaca", "stroke": "#b91c1c" },
{ "id": "pep", "type": "firewall", "label": "Identity-aware proxy (PEP)", "x": 740, "y": 230, "width": 200, "height": 104, "fill": "#fee2e2", "stroke": "#b91c1c", "bold": true },
{ "id": "siem", "type": "bar-chart", "label": "SIEM — every decision logged", "x": 740, "y": 430, "width": 200, "height": 104, "fill": "#f1f5f9", "stroke": "#475569" },
{ "id": "app1", "type": "browser-window", "label": "HR system", "x": 1030, "y": 90, "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "app2", "type": "cloud-sql", "label": "Finance database", "x": 1030, "y": 230, "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "app3", "type": "docker-container", "label": "Internal admin tools","x": 1030, "y": 370, "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
{ "id": "app4", "type": "bucket", "label": "S3 — sensitive exports","x": 1030, "y": 500, "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" }
],
"edges": [
{ "id": "z1", "source": "usr", "target": "pep", "label": "GET hr.internal", "thickness": 3 },
{ "id": "z2", "source": "usr", "target": "idp", "label": "authenticate" },
{ "id": "z3", "source": "phn", "target": "idp", "label": "MFA push", "style": "dashed" },
{ "id": "z4", "source": "dev", "target": "post", "label": "posture signal", "style": "dashed" },
{ "id": "z5", "source": "idp", "target": "pdp" },
{ "id": "z6", "source": "post", "target": "pdp" },
{ "id": "z7", "source": "risk", "target": "pdp" },
{ "id": "z8", "source": "ctx", "target": "pdp" },
{ "id": "z9", "source": "pdp", "target": "pep", "label": "allow / step-up / deny", "thickness": 3 },
{ "id": "z10", "source": "cert", "target": "pep", "label": "mTLS to workloads", "style": "dashed" },
{ "id": "z11", "source": "pep", "target": "app1" },
{ "id": "z12", "source": "pep", "target": "app2", "label": "read-only role" },
{ "id": "z13", "source": "pep", "target": "app3" },
{ "id": "z14", "source": "pep", "target": "app4", "label": "just-in-time grant" },
{ "id": "z15", "source": "pep", "target": "siem", "label": "audit event", "style": "dashed" },
{ "id": "z16", "source": "pep", "target": "deny", "label": "no matching policy", "style": "dashed" }
]
}