Skip to content
Weave templates

Zero-Trust Network Access

No network perimeter: identity, device posture, risk and context feed a policy decision point, and an identity-aware proxy enforces per-request access to micro-segmented resources, logging every decision.

Template previewWeave
Rendering…

Make it your own.

{
  "nodes": [
    { "id": "trust", "type": "container", "label": "Continuous trust evaluation", "x": 260,  "y": 40, "width": 420, "height": 460, "fill": "rgba(237,233,254,0.26)", "stroke": "#6d28d9" },
    { "id": "res",   "type": "container", "label": "Micro-segmented resources",   "x": 1000, "y": 40, "width": 380, "height": 580, "fill": "rgba(219,234,254,0.26)", "stroke": "#1d4ed8" },

    { "id": "usr",  "type": "user-circle",   "label": "Employee — café Wi-Fi", "x": 40, "y": 60,  "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
    { "id": "dev",  "type": "laptop",        "label": "Managed laptop (MDM)",  "x": 40, "y": 210, "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
    { "id": "phn",  "type": "mobile-device", "label": "Phone — push MFA",      "x": 40, "y": 360, "width": 150, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },

    { "id": "idp",  "type": "fingerprint",  "label": "Identity provider + MFA",   "x": 290, "y": 90,  "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "post", "type": "shield-check", "label": "Device posture — patch, disk", "x": 290, "y": 230, "width": 190, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "pdp",  "type": "gear",         "label": "Policy decision point (OPA)","x": 290, "y": 370, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9", "bold": true },
    { "id": "risk", "type": "gauge-chart",  "label": "Risk — impossible travel",   "x": 490, "y": 90,  "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "ctx",  "type": "clock",        "label": "Context — time, geo, ASN",   "x": 490, "y": 230, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "cert", "type": "certificate",  "label": "Short-lived mTLS cert",      "x": 490, "y": 370, "width": 170, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },

    { "id": "deny", "type": "octagon",   "label": "Deny by default",                  "x": 740, "y": 60,  "width": 150, "height": 80,  "fill": "#fecaca", "stroke": "#b91c1c" },
    { "id": "pep",  "type": "firewall",  "label": "Identity-aware proxy (PEP)",       "x": 740, "y": 230, "width": 200, "height": 104, "fill": "#fee2e2", "stroke": "#b91c1c", "bold": true },
    { "id": "siem", "type": "bar-chart", "label": "SIEM — every decision logged",     "x": 740, "y": 430, "width": 200, "height": 104, "fill": "#f1f5f9", "stroke": "#475569" },

    { "id": "app1", "type": "browser-window",   "label": "HR system",           "x": 1030, "y": 90,  "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "app2", "type": "cloud-sql",        "label": "Finance database",    "x": 1030, "y": 230, "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "app3", "type": "docker-container", "label": "Internal admin tools","x": 1030, "y": 370, "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "app4", "type": "bucket",           "label": "S3 — sensitive exports","x": 1030, "y": 500, "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" }
  ],
  "edges": [
    { "id": "z1",  "source": "usr",  "target": "pep",  "label": "GET hr.internal", "thickness": 3 },
    { "id": "z2",  "source": "usr",  "target": "idp",  "label": "authenticate" },
    { "id": "z3",  "source": "phn",  "target": "idp",  "label": "MFA push", "style": "dashed" },
    { "id": "z4",  "source": "dev",  "target": "post", "label": "posture signal", "style": "dashed" },
    { "id": "z5",  "source": "idp",  "target": "pdp" },
    { "id": "z6",  "source": "post", "target": "pdp" },
    { "id": "z7",  "source": "risk", "target": "pdp" },
    { "id": "z8",  "source": "ctx",  "target": "pdp" },
    { "id": "z9",  "source": "pdp",  "target": "pep",  "label": "allow / step-up / deny", "thickness": 3 },
    { "id": "z10", "source": "cert", "target": "pep",  "label": "mTLS to workloads", "style": "dashed" },
    { "id": "z11", "source": "pep",  "target": "app1" },
    { "id": "z12", "source": "pep",  "target": "app2", "label": "read-only role" },
    { "id": "z13", "source": "pep",  "target": "app3" },
    { "id": "z14", "source": "pep",  "target": "app4", "label": "just-in-time grant" },
    { "id": "z15", "source": "pep",  "target": "siem", "label": "audit event", "style": "dashed" },
    { "id": "z16", "source": "pep",  "target": "deny", "label": "no matching policy", "style": "dashed" }
  ]
}