Zero Trust Depends on the Access Beneath It
4 Aug 2026We are pleased that Nexis is named in the AI for Access Administration category of the Gartner® Hype Cycle™ for Zero-Trust Technology, 2026 [1]. In our view, the placement is telling, because it puts access administration where we believe it belongs: at the core of the zero-trust conversation, not alongside it.
Zero trust is usually discussed through network controls and continuous verification. In our experience, its core principles all lead back to one question: Is the underlying access model correct? Least privilege, risk-based access, and continuous verification only work when the access model beneath them is correct. Get that foundation wrong, and zero trust will enforce incorrect access with perfect consistency.
Zero Trust Assumes You Know What Correct Access Looks Like
“Never trust, always verify” is a strong principle, but it comes with an implicit dependency. Verification confirms that a user is who they claim to be and that policy permits the access. It does not assess whether that access should exist at all.
If entitlements are over-provisioned, verification simply grants the wrong access reliably. This means the first zero-trust task is not a network challenge. It is defining what correct, least-privilege access actually looks like across roles, policies, and systems. Everything else builds on that.
Least Privilege Is the Hardest Principle to Maintain
Least privilege is easy to define, but difficult to sustain. Access accumulates as people join, move, and take on new responsibilities, and it is rarely removed at the same pace. Over time, the gap between the access people hold and the access they need continues to grow.
Zero trust should treat this as a continuous discipline rather than an occasional cleanup. That is where AI for access administration adds value. It can review large volumes of access data, flag excess or unused entitlements, and keep the model aligned with least privilege as the organization evolves. Continuous right-sizing turns least privilege from a concept into an operational reality.
Adaptive Access Still Requires a Strong Baseline
Zero trust adapts access based on context. Device posture, location, and risk signals influence what a user can access at any given moment. This adaptive layer is valuable, but it depends entirely on the model it adjusts.
Context can tighten or loosen access, but it always operates on an existing baseline. If that baseline is flawed, adaptive controls only refine an already incorrect model. A well-defined role and policy structure is what makes adaptive, risk-based access meaningful rather than superficial.
How Nexis Addresses This
Nexis focuses on the access foundation that zero trust depends on. The NEXIS Platform models roles and policies across systems and keeps them up to date as people and applications evolve.
NEXIS ISPM (Identity Security Posture Management) supports the continuous aspect of least privilege by identifying unused access and helping remove it, ensuring that privileges remain tightly managed over time. Cross-application segregation-of-duties checks provide clear policy enforcement across business and administrative systems, preventing hidden conflicts between them. For adaptive access, NEXIS dynamic authorization combines role-, attribute-, and policy-based rules with context and risk signals. Access decisions therefore reflect the current situation rather than a static assignment. AI supports these processes throughout, and every recommendation is transparent in its reasoning, so reviewers remain in control.
The common thread is simple: access remains correct, current, and transparent, which is exactly what a zero-trust strategy requires.
Looking Ahead
Zero trust will continue to evolve across network, device, and identity controls. Its effectiveness, however, will always depend on the quality of the access model underneath. Getting access right, and keeping it right as organizations change, is what turns least privilege and adaptive access from theory into practice. That foundation is where Nexis focuses its work, and it is the perspective we bring.
See how NEXIS keeps access correct and current in a live walkthrough:
[1] Gartner, Hype Cycle for Zero-Trust Technology, 2026, by Thomas Lintemuth & Andrew Lerner, July 2026. Gartner subscribers can access the report here: https://www.gartner.com/en/documents/8153029
GARTNER and Hype Cycle are a trademark of Gartner, Inc. and its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.