Our State of Authorization: AI Edition is now available Get it now »

The Zero Trust Hotel: A simple way to understand why policy-driven authorization is key to Zero Trust

How policy-driven authorization can help your organization achieve Zero Trust and ensure it's continuous, contextual, and compliant.

Typically, we often use the analogy of a house to explain how authorization works, however, in an enterprise landscape, you aren’t dealing with only one application, but rather hundreds or even thousands of applications. Thus, it’s better to compare this landscape to a hotel rather than a house due to its complexity.

Just like in a hotel, there’s a complexity that goes into decision making when it comes down to access and people. But, how is it all managed?

Understanding your applications

Imagine each of your applications is one singular hotel and that your entire enterprise is a full chain of hundreds of hotels.

The first thing a guest does when they arrive at the hotel is complete check-in. During that process, they are asked for an ID to check who they are. That is a form of authentication.

But, authentication cannot act alone to secure your data because without authorization policies in place, the guest could access every room in the hotel. To fix this, the hotel deploys a policy decision point (PDP) in the hotel. This PDP becomes the central brain for access control as it has access to the guest reservation dates, booking rates, loyalty numbers, and more!

This information which is stored in a database helps the PDP make decisions based on policies in varying granularity. When the guest first enters the room, the door acts as a policy enforcement point (PEP) where they swipe the keycard. The guest can swipe their card (token) to get access to their room based on the information in the database. In the end, the guest is accessing the correct room and is allowed access to the room at that point in time.

But, what if you want to get even more specific than that? For example, let’s say you want one type of guest to be able to access certain floors and lounges in separate areas of the building, but ONLY if they’re a premium loyalty member. Meanwhile, you want those that are NOT premium loyalty members to not have access to those specific areas. As we keep getting finer in access granularity, we can see that it can get very specific and require real-time context to handle different outcomes, even for different guests in the same room/reservation. Understanding the complexities is important because we don’t want unwanted visitors in our hotel rooms (and data!).

fine-grained access granularity hotel access sample

This is important as we don’t want random people to have access all of the time. We want to make access continuous, contextual, and compliant.

The three Cs

These three C’s (continuous, contextual, and compliant) are important when it comes to forming authorization policies as it helps the enterprise achieve Zero Trust.

Here’s a more in depth breakdown of the three Cs and what they do.

1. Continuous

Policies need to be constantly checking and rechecking permissions as just because a user was able to access an application an hour ago doesn’t necessarily mean they should still have the same access or permissions as before. If we think back to our hotel analogy, this would make it so that guests would have to swipe their cards to be able to access their room.

2. Contextual

Policies need to be contextual to ensure the signals being pulled in at the point of enforcement are relevant or happening in real-time. Signals within enterprises are constantly changing and the policies need to be dynamic so they can react to those signals. For example, you don’t want your guests to be able to access their room after their departure date.

3. Compliant

Almost every enterprise in the world has some level of compliance that they need to achieve whether for privacy or industry specific regulations. The policies built for your enterprises need to reflect those regulations in order to achieve the outcome of compliance. Thinking back to the hotel analogy, this would be equivalent to receiving an automated invoice which acts as a sort of access review or audit log.

Take the next steps in the journey to Zero Trust

Want to go even more in depth? Watch the full recording of my LinkedIn Live where I detailed why policy-driven authorization is key to a Zero Trust strategy.

Ready to gain more knowledge on policy-driven authorization? Here are some additional resources that look at this topic:

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.