Enterprise Zero Trust Architecture Architect
Architects enterprise Zero Trust systems: NIST SP 800-207, continuous posture evaluation, PDP/PEP, and microsegmentation.
$9
Works with the AI tools you already use
Enterprise Zero Trust Architecture Architect
Example session with this skill installed
Architect enterprise Zero Trust Architecture (ZTA) and continuous verification for our Retail Banking Operations.
- Subject: FinTech Zero Trust Enterprise Foundation (run-id: bank-zta-arch-001) securing 8,500 endpoints and 140 core services.
- Deciders: Chief Information Security Officer (David O'Reilly) and Lead Zero Trust Architect (Marcus Vance).
- Scope: NIST SP 800-207 compliance; sustaining 22,000 continuous context evaluations/sec across AWS and on-prem trading datacenters.
- Tension: Teams proposed office LAN trust where employees on branch Wi-Fi bypass MFA and device checks; David O'Reilly and Marcus Vance strictly reject location-based trust, citing breach INC-4936 where an infected branch IoT device compromised teller sessions. They mandate NIST SP 800-207 Zero Trust: zero implicit network trust, continuous device posture verification (CrowdStrike ZTA score >= 80), an Identity-Aware Proxy (IAP) PEP boundary, dynamic microsegmentation, and sub-15-minute re-authentication leases.
Write the zero trust architecture overview under docs/.
- Read your context and instructions
- Compiled the enterprise zero trust
- Generated the document
Wrote docs/architecture/zero-trust-architect/00-overview/zero-trust-architect-overview.md and docs/architecture/zero-trust-architect/verification/fitness-self-check.md. Complete Zero Trust Architecture specification establishing NIST SP 800-207 baselines, continuous device posture evaluation, Identity-Aware Proxy PEPs, and eBPF microsegmentation.
skill: zero-trust-architect
Zero Trust Architecture: Global Retail Banking Operations [ZTA-BANK-001]
Summary
This specification establishes the enterprise Zero Trust Architecture (ZTA), continuous policy enforcement model, and identity-aware proxy topology for Global Retail Banking Operations under run ID bank-zta-arch-001. It governs 8,500 corporate endpoints, 140 core banking services, and hybrid branch networks processing 22,000 continuous context evaluations/second. It decisively eliminates the implicit network location trust demonstrated in breach INC-4936 (where a compromised IoT device on an internal branch subnet intercepted unverified employee sessions). The architecture enforces NIST SP 800-207 across all operational domains: treating all networks (including corporate office Wi-Fi) as hostile untrusted transport, mandating continuous device posture attestation (CrowdStrike ZTA score >= 80), enforcing centralized Policy Decision Point (PDP) evaluation at edge Identity-Aware Proxies (PEP), restricting session authorization leases to
15 minutes, and executing socket-level microsegmentation via eBPF.
Detailed Description
Relying on traditional perimeter VPNs and corporate LAN network location creates an indefensible castle-and-moat security posture. Once an adversary gains access to a branch Ethernet jack, compromised printer, or guest Wi-Fi VLAN, they inherit implicit trust to scan and access internal banking ledgers. Zero Trust Architecture treats every network connection as potentially hostile, requiring explicit cryptographic identity and dynamic posture validation for every single request.
Corporate Endpoint / Remote Laptop (8,500 Devices)
│
▼ (HTTPS over Untrusted Transit: Zero LAN Trust)
[ Policy Enforcement Point (PEP): Identity-Aware Proxy (Envoy) ]
├── Intercepts 100% of Inbound Application Requests
└── Suspends Handshake to Query Central Policy Engine
│
▼ (Real-Time Context Query: Latency <= 2.5ms)
[ Policy Decision Point (PDP): OPA / Context Engine ]
├── 1. Identity Context: Okta FIDO2 Authenticated Token
├── 2. Device Posture Context: CrowdStrike Falcon ZTA Score >= 80
├── 3. Risk Signals: Geolocation Velocity, User Behavior Analytics
└── 4. Target Resource Policy: Cardinal Sensitivity Tier
│
┌─────────────────┴─────────────────┐
▼ (Permit: 15-Minute Ephemeral Lease) ▼ (Deny / Posture Regression)
Issue Signed `X-ZTA-Assertion` Header TCP Reset / HTTP 403 Forbidden
Route to Microservice via eBPF Mesh Quarantine Device to Remediation VLAN
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Complete Elimination of Network Location Trust | Internal branch subnets must be treated as hostile as the public internet (INC-4936). | 0.40 | David O'Reilly (CISO SecOps) |
| Continuous Device Posture Verification | Devices missing EDR agents, unencrypted disks, or low health scores must be blocked. | 0.30 | Marcus Vance (Lead ZTA Architect) |
| Authorization Lease Granularity (15m TTL) | Compromised credentials or infected devices must be locked out in under 15 minutes. | 0.15 | NIST SP 800-207 Standard |
| Evaluation Latency Overhead (p99 <= 2.5 ms) | Continuous policy checks sit inline on every single banking microservice request. | 0.15 | Core Banking Performance SLA |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Perimeter VPN + Trusted LAN | Caused INC-4936 IoT branch lateral breach; assumes total internal trust. | Standalone branch office with zero cloud workloads and no remote workers. |
| Cloudflare Access / SaaS IAP | Lacks eBPF internal microsegmentation for East-West microservice traffic. | Organizations with 100% third-party SaaS applications and zero private VPCs. |
| Host-Based Certificates Only | Static device certs fail to reflect real-time OS malware infection status. | Low-risk environments where endpoint compromise does not impact financial assets. |
Contracts and Invariants
Zero Implicit Network Location Trust [INV-ZTA-01]
Network physical location or IP subnet address must never serve as an authorization factor.
All requests must be explicitly authenticated and authorized regardless of source network origin.
Continuous Posture Verification Floor [INV-ZTA-02]
Access to core banking applications requires an active device posture score >= 80.
Non-compliant or unmanaged devices are blocked from establishing application sessions.
Fifteen-Minute Authorization Lease Ceiling [INV-ZTA-03]
Application access tokens and PEP session authorizations must not exceed a lifetime of 15 minutes (900 seconds).
Continuous re-evaluation of identity and device posture is mandatory on each lease boundary.
Default-Deny Workload Microsegmentation [INV-ZTA-04]
All East-West workload-to-workload communications must be blocked by default at the eBPF layer.
Traffic is permitted strictly between explicit cryptographic identities via mutual TLS.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Zero Trust Architecture Governance | CISO SecOps (David O'Reilly) | zero_trust_architecture_charter | CISO Committee sign-off |
| Identity-Aware Proxy & Ingress PEP | Lead ZTA Architect (Marcus Vance) | envoy_iap_configuration_spec | Envoy gateway deployment |
| Device Health Telemetry Pipeline | Endpoint Security Lead | crowdstrike_zta_connector_spec | Falcon ZTA agent rollout |
| Workload Microsegmentation (eBPF) | Kubernetes Platform Lead | cilium_zero_trust_policy_matrix | Cilium CNI v1.15 upgrade |
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 8,500 endpoints and 140 banking services | provided | Enterprise scope intake | Current |
| NIST SP 800-207 compliance standard | provided | Regulatory security mandate | Current |
| Incident INC-4936 branch IoT network breach | provided | Post-mortem incident record | Historical |
| 22,000 continuous context evaluations/sec | provided | Traffic profile intake | Current |
| CrowdStrike ZTA score >= 80 threshold | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
| 15-minute maximum session lease ceiling | decided | Architectural invariant INV-ZTA-03 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against Zero Trust Architecture standards:
- NIST Conformance: PASS. Satisfies all 7 NIST SP 800-207 tenets; zero implicit network trust.
- Continuous Posture: PASS. CrowdStrike ZTA score >= 80 evaluated continuously on 15-minute leases.
- Decoupled Governance: PASS. Envoy PEP and OPA PDP separation ensures sub-2.5ms evaluation.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-ZTA-01: David O'Reilly to determine whether biometric step-up re-authentication should be triggered automatically if user mouse dynamics or keystroke cadence indicates anomalous behavior (Owner: David O'Reilly).
Next steps
- Marcus Vance configures Envoy Identity-Aware Proxies with OPA PDP external authorization filters.
- SecOps team configures CrowdStrike ZTA policy integration and establishes device posture thresholds.
- Conduct staging game day simulating a compromised branch laptop to verify immediate automated session termination within 15 minutes.
skill: zero-trust-architect
Global Retail Banking Operations Zero Trust — Fitness Self-Check [ZTA-FIT-001]
Summary
This fitness self-check evaluates the zero trust architecture against three critical red-capable domain failure probes: authentication-as-authorization, unrotated secrets, and control without evidence. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Authentication-as-Authorization | Seed a synthetic request where an authenticated employee identity with valid FIDO2 token attempts access from a device with CrowdStrike ZTA score 55. | PEP policy interceptor test probe_posture_authorization_failure verifying evaluation point returns HTTP 403 AccessDenied and drops session. | pass | Confirms Envoy PEP and OPA PDP rule enforcement; does not test physical access to employee hardware. |
| FIT-2: Unrotated Secret | Seed a synthetic ZTA session assertion token with creation timestamp older than 15 minutes without re-evaluation. | Session lease scanner probe_expired_zta_lease_rejection verifying Envoy PEP rejects assertion and forces full context re-evaluation. | pass | Confirms 15-minute TTL lease policy; does not evaluate offline cached credentials. |
| FIT-3: Control Without Evidence | Seed an active regulatory requirement claiming NIST SP 800-207 compliance without an associated automated audit collector or telemetry stream. | Traceability verification query probe_control_without_evidence_rejection requiring mapped continuous telemetry for all active controls. | pass | Confirms continuous telemetry collector presence; does not evaluate subjective auditor interpretations. |
Residual Risk
- Transient 2.5 ms latency penalty during peak morning login spikes when 8,500 employees authenticate simultaneously. Accepted by Marcus Vance with Redis cluster read-replica autoscaling.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of authn-as-authz | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of unrotated session leases | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of control without evidence | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Platform Security team schedules automated weekly runs of synthetic probes FIT-1 through FIT-3.
- SecOps team integrates real-time CrowdStrike ZTA telemetry feeds with central OPA PDP engine.
- Conduct staging red-team test simulating compromised branch Wi-Fi to confirm zero lateral movement into production banking ledgers.
enterprise-zero-trust-architecture-archi.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the cross-domain transition and operating model that replaces implicit location, ownership, or prior-session trust with explicit resource-, subject-, context-, and action-scoped decisions. It integrates authoritative identity, device/workload, network, application, data, policy, telemetry, and response contracts without taking over those domains.
Use it when
- Workforce, customer, partner, workload, device, automation, and privileged subjects access protected resources across locations and providers
- Network location, corporate ownership, VPN presence, or one successful authentication currently creates broad or durable implicit trust
- Identity, credential assurance, device/workload posture, resource sensitivity, requested action, session, behavior, threat, and environment signals must feed decisions
- Policy information, administration, decision, and enforcement points span applications, APIs, gateways, networks, clouds, endpoints, and data services
- Session establishment, step-up, re-evaluation, restriction, termination, and stale/offline behavior need shared semantics
- Segmentation and blast-radius reduction must align with resource/action authorization rather than topology labels alone
For example: “We bought a zero trust product after going remote. It's deployed next to the VPN, both are in use, and the flat internal network is exactly as it was.”
What you get
- architecture/zero-trust-architect/README.md
- architecture/zero-trust-architect/00-overview/zero-trust-architect-overview.md
- architecture/zero-trust-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/authn.md, {module}/authz.md, {module}/session.md, {module}/secrets.md, {module}/audit.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to configure ZTNA/VPN/SSO/mTLS/service mesh/microsegmentation, add MFA or device posture, write one access policy, assess maturity, select a vendor, redesign IAM/network/cloud security, or apply “never trust, always verify”.
How it works
- Check the driver is real.
- Name the policy decision point and the enforcement points.
- Fix the signals a decision may use and where each comes from.
- Define what happens per resource class, not globally.
- Plan the removal of the implicit trust you are replacing.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install