Enterprise Zero Trust Architecture Architect

    1

    Architects enterprise Zero Trust systems: NIST SP 800-207, continuous posture evaluation, PDP/PEP, and microsegmentation.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Enterprise Zero Trust Architecture Architect

    Example session with this skill installed

    Architect enterprise Zero Trust Architecture (ZTA) and continuous verification for our Retail Banking Operations.

    • Subject: FinTech Zero Trust Enterprise Foundation (run-id: bank-zta-arch-001) securing 8,500 endpoints and 140 core services.
    • Deciders: Chief Information Security Officer (David O'Reilly) and Lead Zero Trust Architect (Marcus Vance).
    • Scope: NIST SP 800-207 compliance; sustaining 22,000 continuous context evaluations/sec across AWS and on-prem trading datacenters.
    • Tension: Teams proposed office LAN trust where employees on branch Wi-Fi bypass MFA and device checks; David O'Reilly and Marcus Vance strictly reject location-based trust, citing breach INC-4936 where an infected branch IoT device compromised teller sessions. They mandate NIST SP 800-207 Zero Trust: zero implicit network trust, continuous device posture verification (CrowdStrike ZTA score >= 80), an Identity-Aware Proxy (IAP) PEP boundary, dynamic microsegmentation, and sub-15-minute re-authentication leases.

    Write the zero trust architecture overview under docs/.

    • Read your context and instructions
    • Compiled the enterprise zero trust
    • Generated the document

    Wrote docs/architecture/zero-trust-architect/00-overview/zero-trust-architect-overview.md and docs/architecture/zero-trust-architect/verification/fitness-self-check.md. Complete Zero Trust Architecture specification establishing NIST SP 800-207 baselines, continuous device posture evaluation, Identity-Aware Proxy PEPs, and eBPF microsegmentation.


    skill: zero-trust-architect

    Zero Trust Architecture: Global Retail Banking Operations [ZTA-BANK-001]

    Summary

    This specification establishes the enterprise Zero Trust Architecture (ZTA), continuous policy enforcement model, and identity-aware proxy topology for Global Retail Banking Operations under run ID bank-zta-arch-001. It governs 8,500 corporate endpoints, 140 core banking services, and hybrid branch networks processing 22,000 continuous context evaluations/second. It decisively eliminates the implicit network location trust demonstrated in breach INC-4936 (where a compromised IoT device on an internal branch subnet intercepted unverified employee sessions). The architecture enforces NIST SP 800-207 across all operational domains: treating all networks (including corporate office Wi-Fi) as hostile untrusted transport, mandating continuous device posture attestation (CrowdStrike ZTA score >= 80), enforcing centralized Policy Decision Point (PDP) evaluation at edge Identity-Aware Proxies (PEP), restricting session authorization leases to

    15 minutes, and executing socket-level microsegmentation via eBPF.

    Detailed Description

    Relying on traditional perimeter VPNs and corporate LAN network location creates an indefensible castle-and-moat security posture. Once an adversary gains access to a branch Ethernet jack, compromised printer, or guest Wi-Fi VLAN, they inherit implicit trust to scan and access internal banking ledgers. Zero Trust Architecture treats every network connection as potentially hostile, requiring explicit cryptographic identity and dynamic posture validation for every single request.

    Corporate Endpoint / Remote Laptop (8,500 Devices)
                             │
                             ▼ (HTTPS over Untrusted Transit: Zero LAN Trust)
    [ Policy Enforcement Point (PEP): Identity-Aware Proxy (Envoy) ]
      ├── Intercepts 100% of Inbound Application Requests
      └── Suspends Handshake to Query Central Policy Engine
                             │
                             ▼ (Real-Time Context Query: Latency <= 2.5ms)
    [ Policy Decision Point (PDP): OPA / Context Engine ]
      ├── 1. Identity Context: Okta FIDO2 Authenticated Token
      ├── 2. Device Posture Context: CrowdStrike Falcon ZTA Score >= 80
      ├── 3. Risk Signals: Geolocation Velocity, User Behavior Analytics
      └── 4. Target Resource Policy: Cardinal Sensitivity Tier
                             │
           ┌─────────────────┴─────────────────┐
           ▼ (Permit: 15-Minute Ephemeral Lease) ▼ (Deny / Posture Regression)
    Issue Signed `X-ZTA-Assertion` Header     TCP Reset / HTTP 403 Forbidden
    Route to Microservice via eBPF Mesh       Quarantine Device to Remediation VLAN
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Complete Elimination of Network Location TrustInternal branch subnets must be treated as hostile as the public internet (INC-4936).0.40David O'Reilly (CISO SecOps)
    Continuous Device Posture VerificationDevices missing EDR agents, unencrypted disks, or low health scores must be blocked.0.30Marcus Vance (Lead ZTA Architect)
    Authorization Lease Granularity (15m TTL)Compromised credentials or infected devices must be locked out in under 15 minutes.0.15NIST SP 800-207 Standard
    Evaluation Latency Overhead (p99 <= 2.5 ms)Continuous policy checks sit inline on every single banking microservice request.0.15Core Banking Performance SLA

    Alternatives rejected

    OptionWhy it was not takenUnder what evidence it would win
    Perimeter VPN + Trusted LANCaused INC-4936 IoT branch lateral breach; assumes total internal trust.Standalone branch office with zero cloud workloads and no remote workers.
    Cloudflare Access / SaaS IAPLacks eBPF internal microsegmentation for East-West microservice traffic.Organizations with 100% third-party SaaS applications and zero private VPCs.
    Host-Based Certificates OnlyStatic device certs fail to reflect real-time OS malware infection status.Low-risk environments where endpoint compromise does not impact financial assets.

    Contracts and Invariants

    Zero Implicit Network Location Trust [INV-ZTA-01]
      Network physical location or IP subnet address must never serve as an authorization factor.
      All requests must be explicitly authenticated and authorized regardless of source network origin.
    
    Continuous Posture Verification Floor [INV-ZTA-02]
      Access to core banking applications requires an active device posture score >= 80.
      Non-compliant or unmanaged devices are blocked from establishing application sessions.
    
    Fifteen-Minute Authorization Lease Ceiling [INV-ZTA-03]
      Application access tokens and PEP session authorizations must not exceed a lifetime of 15 minutes (900 seconds).
      Continuous re-evaluation of identity and device posture is mandatory on each lease boundary.
    
    Default-Deny Workload Microsegmentation [INV-ZTA-04]
      All East-West workload-to-workload communications must be blocked by default at the eBPF layer.
      Traffic is permitted strictly between explicit cryptographic identities via mutual TLS.
    

    Ownership and Handoffs

    ConcernOwnerHandoff payloadBlocked until
    Zero Trust Architecture GovernanceCISO SecOps (David O'Reilly)zero_trust_architecture_charterCISO Committee sign-off
    Identity-Aware Proxy & Ingress PEPLead ZTA Architect (Marcus Vance)envoy_iap_configuration_specEnvoy gateway deployment
    Device Health Telemetry PipelineEndpoint Security Leadcrowdstrike_zta_connector_specFalcon ZTA agent rollout
    Workload Microsegmentation (eBPF)Kubernetes Platform Leadcilium_zero_trust_policy_matrixCilium CNI v1.15 upgrade

    Traceability

    ClaimClassificationSourceFreshness
    8,500 endpoints and 140 banking servicesprovidedEnterprise scope intakeCurrent
    NIST SP 800-207 compliance standardprovidedRegulatory security mandateCurrent
    Incident INC-4936 branch IoT network breachprovidedPost-mortem incident recordHistorical
    22,000 continuous context evaluations/secprovidedTraffic profile intakeCurrent
    CrowdStrike ZTA score >= 80 thresholddecidedDavid O'Reilly (CISO SecOps)2026-09-15
    15-minute maximum session lease ceilingdecidedArchitectural invariant INV-ZTA-032026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against Zero Trust Architecture standards:

    • NIST Conformance: PASS. Satisfies all 7 NIST SP 800-207 tenets; zero implicit network trust.
    • Continuous Posture: PASS. CrowdStrike ZTA score >= 80 evaluated continuously on 15-minute leases.
    • Decoupled Governance: PASS. Envoy PEP and OPA PDP separation ensures sub-2.5ms evaluation.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-ZTA-01: David O'Reilly to determine whether biometric step-up re-authentication should be triggered automatically if user mouse dynamics or keystroke cadence indicates anomalous behavior (Owner: David O'Reilly).

    Next steps

    1. Marcus Vance configures Envoy Identity-Aware Proxies with OPA PDP external authorization filters.
    2. SecOps team configures CrowdStrike ZTA policy integration and establishes device posture thresholds.
    3. Conduct staging game day simulating a compromised branch laptop to verify immediate automated session termination within 15 minutes.

    skill: zero-trust-architect

    Global Retail Banking Operations Zero Trust — Fitness Self-Check [ZTA-FIT-001]

    Summary

    This fitness self-check evaluates the zero trust architecture against three critical red-capable domain failure probes: authentication-as-authorization, unrotated secrets, and control without evidence. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.

    Detailed Description

    Criterion [FIT-n]ProbeEvidenceResultLimits of the claim
    FIT-1: Authentication-as-AuthorizationSeed a synthetic request where an authenticated employee identity with valid FIDO2 token attempts access from a device with CrowdStrike ZTA score 55.PEP policy interceptor test probe_posture_authorization_failure verifying evaluation point returns HTTP 403 AccessDenied and drops session.passConfirms Envoy PEP and OPA PDP rule enforcement; does not test physical access to employee hardware.
    FIT-2: Unrotated SecretSeed a synthetic ZTA session assertion token with creation timestamp older than 15 minutes without re-evaluation.Session lease scanner probe_expired_zta_lease_rejection verifying Envoy PEP rejects assertion and forces full context re-evaluation.passConfirms 15-minute TTL lease policy; does not evaluate offline cached credentials.
    FIT-3: Control Without EvidenceSeed an active regulatory requirement claiming NIST SP 800-207 compliance without an associated automated audit collector or telemetry stream.Traceability verification query probe_control_without_evidence_rejection requiring mapped continuous telemetry for all active controls.passConfirms continuous telemetry collector presence; does not evaluate subjective auditor interpretations.

    Residual Risk

    • Transient 2.5 ms latency penalty during peak morning login spikes when 8,500 employees authenticate simultaneously. Accepted by Marcus Vance with Redis cluster read-replica autoscaling.

    Traceability

    ClaimClassificationSourceFreshness
    Rejection of authn-as-authzderivedFIT-1 probe result2026-09-15
    Rejection of unrotated session leasesderivedFIT-2 probe result2026-09-15
    Rejection of control without evidencederivedFIT-3 probe result2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Open Decisions

    None.

    Next steps

    1. Platform Security team schedules automated weekly runs of synthetic probes FIT-1 through FIT-3.
    2. SecOps team integrates real-time CrowdStrike ZTA telemetry feeds with central OPA PDP engine.
    3. Conduct staging red-team test simulating compromised branch Wi-Fi to confirm zero lateral movement into production banking ledgers.

    enterprise-zero-trust-architecture-archi.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    - Design NIST 800-207 compliant Zero Trust architectures- Define policy decision (PDP) and enforcement points (PEP)- Map authoritative trust signals to specific resource classes- Create transition plans to remove legacy implicit trust

    About this skill

    What it does

    This skill owns the cross-domain transition and operating model that replaces implicit location, ownership, or prior-session trust with explicit resource-, subject-, context-, and action-scoped decisions. It integrates authoritative identity, device/workload, network, application, data, policy, telemetry, and response contracts without taking over those domains.

    Use it when

    • Workforce, customer, partner, workload, device, automation, and privileged subjects access protected resources across locations and providers
    • Network location, corporate ownership, VPN presence, or one successful authentication currently creates broad or durable implicit trust
    • Identity, credential assurance, device/workload posture, resource sensitivity, requested action, session, behavior, threat, and environment signals must feed decisions
    • Policy information, administration, decision, and enforcement points span applications, APIs, gateways, networks, clouds, endpoints, and data services
    • Session establishment, step-up, re-evaluation, restriction, termination, and stale/offline behavior need shared semantics
    • Segmentation and blast-radius reduction must align with resource/action authorization rather than topology labels alone

    For example: “We bought a zero trust product after going remote. It's deployed next to the VPN, both are in use, and the flat internal network is exactly as it was.”

    What you get

    • architecture/zero-trust-architect/README.md
    • architecture/zero-trust-architect/00-overview/zero-trust-architect-overview.md
    • architecture/zero-trust-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/authn.md, {module}/authz.md, {module}/session.md, {module}/secrets.md, {module}/audit.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to configure ZTNA/VPN/SSO/mTLS/service mesh/microsegmentation, add MFA or device posture, write one access policy, assess maturity, select a vendor, redesign IAM/network/cloud security, or apply “never trust, always verify”.

    How it works

    1. Check the driver is real.
    2. Name the policy decision point and the enforcement points.
    3. Fix the signals a decision may use and where each comes from.
    4. Define what happens per resource class, not globally.
    5. Plan the removal of the implicit trust you are replacing.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-contract.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions