New research: the Runtime Identity Security category, defined. See how Whiteswan closes the gap →
Start a pilot
Start a pilot

Insights / Identity Centric ZTNA

Cloud Identity · Updated 2026

Identity-Centric ZTNA: The Future of Access Management.

Network-centric access control assumes a perimeter that no longer exists. What changes when identity, not network location, becomes the control point for every connection.

Identity centric ZTNA

The Perimeter Assumption Doesn't Hold Anymore

Traditional VPN and network-segmentation access control asks one question: is this connection coming from inside the trusted network? Once the answer is yes, a wide range of internal resources becomes reachable. That model made sense when "inside the network" meant something — a corporate office, a managed device, a known IP range.

It doesn't hold when workloads run across multiple clouds, employees connect from anywhere, contractors and vendors need scoped access without a VPN client, and AI agents make tool calls that never touch a traditional network boundary at all. The perimeter isn't just porous — for a growing share of access, it doesn't exist. That's a large part of why Zero Trust is hard to actually operationalize, not just define.

What "Identity-Centric" Actually Changes

Identity-centric ZTNA replaces "where is this connection from" with "who — or what — is asking, and is this specific action appropriate right now." The control point moves from the network edge to the identity itself, evaluated continuously rather than once at connection time — the same shift we cover in more depth in Modern Identity & Access Security.

No standing network access

Connections are scoped to the specific resource and action, not a broad segment of the network.

Works the same for every identity type

Human, service account, or AI agent — the same evaluation applies, regardless of where the request originates.

Agentless, by design

Whiteswan's Cloud Identity gateway governs cloud workloads, service accounts, and API keys the same way it governs human sessions — without instrumenting every workload. No VPN dependency, no standing network segment to defend.

See Cloud Identity

Related Reading

One Engine, Every Surface.