Implicit trust and broad privilege
Flat networks and inherited administrator roles allow one compromised identity to travel too far. We define workload and user identities, narrow authorisation by policy, segment sensitive paths and log decisions at the point of access.