IBM's Azure Foundry Enterprise Kit

Zero Trust Posture Heatmap

Visualize which Zero Trust controls are active or inactive for each deployment profile. Use the profile selector to compare coverage and identify risk gaps.

Coverage: 12/17 (71%)
ControlNameIdentityExecutionGovernanceTrustStatus
ZT-01Identity Foundation
ZT-02RBAC Assignments
ZT-03Content Safety
ZT-04Decision Ledger
ZT-05Runtime Interceptor
ZT-06Private Networking
ZT-07MCP Gateway (APIM)
ZT-08Observability
ZT-09Policy Engine
ZT-10Agent Scorecards
ZT-11Certification Pipeline
ZT-12Toolbox Governance
ZT-13OTel Tracing
ZT-14Eval Release Gates
ZT-15MCP mTLS SecurityPreview
ZT-16Compliance Mapper
ZT-17Data Residency
Active Inactive N/A
ZT-12Toolbox Governancemedium Per-agent tool allowlists — upgrade to Regulated profile
ZT-14Eval Release Gateshigh Requires eval packs + CI integration — upgrade to Regulated
ZT-15MCP mTLS Securitymedium Enable private networking for mTLS on MCP adapters
ZT-16Compliance Mapperlow Enable policy engine for compliance mapping
ZT-17Data Residencyhigh Select a sovereign boundary in the wizard

Upgrading to Regulated Production covers all 5 gaps.