Zero Trust Posture Heatmap
Visualize which Zero Trust controls are active or inactive for each deployment profile. Use the profile selector to compare coverage and identify risk gaps.
Coverage: 12/17 (71%)
ControlNameIdentityExecutionGovernanceTrustStatus
ZT-01Identity Foundation
ZT-02RBAC Assignments
ZT-03Content Safety
ZT-04Decision Ledger
ZT-05Runtime Interceptor
ZT-06Private Networking
ZT-07MCP Gateway (APIM)
ZT-08Observability
ZT-09Policy Engine
ZT-10Agent Scorecards
ZT-11Certification Pipeline
ZT-12Toolbox Governance
ZT-13OTel Tracing
ZT-14Eval Release Gates
ZT-15MCP mTLS SecurityPreview
ZT-16Compliance Mapper
ZT-17Data Residency
Active Inactive N/A
ZT-12Toolbox Governancemedium Per-agent tool allowlists — upgrade to Regulated profile
ZT-14Eval Release Gateshigh Requires eval packs + CI integration — upgrade to Regulated
ZT-15MCP mTLS Securitymedium Enable private networking for mTLS on MCP adapters
ZT-16Compliance Mapperlow Enable policy engine for compliance mapping
ZT-17Data Residencyhigh Select a sovereign boundary in the wizard
Upgrading to Regulated Production covers all 5 gaps.