{
  "slug": "zero-trust-proves-posture",
  "title": "Zero trust verifies the device. It never asks what you meant.",
  "summary": "Zero trust decides whether a subject may access a resource. It cannot prove the human intended the act performed with that access.",
  "lede": "A mature zero trust deployment answers one question extremely well: may this subject, on this device, in this context, access this resource. It does not answer a second question that most of the largest losses turn on: did the accountable human intend the act performed with that access.",
  "date": "2026-09-13",
  "reading_time": "17 min read",
  "category": "Standards",
  "tags": ["zero trust", "NIST SP 800-207", "business email compromise", "transaction authorization", "conditional access", "policy decision point", "deepfake fraud"],
  "image": "https://cdn.twc.sh/images/igcache/Zero%20Trust%20And%20Intent/1200_630/blog.jpg",
  "url": "/blog/zero-trust-proves-posture.html",
  "wordcount": 4453,
  "related": ["session-theft-aitm", "passkeys-prove-login-not-transaction", "identity-failure-map"],
  "schema": "Article"
}
