← All notes

Audit Management

Zero trust and the evidence it should produce

A zero trust rollout that cannot show who accessed what, under which policy, has bought controls without buying assurance.

  • Invexa Technologies
  • 3 min read

There is a version of a zero trust programme that finishes on time, ticks every architecture item, and still leaves the security team unable to answer a simple question from an auditor: on 14 March, which people held access to the production customer database, and what approved that access. The controls existed. The record of them operating did not.

That gap is common because the two things are usually built by different people at different times. Access enforcement gets designed by architects. Evidence gets assembled later by whoever is preparing for the assessment. When policy and proof are decoupled, the proof is always a reconstruction.

Every Decision Point Is an Evidence Point

The useful reframe is that a zero trust architecture is already generating exactly the record an auditor wants, if it is instrumented to keep it. Each authorisation decision carries the identity, the device posture, the resource, the policy that matched and the outcome. That is an access record with its justification attached.

What turns it into evidence is treating those decisions as durable data rather than as operational logs with a 30-day retention.

  • Log the deny decisions, not just the allows. A policy that never denies anything is either perfectly scoped or not enforcing. The denial rate is the cheapest signal that a control is live.
  • Record the policy version that matched. Policies change. Without a version reference, a log line from six months ago cannot be interpreted against the rules that applied then.
  • Bind non-human identities to owners. Service accounts and API keys are where lateral movement usually happens, and they are the identities least likely to appear in a review. Each one needs a named owner, a stated purpose and an expiry.
  • Make access grants reference their approval. The grant record should point at the ticket or request that authorised it. Access with no traceable origin is the finding that comes up in nearly every first assessment.
  • Retain in line with your assessment cycle. If you are audited annually, 30 days of retention guarantees you will be reconstructing from memory.

Continuous Beats Point in Time

The traditional pattern is an annual sample. An assessor asks for 25 access grants, someone pulls the evidence, and the organisation learns in week three of the audit that a control drifted in month four.

Continuous control monitoring inverts that. Automated checks run daily against the same criteria the assessor uses: are there accounts without MFA, are there privileged accounts unreviewed beyond 90 days, are there service credentials past their rotation window, are there production access grants without an approval reference. Each check writes a pass or fail with a timestamp.

The operational payoff is that failures surface in days rather than quarters. The audit payoff is that the evidence request becomes an export instead of a project. Teams running this well typically cut audit preparation from several weeks to a few days, and the findings that remain are genuine gaps rather than documentation lag.

Frameworks reward this too. SOC 2 Type II and ISO 27001 both assess whether controls operated effectively over a period, which is precisely what a daily check history demonstrates and precisely what a point-in-time screenshot does not.

Start Where the Blast Radius Is

Instrument the systems where compromise would matter most: production data stores, payment paths, the identity provider itself, and the deployment pipeline. Get complete, well-retained decision records there before extending coverage sideways. Partial evidence on critical systems is worth considerably more than thin evidence everywhere.

At Invexa, we design access control and its audit trail as one piece of work. Enforcement without a durable record proves nothing when it is questioned, and the marginal cost of capturing that record properly at design time is close to nothing.

Next step

Have a project in mind?

A 30-minute call is usually enough to know whether we are the right team for it. If we are not, we will say so.

Start a project

Replies within one working day

Start a project