Zero Trust Has a Timing Problem: Keeping Access Decisions Accurate After Login
Zero Trust is built on the idea that every access request should be evaluated on its own, rather than trusting anything that sits inside a network or connects through a VPN. CrowdStrike notes that AI, cloud adoption, mobile access and remote work pushed organisations away from this older "walled garden" approach. Yet one challenge is often overlooked: keeping access decisions accurate as real-world conditions change.
Early Zero Trust designs often relied on checking a session cookie or access token with each web and API request. According to CrowdStrike, this leaves gaps, because conditions can change while a token is still valid. Organisations usually consider two fixes, and neither is ideal. Re-validating with the identity provider on every access could mean a burden roughly 1000 times higher, using a conservative estimate for a 24-hour token, which is usually considered technically unviable. Shorter-lived tokens, such as one hour instead of 24, cut that load to around 24 times but frustrate users, who are repeatedly sent back to the identity provider.
This leaves an open question: how can a system react to changes that affect access while a token remains valid? The article suggests that the evaluation needs to happen at the service being accessed, at the time of access, and within milliseconds so users do not notice any slowdown. The excerpt introduces this idea but does not cover the full solution.