Recommended alignment · NIST SP 800-207 · Zero Trust Architecture
The Zero Trust standard sets out seven tenets. For each one, here's what it requires, the approach we recommend, the configuration that implements it, and how you confirm it's working. This is a recommended reference — the exact configs are finalized against your deployment.
Source: NIST SP 800-207, Zero Trust Architecture ↗ · tenets paraphrased; read the original for the authoritative text.
# Each capability is a separate governed resource, not one flat zone
ziti edge create service private-ai --configs ai-host,ai-intercept
ziti edge create service docs-index --configs docs-host,docs-intercept
ziti edge create service tool-runner --configs tool-host,tool-intercept
$ ziti edge list services private-ai # the model endpoint docs-index # the document store tool-runner # any tool the AI may call # each resource is addressed and policed on its own
# Bind the model to localhost only; expose it as a dark Ziti service
ziti edge create config ai-host host.v1 \
'{"protocol":"tcp","address":"127.0.0.1","port":8899}'
ziti edge create config ai-intercept intercept.v1 \
'{"protocols":["tcp"],"addresses":["private-ai.ziti"],
"portRanges":[{"low":80,"high":80}]}'
ziti edge create service private-ai --configs ai-host,ai-intercept
$ nmap -Pn appliance.local All 1000 scanned ports are filtered # nothing listens on the LAN # reachable only as private-ai.ziti, over mTLS, by an enrolled identity
# Each resource has its own dial policy — granting one never grants another ziti edge create service-policy docs-dial Dial \ --service-roles '@docs-index' --identity-roles '#staff-legal' # a session to 'private-ai' is not a session to 'docs-index'
$ ziti edge list sessions identity=jdoe service=private-ai # this resource only # jdoe reaching docs-index is authorized separately, against docs-dial
# Require MFA + a healthy OS before the dial policy grants a route ziti edge create posture-check require-mfa MFA ziti edge create posture-check managed-os OS --os 'macOS:>=14' ziti edge update service-policy ai-dial \ --posture-check-roles '@require-mfa,@managed-os'
$ ziti edge list posture-checks require-mfa MFA managed-os OS macOS >= 14 # a device with no MFA, or on an old OS, gets no route — even if enrolled
# Posture is re-checked during the session (Ziti drops access on drift). # Appliance self-integrity — the agent cannot alter its own controls: guardrails: config_self_protection: true # its config is read-only to the agent reality_check: true # post-turn verification stays on
$ hermes doctor posture monitoring ......... ON # drops access on MFA/OS drift config self-protection ..... ON reality-check .............. ON
# Who may serve it, and who may reach it — deny-by-default ziti edge create service-policy ai-bind Bind \ --service-roles '@private-ai' --identity-roles '@ai-appliance' ziti edge create service-policy ai-dial Dial \ --service-roles '@private-ai' --identity-roles '#staff'
$ ziti edge list service-policies ai-bind Bind @private-ai @ai-appliance ai-dial Dial @private-ai #staff # a device with no enrolled identity in #staff gets no route at all
# Record every access & action to a local, plain-English log audit: enabled: true path: /var/hermes/audit.log # stays on the appliance fields: [time, identity, action, target, decision, policy]
2026-07-29 14:22:01 identity=jdoe action=read
target=/matters/acme/contract.pdf decision=ALLOW policy=reader
All seven tenets of NIST SP 800-207, each with the requirement, the approach we recommend, the configuration that implements it, and how you confirm it's working. This is standard 1 of the alignment set — where 800-207 governs who can connect, standard 2 governs what the AI may do: NIST AI RMF →
The free Readiness Check tells you which of these you already meet and which need work — then the build puts the recommended configuration in place.
Start the free Readiness Check →