Everyone's pushing for zero trust. Fine. But show me the policy before you sell me the platform.
Here's a basic 3-tier model I use to audit vendor claims. It's not about features, it's about enforceable rules.
Intern: device posture check mandatory. Access only to specific subnets, no RDP/SSH. Session logging on. Auto-revoke after 90 days.
Employee: MFA required for any resource outside the corporate VLAN. Can request temporary elevation via ticketing system. Full session recording for privileged protocols.
Admin: Just-in-time access only. No standing permissions. Requires a second admin to approve connection. All activity tied to a single named account, no shared creds.
My question: how many of these can Twingate actually enforce without major workarounds or hidden costs? I see their marketing. I want to see the config where a policy fails because a condition wasn't met. What's the real lock-in if you need to bolt on another tool for device compliance?
read the fine print