I asked a state agency CIO a simple question a few years ago. How do you know when someone stops being entitled to access your systems? He answered immediately and correctly. HR tells us.
So I asked the follow-up. What about the people with access who are not your employees? He did the arithmetic in his head, out loud, and got to somewhere north of a third of all active accounts before he stopped.
Nobody in that room was doing a bad job. They were running a zero trust program that was well designed, correctly funded and building on a foundation that did not exist for a large fraction of the people it governed.
What zero trust actually depends on
Nobody argues about the direction any more. Perimeter trust is finished, federal guidance has been explicit for years, and state and local agencies have been moving with real seriousness. That part is settled and this is not an argument against it.
Strip the model to its dependency instead. Every policy decision point in a zero trust architecture asks one question, continuously. Is this the right person, in the right state, right now?
The second clause is the load-bearing one. Right state means still employed, still assigned, still cleared, still entitled. Answering it requires an authority that knows the person's current status and tells you when it changes.
In a commercial enterprise that authority is payroll. Someone is hired, an event fires, an account exists. Someone is terminated, an event fires, access ends within minutes. It is authoritative, timely and auditable, and every enterprise zero trust deployment quietly hangs off it. Zero trust in a corporation is, at bottom, an elaborate structure built on top of the human resources system.
Now look at who holds credentials in a state agency, a county, a district or a city. Contractors working an 18-month task order for a prime you do not contract with directly. Staff seconded from another agency. Elected officials whose termination event is an election. Volunteers. Employees of a city using a county system under an inter-local agreement. Grant-funded staff whose funding ends on a date recorded in a finance system nobody has connected to anything. School staff on a state platform.
For most of those populations there is no payroll event, because the organisation enforcing access never hired the person. And often the entity that does know the person's status has neither an obligation nor a mechanism to tell you.
Which is the point. Zero trust does not struggle in the public sector because of legacy systems. It struggles because it has no authoritative source for the question it is required to ask every single time.
Fourteen months
Here is how that plays out, and it is not a hypothetical shape.
A contractor finishes a task order on a Friday. Three parties know. The prime knows, because they stop billing. The contracting officer knows, because the task order closed in the procurement system. The individual knows, because they packed up.
The agency's identity provider does not know, and never will, because no wire has ever been built between the system that records entitlement and the system that enforces it. The account stays active. Fourteen months later an audit finds it, and it gets written up as a provisioning failure.
It was not a provisioning failure. Provisioning worked exactly as designed. The failure is that the fact existed in a procurement system and the enforcement lived in an identity system, and in between there was nothing at all.
What makes this worse rather than better under zero trust is that the architecture around that account is excellent. Multifactor is enforced. Device posture is checked. Sessions are re-evaluated. Segmentation is tight. Every one of those controls performs perfectly, on an entitlement that ended over a year ago, and the precision of the enforcement is what generates the confidence that nothing is wrong.
The sequencing that costs the money
There is a real objection here, and it is not the technical one.
It goes like this. None of this is news. It is identity governance, every agency knows they need it, and the reason they do not have it is procurement cycles and budget, not a gap in understanding. Telling public sector CIOs to fix identity governance is telling them something they have known for a decade and cannot fund.
That objection is substantially right about the constraint and wrong about the sequence, and the sequence is where the money goes.
Cybersecurity Insiders surveyed 851 IT, networking and security professionals in late 2025 across industries. Eighty-two percent considered universal zero trust network access essential and 17 percent had fully implemented it. More telling for this argument is where they started. Thirty percent began by replacing VPNs with ZTNA, and 26 percent began with platform consolidation. Only 17 percent began with identity. Meanwhile 52 percent said excessive entitlements were very or moderately widespread in their environment, and 56 percent named employee over-privilege as the leading contributor to unauthorised access.
That sample is cross-industry rather than government-specific, so read it as directional. The direction is unambiguous. Organisations overwhelmingly buy the enforcement layer first, because that is what mandates score, what vendors demonstrate and what produces a visible milestone. Then the policy decision point turns out to have nothing authoritative to decide against.
The step that has to come first is not expensive. It is a table.
The table
Before the next phase of any zero trust program, produce one page. For every population that holds credentials in your environment, five columns. What the population is. How many people. What event should end their access. Which system records that event today. And whether a wire exists between that system and your identity provider.
That document takes a few weeks of one person's time and no procurement. It will not be flattering. In most public sector organisations, the fourth column comes back as a finance system, a procurement system, a state personnel system belonging to a different agency, an election schedule, or a spreadsheet on somebody's laptop. The fifth column will be mostly empty.
The empty cells are the actual roadmap, and many of them close for far less than the enforcement tooling costs. A monthly export from the procurement system into a review queue is unglamorous, would embarrass nobody's architecture diagram, and closes a fourteen-month gap down to thirty days. Do that first and the expensive layer you buy afterwards is enforcing something true.
Three questions worth asking on Monday. What percentage of active accounts in your environment belong to people your organisation did not hire. For the largest of those groups, name the system that knows when their entitlement ends. And ask when someone last compared that system's records against your identity provider, line by line.
If the first answer is above a quarter, which in state and local government it very often is, then the majority of your zero trust investment is currently protecting a boundary and a minority of it is establishing who belongs inside.
What this changes
You end up spending less, in a different order, on things that are harder to put in a press release. That is the honest description and it is worth saying plainly.
What you get in exchange is an architecture whose enforcement is attached to facts. Leadership and the board, or in this sector the commission, the council or the oversight committee, get a number they can track that actually moves. Percentage of credentialed populations with a connected authoritative source is a better measure of zero trust maturity than any tooling milestone, and it survives an audit far more comfortably.
Zero trust promises to verify continuously. It cannot verify against a fact that nobody is telling you.