{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"secure-access","name":"Secure access & security service edge","short":"SSE / ZTNA"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"remote-user-public-private-access","name":"Remote-user public and private access","scope":"Selected commercial configurations providing both outbound web policy and private application access for managed remote users. Required SWG/private-access modules, clients and connectors are explicit. No score credit for SD-WAN, branch hardware, backbone size, optional CASB API scanning, DLP, RBI or managed services."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating workflow for the selected public and private access configuration. It measures evidence of operation, not uptime or deployment age.","question":"Can operators configure access, investigate policy outcomes and understand change or failure behavior?","anchors":["The vendor explicitly states that the selected access service is unavailable.","A documented public or private access setup.","Stage 1 plus both public-web and private-resource paths with configurable access policy.","Stage 2 plus reviewable policy or connection logs for investigation.","Stage 3 plus connection diagnostics, documented policy-change/session behavior and connector or service recovery procedures.","Stage 4 plus controlled configuration promotion and independently exercised failure recovery."],"refinements":[{"base":3,"criteria":[{"id":"diagnostics","label":"Documented procedure or report for diagnosing failed client or access connections","weight":3},{"id":"change-behavior","label":"Documented effect of policy changes on existing sessions or connected clients","weight":3},{"id":"recovery","label":"Documented connector or service failure recovery in the selected scope","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Evidence of a shipped access workflow beyond the established identity-aware public/private policy model.","question":"Which delivered workflow exceeds the comparison baseline with explicit evidence and limits?","anchors":["The vendor explicitly states that automated access policy is unsupported.","Automated allow or block enforcement.","Stage 1 plus identity-aware policy for a documented resource.","Established baseline: stage 2 with both public-web and private-resource access. No novelty claim.","Stage 3 plus a specific shipped beyond-baseline workflow with documented distinction and limits.","Stage 4 plus multiple beyond-baseline workflows with independently evaluated outcomes."]},{"id":"breadth","name":"Capability breadth","description":"Capabilities within the selected remote-user baseline; unrelated suite breadth is excluded.","question":"Which access paths and policy context are documented for the selected configuration?","anchors":["The vendor explicitly states that neither public nor private access is supported.","A documented public-web or private-resource access path.","Both public-web filtering and private-resource access.","Stage 2 plus identity and device-context selectors in the selected access policy.","Stage 3 plus documented non-browser private protocols and unmanaged-device access within the purchased scope.","Stage 4 plus explicit protocol and device limitations across every selected path."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented client, identity and evidence connections, without awarding points for portfolio size.","question":"How does the access service connect to identity systems and security operations?","anchors":["The vendor explicitly states that external integration is unsupported.","A documented client, connector or identity integration.","Stage 1 plus an external log-export or configuration interface.","Stage 2 plus documented interface authentication and integration permissions.","Stage 3 plus version compatibility, limits and failure diagnosis for the selected interfaces.","Stage 4 plus extensibility lifecycle and independently tested integration recovery."]},{"id":"governance","name":"Governance & control","description":"Documented authority and audit for changing access policy; compliance is not inferred.","question":"Who can change access and reconstruct the change?","anchors":["The vendor explicitly states that administration controls are absent.","Configurable access rules.","Stage 1 plus documented administrator roles separating observation from changes or defining scoped authority.","Stage 2 plus actor-attributed configuration audit records.","Stage 3 plus controlled exceptions and delegated administration across selected services.","Stage 4 plus exportable change evidence and recurring access-review procedures."]},{"id":"operations","name":"Operator enablement","description":"Practitioner instructions for setup, investigation and safe change in the selected access scope.","question":"Can a team follow the setup and diagnose why access succeeds or fails?","anchors":["The vendor explicitly states that operational guidance is unavailable.","Documented setup or policy configuration.","Stage 1 plus instructions to inspect access or policy outcomes.","Stage 2 plus connection diagnostics and explicit path, device or policy limitations.","Stage 3 plus repeatable rollout and connector or service recovery procedures.","Stage 4 plus training and a documented service-exit procedure."]}],"assessments":[{"vendor":"zscaler-secure-access","cohort":"remote-user-public-private-access","edition":"Zscaler ZIA URL Filtering plus ZPA private application access, Client Connector, App Connectors and ZPA log streaming; no ZDX, RBI or SD-WAN credit","asOf":"2026-09-21","status":"research-preview","summary":"The documentation establishes two traffic paths, application policy and log streaming. It does not establish a measured performance or availability advantage.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"ZPA setup and logging, paired with documented ZIA URL policy, establish public/private policy and investigation. Diagnostics, live-session change effects and complete recovery were not verified.","sourceIds":["s1","s2","s5"]},"innovation":{"score":3,"confidence":"medium","rationale":"Identity-aware private access and public URL policy satisfy the established baseline. Architecture branding is not evidence of beyond-baseline innovation.","sourceIds":["s1","s2","s5"]},"breadth":{"score":3,"confidence":"medium","rationale":"Both traffic paths are documented; private access policy additionally accepts identity and device posture conditions. Broader protocol and unmanaged access entitlements were not fully audited.","sourceIds":["s1","s2","s5","s6"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Client and identity setup, log streaming and a policy API are documented. The selected external API authentication/permission contract was not fully inspected for stage 3.","sourceIds":["s1","s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Private Access setup identifies administrator roles, while URL filtering describes admin rank boundaries. Complete actor-attributed change-audit fields across both services were not verified.","sourceIds":["s1","s5"]},"operations":{"score":2,"confidence":"medium","rationale":"Setup, policy and log-streaming guidance support configuration and outcome inspection. The selected evidence does not establish a full connection-diagnostic procedure.","sourceIds":["s1","s5"]}},"constraints":["ZIA and ZPA are explicitly selected services; a ZPA-only license does not satisfy this cohort.","The posture-policy source documents a legacy UI; validate the equivalent current-console settings in the pilot.","Direct rendering of some help pages was limited; specific official indexed text supplied the cited workflow evidence.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"ZPA configuration workflow","url":"https://help.zscaler.com/zpa/step-step-configuration-guide-private-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Private Access architecture","url":"https://help.zscaler.com/zpa/understanding-zpa-cloud-architecture","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"ZIA to ZPA forwarding policy","url":"https://help.zscaler.com/zia/configuring-forwarding-policies-source-ip-anchoring-using-zpa","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Private Access policy API","url":"https://help.zscaler.com/zpa/configuring-access-policies-using-api","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"ZIA URL policy","url":"https://help.zscaler.com/zia/configuring-url-filtering-policy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"ZPA access policy context","url":"https://help.zscaler.com/legacy-zpa//about-access-policy","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Zscaler Internet & SaaS and Private Access","company":"Zscaler","profileUrl":"/landscape/vendors/zscaler-secure-access/"},{"vendor":"cloudflare-one-access","cohort":"remote-user-public-private-access","edition":"Cloudflare One Enterprise configuration selecting Access and Gateway HTTP filtering, Cloudflare One Client, Tunnel and log export; DLP/RBI/CASB/WAN excluded","asOf":"2026-09-21","status":"research-preview","summary":"Public and private policy procedures are documented alongside client diagnostics and account-change logs. Required routing and certificate trust remain deployment responsibilities.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Access/Tunnel setup, Gateway policy and logs establish stage 3. Client diagnostic collection adds 0.3; live-session change behavior and service recovery were not audited.","sourceIds":["s1","s2","s3","s4","s5"],"refinement":{"base":3,"evidence":[{"criterion":"diagnostics","rationale":"The client documentation provides a diagnostic collection workflow for failed connectivity.","sourceIds":["s5"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Application identity policy plus public HTTP policy is the established baseline. No extra innovation credit is inferred from the common platform.","sourceIds":["s1","s2","s4"]},"breadth":{"score":3,"confidence":"medium","rationale":"Private web access and public HTTP filtering are documented with identity and device-posture selectors. Broader agentless protocols are outside this selected baseline.","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Tunnel/client and identity-provider paths plus documented external log export establish stage 2. Export/API authentication and permissions were not fully audited.","sourceIds":["s3","s4","s6"]},"governance":{"score":3,"confidence":"medium","rationale":"Roles distinguish access to configuration, and admin logs identify the actor, action and old/new values. A controlled exception-approval lifecycle was not established.","sourceIds":["s1","s6","s7"]},"operations":{"score":3,"confidence":"medium","rationale":"Private application setup, policy/log review, client diagnostics and TLS prerequisites establish stage 3. Complete rollout/recovery was not reviewed.","sourceIds":["s2","s3","s4","s5"]}},"constraints":["Gateway HTTPS inspection requires the appropriate certificate and traffic path. A connection alone is not evidence of inspection.","Retention varies by log type. Administrative Logpush export is evaluated only with the explicitly selected Enterprise entitlement.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Access policies","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/policies/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"HTTP policies and TLS requirements","url":"https://developers.cloudflare.com/cloudflare-one/traffic-policies/http-policies/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Zero Trust logs","url":"https://developers.cloudflare.com/cloudflare-one/insights/logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Private web application setup","url":"https://developers.cloudflare.com/cloudflare-one/setup/secure-private-apps/private-web-app/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Client diagnostic logs","url":"https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Administrative change logs","url":"https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/admin-activity-logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Roles and permissions","url":"https://developers.cloudflare.com/cloudflare-one/roles-permissions/","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Cloudflare One: Access and Gateway","company":"Cloudflare","profileUrl":"/landscape/vendors/cloudflare-one-access/"},{"vendor":"cisco-secure-access","cohort":"remote-user-public-private-access","edition":"Cisco Secure Access subscription selecting internet and private access, associated client/connectivity and Activity Search; optional DLP/RBI and separate Cisco products excluded","asOf":"2026-09-21","status":"research-preview","summary":"Resource policy and outcome validation are documented, with administrative roles and remote-access troubleshooting evidence. A wider Cisco portfolio does not receive implicit credit.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"The quickstart configures both internet and private rules and validates traffic in Activity Search. Remote-access diagnostic fields add 0.3; session-change behavior and recovery were not verified.","sourceIds":["s1","s2","s4"],"refinement":{"base":3,"evidence":[{"criterion":"diagnostics","rationale":"The report documents failed-event, device and posture fields useful for diagnosing access connections.","sourceIds":["s4"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"User/resource policy across public and private access is an established SSE workflow. No beyond-baseline shipped innovation was substantiated.","sourceIds":["s1","s2"]},"breadth":{"score":2,"confidence":"medium","rationale":"Internet and private resource rules are documented. Posture-related diagnostic fields alone do not establish every device-context policy condition for the next anchor.","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":1,"confidence":"medium","rationale":"Documented resource and remote-client connections establish the baseline integration. External log-export or authenticated configuration interfaces were not audited.","sourceIds":["s1","s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Administrator roles distinguish viewing from changing service configuration. The selected sources do not establish actor-attributed configuration audit.","sourceIds":["s2","s3"]},"operations":{"score":3,"confidence":"medium","rationale":"Setup and an explicit traffic-validation exercise combine with diagnostic fields and documented resource limits. Full rollout/recovery was not established.","sourceIds":["s1","s2","s4"]}},"constraints":["Zero trust access and remote-access VPN reporting have different meanings. An enrollment event does not by itself prove an application-policy decision.","Confirm the current commercial package enables both compared paths; existing Umbrella or other Cisco entitlements are not assumed sufficient.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Resource objects and scope","url":"https://docs.sse.cisco.com/sse-user-guide/docs/manage-network-and-service-objects","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Policy and validation quickstart","url":"https://docs.sse.cisco.com/sse-user-guide/docs/quickstart-network-and-service-objects","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Administrator roles","url":"https://docs.sse.cisco.com/sse-user-guide/docs/manage-accounts","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Remote access diagnostics","url":"https://docs.sse.cisco.com/sse-user-guide/docs/remote-access-log-report","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Cisco Secure Access","company":"Cisco","profileUrl":"/landscape/vendors/cisco-secure-access/"},{"vendor":"fortinet-fortisase","cohort":"remote-user-public-private-access","edition":"FortiSASE Secure Internet Access plus Secure Private Access for managed remote users, FortiClient and the selected SPA connectivity; no SD-WAN/RBI credit","asOf":"2026-09-21","status":"research-preview","summary":"Documented traffic steering, ordered policy and retention controls establish a public/private operating baseline. Policy-change timing is explicitly important for connected agents.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Internet/private configuration, traffic policy and logs establish stage 3. The documented reconnect requirement for affected agents earns 0.3 for change behavior; diagnostics and recovery were not established.","sourceIds":["s1","s2","s3","s4"],"refinement":{"base":3,"evidence":[{"criterion":"change-behavior","rationale":"Policy guidance states that existing policy changes take effect for affected SSL remote agents after reconnecting.","sourceIds":["s2"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Configured user-aware public/private traffic enforcement meets the established access baseline. No beyond-baseline innovation evidence was reviewed.","sourceIds":["s1","s2","s3"]},"breadth":{"score":2,"confidence":"medium","rationale":"Public web and private resource paths are documented. A complete device-context selector contract for the selected configuration was not audited.","sourceIds":["s1","s3"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Client/connector steering and an external log-forwarding path are documented. Export authentication and permissions were not verified for the next anchor.","sourceIds":["s1","s4"]},"governance":{"score":1,"confidence":"medium","rationale":"Configurable traffic rules establish stage 1. The administration source could not be directly accessed and a complete role/authority evidence chain was not established for the next anchor.","sourceIds":["s2"]},"operations":{"score":2,"confidence":"medium","rationale":"Configuration, ordered policy and log-retention procedures support operating the baseline. A complete connection-diagnostic procedure was not verified.","sourceIds":["s1","s2","s3","s4"]}},"constraints":["Policy changes can require reconnecting affected SSL agents. The scored source documents SPA client-to-server behavior in version 7.2.0; validate version equivalence for the deployed release.","Log storage can rotate before the requested retention window. External forwarding and adequate capacity require explicit configuration.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Secure Internet Access architecture","url":"https://docs.fortinet.com/document/fortisase/latest/secure-internet-access-architecture-guide","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Policy ordering and reconnect behavior","url":"https://docs.fortinet.com/document/fortisase/latest/administration-guide/525953/policies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Private access policy","url":"https://docs.fortinet.com/document/fortisase/7.2.0/administration-guide/544322/configuring-a-private-access-policy-for-client-to-server-traffic","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Log retention policy","url":"https://docs.fortinet.com/document/fortisase/latest/mature-administration-guide/737460","accessedAt":"2026-09-21","kind":"documentation"}],"name":"FortiSASE","company":"Fortinet","profileUrl":"/landscape/vendors/fortinet-fortisase/"}],"scenarios":[{"id":"contractor-private-app","name":"One contractor, one private application","description":"An authorized test contractor needs one lab application while adjacent resources remain inaccessible.","questions":["Which identity and device conditions authorize the session?","Can the user reach neighboring applications or network ranges?","What happens to an existing session when access is removed?"],"priorities":["maturity","governance","breadth"]},{"id":"web-policy-evidence","name":"Explain an outbound web decision","description":"Trace one harmless allowed request and one blocked request through a managed endpoint and the selected web policy.","questions":["Was the request actually steered through the service?","Was HTTPS content inspected or bypassed?","Can another analyst reconstruct the policy and decision from exported evidence?"],"priorities":["operations","ecosystem","maturity"]}],"researchNotes":["Public primary-source baseline dated 2026-09-21. No service was deployed or benchmarked and no historical momentum is inferred.","SSE and SASE portfolio labels do not define comparable entitlements. These assessments select the public-web/private-access workflow; optional networking and data modules receive no score credit.","Documentation alone earns at most medium confidence. Scores are conservative verified stages; unknown cells identify a missing evidence chain, not an absent product feature.","Shared maturity refinements divide the next anchor into diagnostics (0.3), change behavior (0.3) and recovery (0.4). No vendor-specific weighting or visual spreading is used.","Zscaler and Fortinet pages can be JavaScript-heavy or deny direct fetch. Specific indexed official documentation was readable for the cited claims; direct-access limitations are recorded in the research report."],"history":{"segment":"secure-access","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"secure-access","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"remote-user-public-private-access","name":"Remote-user public and private access","scope":"Selected commercial configurations providing both outbound web policy and private application access for managed remote users. Required SWG/private-access modules, clients and connectors are explicit. No score credit for SD-WAN, branch hardware, backbone size, optional CASB API scanning, DLP, RBI or managed services."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented operating workflow for the selected public and private access configuration. It measures evidence of operation, not uptime or deployment age.","question":"Can operators configure access, investigate policy outcomes and understand change or failure behavior?","anchors":["The vendor explicitly states that the selected access service is unavailable.","A documented public or private access setup.","Stage 1 plus both public-web and private-resource paths with configurable access policy.","Stage 2 plus reviewable policy or connection logs for investigation.","Stage 3 plus connection diagnostics, documented policy-change/session behavior and connector or service recovery procedures.","Stage 4 plus controlled configuration promotion and independently exercised failure recovery."],"refinements":[{"base":3,"criteria":[{"id":"diagnostics","label":"Documented procedure or report for diagnosing failed client or access connections","weight":3},{"id":"change-behavior","label":"Documented effect of policy changes on existing sessions or connected clients","weight":3},{"id":"recovery","label":"Documented connector or service failure recovery in the selected scope","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Evidence of a shipped access workflow beyond the established identity-aware public/private policy model.","question":"Which delivered workflow exceeds the comparison baseline with explicit evidence and limits?","anchors":["The vendor explicitly states that automated access policy is unsupported.","Automated allow or block enforcement.","Stage 1 plus identity-aware policy for a documented resource.","Established baseline: stage 2 with both public-web and private-resource access. No novelty claim.","Stage 3 plus a specific shipped beyond-baseline workflow with documented distinction and limits.","Stage 4 plus multiple beyond-baseline workflows with independently evaluated outcomes."]},{"id":"breadth","name":"Capability breadth","description":"Capabilities within the selected remote-user baseline; unrelated suite breadth is excluded.","question":"Which access paths and policy context are documented for the selected configuration?","anchors":["The vendor explicitly states that neither public nor private access is supported.","A documented public-web or private-resource access path.","Both public-web filtering and private-resource access.","Stage 2 plus identity and device-context selectors in the selected access policy.","Stage 3 plus documented non-browser private protocols and unmanaged-device access within the purchased scope.","Stage 4 plus explicit protocol and device limitations across every selected path."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented client, identity and evidence connections, without awarding points for portfolio size.","question":"How does the access service connect to identity systems and security operations?","anchors":["The vendor explicitly states that external integration is unsupported.","A documented client, connector or identity integration.","Stage 1 plus an external log-export or configuration interface.","Stage 2 plus documented interface authentication and integration permissions.","Stage 3 plus version compatibility, limits and failure diagnosis for the selected interfaces.","Stage 4 plus extensibility lifecycle and independently tested integration recovery."]},{"id":"governance","name":"Governance & control","description":"Documented authority and audit for changing access policy; compliance is not inferred.","question":"Who can change access and reconstruct the change?","anchors":["The vendor explicitly states that administration controls are absent.","Configurable access rules.","Stage 1 plus documented administrator roles separating observation from changes or defining scoped authority.","Stage 2 plus actor-attributed configuration audit records.","Stage 3 plus controlled exceptions and delegated administration across selected services.","Stage 4 plus exportable change evidence and recurring access-review procedures."]},{"id":"operations","name":"Operator enablement","description":"Practitioner instructions for setup, investigation and safe change in the selected access scope.","question":"Can a team follow the setup and diagnose why access succeeds or fails?","anchors":["The vendor explicitly states that operational guidance is unavailable.","Documented setup or policy configuration.","Stage 1 plus instructions to inspect access or policy outcomes.","Stage 2 plus connection diagnostics and explicit path, device or policy limitations.","Stage 3 plus repeatable rollout and connector or service recovery procedures.","Stage 4 plus training and a documented service-exit procedure."]}],"assessments":[{"vendor":"zscaler-secure-access","cohort":"remote-user-public-private-access","edition":"Zscaler ZIA URL Filtering plus ZPA private application access, Client Connector, App Connectors and ZPA log streaming; no ZDX, RBI or SD-WAN credit","asOf":"2026-09-21","status":"research-preview","summary":"The documentation establishes two traffic paths, application policy and log streaming. It does not establish a measured performance or availability advantage.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"ZPA setup and logging, paired with documented ZIA URL policy, establish public/private policy and investigation. Diagnostics, live-session change effects and complete recovery were not verified.","sourceIds":["s1","s2","s5"]},"innovation":{"score":3,"confidence":"medium","rationale":"Identity-aware private access and public URL policy satisfy the established baseline. Architecture branding is not evidence of beyond-baseline innovation.","sourceIds":["s1","s2","s5"]},"breadth":{"score":3,"confidence":"medium","rationale":"Both traffic paths are documented; private access policy additionally accepts identity and device posture conditions. Broader protocol and unmanaged access entitlements were not fully audited.","sourceIds":["s1","s2","s5","s6"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Client and identity setup, log streaming and a policy API are documented. The selected external API authentication/permission contract was not fully inspected for stage 3.","sourceIds":["s1","s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Private Access setup identifies administrator roles, while URL filtering describes admin rank boundaries. Complete actor-attributed change-audit fields across both services were not verified.","sourceIds":["s1","s5"]},"operations":{"score":2,"confidence":"medium","rationale":"Setup, policy and log-streaming guidance support configuration and outcome inspection. The selected evidence does not establish a full connection-diagnostic procedure.","sourceIds":["s1","s5"]}},"constraints":["ZIA and ZPA are explicitly selected services; a ZPA-only license does not satisfy this cohort.","The posture-policy source documents a legacy UI; validate the equivalent current-console settings in the pilot.","Direct rendering of some help pages was limited; specific official indexed text supplied the cited workflow evidence.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"ZPA configuration workflow","url":"https://help.zscaler.com/zpa/step-step-configuration-guide-private-access","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Private Access architecture","url":"https://help.zscaler.com/zpa/understanding-zpa-cloud-architecture","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"ZIA to ZPA forwarding policy","url":"https://help.zscaler.com/zia/configuring-forwarding-policies-source-ip-anchoring-using-zpa","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Private Access policy API","url":"https://help.zscaler.com/zpa/configuring-access-policies-using-api","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"ZIA URL policy","url":"https://help.zscaler.com/zia/configuring-url-filtering-policy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"ZPA access policy context","url":"https://help.zscaler.com/legacy-zpa//about-access-policy","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cloudflare-one-access","cohort":"remote-user-public-private-access","edition":"Cloudflare One Enterprise configuration selecting Access and Gateway HTTP filtering, Cloudflare One Client, Tunnel and log export; DLP/RBI/CASB/WAN excluded","asOf":"2026-09-21","status":"research-preview","summary":"Public and private policy procedures are documented alongside client diagnostics and account-change logs. Required routing and certificate trust remain deployment responsibilities.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Access/Tunnel setup, Gateway policy and logs establish stage 3. Client diagnostic collection adds 0.3; live-session change behavior and service recovery were not audited.","sourceIds":["s1","s2","s3","s4","s5"],"refinement":{"base":3,"evidence":[{"criterion":"diagnostics","rationale":"The client documentation provides a diagnostic collection workflow for failed connectivity.","sourceIds":["s5"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Application identity policy plus public HTTP policy is the established baseline. No extra innovation credit is inferred from the common platform.","sourceIds":["s1","s2","s4"]},"breadth":{"score":3,"confidence":"medium","rationale":"Private web access and public HTTP filtering are documented with identity and device-posture selectors. Broader agentless protocols are outside this selected baseline.","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Tunnel/client and identity-provider paths plus documented external log export establish stage 2. Export/API authentication and permissions were not fully audited.","sourceIds":["s3","s4","s6"]},"governance":{"score":3,"confidence":"medium","rationale":"Roles distinguish access to configuration, and admin logs identify the actor, action and old/new values. A controlled exception-approval lifecycle was not established.","sourceIds":["s1","s6","s7"]},"operations":{"score":3,"confidence":"medium","rationale":"Private application setup, policy/log review, client diagnostics and TLS prerequisites establish stage 3. Complete rollout/recovery was not reviewed.","sourceIds":["s2","s3","s4","s5"]}},"constraints":["Gateway HTTPS inspection requires the appropriate certificate and traffic path. A connection alone is not evidence of inspection.","Retention varies by log type. Administrative Logpush export is evaluated only with the explicitly selected Enterprise entitlement.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Access policies","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/policies/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"HTTP policies and TLS requirements","url":"https://developers.cloudflare.com/cloudflare-one/traffic-policies/http-policies/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Zero Trust logs","url":"https://developers.cloudflare.com/cloudflare-one/insights/logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Private web application setup","url":"https://developers.cloudflare.com/cloudflare-one/setup/secure-private-apps/private-web-app/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Client diagnostic logs","url":"https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Administrative change logs","url":"https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/admin-activity-logs/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Roles and permissions","url":"https://developers.cloudflare.com/cloudflare-one/roles-permissions/","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cisco-secure-access","cohort":"remote-user-public-private-access","edition":"Cisco Secure Access subscription selecting internet and private access, associated client/connectivity and Activity Search; optional DLP/RBI and separate Cisco products excluded","asOf":"2026-09-21","status":"research-preview","summary":"Resource policy and outcome validation are documented, with administrative roles and remote-access troubleshooting evidence. A wider Cisco portfolio does not receive implicit credit.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"The quickstart configures both internet and private rules and validates traffic in Activity Search. Remote-access diagnostic fields add 0.3; session-change behavior and recovery were not verified.","sourceIds":["s1","s2","s4"],"refinement":{"base":3,"evidence":[{"criterion":"diagnostics","rationale":"The report documents failed-event, device and posture fields useful for diagnosing access connections.","sourceIds":["s4"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"User/resource policy across public and private access is an established SSE workflow. No beyond-baseline shipped innovation was substantiated.","sourceIds":["s1","s2"]},"breadth":{"score":2,"confidence":"medium","rationale":"Internet and private resource rules are documented. Posture-related diagnostic fields alone do not establish every device-context policy condition for the next anchor.","sourceIds":["s1","s2","s4"]},"ecosystem":{"score":1,"confidence":"medium","rationale":"Documented resource and remote-client connections establish the baseline integration. External log-export or authenticated configuration interfaces were not audited.","sourceIds":["s1","s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Administrator roles distinguish viewing from changing service configuration. The selected sources do not establish actor-attributed configuration audit.","sourceIds":["s2","s3"]},"operations":{"score":3,"confidence":"medium","rationale":"Setup and an explicit traffic-validation exercise combine with diagnostic fields and documented resource limits. Full rollout/recovery was not established.","sourceIds":["s1","s2","s4"]}},"constraints":["Zero trust access and remote-access VPN reporting have different meanings. An enrollment event does not by itself prove an application-policy decision.","Confirm the current commercial package enables both compared paths; existing Umbrella or other Cisco entitlements are not assumed sufficient.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Resource objects and scope","url":"https://docs.sse.cisco.com/sse-user-guide/docs/manage-network-and-service-objects","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Policy and validation quickstart","url":"https://docs.sse.cisco.com/sse-user-guide/docs/quickstart-network-and-service-objects","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Administrator roles","url":"https://docs.sse.cisco.com/sse-user-guide/docs/manage-accounts","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Remote access diagnostics","url":"https://docs.sse.cisco.com/sse-user-guide/docs/remote-access-log-report","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"fortinet-fortisase","cohort":"remote-user-public-private-access","edition":"FortiSASE Secure Internet Access plus Secure Private Access for managed remote users, FortiClient and the selected SPA connectivity; no SD-WAN/RBI credit","asOf":"2026-09-21","status":"research-preview","summary":"Documented traffic steering, ordered policy and retention controls establish a public/private operating baseline. Policy-change timing is explicitly important for connected agents.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Internet/private configuration, traffic policy and logs establish stage 3. The documented reconnect requirement for affected agents earns 0.3 for change behavior; diagnostics and recovery were not established.","sourceIds":["s1","s2","s3","s4"],"refinement":{"base":3,"evidence":[{"criterion":"change-behavior","rationale":"Policy guidance states that existing policy changes take effect for affected SSL remote agents after reconnecting.","sourceIds":["s2"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Configured user-aware public/private traffic enforcement meets the established access baseline. No beyond-baseline innovation evidence was reviewed.","sourceIds":["s1","s2","s3"]},"breadth":{"score":2,"confidence":"medium","rationale":"Public web and private resource paths are documented. A complete device-context selector contract for the selected configuration was not audited.","sourceIds":["s1","s3"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Client/connector steering and an external log-forwarding path are documented. Export authentication and permissions were not verified for the next anchor.","sourceIds":["s1","s4"]},"governance":{"score":1,"confidence":"medium","rationale":"Configurable traffic rules establish stage 1. The administration source could not be directly accessed and a complete role/authority evidence chain was not established for the next anchor.","sourceIds":["s2"]},"operations":{"score":2,"confidence":"medium","rationale":"Configuration, ordered policy and log-retention procedures support operating the baseline. A complete connection-diagnostic procedure was not verified.","sourceIds":["s1","s2","s3","s4"]}},"constraints":["Policy changes can require reconnecting affected SSL agents. The scored source documents SPA client-to-server behavior in version 7.2.0; validate version equivalence for the deployed release.","Log storage can rotate before the requested retention window. External forwarding and adequate capacity require explicit configuration.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Secure Internet Access architecture","url":"https://docs.fortinet.com/document/fortisase/latest/secure-internet-access-architecture-guide","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Policy ordering and reconnect behavior","url":"https://docs.fortinet.com/document/fortisase/latest/administration-guide/525953/policies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Private access policy","url":"https://docs.fortinet.com/document/fortisase/7.2.0/administration-guide/544322/configuring-a-private-access-policy-for-client-to-server-traffic","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Log retention policy","url":"https://docs.fortinet.com/document/fortisase/latest/mature-administration-guide/737460","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"contractor-private-app","name":"One contractor, one private application","description":"An authorized test contractor needs one lab application while adjacent resources remain inaccessible.","questions":["Which identity and device conditions authorize the session?","Can the user reach neighboring applications or network ranges?","What happens to an existing session when access is removed?"],"priorities":["maturity","governance","breadth"]},{"id":"web-policy-evidence","name":"Explain an outbound web decision","description":"Trace one harmless allowed request and one blocked request through a managed endpoint and the selected web policy.","questions":["Was the request actually steered through the service?","Was HTTPS content inspected or bypassed?","Can another analyst reconstruct the policy and decision from exported evidence?"],"priorities":["operations","ecosystem","maturity"]}],"researchNotes":["Public primary-source baseline dated 2026-09-21. No service was deployed or benchmarked and no historical momentum is inferred.","SSE and SASE portfolio labels do not define comparable entitlements. These assessments select the public-web/private-access workflow; optional networking and data modules receive no score credit.","Documentation alone earns at most medium confidence. Scores are conservative verified stages; unknown cells identify a missing evidence chain, not an absent product feature.","Shared maturity refinements divide the next anchor into diagnostics (0.3), change behavior (0.3) and recovery (0.4). No vendor-specific weighting or visual spreading is used.","Zscaler and Fortinet pages can be JavaScript-heavy or deny direct fetch. Specific indexed official documentation was readable for the cited claims; direct-access limitations are recorded in the research report."]},"changes":[]}]},"unassessed":[{"slug":"netskope-one-sse","name":"Netskope One SSE","company":"Netskope","profileUrl":"/landscape/vendors/netskope-one-sse/"},{"slug":"palo-alto-prisma-access","name":"Prisma Access","company":"Palo Alto Networks","profileUrl":"/landscape/vendors/palo-alto-prisma-access/"},{"slug":"cato-sse","name":"Cato SSE","company":"Cato Networks","profileUrl":"/landscape/vendors/cato-sse/"},{"slug":"checkpoint-sase","name":"Check Point SASE","company":"Check Point","profileUrl":"/landscape/vendors/checkpoint-sase/"}]}