Open reference architecture

Zero-Trust SaaS Architecture

A practical identity-first control model for organisations whose business estate spans multiple SaaS platforms.

Identity first

Centralise identity where practical, enforce MFA appropriate to risk and remove dormant identities quickly.

Least privilege

Use role-based access and time-bounded elevation; separate normal work from privileged administration.

Device & session

Use device/session controls proportionate to sensitivity; reduce persistent sessions for privileged functions.

SaaS inventory

Maintain ownership, purpose, data classification, integrations, renewal and exit information for material services.

OAuth & integrations

Review scopes and service accounts; revoke abandoned tokens and avoid broad delegated access.

Data boundaries

Know what data enters each SaaS service, where exports exist and which subprocessors/regions materially affect risk.

Detection

Monitor meaningful authentication, privilege, sharing and integration events where the service exposes them.

Offboarding

Remove identity, sessions, tokens, shared access and data copies through a documented leaver/supplier-exit process.