Policy engines create critical dependencies

If every request is checked against a central policy service, that service is now load-bearing for everything.

When it is slow, everything is slow. When it is unavailable, you have to decide in advance whether the answer is to let everything through or block everything, and both are bad in different ways. It is a reasonable architecture and it moves the risk rather than removing it, which is worth knowing before it is the thing that is down.

More on Zero trust