Published · yesterdayLeadership3 min read
Beyond Zero: Google names the agent era's default security model before anyone else can
Google's new model extends zero trust into the authorization layer, and it arrives the way BeyondCorp did: paper first, implementation data later. The vocabulary reaches auditors before the numbers do.
Context for builders, not their beat.See today for builders
What happened
- Google released the BeyondCorp whitepaper in 2014, the start of what it describes as a near decade-long push to establish zero trust as the desired model for securing enterprise networks.
- Google says other enterprises and the wider security industry adopted zero trust as the standard for what good enterprise security looks like.
- Beyond Zero is described by Google as a contextual, risk-based, resource-level authorization model designed to run at machine speed for humans and agents alike, extending zero trust into the authorization layer so that every single action taken inside an enterprise is authorized.
- First principle: authorization decisions are evaluated at the level of individual actions on specific resources rather than granting broad access to an entire application or tool, and this applies uniformly across all access methods including front-end interfaces, APIs and the Model Context Protocol (MCP).
- Second principle: granular static policies are paired with dynamic controls that apply heightened security measures during high-risk or complex scenarios, rather than moving to a fully dynamic model that is hard to verify statically.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
The instrument here is a paper series, and that is the part operators should study. Google says later papers will carry implementation data and operational insight, following the sequencing it used for the original BeyondCorp series [11]. It also says the 2014 BeyondCorp whitepaper opened a near decade-long push before zero trust became the accepted description of good enterprise network security [1][2]. So the shape of this is known: the words circulate for years while the evidence stays internal [16]. Nobody outside Alphabet will be able to check the claim for a while, and everybody will be able to quote the term next quarter.
What is actually specified is more demanding than the announcement language implies. Authorization is to be decided per action on a specific resource rather than by granting access to a whole application or tool, and the same rule is meant to hold across front-end interfaces, APIs and the Model Context Protocol [4]. For any application that currently grants access at the application or role level, satisfying that means lifting the decision out of the application and into a service that can be handed context about the user, the data being touched, and what the action intends to do with it [6]. That is engineering on the applications you already own. It does not arrive as a licence.
Two of the five principles push the work further into the agents themselves. Risk signals are supposed to trigger investigations autonomously, deploying challenges or containment across the access stream [7], and policy is supposed to be able to demand additional risk telemetry from a user or an agent on demand [8]. An agent that cannot answer a challenge fails closed. That is a design requirement on the things your teams are building this year, not a control the security group can bolt on afterwards.
The evidence offered is thin by Google's own presentation: no figures accompany the reported internal results [15]. And the architecture in the first paper is the one built inside Alphabet [10], which is where the cost of translation sits, unpriced.
Google says industry-wide adoption of continuous authorization is early and that peer organizations and industry bodies are starting to build comparable frameworks [12], without naming them in the post. That is the real contest. Five named principles are a checklist an audit committee can read out loud, one line at a time [4][5][6][7][8]. "We run zero trust" answers none of those five for an agent calling tools at machine speed [3]. Whoever gets the checkable list into circulation first owns the question, and Google has just filed it.
The defensible position: Beyond Zero is a statement of intent with a named author and no conformance test. The plumbing it describes, per-action authorization with enriched context, is what any organisation letting agents act on resources at speed will need under some name [3][13]. Buy the plumbing, not the term.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Google released the BeyondCorp whitepaper in 2014, the start of what it describes as a near decade-long push to establish zero trust as the desired model for securing enterprise networks.
- [2]
Google says other enterprises and the wider security industry adopted zero trust as the standard for what good enterprise security looks like.
- [3]
Beyond Zero is described by Google as a contextual, risk-based, resource-level authorization model designed to run at machine speed for humans and agents alike, extending zero trust into the authorization layer so that every single action taken inside an enterprise is authorized.
- [4]
First principle: authorization decisions are evaluated at the level of individual actions on specific resources rather than granting broad access to an entire application or tool, and this applies uniformly across all access methods including front-end interfaces, APIs and the Model Context Protocol (MCP).
- [5]
Second principle: granular static policies are paired with dynamic controls that apply heightened security measures during high-risk or complex scenarios, rather than moving to a fully dynamic model that is hard to verify statically.
- [6]
Third principle: decision systems draw on automatically enriched context including the user action, what the user should be working on, what data the action interacts with, what it is attempting to do with that data, and what risk mitigations are available; these facts are always available to the decision infrastructure.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- blog.google2d agoGoogle introduces Beyond Zero for AI enterprise security
Cited in this coverage: blog.google



