Enterprise Trust — Zero Trust / PKI / IAM / Segmentation

Every system has a boundary. We make sure it's the right one, it holds, and nobody notices it's there.

Barbican Cloud designs, builds, and tests the access boundaries — identity, network, and cryptographic — that enterprises actually rely on, not just the ones on the architecture diagram.

Sample — Boundary Decision
Identity
priya.natarajan@acme-corp.com
Method
SAML — Entra ID
Resource
finance/reporting — restricted
Policy
mfa + corp-device + group:finance-ro
Decision ALLOW — 0.04s

Every request evaluated. Every decision recorded.

What We Secure

Four boundaries, one discipline.

Different mechanisms, same question at every layer: what's allowed through, and what proves it should be.

ZT

Zero Trust Access

Policy enforced at every request, not once at the network edge. Identity, device, and context evaluated continuously — not inherited from a VPN handshake.

PKI

Public Key Infrastructure

Certificate authorities, issuance, and revocation that hold up under audit — not just on the day they were issued. Mutual TLS as a real, tested boundary.

IAM

Identity & Access Management

Federation, provisioning, and lifecycle across the identity providers you actually run — SAML and OIDC that behave correctly under real claim mapping, not the demo case.

NS

Network Segmentation

Boundaries drawn around what matters, not around the whole flat network. Segmentation that survives contact with how the business actually operates.

How We Work

Five questions, asked in order, every engagement.

Not a framework for its own sake — the order matters, because each answer changes what the next one has to be.

01

What boundary should exist

Scope the actual asset and the actual threat — not the generic checklist someone else wrote.

02

Does it exist

Audit what's really enforced, versus what's documented as enforced.

03

How is it secured

The actual mechanism — certificate, token, policy, segmentation rule — and what happens when it's bypassed.

04

Does it work

Tested like an attacker would test it, not like a compliance form expects it to be tested.

05

Is it frictionless

A boundary people route around isn't a boundary. The measure of success is that nobody has to think about it.

The Workshop

Every protocol here is actually wired up.

OIDC, SAML, SCIM, mTLS, service tokens — implemented and running, not slides. It's where we learn by building, and where you can see the mechanics instead of taking our word for them.

Field Notes

Short-form writing, not thought leadership.

Notes from building the workshop, not marketing copy about it. First pieces in progress:

"Zero Trust" is a marketing term for access control

The industry needed a name for "stop trusting the network." Here's what actually changed underneath it.

In progress

What SCIM sync actually breaks in practice

Group membership changes propagate — until they don't. Notes from wiring Entra to Cloudflare Access.

In progress

mTLS is the boundary nobody notices until it fails

Client certificates are the quietest access control mechanism in production — and the least forgiving when they expire.

In progress