Glossary
No access is trusted merely because it comes from the internal network. Every request is verified.
The model replaces the idea of inside and outside. Instead of a wall around the network, every connection is authenticated and authorized, regardless of location.
In practice that means identity for services, short-lived credentials, encryption internally too, and permissions checked per request.