A cloud-based private access
system integrates static CMDB data with real-time access
telemetry to automate Zero Trust segmentation. Administrators upload CMDB files (e.g., CSV /
JSON) describing applications, FQDNs, IPs, ports, protocols, ownership, and priorities. An analytics management service stages and normalizes the data, retrieves reference domain data from an in-memory cache, and queries a
telemetry engine to correlate intended configurations with observed usage. The
system detects mismatches, over-permissive wildcard access, and auto-discovers non-listed elements such as subdomains, ports, or protocol combinations. It then generates prioritized recommendations to refine wildcard rules, create explicit allow policies, and merge or split application groups. Administrators review, simulate, and approve updates, enabling phased rollout,
rollback, auditing, and continuous policy tuning based on evolving user and application behavior.