The early win is easy: stronger logins, cleaner access rules, better visibility. The hard part is keeping a zero-trust program coherent once exceptions, legacy systems, and shared ownership start to pile up.