Zscaler Internet Access
Integration & Setup Manual
Zscaler Internet Access (ZIA) Integration Guide
Overview
Cup’n’String Guard integrates with Zscaler Internet Access (ZIA) to enforce AI tool outbound network policies at the Zscaler cloud firewall layer. Guard uses the ZIA API with staged edits and an activation gate — it stages firewall filtering rules, activates only after successful staging, and rolls back by re-staging the previous snapshot if activation fails.
Support level
ZTNA Orchestration — activation-gated staged apply with revision-based drift detection. Identity-aware enforcement (Zscaler user/device identity flows through ZIA).
Recommended Guard mode
Observe first — ZIA activation gates provide a natural audit point. Promote to Enforce once the desired rule baseline is validated.
Known limitations
- ZIA activation is tenant-wide — it activates all pending staged changes across all ZIA policy categories, not just Guard’s rules. Coordinate with your ZIA admin team on activation windows.
- Per-process enforcement is not available at the ZIA layer.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix