Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Zscaler Internet Access Guide
ZS

Zscaler Internet Access

Integration & Setup Manual

Zscaler Internet Access (ZIA) Integration Guide

Overview

Cup’n’String Guard integrates with Zscaler Internet Access (ZIA) to enforce AI tool outbound network policies at the Zscaler cloud firewall layer. Guard uses the ZIA API with staged edits and an activation gate — it stages firewall filtering rules, activates only after successful staging, and rolls back by re-staging the previous snapshot if activation fails.

Support level

ZTNA Orchestration — activation-gated staged apply with revision-based drift detection. Identity-aware enforcement (Zscaler user/device identity flows through ZIA).

Observe first — ZIA activation gates provide a natural audit point. Promote to Enforce once the desired rule baseline is validated.

Known limitations

  • ZIA activation is tenant-wide — it activates all pending staged changes across all ZIA policy categories, not just Guard’s rules. Coordinate with your ZIA admin team on activation windows.
  • Per-process enforcement is not available at the ZIA layer.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelZTNA Orchestration
CategoryFirewalls
Setup ComplexityAdvanced
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix