A design document moves between two internal teams. Routine.

The same document moves to a personal cloud drive. Incident.

Nothing about the file changed. Not a byte. The boundary it crossed changed, and that is the entire difference between a Tuesday and a disclosure.

Identity answers a different question, and accumulates exceptions

Most controls resolve this with identity. Is this person allowed to do this. It is a reasonable question and it has a well-known decay curve.

Identity policy accretes. A directory group here, an exception there, a VIP who got exempted two years ago for a deadline that has long since passed and whose exemption nobody dares remove. Every one of those is a small, locally sensible decision, and the sum of them is a policy nobody can describe in a sentence.

Worse, the exceptions cluster exactly where the risk is. The people most likely to be phished are the people most likely to have been exempted, because they are the people most able to demand it.

Position asks something the bearer cannot answer

Verdict as a function of content and position asks a different thing: is this content allowed to cross this line. Not who is holding it. Not what group they are in. What is in it, and where is it trying to go.

Content decides what the file actually is. Position decides what that means here. Neither of them consults the bearer.

An exemption is a per-user knob. If the control has no per-user state, there is no knob to turn.

What it rules out

A control that decides on content and position has no VIP lane. Not as a policy choice. As architecture. There is no field to set.

That cuts both ways, and it should be said plainly. The loudest person in the building cannot be exempted. Neither can the person with a genuine reason.

So a boundary control needs an override, and the shape of it matters. A per-user rule is a permanent hole with someone’s name on it. An accountable override is a single action: logged, attributed, reviewable. One turns the exception into a state you forget about. The other turns it into an event you can audit.

Subtext puts that override where the argument says it belongs. A blocked file can be released by a person and sent on again, and the release is logged against the person who made it. That is an action taken once, on one file. Nothing about it is written back into the control, so the next file carrying the same content gets the same verdict, from the same reasoning, for everyone.

Zero Trust for Files asks the question the access layer never asks, and it asks it of the file rather than the person carrying it.