The State of Zero Trust Security (2021) [pdf]
okta.com
okta.com
It has nothing to do with whether you trust your staff or not.
In fact, you should not trust your staff from a security perspective, insider attacks are a valid threat. This is true regardless of whether you use a zero trust architecture or not.
Especially if their machine's compromised.
The basics are pretty straight forward, but every vendor has stretched to include their key capabilities which makes the idea murky.
There strict firewalls about who could talk to who. We were given lists of things we could talk about socially (the weather, etc).
But the effect was more of an information clean room, rather than a dictatorship. There were always numerous ways to report wrongdoing.
If you go back to the original sources of the zero trust concept stress that it should only apply to machines. Processes really don't have the concept of "trust" that people do (gain/lose trust, trusted to a degree, etc.). So we should build systems with that in mind.
Ultimately you'd have to trust someone even that reduced to one, do you even trust yourself?
It's infeasible to implement something that's absolutely based on trust none. The so called "Zero trust" is merely escalated restriction but still "as need basis".