Tech blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security.

Can non-engineers manage authorization policies with Cerbos?
How non-engineers manage authorization policies with Cerbos. Product managers, security leads, and even end customers can write and update YAML policies thanks to readable syntax and CEL conditions. Includes Supy's self-service custom roles, Human Managed's five-minute policy changes, and the Git review workflow that keeps changes safe.

Governing AI coding agents with Cerbos Synapse
Learn how to control every tool call with policy, enforce role-based access, and get full audit visibility using Cerbos Synapse

Your AI coding agents need guardrails. Not the kind you think
What can your Claude Code agent do on your machine right now? A deep dive into how to actually control it with real enforcement, policies, and audit visibility.

From open-source policy engine to enterprise authorization management platform
From open-source policy engine to complete authorization platform: how Cerbos evolved to cover every access control use case.

Mapping business requirements to authorization policy for utilities
Learn how to write and manage authorization policies for utility companies using PBAC. Compare RBAC vs. ABAC across real-world scenarios like SCADA access control, gas sensor policies, compliance audits, and vendor onboarding - with practical YAML and code examples that reduce downtime, cut costs, and simplify operations.

Introducing Cerbos Synapse: unified authorization context and enforcement across your stack
Learn how Cerbos Synapse centralizes authorization context and enforcement by assembling identity and resource data and applying consistent policies across your stack

The CISO’s guide to implementing Zero Trust: Making adaptive access control work in practice
Learn how to move Zero Trust from buzzword to reality with adaptive authentication, dynamic authorization, and policy-as-code. This guide covers ABAC, contextual access controls, and a practical maturity roadmap to help CISOs operationalize Zero Trust without overhauling their entire stack.

Automating IAM for compliance, security, and business agility
Learn how to move IAM beyond manual approvals with just-in-time access and policy-based access control (PBAC). Explore practical strategies for automating identity governance, reducing privilege creep, and aligning with zero trust — plus where AI fits and where it doesn't.

Authorization became the main character at Gartner IAM London
Insights from the Gartner Identity & Access Management Summit EMEA: why authorization is becoming core infrastructure for securing AI agents. Learn how Authorization Management Platforms, the AuthZEN authorization protocol, and policy-based access control are shaping the future of identity and runtime authorization.

The privilege creep time bomb: Why timely access review is critical for security leaders
Privilege creep silently expands access beyond what users need, creating hidden security and compliance risks. Learn how entitlement drift happens, why it’s dangerous, and how to fix it using least privilege, regular access reviews, and dynamic authorization controls to reduce attack surface.

How does Cerbos help with compliance audits and certifications?
Speed up compliance audits with Cerbos audit logging and policy versioning. Track who accessed what, why decisions were made, and prove authorization controls for SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR.

Overcoming IAM blind spots and fragmentation for continuous governance
Fragmented IAM creates blind spots, audit chaos, and hidden security risk. Learn why identity sprawl undermines compliance and how continuous governance, policy-as-code, and real-time visibility help CISOs stay audit-ready and reduce identity-related breaches.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
