Tech blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security.

Cerbos Hub Playground: Recent updates
Explore the latest Cerbos Hub Playground updates, including permission matrices, execution traces, diff views, templates, and sandboxed policy testing to build and debug authorization faster.

Announcing ePDP Rules: Fine-grained control for embedded policy bundles
Learn about ePDP Rules that have been released. Take advantage of fine-grained control over bundle composition and distribution. Deploy policies more broadly while maintaining security and performance.

What is externalized authorization management (EAM) and its benefits
As systems grow in complexity, managing authorization becomes increasingly challenging. Learn what externalized authorization management (EAM) is, and how it can help.

Mapping business requirements to authorization policy for aviation
A practical guide to authorization in aviation. Learn how to implement RBAC and ABAC to secure flight, maintenance, and ticketing systems with contextual policies, audits, and real-time enforcement.

A shared authorization layer that adapts to context
A shared, context-aware authorization layer prevents policy sprawl, ensures consistent decisions across services, and improves auditability. Learn how externalized, runtime authorization with Cerbos centralizes policy while keeping enforcement local, fast, and reliable.

What is authorization as a service?
'Authorization as a serviceā refers to using a third-party service to take care of an applicationās authorization. Read the full definition and learn more here.

Cerbos Hub is now available on-premise
Cerbos Hub is now available self hosted and on premise, enabling centralized, auditable authorization for regulated, air-gapped, and private environments without relying on cloud-based control planes.

Authorization as a continuously governed control
Runtime authorization requires continuous governance without adding latency or risk. Learn how centralized policy, consistent decision logic, and auditable evidence enable scalable, low-latency authorization across humans, services, and AI agents - without becoming a bottleneck.

When authorization is static, risk accumulates silently
Authorization failures happen at decision time. Learn why static access models break in production, create audit blind spots, and let risk accumulate, plus what CISOs need to make authorization observable, explainable, and enforceable at runtime.

Year in review: 2025
Cerbosā 2025 year in review. Enterprise adoption, audit-ready runtime authorization, AI and non-human identity security, plus key product releases and industry recognition.

OpenID AuthZEN is official, and Cerbos is ready
AuthZEN is now ratified. Learn how this new OpenID standard brings interoperable, fine-grained authorization to modern systems, how it complements OAuth and OIDC, and how Cerbos supports AuthZEN for scalable, externalized authorization.

MCP and Zero Trust: Securing AI agents with identity and policy
MCP and Zero Trust explained: how to secure AI agents with identity, policy, and fine-grained authorization. Learn why MCP changes the security model and how Zero Trust principles apply to agent access, tools, and data.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
