Tech blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security.

Service-to-service authorization: A guide to non-user principals
Read this article to understand what non-user principals are, when you might need them, and how they relate to service-to-service authorization.

Making Cerbos policies bulletproof with schemas
Learn how JSON schemas make Cerbos policies more reliable, secure, and easy to maintain. Catch integration errors early, prevent attribute injection attacks, and create bulletproof authorization for your applications.

Designing an authorization model for an enterprise
Learn how to design an authorization model for an enterprise. An authorization model plays a vital role in securing an enterprise’s sensitive data. Businesses often code additional custom logic on top of traditional access control solutions, like Active Directory. However, as businesses grow, they need access control that can scale to match their growth.

Why using GitOps for authorization and access control is a good idea
Getting developers working in harmony is no easy task. Tools like GitHub make it much easier to manage code, but as infrastructure and deployment become more complex, issues arise with the systems projects are built on.

Mapping business requirements to authorization policy for fintech
Best practices for translating business requirements into authorization policy for your fintech. We walk through the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible.

Making application authorization context-aware with Cerbos outputs
Discover how Cerbos outputs turn binary authorization into rich, contextual decisions. Enable audit trails, rate limits, emergency access, and user guidance - without scattered code or compliance gaps.

The productivity paradox of AI coding assistants
AI coding assistants promise speed, but do they deliver? Explore data, developer insights, and security risks showing why AI feels faster but often slows production. Learn where tools like Cursor and Claude Code help, and where they fail.

Stop trusting your employees. Uber's "God view" proves you can't
Uber’s ‘God View’ exposed the dangers of unchecked internal tools. Learn why coarse admin access, weak audit trails, and hard-coded authorization are ticking time bombs—and how externalized authorization with Cerbos prevents abuse, ensures compliance, and protects sensitive data.

How to Add Authorization in a Node.js Application
Our guide demonstrates how to add authorization to a Node.js web application.

Building a shared authorization vocabulary with Cerbos variables
Cerbos variables let you create a shared authorization vocabulary. Your platform or security team defines what these core concepts mean once. Product teams then build their features using these pre-validated, centrally-managed definitions without worrying about the implementation details.

Strategies for securing Non-Human Identities
Strategies for securing Non-Human Identities. A 6-step framework covering Zero Trust, least privilege, lifecycle governance, metrics, and standards like SPIFFE and OIDC to protect AI agents, services, and workloads.

Trace authorization decisions and track organization-wide usage with new Cerbos Hub features
Authorization debugging just got easier. We're shipping two features that tackle problems we've heard about repeatedly from customers running Cerbos at scale: understanding why specific authorization decisions were made and getting visibility into usage patterns across multiple teams.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
