Tech blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security.

Agent skill for writing authorization policies
Writing authorization policies from a blank file is slow. The Cerbos agent skill handles the drafting for you, asking clarifying questions in plain English before generating a full Cerbos policy bundle with schemas, roles, resource policies, and tests. Works with Claude Code, Cursor, Codex, and more.

Why centralized authorization governance reduces incident response time
Centralized authorization governance gives security leaders instant visibility into every access decision during a breach. This article covers why fragmented access control stalls incident response, how AI agents expand the authorization surface, CISO personal liability under SEC rules, and how to evaluate solutions.

OPA alternative
This article examines why Cerbos stands out as the best alternative to Styra and OPA for authorization needs. Comparison is based on policy language, deployment, performance, observability, DX and scalability.

Why AI agents make authorization a right now problem
AI agents don't create new vulnerabilities. They find the authorization ones you already had, faster and at scale. Why Gartner's new Authorization Management Platform category matters, what deterministic policy enforcement looks like, and how to close the gaps before the next model release finds them.

Implement authorization and access control in an Express application
Explore importance of roles and permissions in webapps and learn how to use Cerbos authorization to enforce RBAC for a sample LMS implemented in Express and Node.

Modernizing legacy application authorization: why it’s your biggest security blind spot
Your legacy applications have the weakest authorization controls and the most sensitive data. Learn how security and identity teams can close the governance gap by adding policy-based authorization, compliance-ready audit trails, and context-aware access decisions at the gateway without modifying the application.

How to add authorization to legacy applications without code changes
Learn how to add authorization to legacy applications without modifying a single line of code. This guide covers the gateway pattern with Cerbos Synapse and Envoy, route-level policy enforcement, device posture checks, audit trail coverage, and a phased path from zero visibility to full authorization governance.

5 authorization blind spots auditors find, and how to fix them
A practical guide to the 5 authorization gaps that drive access control audit findings in regulated enterprises. Covers scattered authorization logic, proof of enforcement, role versus permission reviews, non-human identity governance, and AI agent authorization, with concrete steps to fix each one.

Row-level security for Apache Trino, powered by Cerbos Synapse
Add row-level security, column masking, and table-level access control to Apache Trino using Cerbos policies. No Rego, no custom plugins. Covers policy examples, attribute-based filtering from your IdP, per-role masking rules, and compliance audit logging through Cerbos Hub.

AI Security Platforms (AISP): What they are, why they matter, and how they work
AI Security Platforms (AISP) explained. Learn what AISPs are, why they matter, and how they secure AI agents, LLMs, and workflows against prompt injection, data leakage, and rogue behavior with real-world, technical examples.

Top 9 Identity & Access Management (IAM) Tools for 2026
IAM tools are essential for enhancing security, streamlining access management processes, and ensuring compliance in organizations. In this blog, we're going to discuss the top 9 identity and access management (IAM) tools of 2026.

Authelia vs Authentik in 2026: Which self-hosted IdP should you choose
Authelia vs Authentik explained: compare a lightweight forward-auth gateway and a full IdP, when to choose each, security notes. This guide covers MFA, SSO, protocol support, deployment trade-offs, CVE track records, and community insights to help you pick the right fit for your stack.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
