Guide
All articles tagged Guide.

Rich Authorization Requests (RAR) for agent tokens
OAuth scopes can say read the profile, not transfer 45 euros to this merchant. Here is how Rich Authorization Requests express precise, per-hop grants for AI agents.

The Cerbos PDP dashboard is now on Grafana Cloud
The Cerbos PDP dashboard is now on the Grafana Cloud dashboards site. Import it by ID, point it at your Prometheus data source, and every instance in your fleet is on one screen, from health and loaded policy count down to latency percentiles.

Best zero trust security tools and solutions for 2026
The best zero trust security tools and solutions, broken down by layer. Identity and access management, privileged access, zero trust network access, device trust, authorization and policy enforcement, data protection, and visibility, with the notable tools in each and how to prioritize the layer most stacks leave hardcoded.

Why your audit trail breaks at the sub-agent boundary
When agent A delegates to agent B, the downstream logs show the service account, not the user. Here is why the audit trail breaks at the sub-agent boundary, and how to fix it.

Keycloak vs Ory
Compare Keycloak and Ory on architecture, login UI, federation and operational load, and see where each one's authorization model stops.

LDAP and Active Directory authorization without changing the application
LDAP and Active Directory groups encode the access rules for applications nobody will fund a rewrite for. Covers resolving those groups at the proxy in front of the application, turning them into an input to policy rather than the access model itself, cache staleness, and where boundary enforcement stops.

Identity Week America 2026: Same AI agent authorization problem, different badges
Notes from Identity Week America 2026 in Washington DC, where federal agencies, defense contractors and SaaS teams brought the same AI agent authorization question to the booth. Covers the License to Thrill panel, agent ownership and blast radius, policy based access control at runtime, and why audit is still unsolved.

Per-hop PBAC: enforcing scope at every delegation step
Checking authorization once at the edge leaves every downstream hop unguarded. Here is why agent delegation needs a policy decision at every hop, and how to do it.

Best Keycloak alternatives
Compare Keycloak alternatives by protocol, deployment model, limitations, and migration path. Covers ZITADEL, Authentik, Authelia, SuperTokens, and Ory Hydra, plus when to keep Keycloak and add Cerbos for fine-grained authorization instead.

Best AI agent security and governance tools for 2026
The best AI agent security and governance tools, broken down by layer. Prompt security, guardrails, posture and shadow-agent discovery, non-human identity, authorization and access control, data and RAG protection, and runtime monitoring, with the notable tools in each and how to prioritize what to cover first.

Multi-hop delegation for AI agents, and how the consent chain gets lost
When agent A delegates to agent B to a tool, the user's consent and identity get lost along the way. Here is how multi-hop delegation should actually work.

Kubernetes admission control does not need a second policy language
Platform teams usually keep two sets of access rules, one for what may be admitted into the cluster and one for what users may do in the applications there. Covers serving the admission webhook from the same policy layer, what a full ruleset looks like, and failure policy trade offs.

Not every authorization decision is allow or deny
Not every authorization decision is allow or deny. Some denials are conditional, and the policy can return what would unblock them. Covers Cerbos policy outputs, the conditionNotMet trigger, the AuthZEN ARAP draft profile for requestable denials, and why an approval is an input to a new decision.

What is authorization? Types, examples and definitions
Learn what authorization is all about! Explore several key authorization design patterns, how they work, and possible scenarios where they may be implemented. This guide covers RBAC, ABAC, PBAC, DAC, MAC, and ReBAC, how authorization differs from authentication, how it works with tokens and OAuth scopes, real-world examples, and best practices for getting it right.

Istio authorization stops at identity, not at what a workload may do
Istio proves which workload is calling with mTLS and SPIFFE, and stops there. This guide covers where AuthorizationPolicy runs out, handing the decision to an external authorizer through the CUSTOM action, running one policy set across north south and east west traffic, and what the extra network hops cost.

Stale JWT claims in authorization, and how to look up identity attributes at decision time
How to resolve identity attributes at decision time rather than reading stale JWT claims. Covers Envoy verifying the token while a Synapse data source fetches current profile and group data, policies that read attributes rather than claims, per source cache expiry, and failure behavior when the provider is unreachable.

Policy-driven MCP routing: enforcing tool gates outside the agent
Telling an agent which tools not to use is a request, not a control. Here is how to gate MCP tool calls with policy enforced outside the agent, at the execution boundary.

Full guide to Next.js authorization & authentication
Next.js has two main patterns of authentication. Meanwhile when it comes to authorization, nothing is as simple as adding Cerbos. Read our full guide.