Tag

Guide

All articles tagged Guide.

Filtering database results with Cerbos query plans

Filtering database results with Cerbos query plans

Learn how Cerbos PlanResources API uses partial evaluation to streamline authorization. Discover how query plans translate into efficient database filters, boost performance, and simplify access control with custom adapters.

EngineeringDocumentationGuide
Alex OlivierSeptember 25, 2025
Service-to-service authorization: A guide to non-user principals

Service-to-service authorization: A guide to non-user principals

Read this article to understand what non-user principals are, when you might need them, and how they relate to service-to-service authorization.

Guide
James HickeySeptember 24, 2025
Making Cerbos policies bulletproof with schemas

Making Cerbos policies bulletproof with schemas

Learn how JSON schemas make Cerbos policies more reliable, secure, and easy to maintain. Catch integration errors early, prevent attribute injection attacks, and create bulletproof authorization for your applications.

EngineeringDocumentationGuide
Alex OlivierSeptember 22, 2025
Designing an authorization model for an enterprise

Designing an authorization model for an enterprise

Learn how to design an authorization model for an enterprise. An authorization model plays a vital role in securing an enterprise’s sensitive data. Businesses often code additional custom logic on top of traditional access control solutions, like Active Directory. However, as businesses grow, they need access control that can scale to match their growth.

Guide
Nikhila JainSeptember 22, 2025
Why using GitOps for authorization and access control is a good idea

Why using GitOps for authorization and access control is a good idea

Getting developers working in harmony is no easy task. Tools like GitHub make it much easier to manage code, but as infrastructure and deployment become more complex, issues arise with the systems projects are built on.

Guide
James KonikSeptember 17, 2025
Mapping business requirements to authorization policy for fintech

Mapping business requirements to authorization policy for fintech

Best practices for translating business requirements into authorization policy for your fintech. We walk through the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible.

EngineeringGuide
H.A. WriterSeptember 17, 2025
Making application authorization context-aware with Cerbos outputs

Making application authorization context-aware with Cerbos outputs

Discover how Cerbos outputs turn binary authorization into rich, contextual decisions. Enable audit trails, rate limits, emergency access, and user guidance - without scattered code or compliance gaps.

DocumentationEngineeringGuide
Alex OlivierSeptember 15, 2025
The productivity paradox of AI coding assistants

The productivity paradox of AI coding assistants

AI coding assistants promise speed, but do they deliver? Explore data, developer insights, and security risks showing why AI feels faster but often slows production. Learn where tools like Cursor and Claude Code help, and where they fail.

Guide
Lisa DziubaSeptember 12, 2025
Stop trusting your employees. Uber's "God view" proves you can't

Stop trusting your employees. Uber's "God view" proves you can't

Uber’s ‘God View’ exposed the dangers of unchecked internal tools. Learn why coarse admin access, weak audit trails, and hard-coded authorization are ticking time bombs—and how externalized authorization with Cerbos prevents abuse, ensures compliance, and protects sensitive data.

Guide
Emre BaranSeptember 11, 2025
How to Add Authorization in a Node.js Application

How to Add Authorization in a Node.js Application

Our guide demonstrates how to add authorization to a Node.js web application.

DocumentationGuideIntegration
Daniel OlaogunSeptember 10, 2025
Building a shared authorization vocabulary with Cerbos variables

Building a shared authorization vocabulary with Cerbos variables

Cerbos variables let you create a shared authorization vocabulary. Your platform or security team defines what these core concepts mean once. Product teams then build their features using these pre-validated, centrally-managed definitions without worrying about the implementation details.

GuideEngineeringDocumentation
Alex OlivierSeptember 08, 2025
Strategies for securing Non-Human Identities

Strategies for securing Non-Human Identities

Strategies for securing Non-Human Identities. A 6-step framework covering Zero Trust, least privilege, lifecycle governance, metrics, and standards like SPIFFE and OIDC to protect AI agents, services, and workloads.

Guide
Lisa DziubaSeptember 07, 2025
Trace authorization decisions and track organization-wide usage with new Cerbos Hub features

Trace authorization decisions and track organization-wide usage with new Cerbos Hub features

Authorization debugging just got easier. We're shipping two features that tackle problems we've heard about repeatedly from customers running Cerbos at scale: understanding why specific authorization decisions were made and getting visibility into usage patterns across multiple teams.

GuideAnnouncement
Alex OlivierSeptember 05, 2025
Guide to Java authentication and authorization

Guide to Java authentication and authorization

Authorization technologies have seen significant changes and advancements in recent years—especially when it comes to Java. This article provides an overview of the evolving landscape to help you choose the best authorization framework for your Java application.

Guide
Rajkumar VenkatasamySeptember 03, 2025
PBAC is back. Why policy‑based access control is trending again for enterprise security

PBAC is back. Why policy‑based access control is trending again for enterprise security

Discover why Policy Based Access Control (PBAC) is making a comeback. Learn PBAC benefits for enterprises, how to implement PBAC with Cerbos, and why analysts like KuppingerCole name it a top identity and security trend.

Guide
Emre BaranAugust 28, 2025
Safeguarding non-human identities: Understanding and addressing the OWASP top 10 threats

Safeguarding non-human identities: Understanding and addressing the OWASP top 10 threats

In this article, we’ll review each of the top 10 NHI threats, explain their real-world implications, and discuss how you can mitigate them. We’ll also demonstrate how Cerbos can help address some of these risks by enforcing fine-grained, contextual authorization rules for NHIs. Learn how to manage non-human identities securely.

Guide
Alex OlivierAugust 15, 2025
Using Cerbos PDP with the Java Spring Security Framework

Using Cerbos PDP with the Java Spring Security Framework

Learn how to integrate the Cerbos Policy Decision Point with Java Spring Security to replace hard-coded, scattered permission checks with clean, policy-driven authorization. This hands-on guide walks you through building a declarative, annotation-based approach that keeps your business rules flexible, maintainable, and out of your application code.

GuideIntegration
Twain TaylorAugust 13, 2025
The technical complexities of externalized authorization

The technical complexities of externalized authorization

Externalizing the authorization module can bring about a host of benefits. But what are the complexities of this approach? And how can they be addressed? In this guide, you can familiarize yourself with the important technical aspects of externalizing authorization.

Guide
James WalkerAugust 05, 2025