Guide
All articles tagged Guide.

Filtering database results with Cerbos query plans
Learn how Cerbos PlanResources API uses partial evaluation to streamline authorization. Discover how query plans translate into efficient database filters, boost performance, and simplify access control with custom adapters.

Service-to-service authorization: A guide to non-user principals
Read this article to understand what non-user principals are, when you might need them, and how they relate to service-to-service authorization.

Making Cerbos policies bulletproof with schemas
Learn how JSON schemas make Cerbos policies more reliable, secure, and easy to maintain. Catch integration errors early, prevent attribute injection attacks, and create bulletproof authorization for your applications.

Designing an authorization model for an enterprise
Learn how to design an authorization model for an enterprise. An authorization model plays a vital role in securing an enterprise’s sensitive data. Businesses often code additional custom logic on top of traditional access control solutions, like Active Directory. However, as businesses grow, they need access control that can scale to match their growth.

Why using GitOps for authorization and access control is a good idea
Getting developers working in harmony is no easy task. Tools like GitHub make it much easier to manage code, but as infrastructure and deployment become more complex, issues arise with the systems projects are built on.

Mapping business requirements to authorization policy for fintech
Best practices for translating business requirements into authorization policy for your fintech. We walk through the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible.

Making application authorization context-aware with Cerbos outputs
Discover how Cerbos outputs turn binary authorization into rich, contextual decisions. Enable audit trails, rate limits, emergency access, and user guidance - without scattered code or compliance gaps.

The productivity paradox of AI coding assistants
AI coding assistants promise speed, but do they deliver? Explore data, developer insights, and security risks showing why AI feels faster but often slows production. Learn where tools like Cursor and Claude Code help, and where they fail.

Stop trusting your employees. Uber's "God view" proves you can't
Uber’s ‘God View’ exposed the dangers of unchecked internal tools. Learn why coarse admin access, weak audit trails, and hard-coded authorization are ticking time bombs—and how externalized authorization with Cerbos prevents abuse, ensures compliance, and protects sensitive data.

How to Add Authorization in a Node.js Application
Our guide demonstrates how to add authorization to a Node.js web application.

Building a shared authorization vocabulary with Cerbos variables
Cerbos variables let you create a shared authorization vocabulary. Your platform or security team defines what these core concepts mean once. Product teams then build their features using these pre-validated, centrally-managed definitions without worrying about the implementation details.

Strategies for securing Non-Human Identities
Strategies for securing Non-Human Identities. A 6-step framework covering Zero Trust, least privilege, lifecycle governance, metrics, and standards like SPIFFE and OIDC to protect AI agents, services, and workloads.

Trace authorization decisions and track organization-wide usage with new Cerbos Hub features
Authorization debugging just got easier. We're shipping two features that tackle problems we've heard about repeatedly from customers running Cerbos at scale: understanding why specific authorization decisions were made and getting visibility into usage patterns across multiple teams.

Guide to Java authentication and authorization
Authorization technologies have seen significant changes and advancements in recent years—especially when it comes to Java. This article provides an overview of the evolving landscape to help you choose the best authorization framework for your Java application.

PBAC is back. Why policy‑based access control is trending again for enterprise security
Discover why Policy Based Access Control (PBAC) is making a comeback. Learn PBAC benefits for enterprises, how to implement PBAC with Cerbos, and why analysts like KuppingerCole name it a top identity and security trend.

Safeguarding non-human identities: Understanding and addressing the OWASP top 10 threats
In this article, we’ll review each of the top 10 NHI threats, explain their real-world implications, and discuss how you can mitigate them. We’ll also demonstrate how Cerbos can help address some of these risks by enforcing fine-grained, contextual authorization rules for NHIs. Learn how to manage non-human identities securely.

Using Cerbos PDP with the Java Spring Security Framework
Learn how to integrate the Cerbos Policy Decision Point with Java Spring Security to replace hard-coded, scattered permission checks with clean, policy-driven authorization. This hands-on guide walks you through building a declarative, annotation-based approach that keeps your business rules flexible, maintainable, and out of your application code.

The technical complexities of externalized authorization
Externalizing the authorization module can bring about a host of benefits. But what are the complexities of this approach? And how can they be addressed? In this guide, you can familiarize yourself with the important technical aspects of externalizing authorization.