Guide
All articles tagged Guide.

The ROI of NHI security: Why investing in machine identity protection pays off
Unsecured NHIs are not just a technical oversight, but a full-blown business liability. Unsecured machine identity can trigger downtime, compliance failures, and multi-million-dollar losses. Learn the risks associated with NHIs, the cost of not securing them, and how to approach a solution that is policy-based, and future-proof.

Announcing the new Cerbos Hub usage dashboard
We are excited to launch the new usage dashboard in Cerbos Hub. This new feature provides a comprehensive, real-time view of your authorization service, allowing you to monitor key metrics, analyze trends, and gain valuable insights into your policies and their consumers.

Deploying Cerbos PDP on AWS Lambda and API Gateway: Step-by-step guide
Cerbos makes it easy to decouple and scale your access control with policy-as-code. In this guide, youâll deploy a fully serverless Cerbos PDP using AWS Lambda and API Gateway, with audit logging, S3-based policies, and flexible endpoint protection.

Integrating scalable authorization in .NET
Struggling with brittle role-based authorization in .NET Core Identity? This hands-on guide shows how to decouple complex access logic from your application by integrating Cerbos as a custom authorization providerâenabling scalable, policy-driven access control without scattering business rules across your codebase. Learn how to plug Cerbos into your ASP.NET Core pipeline and write policies that adapt as fast as your requirements do.

Advanced multi-tenant SaaS authorization with Cerbos: Role policies and scoped resource policies
Learn how Cerbos, with features like role policies and the fine-grained control offered by scoped resource policies (governed by scope permissions mode), provides a powerful toolkit to define and enforce multi-tenant security effectively.

Supercharging LLM understanding of Cerbos documentation
Learn how Cerbos improves Large Language Model (LLM) comprehension of its documentation using the new llms.txt standardâplus an open-source Antora plugin to help others do the same.

Context Aware Auth0 Authorization: RBAC & ABAC
For complex and dynamic applications in Auth0, a dedicated authorization system (more than just RBAC) is required â enter ABAC!

Dynamic authorization for AI agents. A guide to fine-grained permissions in MCP servers
Learn how to building a secure MCP server where AI Agent tool access is managed by Cerbos, a decoupled, policy-driven Authorization service. You will learn how to enforce fine-grained authorization by externalizing access controls into human-readable policies.

Don't fetch that. A developer's guide to pre- vs. post-filtering for authorization
While the initial simplicity of post-filtering is alluring, itâs a solution with a ceiling. It creates performance bottlenecks and security concerns that are difficult to engineer your way out of later. For modern, scalable, and secure applications, pre-filtering is the clear winner - you build a system that is performant, secure by design, and ready for future growth. And for those who need absolute certainty, the hybrid approach offers truly bulletproof authorization.

Practices that set great software architects apart
Great software architects donât just make technical decisionsâthey balance competing priorities, navigate messy org charts, and align engineering with business strategy. This post explores the habits and mindset that separate competent architects from truly impactful ones, and why those differences matter. Whether you're eyeing the role or already in it, these are the practices that move the needle.

Cloud native chronicles: Lessons learned from building Cerbos in the open
What does it actually mean in practice to be Cloud Native? Having spent the last 2 years building the open source authorization layer Cerbos, we will cover the key software ingredients that contribute to a successful cloud-native project. Hear some of the hard-learned lessons, and the most sought-after aspects when venturing into your own cloud-native endeavours.

Revolutionize your authorization with Cerbos: A comprehensive video demo | ByteGrad
Discover how Cerbos simplifies authorization for microservices and Next.js applications in this video. Dive deep into Cerbos Hub's capabilities with a practical demo, showcasing ease of management and deployment. Watch now to enhance your security strategy.

Insights from KubeCon Europe 2025 - AI gets real, and identity gets serious
KubeCon Europe 2025 revealed a shift from AI hype to real-world operations, spotlighting the rise of identity-first architecture and policy-based access control. From secure workload identities to operationalizing AI, the cloud-native community is embracing maturity with scalable, secure infrastructure.

Cerbos Hub Audit Logs Live in Beta
Explore Cerbos Hub Audit Logs, now in beta! Capture detailed access and decision records across your PDPs, enabling faster debugging, enhanced security, and compliance verification. Ideal for developers, security engineers, and product managers, this feature streamlines your workflow and provides deep insights into authorization decisions.

Recap of webinar: "Simplify access controls in Node.js, React & serverless apps" | Cerbos & ByteGrad
Join Alex Olivier, Cerbos Chief Product Officer, and Wesley, presenter of the popular ByteGrad Youtube channel, as they demonstrate how to author permissions and policy changes using Cerbos, and deploy those changes without changing any other code.

From OPA to our own engine - the Cerbos journey
When we started building Cerbos in January of 2021, we had a clear mission. We wanted to help developers separate their roles and permissions management from the core application code, creating a more scalable and future-proof way of handling permissions. This is the story of how we began with Open Policy Agent (OPA) and eventually built our own policy decision engine, and why that transition was crucial for our product's evolution.

What is admin-time / static authorization?
This article will explain what admin time authorization is, why it matters for software architects and developers, and how it contrasts with dynamic, run-time checks. Weâll also touch on real-world scenarios to illustrate the concept, and briefly discuss how newer solutions tie these models together for better security and compliance.

Implementing an authorization model for a SaaS application
SaaS applications require robust authorization models, although selecting the right approach for your system can be daunting. This article outlines a solid method for implementing authorization within a typical workspace SaaS application.