Guide
All articles tagged Guide.

What is data authorization?
Data authorization provides fine-grained access control. Understand why data authorization matters, and how organizations can implement it to reduce risk, meet compliance requirements, and enhance user experience.

How Cerbos works
Discover how Cerbos can integrate seamlessly into your existing software ecosystem. In this blog post, we go through Cerbos' functionality, main features, and the benefits of using Cerbos for fine-grained authorization in your applications.

Embracing WebAssembly in authorization | Cerbos, KubeCon + CloudNativeCon Paris
The intersection of Kubernetes, cloud-native solutions, and WebAssembly (WASM) represents a frontier of innovation. At the recent KubeCon EU conference, Alex Olivier, CPO and Co-Founder of Cerbos, shared insights during an interview with Milo Oudenaller from Amazic.

Access control and permission management for AI agents: building with security in mind
AI-powered chatbots and agents are value-adding features for many companies, helping both company employees and external users, who interact with the company products. The key challenge here is that these chatbots should provide contextually useful responses that would solve users' problems without leaking sensitive information. Read on to see how this can be achieved.

Role-based access control best practices: 11 top tips
Role-Based Access Control is an access control model based on clearly defined roles. Read on to learn more about Role-Based Access Control best practices.

Cerbos Playground: Dive into the RBAC policy generator
Access control in modern applications is crucial to ensure data privacy and system integrity. As applications become more complex and interconnected, so does the need for a more simplified way to manage access controls. This piece showcases Cerbos Playground's newest feature - the RBAC Policy Generator.

Cerbos Dagger module for authorization testing
Introducing the Cerbos Dagger module: a tool to streamline authorization testing by externalizing policies, integrating with CI pipelines, and simplifying permission management. Learn how this module can enhance your application's security and maintainability. Watch the demo and explore more on GitHub.

Understanding security and access control requirements of microservices environment
Learn how you can implement robust security protocols and access control measures to ensure inter-services communicating is not compromised.

Authorization in developer workflows: best practices and tools
Authorization can be a powerful enabler of developer creativity and seamless user experiencesâbut only when treated as a first-class workflow concern. Explore how modern authorization patterns can improve security, productivity, and the developer experience itself!

5 common authentication methods for NHIs
Deep dive into NHI authentication. Learn 5 common methods for authenticating non-human identities, their architecture, use cases, and security posture.

3 Most Common Authorization Designs for SaaS Products
There are many ways to design and implement an authorization system. Read this article to discover the 3 most common authorization designs for SaaS products.

What is run-time authorization?
Explore what run-time authorization is, how it compares to admin-time models, and when it makes sense to use each. Youâll learn how run-time checks work, why they matter, and how they help strike a balance between flexibility, security, and control. We'll also touch on tools and design patterns that make dynamic access decisions practical to implement.

Simple role-based access control in Ruby
Tired of tangled if statements and scattered permission logic? This post walks through the evolution from DIY role checks in Ruby to scalable, production-grade authorization using Cerbosâimproving your flow without rewriting your app.

Designing a Zero Trust Architecture: 20 open-source tools to secure every layer
Explore 20 open-source tools to implement Zero Trust Architecture across firewalls, network segmentation, encryption, workload identity, authentication, and authorization layers. Enhance security by eliminating implicit trust and enforcing continuous verification at every level.

How to avoid common authorization errors for efficient access control
Discover the hidden pitfalls of authorization that could expose your application to serious security risks. Unpack common anti-patternsâlike over-permissioning and hardcoded access logicâand explore practical strategies for building safer, more maintainable systems.

Authorization for non-human identities (NHIs) with Cerbos
Learn all about non-human identities - what they are, why securing them is important, along with how Cerbos can be used to effectively authorize NHIs.

SPIFFE identity parsing added to Cerbos PDP
Cerbos PDP now supports native parsing and evaluation of SPIFFE identities in authorization policies. This unlocks precise access control for non-human identities (NHIs) like services, workloads, and containers that rely on SPIFFE-based workload identity.

Insights from Gartner IAM Summit 2025 - Identity, authorization, and the road ahead
The 2025 Gartner Identity and Access Management (IAM) Summit in London brought the identity community face-to-face with the future. From the surge of machine identities to evolving authorization patterns and policy-based control, the event underlined a clear shift: identity and access are no longer just IT plumbing - they're strategic infrastructure.