Guide
All articles tagged Guide.

Open source Cerbos vs paid Cerbos
Open source vs paid Cerbos explained. The Apache 2.0 engine is complete and free, running over 2 billion checks a month. See what the commercial platform adds around it, policy distribution, compliance audit, and data enrichment, plus the roughly 19 engineer months it takes to build the equivalent yourself.

Delegated authorization: Why acting on behalf of someone else is not a role
Delegated authorization explained. Why modeling on-behalf-of access as a role loses the subject, the approver and the expiry. Covers the RFC 8693 act claim, delegation versus impersonation, AuthZEN and COAZ, multi-party policy conditions, revocation before expiry, and audit lineage for delegated actions.

MCP server vetting checklist for enterprises
Every MCP server you connect is a third party you have handed an agent a door to. Here is a practical checklist for vetting MCP servers and governing the ones you cannot fully trust.

Authorizing MCP tool calls at the gateway or inside the proxy, and what each one stops
Two ways to authorize MCP tool calls, in the request path or inside the proxy, and they stop different things. Covers in-path gateway enforcement against a pre-call hook, why denying a tool and hiding a tool are different security properties, fail closed behavior, and where both shapes stop working.

Envoy ext_authz: enforcing one authorization policy at the gateway and in the service
Envoy external authorization with the ext_authz filter lets the gateway and the service run checks against one policy set. This guide covers the CheckRequest to Cerbos mapping in CEL, policy outputs as request headers, embedded versus external PDP, bypass paths, caching trade offs and what AuthZEN leaves undefined.

MCP authorization standards: OAuth scopes, AuthZEN, and what's still missing
MCP leans on OAuth 2.1 for authentication, but OAuth scopes cannot answer fine-grained tool authorization. Here is what the standards cover, and what AuthZEN adds.

Mapping business requirements to authorization policy
Learn about how to map your business requirements to RBAC and ABAC policies and adopt Cerbos

What is an MCP gateway? And where authorization actually fits
An MCP gateway routes and manages traffic to MCP servers, but routing is not authorization. Here is what a gateway does, where the authorization gap is, and how to close it.

Mapping business requirements to authorization policy for gaming
Mapping business requirements to authorization policy for gaming, with three worked examples covering player profiles and inventory, virtual asset trading, and moderation actions. Each starts with the business rule and ends with a working Cerbos policy, including derived roles, ABAC conditions, and test cases you can run yourself.

Cerbos security and trust: Data handling, certifications, and deployment isolation
How Cerbos handles your data, where it lives, and what leaves your network. A security and trust overview for CISOs and security teams evaluating Cerbos, covering the stateless PDP, deployment isolation, local field masking, certifications, penetration testing, and the Cerbos Trust Center.

Framework for evaluating authorization providers and solutions
In this guide, we provide a framework for evaluating authorization providers and solutions, tailored to the priorities of enterprise decision-makers. We cover all the key criteria - from integration and performance to admin experience and compliance, and back them with data, industry research, and success metrics.

Best OpenZiti alternatives
Picking an OpenZiti alternative depends on the layer you need to replace. Compare ZTNA and overlay networking, self-hosted identity providers, OAuth2 and OIDC token services, and reverse proxy login gateways, plus where Cerbos handles fine-grained authorization once identity and connectivity are already solved.

Your IdP proves who an AI agent is. DORA expects you to control what it does
Your IdP proves who an AI agent is. DORA also expects you to control what it can do at runtime, which is authorization, not authentication. This guide covers where agents fall into DORA scope, how runtime authorization maps to Article 9 and audit requirements, and the steps to take while agents are still early.

Authentik vs Zitadel for authentication
Compare Authentik and Zitadel for authentication. Decide faster across SSO, MFA, proxy mode, LDAP, multi-tenancy, deployment, operations, and where Cerbos authorization fits.

You have Keycloak. What authorization capabilities do you still need?
Keycloak authentication and Keycloak SSO handle identity well. Authorization at scale is a different problem. Here's where the gap appears and how to fix it.

Claude Fable 5 and GPT-5.6 Sol authorization refusals
The models that refuse legitimate security work will also run destructive commands without asking. Both are reasons to enforce authorization outside the agent, not in its prompt.

Agent skill for writing authorization policies in VSCode
A practical guide to writing authorization policies in VSCode using GitHub Copilot agent mode and the Cerbos policy skill. Covers install, the gh skill CLI, chat.agentSkillsLocations, file-scoped *.instructions.md, a typical drafting session, and how validation runs in the integrated terminal.

Agent skill for writing authorization policies in Cursor
Cursor's composer makes it a strong fit for authorization policy work. This guide walks through installing the Cerbos policy skill in Cursor, describing access rules in plain English, letting the composer pull schemas and derived roles into context, validating against the real compiler in the integrated terminal, and producing a complete policy bundle.