Tag

Guide

All articles tagged Guide.

Authorization in microservices: Patterns, pitfalls, and how to scale it

Authorization in microservices: Patterns, pitfalls, and how to scale it

Authorization in microservices explained. Why it is harder than a monolith, where it gets enforced, the three patterns for handling authorization data, choosing RBAC or ABAC, service-to-service authorization, and the externalized policy decision point pattern that scales across services without scattered checks or redeploys.

GuideEngineering
Alex OlivierJuly 15, 2026
Ory vs SuperTokens for authentication

Ory vs SuperTokens for authentication

Ory Hydra and SuperTokens solve different authentication problems. Compare OAuth2 and OIDC token infrastructure against fast product login and session handling, and see where Cerbos fits as the authorization layer after authentication.

Guide
S. B. WriterJuly 15, 2026
RBAC vs ABAC - Which is better for your use case?

RBAC vs ABAC - Which is better for your use case?

A practical RBAC vs ABAC guide covering what each model is, the key differences, whether ABAC is more secure, role explosion, when to use RBAC or ABAC, and how to combine them in one set of policies instead of choosing between them.

Guide
Alex OlivierJuly 13, 2026
The incident response workflow that decides how fast you recover

The incident response workflow that decides how fast you recover

A step-by-step incident response workflow for the authorization layer, from mapping a compromised identity's blast radius to proving containment held. Covers how centralized policy and decision logs compress each phase, what makes the workflow feasible in regulated and air-gapped environments, and how AI agents change the runbook.

Guide
Anna PaykinaJuly 13, 2026
Agent skill for writing authorization policies in Codex CLI

Agent skill for writing authorization policies in Codex CLI

A practical guide to writing authorization policies in Codex CLI using the Cerbos policy skill. Covers cross-agent installer setup, $cerbos-policy invocation, the /skills list command, a typical drafting session, validation against the real Cerbos compiler in Docker, and composing the skill with AGENTS.md.

EngineeringDocumentationGuide
Alex OlivierJuly 12, 2026
ABAC examples: Real attribute-based access control policies and use cases

ABAC examples: Real attribute-based access control policies and use cases

A practical guide to attribute-based access control with real ABAC examples and policy code. Covers the four attribute types, industry use cases, how to write your own ABAC policy, the trade-offs, and where ABAC is heading for Zero Trust and AI agents.

Guide
Alex OlivierJuly 10, 2026
You have Auth0. What authorization capabilities do you still need?

You have Auth0. What authorization capabilities do you still need?

Auth0 covers authentication, but authorization capabilities like resource-level ABAC, per-tenant policies, and decision audit logs sit outside its model. This guide covers where Auth0 RBAC and Auth0 FGA stop, five signals you need a dedicated authorization layer, and how to evaluate solutions and run a POC.

Guide
Anna PaykinaJuly 10, 2026
What is fine-grained authorization?

What is fine-grained authorization?

Fine-grained authorization explained. Learn how fine-grained access control uses attributes and conditions to decide access per resource and action, how it differs from coarse-grained control, the RBAC, ABAC and PBAC models behind it, real use cases, and how to implement it without building your own engine.

Guide
Alex OlivierJuly 07, 2026
Agent skill for writing authorization policies in OpenCode

Agent skill for writing authorization policies in OpenCode

OpenCode is open source, self-hosted, and provider-agnostic, so the whole authorization policy workflow stays inside your security perimeter. This guide walks through installing the Cerbos policy skill in OpenCode, drafting policies in plain English, validating against the real Cerbos compiler locally, and pairing the skill with AGENTS.md.

DocumentationEngineeringGuide
Alex OlivierJuly 07, 2026
The authorization POC guide: What to test, who to involve, and how to decide

The authorization POC guide: What to test, who to involve, and how to decide

Most authorization POCs never reach production. This guide covers all details of a proper authorization proof of concept: scoping to one real service, measurable success criteria, stakeholder involvement, and baselines so the review produces a decision, not a debate.

Guide
Emre BaranJuly 06, 2026
Agent skill for writing authorization policies in Pi

Agent skill for writing authorization policies in Pi

Pi is the open-source self-extensible coding agent built around the Agent Skills standard from the start. This guide walks through installing the Cerbos policy skill in Pi, invoking it with /skill:cerbos-policy, drafting authorization policies in plain English, and validating against the real Cerbos compiler in Docker.

GuideEngineeringDocumentation
Alex OlivierJuly 02, 2026
You have Okta. What authorization capabilities do you still need?

You have Okta. What authorization capabilities do you still need?

You've standardized on Okta SSO for authentication. Here's where Okta falls short on authorization, and how to evaluate dedicated authorization solutions.

Guide
Anna PaykinaJuly 01, 2026
Mastering hierarchy-based permissions with Cerbos: Policy-defined roles vs. dynamic attributes

Mastering hierarchy-based permissions with Cerbos: Policy-defined roles vs. dynamic attributes

Learn how to handle authorization in applications with hierarchical data. In this post, we explore two approaches to implementing hierarchy-based permissions. Both methods leverage Attribute-Based Access Control.

GuideDocumentationEngineering
Alex OlivierJune 30, 2026
The Cerbos Hub effect matrix: read your authorization policy at a glance

The Cerbos Hub effect matrix: read your authorization policy at a glance

See how the Cerbos Hub effect matrix turns authorization policy files into a permissions grid of roles and actions, with allowed, denied, and conditional outcomes. Read what each role can do without parsing raw policy, drill into ABAC conditions, and spot over-permissive wildcard rules in review.

AnnouncementDocumentationEngineering+1
Alex OlivierJune 30, 2026
Agent skill for writing authorization policies in AWS Kiro

Agent skill for writing authorization policies in AWS Kiro

AWS Kiro is spec-driven, which means the access model is captured properly before any YAML gets written. This guide walks through installing the Cerbos policy skill in Kiro, the spec-then-policy workflow, how the skill picks up AWS Cognito attributes, and how validation runs against the real Cerbos compiler.

EngineeringGuideDocumentation
Alex OlivierJune 26, 2026
5 factors to weigh when building authorization architecture

5 factors to weigh when building authorization architecture

A product-creation journey always requires new thinking about a permissions strategy. Learn about the 5 instances when your authorization logic needs to be analyzed, evolved, changed and monitored, as your software product evolves.

Guide
Alex OlivierJune 25, 2026
Fine grained access control: What it actually takes to get it right

Fine grained access control: What it actually takes to get it right

Fine grained access control lets you authorize based on user attributes, resource ownership, and context instead of broad roles. This guide covers RBAC, ABAC, ReBAC, PBAC models, embedded vs. externalized authorization, real policy examples, and practical implementation patterns for engineering teams.

GuideEngineering
Anna PaykinaJune 25, 2026
Identiverse 2026: Agents made authorization the story

Identiverse 2026: Agents made authorization the story

Takeaways from Identiverse 2026, where AI agents pushed authorization to the front. Delegated authorization, the Shared Signals Framework, AuthZEN agent authorization, and why prompts aren't controls. Notes from three AuthZEN sessions and the best talks of the week.

Guide
Alex OlivierJune 24, 2026