Guide
All articles tagged Guide.

EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents
The identity stack built for humans does not hold up for AI agents and ephemeral workloads. Takeaways from EIC 2026 on signal-driven authorization, action-based provisioning, delegation chains, token issuer risk, and the four questions every CISO should ask about agent identity in the next 12 months.

Query plan adapter for Elasticsearch (Java)
Externalized authorization with Cerbos. Translate policies into native Elasticsearch Query DSL using the PlanResources API. Push access control to the database layer, avoid post-fetch filtering, and scale secure search with nested query support and operator overrides.

Already have authentication? Here's the authorization layer you still need.
Identity providers cover authentication, not fine-grained access control. See the authorization gaps they leave and how to evaluate a solution.

How much does it cost to build authorization in-house?
The cost of building authorization in-house often runs into seven figures. This guide breaks down real numbers from Salesroom, Debite, Loop, and 4G Capital, plus the hidden costs of maintenance, compliance, and diverted developer time that most teams forget to estimate upfront.

Integrating Cerbos with Kong: A how-to guide for API gateway authorization
Learn how to integrate Cerbos with Kong to offload authorization decisions from your services and centralize policy enforcement at the gateway. This hands-on guide walks through a real setup using Docker Compose, custom plugins, and fine-grained access policies to secure every API request.

Tokens are authorization decisions: a guide to policy-driven token issuance
Tokens are authorization decisions, and most identity teams don't manage them like one. This article explains policy-driven token issuance, the three patterns Gartner calls Authorization Management Platforms, what AuthZEN changes, and how to govern AI agent tokens without hardcoding logic into the IdP.

Query plan adapter for Convex
Externalized authorization with Cerbos moves access control into policy files and pushes filtering to the data layer. Learn how the PlanResources API and a new Convex adapter generate efficient, secure queries without row-by-row checks.

What is a Runtime Authorization Platform
Runtime Authorization Platforms explained. What runtime authorization actually means, how it differs from admin-time and event-time controls, why attacks land on the runtime layer, and what separates a real runtime platform from a policy engine. Covers architecture, deployment shapes, AuthZEN, and continuous evaluation.

It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance
AI agent drift needs more than a kill switch. CISOs and IAM leaders in regulated industries are moving to a dimmer switch model, fine-grained runtime authorization that narrows agent access without breaking the workflow, with a complete audit trail of every decision and policy change.

Query plan adapter for Drizzle ORM
Externalized authorization with Cerbos PlanResources API and Drizzle ORM. Generate efficient, policy-driven SQL filters from query plans. Avoid row-by-row checks, reduce database I/O, and enforce scalable access control at the query layer with @cerbos/orm-drizzle.

Query plan adapter for LangChain.js and ChromaDB
Enforce fine-grained authorization in RAG apps with Cerbos and ChromaDB. Learn how @cerbos/langchain-chromadb converts Cerbos query plans into ChromaDB filters, so vector search respects access policies at retrieval time and prevents unauthorized data from reaching your LLM.

AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel
Notes from the OpenID Foundation enterprise panel on how Shared Signals, AuthZEN, SCIM Events and IPSIE fit as a stack, the missing reference architectures between specs, and where AI agents land against existing OAuth and OIDC primitives. With Atul Tulshibagwale, Mike Kiser, Dick Hardt and Alex Olivier.

How do you update authorization policies without redeploying your application?
Authorization policy updates without redeployment, explained. Cerbos separates policy from application code so permission changes become configuration updates, not code changes. Covers YAML policies, Cerbos Hub distribution, Git-based workflows, and customer results from 4G Capital, Human Managed, 9fin, BarrierSystems, and Utility Warehouse.

IIW42 recap: Where agent authorization got real
IIW42 was the unconference where agent authorization stopped being theoretical. This recap covers what changed in agent identity, why the principal model is breaking, intent drift, the cross-trust-domain problem, and why identity matters more for accountability than for the policy decision itself.

Authorization Management Platforms: what they do, how they work, and where they fit
Authorization Management Platforms. What an AMP actually does, the PAP, PDP, PEP, PIP and POP architecture, integration modes, and where the category fits alongside IGA, PAM, and access management in the identity stack.

PocketOS AI coding agent deleted a production database in 9 seconds
An AI coding agent on Cursor and Claude Opus 4.6 deleted PocketOS's production database in nine seconds, backups included. The fix isn't a smarter model. It's authorization that lives outside the agent. Here's what would have stopped it, and the authorization policy you can ship this week.

Non-Human Identity management still has a blind spot
Non-human identity management today focuses on discovery, inventory, and credential rotation. This guide covers why runtime authorization is the missing layer, how overprivileged NHIs create risk at scale, and how to enforce fine-grained, policy-based access control for every service-to-service request.

Supabase alternative in 2026: Best open source auth options
Compare open source Supabase Auth alternatives for authentication, identity, and authorization. See where SuperTokens, ZITADEL, Authentik, Keycloak, Hanko, and Cerbos PDP fit.