Tag

Guide

All articles tagged Guide.

Benefits of on-premise authorization: Why enterprises are moving toward self-hosted

Benefits of on-premise authorization: Why enterprises are moving toward self-hosted

On-premise authorization gives security teams full control over policies, decision logs, and audit trails without data leaving the perimeter. This guide covers why regulated enterprises are moving to self-hosted, when cloud-hosted still makes sense, and what to look for in a deployment-flexible authorization platform.

Guide
Emre BaranApril 24, 2026
Authorization policies: How to write, test, and validate them (faster with AI)

Authorization policies: How to write, test, and validate them (faster with AI)

Writing authorization policies shouldn't take a week. This practical guide covers how to write, structure, and test authorization policies at enterprise scale, the common mistakes that ship security holes, and how to use an AI coding agent to draft full policy bundles while you handle the judgment calls.

Guide
Alex OlivierApril 22, 2026
Agent skill for writing authorization policies

Agent skill for writing authorization policies

Writing authorization policies from a blank file is slow. The Cerbos agent skill handles the drafting for you, asking clarifying questions in plain English before generating a full Cerbos policy bundle with schemas, roles, resource policies, and tests. Works with Claude Code, Cursor, Codex, and more.

EngineeringDocumentationGuide
Alex OlivierApril 21, 2026
Why centralized authorization governance reduces incident response time

Why centralized authorization governance reduces incident response time

Centralized authorization governance gives security leaders instant visibility into every access decision during a breach. This article covers why fragmented access control stalls incident response, how AI agents expand the authorization surface, CISO personal liability under SEC rules, and how to evaluate solutions.

Guide
Alex OlivierApril 17, 2026
OPA alternative

OPA alternative

This article examines why Cerbos stands out as the best alternative to Styra and OPA for authorization needs. Comparison is based on policy language, deployment, performance, observability, DX and scalability.

Guide
Alex OlivierApril 16, 2026
Why AI agents make authorization a right now problem

Why AI agents make authorization a right now problem

AI agents don't create new vulnerabilities. They find the authorization ones you already had, faster and at scale. Why Gartner's new Authorization Management Platform category matters, what deterministic policy enforcement looks like, and how to close the gaps before the next model release finds them.

Guide
Emre BaranApril 15, 2026
Implement authorization and access control in an Express application

Implement authorization and access control in an Express application

Explore importance of roles and permissions in webapps and learn how to use Cerbos authorization to enforce RBAC for a sample LMS implemented in Express and Node.

Guide
Adejoke HaastrupApril 14, 2026
Modernizing legacy application authorization: why it’s your biggest security blind spot

Modernizing legacy application authorization: why it’s your biggest security blind spot

Your legacy applications have the weakest authorization controls and the most sensitive data. Learn how security and identity teams can close the governance gap by adding policy-based authorization, compliance-ready audit trails, and context-aware access decisions at the gateway without modifying the application.

Guide
Alex OlivierApril 14, 2026
How to add authorization to legacy applications without code changes

How to add authorization to legacy applications without code changes

Learn how to add authorization to legacy applications without modifying a single line of code. This guide covers the gateway pattern with Cerbos Synapse and Envoy, route-level policy enforcement, device posture checks, audit trail coverage, and a phased path from zero visibility to full authorization governance.

EngineeringDocumentationGuide
Alex OlivierApril 11, 2026
5 authorization blind spots auditors find, and how to fix them

5 authorization blind spots auditors find, and how to fix them

A practical guide to the 5 authorization gaps that drive access control audit findings in regulated enterprises. Covers scattered authorization logic, proof of enforcement, role versus permission reviews, non-human identity governance, and AI agent authorization, with concrete steps to fix each one.

Guide
Alex OlivierApril 10, 2026
Row-level security for Apache Trino, powered by Cerbos Synapse

Row-level security for Apache Trino, powered by Cerbos Synapse

Add row-level security, column masking, and table-level access control to Apache Trino using Cerbos policies. No Rego, no custom plugins. Covers policy examples, attribute-based filtering from your IdP, per-role masking rules, and compliance audit logging through Cerbos Hub.

EngineeringDocumentationGuide
Alex OlivierApril 07, 2026
AI Security Platforms (AISP): What they are, why they matter, and how they work

AI Security Platforms (AISP): What they are, why they matter, and how they work

AI Security Platforms (AISP) explained. Learn what AISPs are, why they matter, and how they secure AI agents, LLMs, and workflows against prompt injection, data leakage, and rogue behavior with real-world, technical examples.

Guide
Alex OlivierApril 03, 2026
Top 9 Identity & Access Management (IAM) Tools for 2026

Top 9 Identity & Access Management (IAM) Tools for 2026

IAM tools are essential for enhancing security, streamlining access management processes, and ensuring compliance in organizations. In this blog, we're going to discuss the top 9 identity and access management (IAM) tools of 2026.

DocumentationGuide
Rohit GhumareApril 02, 2026
Authelia vs Authentik in 2026: Which self-hosted IdP should you choose

Authelia vs Authentik in 2026: Which self-hosted IdP should you choose

Authelia vs Authentik explained: compare a lightweight forward-auth gateway and a full IdP, when to choose each, security notes. This guide covers MFA, SSO, protocol support, deployment trade-offs, CVE track records, and community insights to help you pick the right fit for your stack.

Guide
S. B. WriterApril 01, 2026
Can non-engineers manage authorization policies with Cerbos?

Can non-engineers manage authorization policies with Cerbos?

How non-engineers manage authorization policies with Cerbos. Product managers, security leads, and even end customers can write and update YAML policies thanks to readable syntax and CEL conditions. Includes Supy's self-service custom roles, Human Managed's five-minute policy changes, and the Git review workflow that keeps changes safe.

Guide
Emre BaranMarch 29, 2026
Governing AI coding agents with Cerbos Synapse

Governing AI coding agents with Cerbos Synapse

Learn how to control every tool call with policy, enforce role-based access, and get full audit visibility using Cerbos Synapse

Guide
Alex OlivierMarch 27, 2026
Your AI coding agents need guardrails. Not the kind you think

Your AI coding agents need guardrails. Not the kind you think

What can your Claude Code agent do on your machine right now? A deep dive into how to actually control it with real enforcement, policies, and audit visibility.

Guide
Alex OlivierMarch 26, 2026
Mapping business requirements to authorization policy for utilities

Mapping business requirements to authorization policy for utilities

Learn how to write and manage authorization policies for utility companies using PBAC. Compare RBAC vs. ABAC across real-world scenarios like SCADA access control, gas sensor policies, compliance audits, and vendor onboarding - with practical YAML and code examples that reduce downtime, cut costs, and simplify operations.

EngineeringGuide
H.A. WriterMarch 23, 2026