Tag

Guide

All articles tagged Guide.

Migrating from OPA and Rego to Cerbos

Migrating from OPA and Rego to Cerbos

Learn how to migrate from from OPA and Rego to Cerbos. This guide walks you through the differences, how to translate common patterns, how to update your integration layer, and how to roll out the migration safely.

GuideEngineeringDocumentation
Alex OlivierNovember 20, 2025
Broken access control still tops the list: OWASP top 10 2025

Broken access control still tops the list: OWASP top 10 2025

Learn why Broken Access Control remains the top OWASP 2025 risk and how Cerbos provides scalable, fine-grained authorization to prevent object-level and contextual access failures.

Guide
Alex OlivierNovember 20, 2025
Platform engineering leaders are racing to enable AI safely - takeaways from KubeCon NA 2025

Platform engineering leaders are racing to enable AI safely - takeaways from KubeCon NA 2025

Discover how platform engineering leaders at KubeCon NA use a three-lane model, sandboxes, and shift-down security to accelerate safe AI adoption, govern AI agents, and protect developer velocity.

Guide
Alex OlivierNovember 18, 2025
AuthZEN: Standards-based authorization for enterprises

AuthZEN: Standards-based authorization for enterprises

Authorization used to lack the standards authentication gained with OAuth and OpenID. AuthZEN, backed by the OpenID Foundation, introduces a unified model for externalized, fine-grained, and interoperable access control. Discover how Cerbos supports AuthZEN to deliver modern, standardized enterprise authorization.

Guide
Alex OlivierNovember 07, 2025
What ISC2 congress 2025 made clear about modern compliance

What ISC2 congress 2025 made clear about modern compliance

ISC2 Congress 2025 highlighted the shift from policy documentation to policy as code. Learn how security leaders are implementing continuous compliance, governing AI systems, quantifying cyber risk, and embedding enforcement directly into infrastructure for measurable, auditable security controls.

Guide
Alex OlivierNovember 06, 2025
Mapping business requirements to authorization policy in HR systems

Mapping business requirements to authorization policy in HR systems

Best practices for translating business requirements into authorization policy for your Human Resources (HR) system. We walk through the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible.

EngineeringGuide
H.A. WriterNovember 02, 2025
Mapping business requirements to authorization policy for insurance

Mapping business requirements to authorization policy for insurance

Explore how insurance companies can combat fraud with modern authorization. This guide explains PBAC in action across auto, life, and property insurance; with practical examples and policy templates to help you implement secure, fraud-resistant access control in your organization.

EngineeringGuide
H.A. WriterOctober 30, 2025
Run Cerbos natively inside AWS Lambda

Run Cerbos natively inside AWS Lambda

Deploy Cerbos directly in AWS Lambda-either as a standalone function or as a lightweight extension layer-while using Cerbos Hub for centralized policy management and audit-logging.

EngineeringDocumentationGuide
Alex OlivierOctober 30, 2025
Building your own authorization solution vs. buying an off-the-shelf one

Building your own authorization solution vs. buying an off-the-shelf one

Build vs. buy for authorization. There is no standard answer to the perennial build vs. buy question, but the argument for rolling your own authorization is getting harder to make. In this article, we help you speedrun the build vs. buy decision by breaking down your choices, so you can evaluate what’s best for your situation.

Guide
Emre BaranOctober 28, 2025
Zero trust has reached operational reality

Zero trust has reached operational reality

Zero Trust is no longer theoretical. Discover how mature identity standards and centralized authorization transform Zero Trust from strategy to execution, delivering continuous compliance, reduced breach impact, and faster, more secure development.

Guide
Alex OlivierOctober 27, 2025
Modern application architecture trends: AI, microservices, and pragmatic security

Modern application architecture trends: AI, microservices, and pragmatic security

Explore modern application architecture trends for AI-driven infrastructure, modular monoliths, microservices, and pragmatic security, as well as patterns shaping cloud, on-prem, and hybrid systems.

GuidePresentation
Alex OlivierOctober 21, 2025
Zero-Trust for microservices, a practical blueprint

Zero-Trust for microservices, a practical blueprint

Learn how to implement a Zero-Trust security model for microservices. Discover how to secure service-to-service communication, manage workload identities, and enforce fine-grained authorization across distributed systems, AI agents, and APIs.

GuideEngineering
Alex OlivierOctober 17, 2025
How to implement resource-based authorization

How to implement resource-based authorization

Learn how to implement resource-based authorization for fine-grained, contextual access control. Compare it to role-based and attribute-based models, explore real-world use cases, such as in microservices and multi-tenant SaaS applications.

Guide
Emre BaranOctober 13, 2025
What is access control?

What is access control?

Learn what access control is, why it’s essential, and how it operates within application environments. We’ll also explore some common challenges developers face when implementing access control and review the types of technologies that can streamline the process.

Guide
Alex OlivierOctober 10, 2025
How to secure your FastMCP server with permission management

How to secure your FastMCP server with permission management

FastMCP is a Python framework for building production-ready MCP servers with minimal code. Without authorization, these servers risk exposing all tools to every user. The **cerbos-fastmcp** middleware adds policy-driven, fine-grained access control to secure FastMCP deployments.

GuideIntegration
Alex OlivierOctober 08, 2025
NHI security: How to manage non-human identities and AI agents

NHI security: How to manage non-human identities and AI agents

Discover NHI security: How to manage non-human identities and AI agents with practical principles. Learn strategies for inventory, least privilege, access controls, and authorization to secure NHIs and prevent AI risks in modern enterprises.

Guide
Emre BaranOctober 03, 2025
MCP security & AI agent authorization. A CISO and architect’s guide to securing the new AI perimeter.

MCP security & AI agent authorization. A CISO and architect’s guide to securing the new AI perimeter.

MCP security and AI agent authorization are critical to protecting enterprise data. This guide explores risks, the “confused deputy” problem, and how externalized authorization builds a zero trust model to secure the new AI perimeter without slowing innovation.

Guide
Emre BaranSeptember 30, 2025
Mapping business requirements to authorization policy for medtech

Mapping business requirements to authorization policy for medtech

Learn how to translate business requirements to authorization policy for medtech. Decouple authorization to keep medtech platforms compliant (HIPAA, GDPR, FDA 21 CFR Part 11, NHS RBAC), resilient to updates, and safe. Explore break-glass access, audit logs, role-based control, and an example case study.

GuideEngineering
H.A. WriterSeptember 28, 2025