Guide
All articles tagged Guide.

Migrating from OPA and Rego to Cerbos
Learn how to migrate from from OPA and Rego to Cerbos. This guide walks you through the differences, how to translate common patterns, how to update your integration layer, and how to roll out the migration safely.

Broken access control still tops the list: OWASP top 10 2025
Learn why Broken Access Control remains the top OWASP 2025 risk and how Cerbos provides scalable, fine-grained authorization to prevent object-level and contextual access failures.

Platform engineering leaders are racing to enable AI safely - takeaways from KubeCon NA 2025
Discover how platform engineering leaders at KubeCon NA use a three-lane model, sandboxes, and shift-down security to accelerate safe AI adoption, govern AI agents, and protect developer velocity.

AuthZEN: Standards-based authorization for enterprises
Authorization used to lack the standards authentication gained with OAuth and OpenID. AuthZEN, backed by the OpenID Foundation, introduces a unified model for externalized, fine-grained, and interoperable access control. Discover how Cerbos supports AuthZEN to deliver modern, standardized enterprise authorization.

What ISC2 congress 2025 made clear about modern compliance
ISC2 Congress 2025 highlighted the shift from policy documentation to policy as code. Learn how security leaders are implementing continuous compliance, governing AI systems, quantifying cyber risk, and embedding enforcement directly into infrastructure for measurable, auditable security controls.

Mapping business requirements to authorization policy in HR systems
Best practices for translating business requirements into authorization policy for your Human Resources (HR) system. We walk through the process of reviewing business requirements, analyzing them, defining policies, and ultimately deploying them to production systems as efficiently as possible.

Mapping business requirements to authorization policy for insurance
Explore how insurance companies can combat fraud with modern authorization. This guide explains PBAC in action across auto, life, and property insurance; with practical examples and policy templates to help you implement secure, fraud-resistant access control in your organization.

Run Cerbos natively inside AWS Lambda
Deploy Cerbos directly in AWS Lambda-either as a standalone function or as a lightweight extension layer-while using Cerbos Hub for centralized policy management and audit-logging.

Building your own authorization solution vs. buying an off-the-shelf one
Build vs. buy for authorization. There is no standard answer to the perennial build vs. buy question, but the argument for rolling your own authorization is getting harder to make. In this article, we help you speedrun the build vs. buy decision by breaking down your choices, so you can evaluate what’s best for your situation.

Zero trust has reached operational reality
Zero Trust is no longer theoretical. Discover how mature identity standards and centralized authorization transform Zero Trust from strategy to execution, delivering continuous compliance, reduced breach impact, and faster, more secure development.

Modern application architecture trends: AI, microservices, and pragmatic security
Explore modern application architecture trends for AI-driven infrastructure, modular monoliths, microservices, and pragmatic security, as well as patterns shaping cloud, on-prem, and hybrid systems.

Zero-Trust for microservices, a practical blueprint
Learn how to implement a Zero-Trust security model for microservices. Discover how to secure service-to-service communication, manage workload identities, and enforce fine-grained authorization across distributed systems, AI agents, and APIs.

How to implement resource-based authorization
Learn how to implement resource-based authorization for fine-grained, contextual access control. Compare it to role-based and attribute-based models, explore real-world use cases, such as in microservices and multi-tenant SaaS applications.

What is access control?
Learn what access control is, why it’s essential, and how it operates within application environments. We’ll also explore some common challenges developers face when implementing access control and review the types of technologies that can streamline the process.

How to secure your FastMCP server with permission management
FastMCP is a Python framework for building production-ready MCP servers with minimal code. Without authorization, these servers risk exposing all tools to every user. The **cerbos-fastmcp** middleware adds policy-driven, fine-grained access control to secure FastMCP deployments.

NHI security: How to manage non-human identities and AI agents
Discover NHI security: How to manage non-human identities and AI agents with practical principles. Learn strategies for inventory, least privilege, access controls, and authorization to secure NHIs and prevent AI risks in modern enterprises.

MCP security & AI agent authorization. A CISO and architect’s guide to securing the new AI perimeter.
MCP security and AI agent authorization are critical to protecting enterprise data. This guide explores risks, the “confused deputy” problem, and how externalized authorization builds a zero trust model to secure the new AI perimeter without slowing innovation.

Mapping business requirements to authorization policy for medtech
Learn how to translate business requirements to authorization policy for medtech. Decouple authorization to keep medtech platforms compliant (HIPAA, GDPR, FDA 21 CFR Part 11, NHS RBAC), resilient to updates, and safe. Explore break-glass access, audit logs, role-based control, and an example case study.