---
title: "Cerbos for architects"
description: "How Cerbos fits an existing architecture: decoupled authorization that integrates with the identity, data and deployment stack you already run."
canonical: "https://www.cerbos.dev/for-architects"
source: "https://www.cerbos.dev/for-architects"
---

# Cerbos for architects

## Externalized authorization for your enterprise applications

- **Policy based access control** — Ensure dynamic and flexible access control with policy-driven decisions. Adapt to changing access needs with ease, define access based on multiple conditions and contexts, and manage policies within your existing governance processes. [PBAC](https://www.cerbos.dev/features-benefits-and-use-cases/pbac)
- **Decision level audit logs** — Achieve transparency, accountability, and compliance with Cerbos' comprehensive audit logging. Feed application decision logs into your existing SIEM tooling for end-to-end visibility. Audit logs in Cerbos Hub capture authorization decisions across all PDP instances in a central, collated feed. [Audit logs](https://www.cerbos.dev/features-benefits-and-use-cases/audit-logs)
- **Distributed decisioning, centrally managed** — Use Cerbos Hub's unified platform to enable collaborative authoring, iteration, and management of authorization policies by developers and product teams. Maintain consistent, transparent, and adaptable authorization logic across all applications. [Cerbos Hub](https://www.cerbos.dev/product-cerbos-hub)

## Why Cerbos?

- **Flexible deployment models** — Self-hosted, compatible with air-gapped, high security environments. Deploy with serverless functions or a sidecar model. [Deployment](https://www.cerbos.dev/features-benefits-and-use-cases/flexible-deployment-models)
- **Open source** — Cerbos PDP source code is freely available under Apache 2.0 license. [GitHub](https://github.com/cerbos)
- **Built for scale** — Cerbos is containerized, stateless, and scales horizontally to handle increasing demands. [Scalability](https://www.cerbos.dev/features-benefits-and-use-cases/scalability)
- **Centralized management** — Use Cerbos Hub for policy management, collaboration, and streamlined deployment. [Cerbos Hub](https://www.cerbos.dev/product-cerbos-hub)
- **Supported authentication providers** — Use any identity provider to authenticate your users. Use Cerbos to enforce access controls. Cerbos natively supports JWT for integration with numerous authentication providers, such as: JWT, Auth0, Okta, and others. [Authentication support](https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem)
- **Fine-grained access control** — Achieve precise control over resource access via RBAC and ABAC policy. [RBAC](https://www.cerbos.dev/features-benefits-and-use-cases/rbac) · [ABAC](https://www.cerbos.dev/features-benefits-and-use-cases/abac)
- **No lock-in** — Maintain full ownership of where policies are stored, and deploy onto any platform. [No lock-in](https://www.cerbos.dev/features-benefits-and-use-cases/no-cloud-vendor-lock-in)
- **Thriving community** — Join an active community of Cerbos users and connect directly with our engineers. [Slack community](https://community.cerbos.dev)

## The Impact of Cerbos

> "We can run Cerbos next to our application, and can have as many instances running as we need to. So we can have one dedicated host we're running it on. And so there's much less risk of it going down and taking everything down without us knowing about it all, without being completely out of our control, like the host solution might be."
>
> — David, Senior Software Engineer

> "One of our favorite features is the audit logs because it allows us to understand what is happening in the black box. We’ve never had that before and we didn’t know we needed it."
>
> — Rob, Principal Engineer

> "Throwing the entire concern of authorization across to Cerbos really did increase my velocity, which in turn increases velocity downstream from me. It has allowed the team to deliver top-tier user experience and concentrate on faster app iterations."
>
> — Steve, Staff Engineer

> "I categorized Cerbos as just one of those things I probably don't have to think about. And that's a very valuable thing to me cause there's a lot of things that take up even a small percentage of our mind space. And if we can just leave it be in the corner and know that we'll be protected. And if something goes wrong, they will do everything in their power to resolve. It gives you that extra bit of confidence."
>
> — Chuck, Head of Engineering

> "Having the separation of the permissions from the code base just makes the code base more elegant. It makes the permissioning more elegant. It means they're centralized, so they're not tied to specific endpoints. And ultimately it means that different business owners, i.e. Joe, in our case, because he's the only one who's not a developer, have the ability to actually make updates."
>
> — Henry, CTO & Co-Founder
