---
title: "Cerbos: authorization for enterprise software and AI"
description: "Enforce fine-grained, contextual, and continuous authorization across applications, gateways, workloads, and AI agents."
canonical: "https://www.cerbos.dev"
source: "https://www.cerbos.dev/index.md"
---

# Authorize every identity. Govern every action.

Enforce fine-grained, contextual, and continuous authorization across applications, gateways, workloads, and AI agents.

Cerbos is an end-to-end authorization management platform. Policies are authored once as human-readable YAML, managed centrally, and enforced at runtime by stateless Policy Decision Points deployed alongside your services — in the cloud, on-premise, or air-gapped.

It replaces the authorization logic scattered through application code with a single call that returns an allow or deny decision, evaluated against the principal, the resource, and the context of the request. RBAC, ABAC, ReBAC and PBAC are all expressed in the same policy language.

## Make roles and permissions an asset, not a chore

- **Faster app development** — Externalize authorization and prioritize your app’s core functionalities. Leverage a plug-and-play, API-based approach, designed to integrate with your existing systems and accelerate development, saving you months of implementation time.
- **Flexible to changing requirements** — Adapt to evolving business needs and regulatory requirements with policy-based authorization. Centralized management which integrates into governance frameworks, enabling changes without compromising compliance.
- **Increased security at scale** — Ensure least-privilege access across all apps and services in your architecture. Implement fine-grained, zero trust runtime access controls to protect your data and systems from evolving threats at runtime.

## Build roles and permissions in minutes

- **Pre-built integrations and policies** — Get up and running in minutes with SDKs and starter projects for common frameworks, servers, ORMs and identity providers.

  [Ecosystem](https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem)
- **Permissions aware data filtering** — Generate dynamic conditions to query and filter based on the access policy for each object and principal.

  [Query filtering](https://www.cerbos.dev/features-benefits-and-use-cases/permission-aware-data-filtering) · [Data-filtering for RAG](https://www.cerbos.dev/features-benefits-and-use-cases/access-control-for-rag)
- **Beyond RBAC/ABAC** — Implement context-aware role definitions and attribute-based access control for adaptable, granular security policies.

  [RBAC](https://www.cerbos.dev/features-benefits-and-use-cases/rbac) · [ABAC](https://www.cerbos.dev/features-benefits-and-use-cases/abac)

## Iterate with ease

- **Human-readable** — Manage policies in configuration instead of code.

  [Low-code](https://www.cerbos.dev/features-benefits-and-use-cases/human-readable-authorization)
- **Policy Playground** — Experiment with policies in a safe environment and get simulated results in real time.

  [Playground](https://www.cerbos.dev/features-benefits-and-use-cases/cerbos-playground)
- **GitOps testing** — Implement a CI/CD workflow with GitOps. Reduce human errors and enhance security.

  [GitOps & CI/CD](https://www.cerbos.dev/features-benefits-and-use-cases/gitops-and-ci-cd)
- **Stateless and scalable** — Stateless decision points run in your environment or at the edge.

  [Stateless authZ](https://www.cerbos.dev/features-benefits-and-use-cases/stateless-authorization)

## Deploy without risk

- **Audit trails** — Capture all actions attempted and decisions made by your Cerbos policies. ISO27001, SOC2, HIPAA compliant.

  [Audit logs](https://www.cerbos.dev/features-benefits-and-use-cases/audit-logs)
- **Coordinated rollout and monitoring** — Centralized management and real-time policy deployment to keep authorization synchronized across your application.

  [Coordinated rollout](https://www.cerbos.dev/features-benefits-and-use-cases/coordinated-rollout-and-monitoring)
- **Low-latency** — Decisions are made locally at runtime in sub-milliseconds without requiring any cloud lookups.

  [Low-latency](https://www.cerbos.dev/features-benefits-and-use-cases/flexible-deployment-models)
- **Flexible deployment models** — Self-hosted, compatible with air-gapped, high security environments. Deploy with serverless functions or a sidecar model.

  [Deployment](https://www.cerbos.dev/features-benefits-and-use-cases/flexible-deployment-models)

## Cerbos benefits for different roles

- **Developers** — Replace complicated authorization logic with a single call and allow product owners or security teams to manage access without touching code.

  [Implement authZ once](https://www.cerbos.dev/for-developers)
- **Product Managers** — Define and evolve complex policies without requiring further developer time.

  [Plug and play collaborative authZ](https://www.cerbos.dev/for-product-teams)
- **Security teams** — Track and audit access requests, grants and denials without without requiring further developer effort.

  [Low-code collaborative authZ](https://www.cerbos.dev/for-security-teams)
- **Architects** — Design a truly zero trust application architecture with externalized authorization.

  [Secure your architecture](https://www.cerbos.dev/for-architects)

## Secure non-human identities at scale

Manage permissions for workloads, microservices, AI agents, and API clients with flexible, policy-driven authorization.

## Centralized management, decentralized decisioning

- Define RBAC and ABAC policies in a single source of truth.
- Manage, govern and audit access control from a central Policy Administration Point.
- Deploy distributed Policy Decision Points (PDP) locally alongside applications and services for local decisioning at runtime

## What our users say about Cerbos

> "It's weird to say an outside company has our back, but Cerbos does. It's the people. It's their open-source code: it's high quality, you can read it, it does what it says on the tin"
>
> — Rob, Principal Engineer, Utility Warehouse

> "It's a good feeling being able to say yes to almost any permissioning requirement." "Cerbos is small, contained and easy to implement. It 100% delivers on the promise of abstracting away the complexity of decision making."
>
> — Joe, Software Engineer, 9fin

> "We're not worried about scaling because we can easily increase our load on Cerbos. It will also be easy for us to change how we're distributing policies as we reach different points of scale."
>
> — David, Senior Software Engineer, Salesroom

> "We went from one user - every role, to a world where there are many users - many roles. And the product, it relies on Cerbos to actually bring the value that we want to bring to customers. All of our customers are relying on Cerbos, by relying on the product, which is of course relying on Cerbos."
>
> — Joe, CEO & Co-Founder, Nook

> "Instead of thinking of how much time Cerbos has saved us, I think about how much time it didn't cost us. It didn't cost us any time. Cerbos just works. I don't have to think about it. It's as simple as that."
>
> — Chuck, Head of Engineering, Salesroom

> "One of our big considerations was speed. We have strict latency tolerances. When it comes to Cerbos - you can call it a hundred times during a request and it doesn't matter. It's incredibly fast."
>
> — Steve, Staff Engineer, Complex

> "If it wasn't for Cerbos, one thing is for sure - we would've launched later than we did. As a result, we would have less customers. And the maintenance part is also very important. Our technical team would be dealing with daily stuff regarding access controls, access logs. Now, we don't have to spend any time on that."
>
> — Engin, Head of Product and Growth & Co-Founder, Debite

> "Cerbos policy writing is quite flexible, and deploying as a unit microservice as well. Cerbos "doesn't get in the way" once integrated, that's the best part."
>
> — Rounak, Founding Engineer, CommandK

> "It is easy to implement and provides a solution for a problem that is often not properly addressed."
>
> — Romina, Tech Lead, Wizeline

> "Having the separation of the permissions from the code base just makes the code base more elegant. It makes the permissioning more elegant. It means they're centralized, so they're not tied to specific endpoints. And ultimately it means that different business owners have the ability to actually make updates."
>
> — Henry, CTO & Co-Founder, Nook

> "Just discovered your embedded testing framework. This is probably the best balance between hyperfocused functionality and embedded tooling I've ever seen in an open source project. Damn, good work!"
>
> — Rasmus, CTO, Firtal

## Next steps

- [Book a demo](https://www.cerbos.dev/workshop)
- [Try Cerbos Hub for free](https://hub.cerbos.cloud/)
- [Cerbos PDP](https://www.cerbos.dev/product-cerbos-pdp.md) — the open-source decision engine
- [Cerbos Hub](https://www.cerbos.dev/product-cerbos-hub.md) — the management control plane
- [Pricing](https://www.cerbos.dev/pricing.md)
- [Documentation](https://docs.cerbos.dev)
- [Index for agents](https://www.cerbos.dev/llms.txt) — every document on this site, with its markdown URL
- Command line: `npm install -g cerbosctl`, or `brew tap cerbos/tap && brew install cerbos`
