---
title: "Cerbos Hub"
description: "The managed control plane for Cerbos: author, test, distribute and audit authorization policy across every deployment."
canonical: "https://www.cerbos.dev/product-cerbos-hub"
source: "https://www.cerbos.dev/product-cerbos-hub"
---

# Cerbos Hub

## Author, test, and iterate

**Web IDE for building policies**

Create policies in YAML with our policy wizard, and use the playground to define, validate, and test authorization rules.

**Real-time group collaboration**

Pair programmers or different team members to edit and review policies like a Google doc. Push authorization policy files changes directly from the Playground IDE to your Github repo.

**Test-driven development (TDD)**

All tests are executed in the Cerbos Hub CI pipeline before policy is rolled out to PDPs.

## Distribution, orchestration and monitoring

**Policy testing**

A managed CI/CD pipeline builds and tests every new commit to the policy repository following Git-ops principles.

**Policy orchestration**

Cerbos Hub keeps policies up-to-date by coordinating each new rollout to all PDPs across your infrastructure.

**Decision point monitoring**

Observability into all deployed PDPs, with instance logs, deployed policy version details and metrics in a single screen.

## Authorize anywhere

**In your infrastructure**

Whether on-premise, cloud, functions, or Kubernetes, Cerbos Hub simplifies testing and distribution keeping policy in sync.

**Serverless architectures**

Works in Vercel, Netlify, AWS Lambda & CloudFront, Google Cloud Functions, and Azure Functions.

**At edge & embedded devices**

Pre-compiled libraries provide local execution for edge devices such as security hardware and cameras.

**In browser runtime**

Make local, in-browser authorization calls for React, Angular, and front-end frameworks, powered by WebAssembly.

## Unified audit trail

**Capture every decision**

Every decision made by a Cerbos PDP is captured - know exactly which principal, did which action on which resource, and whether it was allowed or not.

**Decision lineage**

Audit logs provide not just the decision, but also how it was reached. Every record provides the specific policy, version, and releases which was responsible for the decision being made.

**Collated across environments**

Cerbos Hub collects and aggregates decision logs from every connected PDP, in every environment they are deployed.

## Per-tenant custom policies

Allow teams or end users to create tenant-specific custom roles programmatically, with testing, auditability, and governance built in.

[Read more](https://www.cerbos.dev/features-benefits-and-use-cases/per-tenant-custom-policies)

## Dynamic policies

Programmatically create and update policies from any business event - no custom pipelines or fragile sync logic.

[Read more](https://www.cerbos.dev/features-benefits-and-use-cases/dynamic-policies)

## Authorization for non-human identities

Manage permissions for workloads, microservices, AI agents, and API clients with flexible, policy-driven authorization.

[Read more](https://www.cerbos.dev/features-benefits-and-use-cases/authorization-non-human-identities)

## MCP server security

Dynamically control which AI agents can access specific MCP server tools with policy-based decisions, reducing security risks and simplifying audits.

[Read more](https://www.cerbos.dev/features-benefits-and-use-cases/dynamic-authorization-for-MCP-servers)

## AI systems and RAG data protection

Maintain data security and compliance with fine-grained authorization for your RAG and LLMs.

[Read more](https://www.cerbos.dev/features-benefits-and-use-cases/access-control-for-rag)

## Loved by engineers. Approved by leadership.

- **Externalized authorization** — Define authorization in policy, not code. Reuse across tenants, AI workflows, and environments.
- **One unified policy layer** — Centralize and manage access across apps, APIs, AI systems, and workloads from a single control point.
- **75% fewer authZ bugs and incidents** — Validate and test access policies automatically before every deployment.
- **Deploy new tenant policies in seconds** — Roll out tenant-specific access rules without code changes.

> Cerbos is plug and play. Developers can get Cerbos up and running in minutes. All the configuration there is fits in one nice little file. I can onboard a new developer onto Cerbos in an hour.
>
> — Steve High, Staff Engineer

## Loved by engineers. Approved by leadership.

- **100x faster launch** — Deploy new roles and personas instantly.
- **90% faster changes** — Adjust permissions on the fly to meet new access needs.
- **$500k saved yearly** — Eliminate the need for custom-built authorization infrastructure.
- **100% audit ready** — Centralized logs SOC2, HIPAA, ISO 27001, PCI DSS, and GDPR.

> One of our favorite features is the audit logs because it allows us to understand what is happening in the black box. We’ve never had that before.
>
> — Rob Crowe, Principal Engineer
