Cerbos blog

Blog

Demos, implementation guides, product updates and broader takes on authorization, identity and security. Written for the engineers, architects, security, identity and product leaders shaping how their teams ship and govern access.

Hand the application a query filter, not a per row authorization decision
Featured

Hand the application a query filter, not a per row authorization decision

Per record authorization breaks when an application renders a list. This guide covers asking the policy engine what a user can see, turning a query plan into a database predicate, where AuthZEN search endpoints fit, and why translating to SQL, ORM or vector filters belongs in one place.

GuideEngineering
Alex OlivierOctober 01, 2026
Read authorization attributes from the database, not a copy

Read authorization attributes from the database, not a copy

Authorization attributes like plan tier, team and clearance already live in a database. How Cerbos Synapse fetches them at decision time with a SQL data source and a Starlark proxy extension, how to set cache TTL per attribute, and how checks fail closed when the database is unreachable.

GuideEngineering
Alex OlivierSeptember 25, 2026
Gluu vs Keycloak

Gluu vs Keycloak

A current comparison of Gluu and Keycloak for identity teams, covering the Janssen Project and Flex split, Keycloak's CNCF position, and where each project's authorization engine runs out of room.

Guide
S. B. WriterSeptember 21, 2026
Kafka topic authorization belongs in your policy set, not in a per cluster ACL list

Kafka topic authorization belongs in your policy set, not in a per cluster ACL list

Kafka ACLs accumulate per cluster. This guide covers how Kafka's pluggable authorizer hands topic access decisions to an external policy engine, how ACL bindings map onto resource policies, caching and fail closed tradeoffs on the broker hot path, and what moves topic access into one audited policy set.

EngineeringGuide
Alex OlivierSeptember 18, 2026
Cerbos named a Sample Vendor for AuthZEN in the Gartner® Hype Cycle™ for Digital Identity, 2026

Cerbos named a Sample Vendor for AuthZEN in the Gartner® Hype Cycle™ for Digital Identity, 2026

The Gartner Hype Cycle for Digital Identity, 2026 includes AuthZEN as a category, with Cerbos named as a Sample Vendor. We cover what the OpenID AuthZEN standard does, why interoperable authorization matters as AI agents spread, and where Cerbos fits.

Announcement
Anna PaykinaSeptember 16, 2026
Rich Authorization Requests (RAR) for agent tokens

Rich Authorization Requests (RAR) for agent tokens

OAuth scopes can say read the profile, not transfer 45 euros to this merchant. Here is how Rich Authorization Requests express precise, per-hop grants for AI agents.

Guide
Emre BaranSeptember 16, 2026
The Cerbos PDP dashboard is now on Grafana Cloud

The Cerbos PDP dashboard is now on Grafana Cloud

The Cerbos PDP dashboard is now on the Grafana Cloud dashboards site. Import it by ID, point it at your Prometheus data source, and every instance in your fleet is on one screen, from health and loaded policy count down to latency percentiles.

GuideEngineering
Anna PaykinaSeptember 15, 2026
Best zero trust security tools and solutions for 2026

Best zero trust security tools and solutions for 2026

The best zero trust security tools and solutions, broken down by layer. Identity and access management, privileged access, zero trust network access, device trust, authorization and policy enforcement, data protection, and visibility, with the notable tools in each and how to prioritize the layer most stacks leave hardcoded.

Guide
Anna PaykinaSeptember 12, 2026
Why your audit trail breaks at the sub-agent boundary

Why your audit trail breaks at the sub-agent boundary

When agent A delegates to agent B, the downstream logs show the service account, not the user. Here is why the audit trail breaks at the sub-agent boundary, and how to fix it.

Guide
Alex OlivierSeptember 11, 2026
Keycloak vs Ory

Keycloak vs Ory

Compare Keycloak and Ory on architecture, login UI, federation and operational load, and see where each one's authorization model stops.

Guide
S. B. WriterSeptember 10, 2026
LDAP and Active Directory authorization without changing the application

LDAP and Active Directory authorization without changing the application

LDAP and Active Directory groups encode the access rules for applications nobody will fund a rewrite for. Covers resolving those groups at the proxy in front of the application, turning them into an input to policy rather than the access model itself, cache staleness, and where boundary enforcement stops.

GuideEngineering
Alex OlivierSeptember 09, 2026
Cerbos Hub has a new interface

Cerbos Hub has a new interface

Cerbos Hub has a new interface. Dark and light themes that follow your system, an organization and workspace switcher on every screen, more rows per page in policy lists and audit logs, and improved accessibility. Nothing to migrate and no action needed.

Announcement
Alex OlivierSeptember 08, 2026
Identity Week America 2026: Same AI agent authorization problem, different badges

Identity Week America 2026: Same AI agent authorization problem, different badges

Notes from Identity Week America 2026 in Washington DC, where federal agencies, defense contractors and SaaS teams brought the same AI agent authorization question to the booth. Covers the License to Thrill panel, agent ownership and blast radius, policy based access control at runtime, and why audit is still unsolved.

Guide
Alex OlivierSeptember 07, 2026
Per-hop PBAC: enforcing scope at every delegation step

Per-hop PBAC: enforcing scope at every delegation step

Checking authorization once at the edge leaves every downstream hop unguarded. Here is why agent delegation needs a policy decision at every hop, and how to do it.

Guide
Alex OlivierSeptember 04, 2026
Best Keycloak alternatives

Best Keycloak alternatives

Compare Keycloak alternatives by protocol, deployment model, limitations, and migration path. Covers ZITADEL, Authentik, Authelia, SuperTokens, and Ory Hydra, plus when to keep Keycloak and add Cerbos for fine-grained authorization instead.

Guide
S. B. WriterSeptember 02, 2026
Best AI agent security and governance tools for 2026

Best AI agent security and governance tools for 2026

The best AI agent security and governance tools, broken down by layer. Prompt security, guardrails, posture and shadow-agent discovery, non-human identity, authorization and access control, data and RAG protection, and runtime monitoring, with the notable tools in each and how to prioritize what to cover first.

Guide
Emre BaranSeptember 01, 2026
Multi-hop delegation for AI agents, and how the consent chain gets lost

Multi-hop delegation for AI agents, and how the consent chain gets lost

When agent A delegates to agent B to a tool, the user's consent and identity get lost along the way. Here is how multi-hop delegation should actually work.

Guide
Alex OlivierAugust 28, 2026
Kubernetes admission control does not need a second policy language

Kubernetes admission control does not need a second policy language

Platform teams usually keep two sets of access rules, one for what may be admitted into the cluster and one for what users may do in the applications there. Covers serving the admission webhook from the same policy layer, what a full ruleset looks like, and failure policy trade offs.

Guide
Alex OlivierAugust 27, 2026