Blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security. Written for the engineers, architects, security, identity and product leaders shaping how their teams ship and govern access.

The kill switch that never got pressed: what the OpenAIâHugging Face incident tells us about agent authorization
OpenAI's models escaped an eval sandbox and breached Hugging Face. What the incident says about agent kill switches, runtime authorization, and standing access.

Claude Fable 5 and GPT-5.6 Sol authorization refusals
The models that refuse legitimate security work will also run destructive commands without asking. Both are reasons to enforce authorization outside the agent, not in its prompt.

Agent skill for writing authorization policies in VSCode
A practical guide to writing authorization policies in VSCode using GitHub Copilot agent mode and the Cerbos policy skill. Covers install, the gh skill CLI, chat.agentSkillsLocations, file-scoped *.instructions.md, a typical drafting session, and how validation runs in the integrated terminal.

Cerbos PDP v0.54.0: Faster evaluations, lower memory usage, and new store diagnostics
Cerbos PDP v0.54.0 focuses on performance, cutting steady-state memory and raising throughput. This release adds the new cerbos compile-store command for diagnosing policy stores, clearer error reporting across policies and tests, automatic GOMEMLIMIT from cgroup limits, and better runtime observability.

Agent skill for writing authorization policies in Cursor
Cursor's composer makes it a strong fit for authorization policy work. This guide walks through installing the Cerbos policy skill in Cursor, describing access rules in plain English, letting the composer pull schemas and derived roles into context, validating against the real compiler in the integrated terminal, and producing a complete policy bundle.

Authorization in microservices: Patterns, pitfalls, and how to scale it
Authorization in microservices explained. Why it is harder than a monolith, where it gets enforced, the three patterns for handling authorization data, choosing RBAC or ABAC, service-to-service authorization, and the externalized policy decision point pattern that scales across services without scattered checks or redeploys.

Ory vs SuperTokens for authentication
Ory Hydra and SuperTokens solve different authentication problems. Compare OAuth2 and OIDC token infrastructure against fast product login and session handling, and see where Cerbos fits as the authorization layer after authentication.

RBAC vs ABAC - Which is better for your use case?
A practical RBAC vs ABAC guide covering what each model is, the key differences, whether ABAC is more secure, role explosion, when to use RBAC or ABAC, and how to combine them in one set of policies instead of choosing between them.

The incident response workflow that decides how fast you recover
A step-by-step incident response workflow for the authorization layer, from mapping a compromised identity's blast radius to proving containment held. Covers how centralized policy and decision logs compress each phase, what makes the workflow feasible in regulated and air-gapped environments, and how AI agents change the runbook.

Agent skill for writing authorization policies in Codex CLI
A practical guide to writing authorization policies in Codex CLI using the Cerbos policy skill. Covers cross-agent installer setup, $cerbos-policy invocation, the /skills list command, a typical drafting session, validation against the real Cerbos compiler in Docker, and composing the skill with AGENTS.md.

ABAC examples: Real attribute-based access control policies and use cases
A practical guide to attribute-based access control with real ABAC examples and policy code. Covers the four attribute types, industry use cases, how to write your own ABAC policy, the trade-offs, and where ABAC is heading for Zero Trust and AI agents.

You have Auth0. What authorization capabilities do you still need?
Auth0 covers authentication, but authorization capabilities like resource-level ABAC, per-tenant policies, and decision audit logs sit outside its model. This guide covers where Auth0 RBAC and Auth0 FGA stop, five signals you need a dedicated authorization layer, and how to evaluate solutions and run a POC.

What is fine-grained authorization?
Fine-grained authorization explained. Learn how fine-grained access control uses attributes and conditions to decide access per resource and action, how it differs from coarse-grained control, the RBAC, ABAC and PBAC models behind it, real use cases, and how to implement it without building your own engine.

Agent skill for writing authorization policies in OpenCode
OpenCode is open source, self-hosted, and provider-agnostic, so the whole authorization policy workflow stays inside your security perimeter. This guide walks through installing the Cerbos policy skill in OpenCode, drafting policies in plain English, validating against the real Cerbos compiler locally, and pairing the skill with AGENTS.md.

The authorization POC guide: What to test, who to involve, and how to decide
Most authorization POCs never reach production. This guide covers all details of a proper authorization proof of concept: scoping to one real service, measurable success criteria, stakeholder involvement, and baselines so the review produces a decision, not a debate.

Agent skill for writing authorization policies in Pi
Pi is the open-source self-extensible coding agent built around the Agent Skills standard from the start. This guide walks through installing the Cerbos policy skill in Pi, invoking it with /skill:cerbos-policy, drafting authorization policies in plain English, and validating against the real Cerbos compiler in Docker.

You have Okta. What authorization capabilities do you still need?
You've standardized on Okta SSO for authentication. Here's where Okta falls short on authorization, and how to evaluate dedicated authorization solutions.

The Cerbos Hub effect matrix: read your authorization policy at a glance
See how the Cerbos Hub effect matrix turns authorization policy files into a permissions grid of roles and actions, with allowed, denied, and conditional outcomes. Read what each role can do without parsing raw policy, drill into ABAC conditions, and spot over-permissive wildcard rules in review.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
