Externalized authorization
How the Cerbos authorization management platform works
Authorize every identity, govern every action and prove every decision from one platform. Fine-grained, contextual, and continuous authorization with full audit trails across applications, gateways, workloads, and AI agents.
Cerbos is an end-to-end authorization management platform
Four components work together to give your team a single layer that governs every action and access decision.
Authorization management
Cerbos Hub
Policy Administration Point
Cerbos Hub is the control plane for policy authoring, testing, versioning, distribution, and audit visibility. Hub provides end-to-end policy management out of the box.
Data and integration
Cerbos Synapse
Enrichment and Orchestration
Synapse fetches identity, resource, and relationship data from external systems to enrich authorization requests, and translates infrastructure protocols into Cerbos policy checks.
< 1 ms decision time
Cerbos PDP
Policy Decision Point
PDP is an open source authorization engine that evaluates requests against policies and returns access decisions. It's stateless, high-performance, and built to scale horizontally.
Native SDKs
Cerbos PEP SDK
Policy Enforcement Point
Cerbos PEPs are language-native client libraries that connect applications directly to PDPs to enforce real-time access decisions, with SDKs available for all major languages.
Cerbos reference architecture
The complete picture of Cerbos in production. A defense in depth architecture with consistent enforcement from the edge to the data layer.
This is where teams grow into, not where they begin. Pick one component, like your API gateway or a single service, and go from there.
Start with one service
You don't need to roll out Cerbos everywhere on day one. The platform is built for incremental adoption alongside your existing authorization.
1
Instrument
Add Cerbos to one service. Set your first policies to allow everything so nothing changes for your users. Your existing authorization keeps running.
2
Validate
Cerbos logs every decision it would make. Compare those against what your current system decides, in real time, and tune your policies with real traffic.
3
Enforce
When you're confident, turn enforcement on. Expand to the next service from there.