惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
博客园_首页
量子位
T
Tailwind CSS Blog
博客园 - Franky
G
Google Developers Blog
D
DataBreaches.Net
Vercel News
Vercel News
B
Blog
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
爱范儿
爱范儿
博客园 - 【当耐特】
The Cloudflare Blog
H
Help Net Security
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
C
Check Point Blog
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
How better authorization drives business value for softwa...
Heidi Hokans · 2024-10-10 · via Cerbos - All Posts

Cerbos first launched as an open-source product in 2021 to help engineering teams offload an essential but boring and complicated task. We help engineers spend more time building features instead of authorization. And we help organizations avoid wasting engineering labor and the costs associated with it. Over time, the feedback we received from our users validated our assumed purpose.

But in the past year, especially after releasing Cerbos Hub in Beta and now General Availability, we’ve spoken with an increasing number of CTOs and product leaders who see authorization from a different perspective.

As it turns out, authorization is not just an essential security feature. It's also a user experience feature. When you implement fine-grained access control, you can slice and dice product features and resources for a wider variety of user types in your application. You get better internal workflows and less risk of user error leading to breaches. And the result is often a product that has better user experience, better customer adoption, and is more responsive to customer needs.

Here are a few examples of Cerbos clients whose implementations led directly to improvements in business performance.

Authorization and customer satisfaction

Supy - Improved customer satisfaction from self-service RBAC customization

Supy is a back-of-house restaurant management application. They help companies optimize the cost efficiency of their restaurants.

Restaurant management is very diverse. Every company has a different way of organizing their workflows in their branches. A one-size-fits-all RBAC (role-based access control) approach to authorization was not working. 30% of their customers were asking for custom roles and permissions, and Supy’s engineering team was customizing the authorization logic for each individual account on demand.

Supy implemented Cerbos in the front end and back end of their application and gave their customers the ability to build their own RBAC rules. They delighted their customers and attracted new clients seeking customizable solutions.

“Offering dynamic roles and permissions makes us more competitive in the market. We can offer companies a software that fits into their workflows, rather than forcing them to change.” - Ibrahim Bou Ncoula, Supy’s CTO.

Read more about Supy

Authorization and user adoption

Nook - 3x more customers onboarded by increasing the number of user roles

Nook is a business finance application that streamlines invoicing, approvals, and payouts for accounts payable and accounts receivable. Similar applications in the market are meant to be exclusively used and managed by an accounting team. Nook differentiated themselves by creating roles and permissions in their application for all internal and external actors in the payables and receivables workflow.

This way, accounting teams keep sensitive financial information safe in one system. They do not send documents through outside channels. An external contractor can be given access to view and approve a specific document, without exposing any other resources to that person or allowing any additional actions.

As a result of this capability, Nook estimates that they have 3x the number of users per account than the industry norm.

“For every client we have, we're able to have 2x, 3x, the number of users for that client on Nook than we could without the roles and permissions that we have.” - Joe Lines, CEO of Nook

Read more about Nook

Authorization and product packaging

Human Managed and 9fin: Infinitely flexible product packaging

Human Managed and 9fin are both data intelligence platforms processing large volumes of sensitive data. Human Managed delivers internal business intelligence and action steps to inform operational improvements. 9fin provides real-time data on the tradeable debt market.

Both companies offer a range of products meant for different business types and use cases. And both sometimes have clients whose needs require a non-standard suite of products and features. By implementing Cerbos for backend API authorization, customizing access to products and data sources for each of their clients is as easy as flipping a switch.

Karen Kim, CEO of Human Managed gives an example of how they implemented ABAC (attribute-based access control) in their product:

"Show intel card A, decision recommendation type B, for use case C to operators and analysts from customer D's department E who access our app F through authorized laptops between 9–10am only. Human Managed can apply unlimited conditions, attributes, and parameters at any granularity level as simple configurations without writing any code. It allows us to deliver truly personalized services quickly, securely & at scale.” - Karen Kim, CEO of Human Managed

Read more about Human Managed

Read more about 9fin

Cerbos Hub is now generally available. and you can sign up for free. If you find that authorization had an unexpected impact on your business, we would love to hear about it! Keep in touch with us by joining our Slack community or booking a call with us any time.