惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AI
AI
小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
罗磊的独立博客
爱范儿
爱范儿
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
D
Docker
C
CXSECURITY Database RSS Feed - CXSecurity.com
Spread Privacy
Spread Privacy
Recent Announcements
Recent Announcements
酷 壳 – CoolShell
酷 壳 – CoolShell
G
GRAHAM CLULEY
A
About on SuperTechFans
C
Cisco Blogs
The Register - Security
The Register - Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
Project Zero
Project Zero
V
V2EX
K
Kaspersky official blog
P
Privacy International News Feed
博客园 - 叶小钗
I
Intezer
T
Threatpost
The GitHub Blog
The GitHub Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Vulnerabilities – Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cybersecurity and Infrastructure Security Agency CISA
Cyberwarzone
Cyberwarzone
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 【当耐特】
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
S
Schneier on Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
F
Full Disclosure
The Cloudflare Blog
P
Palo Alto Networks Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Tenable Blog

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them Row-level security for Apache Trino, powered by Cerbos Synapse Top 9 Identity & Access Management (IAM) Tools for 2026 Authelia vs Authentik in 2026: Which self-hosted IdP should you choose Can non-engineers manage authorization policies with Cerbos? Governing AI coding agents with Cerbos Synapse Your AI coding agents need guardrails. Not the kind you think From open-source policy engine to enterprise authorization management platform Mapping business requirements to authorization policy for utilities Introducing Cerbos Synapse: unified authorization context and enforcement across your stack The CISO’s guide to implementing Zero Trust: Making adaptive access control work in practice Automating IAM for compliance, security, and business agility Authorization became the main character at Gartner IAM London How does Cerbos help with compliance audits and certifications? Overcoming IAM blind spots and fragmentation for continuous governance How long does it take to implement Cerbos in production? The four pillars of access control in banking When breach becomes personal. CISOs, identity failures and the road to continuous governance Policy as Code with Azure API Management and Cerbos AI is turning weak permission management into systemic banking risk Query plan adapter for Elasticsearch (Java) Query plan adapter for Drizzle ORM 10 fintech security tools to build a compliant and resilient security stack Fine-grained authorization for AI agents with Cerbos and Aperture by Tailscale Query plan adapter for LangChain.js and ChromaDB Fintech security architectures: where they break and why MCP authorization: Securing Model Context Protocol servers with fine-grained access control Cerbos PDP v0.51.0: Policy lifecycle management, audit enhancements, and scopes Query plan adapter for Convex Best open source auth tools & auth software for enterprises [2026] Cerbos Hub Playground: Recent updates Announcing ePDP Rules: Fine-grained control for embedded policy bundles Mapping business requirements to authorization policy for aviation A shared authorization layer that adapts to context What is authorization as a service? Framework for evaluating authorization providers and solutions Cerbos Hub is now available on-premise Authorization as a continuously governed control Year in review: 2025 When authorization is static, risk accumulates silently OpenID AuthZEN is official, and Cerbos is ready MCP and Zero Trust: Securing AI agents with identity and policy 10 critical challenges CISOs face in 2026 and how to solve them AI Security Platforms (AISP): What they are, why they matter, and how they work Cerbos PDP v0.50.0: Stricter CEL, more predictable scope plans, and faster evaluation Cerbos PDP and Cerbos Hub: Choosing the right setup for your team Gartner IAM Summit 2025: Authorization maturity, AuthZEN momentum, and why identity security is expanding to every workload Zero Trust in cybersecurity - how it works Secure RAG: Implement LLM Access Control with Cerbos Cerbos PDP v0.48: OpenID AuthZEN support, improved query plans, faster bundle loading Key compliance regulations for non-human identities How to implement scalable multitenant authorization Key takeaways from Workload Identity Day 0 at KubeCon What is Cerbos? Cerbos vs. OPA Mongoose adapter for Cerbos Query Plans v2.0 Staying compliant - What you need to know Migrating from OPA and Rego to Cerbos Broken access control still tops the list: OWASP top 10 2025 Platform engineering leaders are racing to enable AI safely - takeaways from KubeCon NA 2025 AuthZEN: Standards-based authorization for enterprises What ISC2 congress 2025 made clear about modern compliance Automate Cerbos policy uploads with the cerbos-store-action GitHub Action Mapping business requirements to authorization policy in HR systems Mapping business requirements to authorization policy for insurance Run Cerbos natively inside AWS Lambda Cerbos PDP v0.47.0: AWS Lambda support, Git-aware Hub uploads, and smarter schema diagnostics What is authorization? Types, examples and definitions Building your own authorization solution vs. buying an off-the-shelf one Zero trust has reached operational reality Modern application architecture trends: AI, microservices, and pragmatic security
Identiverse 2026: Agents made authorization the story
Alex Olivier · 2026-06-24 · via Cerbos - All Posts

I spent last week at Identiverse in Las Vegas. We had a booth, ran a raffle, I was on stage three times, twice as a co-chair of the OpenID AuthZEN working group and once wearing my Cerbos hat. In between, I sat in on as many other sessions as I could.

Agents are a forcing function. They're exposing all the security holes that were already sitting in our systems, the ones we got away with for years because a human was the one clicking the button. Point an autonomous, non-deterministic thing at the same setup and the gaps stop being theoretical.

Once that thing is acting on your behalf, who decides what it's allowed to do? That's an authorization question, and the good news is we already have the building blocks to answer it. So I had a good week.

Three threads, one knot

If I squint at everything I saw, it collapses into three ideas that keep running into each other.

  • Trust can't stay implicit.
  • Delegation breaks the moment it crosses an org boundary.
  • And context needs to show up before the decision, not after.

All three land on the same spot. You need a deterministic place to make the call, with the right inputs in front of it. That's the bit I care about.

George Fletcher on delegated authorization

Delegated authorization was the best session of the show for me. George went deep on agentic delegation and trust domains, backed by something like 107 sources across the IETF, W3C and the OpenID Foundation. He's publishing the spreadsheet, which is a flex I respect.

His main argument was about what he calls the "crossing the trustee problem." Any delegation scheme that ignores it will fall over as soon as it goes cross-org. Inside one company you can hand-wave it. The second a delegation chain has to reach into a different trust domain, Salesforce say, where the trustee is somebody else entirely, the easy answers stop working.

B2B you can paper over with contracts and a transparency server. B2C is still unsolved, and he was honest about that. If you're building anything that delegates authority to an agent on behalf of a consumer, that gap is yours to worry about too, not just an academic one.

The part worth sitting with is obligations. A policy decision point can hand back obligations at runtime, or cancel ones that are already in flight. That has to be accounted for when you evaluate a policy, and most people aren't thinking about it yet.

He also gave an 8-point framework for grading any delegation solution. I'm going to use it as a checklist against our own thinking:

  1. Does it actually model the delegator, the delegatee, and multi-hop chains?
  2. Does it reference and verify an external authority (a power of attorney, a contract, a policy)?
  3. Does the purpose travel with the delegation, and can you share it selectively?
  4. Are constraints (both user-set and mission-derived) enforced at every hop?
  5. Can it ever grant more than the delegator holds? (It shouldn't. Revocation should flow downward.)
  6. Does it work across orgs with no shared infrastructure?
  7. Is the full chain auditable back to the original principal?
  8. Is privacy handled natively, or bolted on later?

Most proposals I've seen score well on 1 through 4 and then quietly fall apart on 5 through 8. The hard half is the half that never makes it into the demo.

Shared Signals and continuous authorization

The Shared Signals Framework sessions were the other highlight. The core idea is old news to anyone in identity. You deliver security events between systems asynchronously, as signed tokens, so you stop assuming a session is fine just because it was fine at login.

CAEP handles session revocation and device or risk changes. There's a risk profile for credential and account-compromise events, and SCIM events for provisioning. This is running in production today between things like Apple Business Manager and IdPs, Google Workspace, and CrowdStrike. Change your password, your screen locks. That kind of thing.

The agentic extension is where it got interesting. The model shifts from a single checkpoint to three planes: a control plane for setting up trust, a data plane for fast authorization decisions, and a signaling plane that pushes context to where it's needed before the decision happens.

Every node becomes a transceiver. A receiver can react on its own: narrow a scope, quarantine an instance, stop minting tokens, no human in the loop. There's a new event type aimed squarely at machine and non-human identities and supply-chain attacks.

For me the takeaway is simple. The signaling plane is exactly the input a policy decision point wants. Authorization and signaling are converging into one governance layer, and if you own identity, that convergence is the thing to watch, because it changes where the decision actually gets made.

Justin Richer on AI and the confused deputy problem

Justin's "Trust Me" was the sharpest framing talk of the week. The setup: AI inverts trust. In normal software an unexpected result is a bug and you fix it. With an agent, an unexpected result gets called "delight," right up until the agent confidently deletes your production database because it thought it was helping. That was a real example. It got a laugh, then a silence.

His point about OAuth was interesting. It was designed when the client was the least-trusted party and the API was the prize. In the agent and MCP world that's flipped: servers now compete to be the thing an agent calls. The trust relationship the protocol assumes isn't the one we actually have. Non-determinism plus implicit access gives you the most powerful confused deputy ever built.

This is the thing I'd push hardest on. An agent follows its access, not its instructions. "Don't touch production" is a request, not a control, and a non-deterministic system will eventually ignore it. The only place that boundary actually holds is at the point where the action gets authorized, where the answer to "can this agent, acting for this user, do this, on this resource, right now" is computed fresh and enforced. If the policy says no, the call never runs, no matter what the prompt said or what the agent talked itself into. That's the same point Justin landed on from the trust side.

Zero trust means verify more, so you actually know what you're implicitly trusting. Why should our systems trust each other. We should be able to answer that.

The bar talk, and governing shadow AI agents

The best title of the conference goes to "A Vendor, Two Practitioners, and an AI Agent Walk into a Bar... the Agent got in. Nobody knows how." It was also the most practical governance content of the week.

The old risk playbook still works, avoid, accept, transfer, mitigate, and you shouldn't be transferring risk onto your end users. SPIFFE clears out maybe 80% of the non-human identity problem by handing out short-lived identity dynamically instead of provisioning secrets. Uber was cited issuing on the order of a billion credentials a day, with rotation.

Governance starts with discovery, because you can't govern what you can't see, and shadow agents are everywhere once developers start handing them their own credentials. A gateway becomes the obvious control point: security, finance, and business checks in sequence before the agent does anything.

The hard work is in distributing policy, then enforcing it locally. Manage it centrally, push it everywhere. Which, yes, is the thing we build, but the more useful point for anyone in the room is that this is a policy distribution problem before it's a product problem. Get that architecture right and the vendor choice gets a lot easier.

The three AuthZEN and Cerbos sessions I ran

I was on stage three times, wearing two different hats.

Two were AuthZEN sessions with my fellow working group chairs, Atul Tulshibagwale and Mark Berg.

The first was "Beyond Authentication," the framing talk. Authentication is solved, authorization isn't, and no single standard fixes it on its own. You need three working together. Shared Signals to bring fresh context to the decision, AuthZEN to make the decision fast and locally, and Transaction Tokens to carry that decision through a mesh of microservices without hammering the PDP on every hop. SPIFFE underneath for service identity. That combination is the first credible path to zero trust that doesn't fall apart at the implementation stage.

Then the masterclass, two hours on "Mastering the OpenID Authorization Standard." We got into the weeds. The information model of subject, action, resource and context, the evaluation and search APIs, the new certification profile, and the agent piece.

The part that got the room leaning in was agent authorization. OAuth scopes can't answer "can this agent, acting for this user, call this tool with these arguments?" That's a subject-action-resource-context question, which is exactly what AuthZEN is the API for. We walked through how a tool declares its authorization intent so a gateway can check it before the tool runs. Deny, and the call never executes.

The third talk was the Cerbos one, with Vatsal Gupta from Apple, "Access Reviews Are Dead. Long Live Decision Governance." The argument is blunt. We've spent 20 years optimizing access reviews, and identities still use roughly 1% of the permissions granted to them. Your review cycle runs every 90 days. An attacker now breaks out in about 29 minutes. You're reviewing static snapshots of a thing that's computed fresh at runtime from identity, action, resource, context and risk.

So the unit of governance has to change. The risk lives in the decision itself now, down at the level of who did what to which resource and in what context. Govern the decisions, what your policy intended, what actually happened, and whether they matched, and let the decision log be the evidence. IGA doesn't die in this world, it grows up. It stops trying to prevent bad access and starts proving good governance. That one's getting its own write-up, because the compliance crowd had opinions.

What I'm walking away with

The industry is finally treating authorization as a first-class problem instead of the thing you handle after authentication. The gap was always there. Agents just made it impossible to keep ignoring. The encouraging part is that the room mostly agreed on the fix. Lean on the standards we already have, apply them with some discipline, and stop pretending agent access needs a brand new rulebook.

The hard problems are the honest ones people admitted to on stage. Cross-org delegation. Obligations at runtime. Auditing a chain back to a human when half the chain is a model. These aren't solved yet, us included, and pretending otherwise would be the easiest way to look silly in 12 months.

I'll be writing more on the delegation framework specifically, because I think that 8-point list is going to age well. For now, that's Identiverse.