惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
P
Proofpoint News Feed
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
量子位
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
博客园 - Franky
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
人人都是产品经理
人人都是产品经理
D
DataBreaches.Net
博客园_首页
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
Insights from Gartner IAM Summit 2025 - Identity, authori...
Alex Olivier · 2025-03-28 · via Cerbos - All Posts

The 2025 Gartner Identity and Access Management (IAM) Summit in London brought the identity community face-to-face with the future. From the surge of machine identities to evolving authorization patterns and policy-based control, the event underlined a clear shift: identity and access are no longer just IT plumbing - they're strategic infrastructure.

Workload IAM: Getting machine identity under control

Machine identities - whether containers, VMs, services, or AI agents - have exploded in number and complexity. In a standout session, Gartner’s Erik Wahlstrom walked through the emerging discipline of Workload IAM, warning that many orgs are sitting on a mountain of unmanaged machine IAM debt.

The solution? A well-structured identity taxonomy that recognizes not just users, but also devices, workloads, and services as first-class identity types. This, paired with what Gartner calls an "identity fabric", creates a functional foundation for managing secrets, credentials, and access across hybrid and cloud-native environments.

For authorization vendors and platform teams alike, the takeaway is clear: machine identities need the same level of rigor and lifecycle management as human users, possibly more.

Modernizing authorization: Externalize or fall behind

Another key theme was authorization modernization. Mehmet Yaliman challenged legacy approaches that hardcode access logic into apps and services.

mehmet gartner iam.jpeg

Authorization, he emphasized, should be:

  • Centralized for consistency and auditability
  • Dynamic to adapt to risk and context
  • Externalized so policy updates don’t require code changes

The framework Gartner proposes combines admin-time controls (e.g., role provisioning) with runtime decisions (e.g., risk-aware access). It’s not either-or - it’s both, working in harmony, and the architecture we have been recommending since the inception of Cerbos.

Critically, the session called out the risks of “authorization sprawl” - a reality many engineering teams know too well. The prescription? Define standardized policy patterns for portals, APIs, services, and mesh layers. And use dedicated authorization tooling to implement them.

Policy-based authorization in practice

Building on that, Mehmet Yaliman’s follow-up session on policy-based authorization made the case for decoupling access control from code entirely. Policy becomes the bridge between strategic intent (Zero Trust, least privilege) and operational execution.

We loved the emphasis on “understanding your facts” - identifying the data needed to evaluate access decisions at runtime. It’s a call to action for engineers and architects to treat policies like first-class software artifacts: versioned, testable, and explainable.

For those evaluating tooling, Gartner compared various engines, policy languages, and authorization models across several factors such as expressiveness, usability, and ecosystem maturity. Spoiler: there’s no silver bullet. Multi-tool orchestration is inevitable.

Cerbos at the OpenID AuthZEN interop

One of the most exciting moments of the conference was the world-exclusive interop session of OpenID AuthZEN. This time, focusing on how to integrate authorization at the API Gateway layer using the specification.

Cerbos was proud to take part in this live interop event, alongside implementers like Aserto, Tyk, WSO2, Okta, Amazon Web Services, Kong, and others. This was the first public demo of API gateway use cases powered by externalized authorization policies, and it drew a queue that wrapped around the hall.

Cerbos at the OpenID AuthZEN interop.png

AuthZEN marks a huge step forward for composable authorization architectures - something we at Cerbos care deeply about. The goal is seamless integration between platforms and services, regardless of the policy engine underneath.

What it all means

The signal from Gartner this year was unambiguous: authorization is no longer just about controlling access. It’s about enabling agility, enforcing compliance, and delivering secure experiences across complex, hybrid systems.

Key takeaways:

  • Treat machine and workload identities with the same discipline as human users.
  • Externalize authorization logic. If it’s hardcoded, it’s technical debt.
  • Use policies as a shared language between developers, security, and governance.
  • Standardize your access control patterns—and test them.
  • Embrace open standards like AuthZEN to build composable, future-ready architectures.

Cerbos was built for this shift. If you're designing for runtime authorization, multi-cloud policy control, or platform-native IAM, we're here to help.