惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
Hugging Face - Blog
Hugging Face - Blog
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Proofpoint News Feed
F
Fortinet All Blogs
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
Jina AI
Jina AI
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
S
SegmentFault 最新的问题
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
美团技术团队
博客园 - 司徒正美
宝玉的分享
宝玉的分享
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Apple Machine Learning Research
Apple Machine Learning Research

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
Decrease the Cost of Failure in Authorization
Heidi Hokans · 2024-07-23 · via Cerbos - All Posts

A few days ago we completed the beta phase of Cerbos Hub and officially entered general availability. The product and the company have come a long way since we first launched our open source policy decision point (PDP) three years ago. Our Cerbos user community has supported us with valuable feedback and enlightening questions the entire way. And their insight is what led us to the creation of Cerbos Hub, a central policy administration point for applications with many distributed PDPs.

During the beta phase of Cerbos Hub, we heard from users about how Cerbos helps them move faster, implement more granular authorization policies, be compliant with regulations, and improve customer experience. But there’s one benefit that we may have underappreciated a bit so, we wanted to give it some airtime: Reducing risk.

Seems like it should be an obvious one, right? Better authorization reduces the risk of security breaches. But what we mean here is a little different.

Reducing the risks associated with authorization failure

Many of our clients shared with us that before using Cerbos, they often worried that when they updated their authorization logic, they might only remember to update it in a few of the places it was deployed, leaving security vulnerabilities that no one was aware of. Others said that without any way of testing their authorization logic, deploying changes was an exercise in blind faith. You crossed your fingers and hoped nothing broke. Authorization failure in these cases meant anything from leaving a backdoor open to crashing the whole application. There’s both a material security risk, and a psychological risk for the engineers responsible.

“It used to be that somebody on the product team goes to change something, and we forgot to change it in 9 of 10 places. So it was always a disaster.” - Steve High, NTWRK

“We realized that our 200+ engineers were doing their own thing, we didn’t have a standard way of doing authorization, and we had no way of testing our pull requests. If we thought it looked right, we merged it and waited to see if it worked.” - Rob Crowe, Utility Warehouse

Cerbos Hub features like automatic testing, the CI/CD pipeline, and centralized management eliminated the potential cost of failure in authorization. If you change a policy and the logic leaves access loopholes in your application, Cerbos Hub will automatically detect it so you can fix it before deployment. There’s no risk of inconsistent or incomplete deployments because Cerbos Hub coordinates deployments to all PDPs at once.

“I categorized authorization as just one of those things I don't have to think about. And that's a very valuable thing.” - Chuck Hardy, Salesroom

Freeing engineers and product designers from the anxiety of authorization maintenance opens up so much bandwidth to think creatively about how authorization logic can be applied. And beyond authorization, less stress means more energy to innovate in all areas of the product.

One of the most interesting things a client shared with us is that just by reducing the mental weight associated with authorization, their whole mindset around user experience design was transformed.

“If you want to increase the rate of innovation, decrease the cost of failure. Our whole posture towards what we can do with our app has changed. You've materially changed the way we design on the front end. We operate quicker with less worry and with fewer errors.” - Cerbos Hub client.

Even more of our users have told us that using Cerbos has let them be much more judicious with the product design requests they entertain. Where before they needed to pick and choose which ideas got investment, Now they have time to explore and test at leisure, with the authorization step no longer being a choke point.

“It’s a good feeling being able to say yes to almost any request” - Joe Qureshi, 9fin.

Cerbos Hub is now generally available

Sign up for free and see for yourself how streamlining authorization can lead to increased innovation in your product.