惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
IT之家
IT之家
Google DeepMind News
Google DeepMind News
罗磊的独立博客
爱范儿
爱范儿
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
U
Unit 42
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
B
Blog
博客园 - 叶小钗
月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
Website Planet: How Cerbos helps developers scale authori...
Emre Baran · 2023-07-24 · via Cerbos - All Posts

In a recent interview with Roberto Popolizio of Website Planet, Cerbos Co-Founder & CEO, Emre Baran, shared insights about the company's journey and its mission to simplify the implementation of roles and permissions in software applications.

Emre, a seasoned entrepreneur with over 20 years of experience in the software field, co-founded Cerbos to address a common challenge faced by developers: managing permissions effectively. Cerbos is an open source authorization layer that separates business logic from authorization logic, thereby improving security, testability, and flexibility. It's designed to be easy to implement, fast, and scalable, providing developers with granular control over user permissions.

The idea for Cerbos was born out of Emre's experiences at Google, CGI, Microsoft, and various startups, where he recognized the need for a reliable authorization system. Unlike competitors that require developers to learn new programming languages or offer only premium, cloud-hosted solutions, Cerbos is open source and free for developers to use. Cerbos is built on six principles:

  1. Security: First and foremost. Cerbos prioritizes security, as an essential aspect of any the application or service to gain trust and be chosen by users.
  2. Reliability: The service is designed to run continuously and handle authorization requests, ensuring that it is always available and reliable for users.
  3. Scalability: Cerbos is built to scale seamlessly, accommodating both small and large applications with unlimited scalability.
  4. Speed: The platform emphasizes speed, recognizing the importance of delivering efficient performance.
  5. Extensibility: Cerbos aims to provide an excellent baseline for developers, but also while making customization and extensibility very simple.
  6. Developer Experience: By offering great documentation, SDKs in every major language, integration with all the popular frameworks and authentication providers, Cerbos offers an unparalleled developer experience which often makes a big difference.

Cerbos' typical clients are often startups that have built their roles and permissions in-house, a process that can take a significant amount of time and resources. By using Cerbos, these companies can save the equivalent of one full-time employee's worth of effort in the first year alone. The solution is also beneficial for larger companies that need to manage complex permissions across various roles, regions, and departments.

Looking ahead, Emre sees shifts in software development between monolithic and microservices architectures, as well as the emergence of self-service public cloud, private cloud, air gap, serverless, and edge computing, hybrid solutions. He believes that zero trust is a crucial component for each of these approaches, as users should have the capability to operate within them securely. Emre highlights: "It is essential for our server infrastructure to accommodate all of these diverse requirements effectively."

Read the full interview he re.