惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
B
Blog RSS Feed
A
About on SuperTechFans
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 司徒正美
D
Docker
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
H
Help Net Security
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
博客园 - Franky
人人都是产品经理
人人都是产品经理
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
Meet four new use cases in the updated Cerbos Hub
Lisa Dziuba, Emre Baran and Alex Olivier · 2025-07-18 · via Cerbos - All Posts

We spent the last year listening to hundreds of customers, attending dozens of industry events, and talking with teams building at scale. Their feedback directly led to support for four new use cases in Cerbos Hub.

Cerbos Hub gives engineering, security, and IAM teams everything they need to manage authorization across any architecture at any scale.

use cases.png

Fine-grained, tenant specific authorization

We often hear from SaaS companies: “We need to let our customers define their own roles and rules without hardcoding every customization.” With Cerbos Hub, each customer’s authorization logic lives in its own secure silo, layered on top of your core rules:

  • Tenant‑isolated policy storage ensures customers can define roles and permissions specific to their context. No code modifications required
  • Real‑time tenant-specific policy updates can be made from the app and pushed to Cerbos Hub for rollout to the PDPs
  • Scoped policies enforce boundaries: tenants can customize within platform-defined guardrails
  • Audit logs and version control are preserved per tenant, ensuring transparency and rollback capabilities

👉 Join our spotlight webinar to learn how to deliver tenant-specific roles and policies dynamically
👉 Check the use case page for more information

Dynamic policy management at scale

With Cerbos Hub’s new dynamic policy capabilities, you can automate the full lifecycle of your authorization policies. Cerbos Hub Policy Stores enable programmatic creation, updates, and deployment of policies via API, triggered by any event or system in your stack. With this new use case, you get:

  • Full CRUD support via Admin API and SDKs enables policy creation, updates, and deletion in response to system events or CI/CD pipelines
  • Built-in compilation and testing validate changes before deployment
  • Instant synchronized distribution pushes policies to all PDPs (cloud, edge, embedded) with no manual steps
  • No custom infrastructure needed. Cerbos Hub handles policy storage, reloading, and testing
  • Every change, from API call to enforcement decision, is logged for full traceability

👉 Join our spotlight webinar to see dynamic policy workflows in action
👉 Visit the dynamic policies use case page for implementation details

Scalable NHI permission management

Microservices, workloads, and AI agents now drive most system-to-system traffic, but many lack enforceable access controls. Overprivileged NHIs can bypass Zero Trust boundaries, leak data, or become invisible backdoors in your architecture.

Cerbos’s NHI support gives you centralized, policy-based authorization for every non-human identity:

  • Apply least privilege by default to every workload, service, or AI agent
  • Implement delegated and impersonated authorization checks between services
  • Define SPIFFE-based policies and enforce ABAC, RBAC, or PBAC rules
  • Track which service accessed what, when, on whose behalf, and why
  • Maintain a unified audit trail for all NHI access decisions across your apps

👉 Join our spotlight webinar to learn how to discover NHIs, assess their risks, and implement fine-grained access controls in a microservice architecture.
👉 Check the use case page to get more details

Secure authorization for MCP servers

Model Context Protocol is powering a new wave of AI apps, but recent breaches have shown how easily misconfigured agents can access more than they should. Cerbos Hub can now control which agents can access which MCP tools, using policies evaluated per agent, per tool, and per session, outside your server logic. New MCP capabilities include:

  • Dynamically authorized tool access for each client using context-aware Cerbos policies
  • Prevent unauthorized tools from appearing in the available_tools list
  • Capture every MCP access decision with full audit context for compliance and debugging

👉 Join our spotlight webinar to see how to secure MCP tools with policy-based access control
👉 Visit the MCP server use case page to learn more about authorization for MCP servers

With the updated Cerbos Hub, you get an enterprise grade control plane that integrates with your identity fabric, delivers built-in compliance and audit logging, and a developer friendly experience. It’s a single hub for all your human and non-human authorization needs.

Our engineers would be happy to give you a personalized demo.