惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
B
Blog
The GitHub Blog
The GitHub Blog
T
Tailwind CSS Blog
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
DataBreaches.Net
月光博客
月光博客
人人都是产品经理
人人都是产品经理
IT之家
IT之家
GbyAI
GbyAI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
C
Check Point Blog
罗磊的独立博客

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them
Website Planet: How Cerbos helps developers scale authori...
Emre Baran · 2023-07-24 · via Cerbos - All Posts

In a recent interview with Roberto Popolizio of Website Planet, Cerbos Co-Founder & CEO, Emre Baran, shared insights about the company's journey and its mission to simplify the implementation of roles and permissions in software applications.

Emre, a seasoned entrepreneur with over 20 years of experience in the software field, co-founded Cerbos to address a common challenge faced by developers: managing permissions effectively. Cerbos is an open source authorization layer that separates business logic from authorization logic, thereby improving security, testability, and flexibility. It's designed to be easy to implement, fast, and scalable, providing developers with granular control over user permissions.

The idea for Cerbos was born out of Emre's experiences at Google, CGI, Microsoft, and various startups, where he recognized the need for a reliable authorization system. Unlike competitors that require developers to learn new programming languages or offer only premium, cloud-hosted solutions, Cerbos is open source and free for developers to use. Cerbos is built on six principles:

  1. Security: First and foremost. Cerbos prioritizes security, as an essential aspect of any the application or service to gain trust and be chosen by users.
  2. Reliability: The service is designed to run continuously and handle authorization requests, ensuring that it is always available and reliable for users.
  3. Scalability: Cerbos is built to scale seamlessly, accommodating both small and large applications with unlimited scalability.
  4. Speed: The platform emphasizes speed, recognizing the importance of delivering efficient performance.
  5. Extensibility: Cerbos aims to provide an excellent baseline for developers, but also while making customization and extensibility very simple.
  6. Developer Experience: By offering great documentation, SDKs in every major language, integration with all the popular frameworks and authentication providers, Cerbos offers an unparalleled developer experience which often makes a big difference.

Cerbos' typical clients are often startups that have built their roles and permissions in-house, a process that can take a significant amount of time and resources. By using Cerbos, these companies can save the equivalent of one full-time employee's worth of effort in the first year alone. The solution is also beneficial for larger companies that need to manage complex permissions across various roles, regions, and departments.

Looking ahead, Emre sees shifts in software development between monolithic and microservices architectures, as well as the emergence of self-service public cloud, private cloud, air gap, serverless, and edge computing, hybrid solutions. He believes that zero trust is a crucial component for each of these approaches, as users should have the capability to operate within them securely. Emre highlights: "It is essential for our server infrastructure to accommodate all of these diverse requirements effectively."

Read the full interview he re.