https://cerbos.dev logo
Join Slack
Powered by
# announcements
  • a

    Anna Paykina

    12/15/2025, 2:36 PM
    Hey everyone! Our CPO and co-founder, Alex Olivier, put together a write-up of the key insights from Gartner IAM Summit 2025 High level summary: Authorization has evolved from a backend control into strategic identity infrastructure. What’s driving this shift: 1️⃣ Workload IAM is the new frontier. 2️⃣ Authorization modernization is no longer optional. 3️⃣ Standards are accelerating adoption. As identity ecosystems expand beyond humans into autonomous agents and distributed infrastructure, organizations need to rethink how access decisions are designed, enforced, and standardized. Feel free to read the full recapfor deeper insights on policy based authorization, the coexistence of authorization models, and why this matters for security architectures 👇 https://www.cerbos.dev/blog/gartner-iam-summit-2025-authorization-authzen-identity-security-expanding-to-every-workload
    👍 2
    cerbie 2
    👀 2
  • a

    Anna Paykina

    12/18/2025, 10:59 AM
    Hey <!channel>! 👋 We just published a blog comparing Cerbos PDP vs. Cerbos Hub – ultimately, when you can use the open source engine alone vs. when you need the managed solution. It breaks down the operational differences across policy writing, testing, distribution, updates, and audit logging – plus the engineering cost of building it yourself. Worth a read if you’re scaling authorization or hitting operational pain points: https://www.cerbos.dev/blog/cerbos-pdp-and-cerbos-hub-choosing-the-right-setup-for-your-team If you have any question - drop them in the thread. Happy to discuss! 💬
    🙌 2
    cerbos 2
    👌 2
    👍 2
  • g

    GitHub

    12/22/2025, 11:10 AM
    Release - v0.50.0 New release published by github-actions[bot] ## Cerbos 0.50.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.50.0.html ## Changelog • a4b548d Add default scope configuration to be used when scope is not specified in the request (#2843) • 76861a6 Add dot as an alias to empty scope in requests (#2846) • 6f76194 Add v0.50.0 release notes (#2863) • 2422259 Introduce InspectPolicies API for rule tables (#2836) • 777ad46 Prevent index lookup of constants, globals, and variables (#2858) • 7db8ae1 Revert breaking change to EPDP interface (#2853) • 0ccb88e Update GoReleaser config (#2855) • 6929c0b Use namer.ScopeValue when fitting (#2848) • 4e2292c chore(deps): Bump github.com/quic-go/quic-go from 0.56.0 to 0.57.0 in /tools (#2841) • 7d58efd chore(deps): Update GitHub Actions deps (#2844) • 1d3758c chore(deps): Update Go deps (#2845) • 60f11a7 chore(deps): Update Go deps (#2862) • 5bffe40 chore(deps): Update Node.js deps (#2851) • 3afeeb8 chore(deps): Update actions/checkout action to v6 (#2852) • 3d67f66 chore(release): Prepare release 0.50.0 • 2ff256b chore(version): Bump version to 0.50.0 • 3eef8f3 chore: Ruletable optimization clean-up (#2860) • c20c6d7 enhancement: Ruletable optimizations and refactoring (#2857) • db9fb5e fix(planner): Union nodes across scope boundaries (#2849) • 1ab8a62 fix: Isolate role policy restrictions (#2842) cerbos/cerbos
  • a

    Anna Paykina

    12/24/2025, 11:26 AM
    Hey community! Happy Holidays from all of us at Cerbos! 🎄✨ Thank you for your support throughout the year, we’re excited for what’s ahead in 2026! In the meantime, if you’re looking for a fun challenge over the holidays, check out our Policy Game. See who among your friends and family can get the high score: https://game.cerbos.dev/?event=happyholidays2025 🕹️ It’s a brain-teasing policy puzzle that’ll test everyone’s accuracy and speed. May the best decision-maker win!
    cerbie 1
    🎯 1
    ❄️ 1
    🧡 1
  • l

    Lisa Dziuba

    02/13/2026, 11:48 AM
    Roses are red. Violets are blue. Implicit trust is risky. Least privilege looks better on you. ❤️ Fall for runtime authorization this #ValentinesDay: https://www.cerbos.dev/ P.S.: Have a happy Valentine's Day!
  • s

    Slackbot

    02/15/2026, 5:41 AM
    @Nishant Vartak joined #announcements. They’re also new to Cerbos Community.
    👋 2
  • l

    Lisa Dziuba

    02/17/2026, 2:16 PM
    Hello everyone 👋 Today we’re announcing our integration with Tailscale to bring fine grained authorization to agentic AI. 🤖 AI agents are now calling internal tools and APIs in production. They often run with broad permissions. That creates real risk. • Aperture by Tailscale sits in the request path and intercepts tool calls. It provides visibility into agent activity and usage across your connected systems. • Cerbos evaluates each tool call against policy and returns an explicit allow or deny decision. • Aperture enforces that decision before the action runs. Cerbos also produces decision-level audit logs tied to identity and policy version. 👉 Learn more: https://www.cerbos.dev/tailscale-aperture
    👏 2
  • a

    Anna Paykina

    03/04/2026, 10:48 AM
    Hey, <!channel> 👋 We’re excited to give a shoutout to Paulo - one of our community members - and his team at Flash! Flash is a Brazilian fintech using Cerbos to power real-time expense controls for hundreds of corporate clients. Since making the switch to Cerbos they’ve seen corporate card usage double, they’re managing 6,000+ policy rules in real-time, and they’ve done it all without adding engineering headcount. 🙌📈 Huge thanks to Paulo and the Flash team - not only for building something impressive with Cerbos, but for being kind enough to share their journey with us. Full story here if you want to explore the details: https://www.cerbos.dev/customers/flash
    cerbos 8
    👏🏻 1
    💫 6
    🚀 7
    🏦 4
    🎉 10
    👏 9
    ❤️ 1
  • a

    Anna Paykina

    03/09/2026, 11:20 AM
    Hey <!channel>! We’re hosting a 💻 📹 free webinar next week on layered security and Zero Trust. If one of your Zero Trust layers fails, what actually catches the threat next? Few teams can confidently answer what happens when a layer breaks - or whether the threat sails straight through to a breach. Aviation solved this decades ago with the Swiss Cheese Model, and we’re applying the same framework to runtime security. You’ll walk away with a practical way to stress-test your security layers, identify where the dangerous gaps are, and build a true Zero Trust Architecture you can stand behind. We’ll cover the six layers of runtime security (identity, authentication, PAM, entitlement management, coarse-grained and fine-grained authorization), where most orgs still have blind spots, and why end-to-end Zero Trust is finally implementable. 📅 Wednesday, March 18th · 6:30pm CET / 9:30am PST · 45 min + Q&A 🔗 Register here, if you’d like: https://zoom.us/webinar/register/9117730533248/WN_rBAJChIBR52EEd5XeNI9xw PS. No worries if you can’t make it live. Register anyway and we’ll send the recording post-webinar.
    💫 5
    👍 7
    🙌 6
    cerbie 3
    👀 4
    cerbos 1
  • l

    Lisa Dziuba

    03/10/2026, 10:25 AM
    Cerbos turns 5 today. 🎉 For five years, Cerbos has been helping teams run secure, scalable authorization. Cerbos is now used by companies around the world to manage complex permissions, enforce policies consistently, and control what AI agents are allowed to access and do. Grateful to everyone building with Cerbos and helping us grow.
    cerbie 7
    💪🏻 1
    🎉 10
    👏 2
    🎂 11
    💪 4
    👏🏻 1
    💜 2
    🥰 1
  • l

    Lisa Dziuba

    03/12/2026, 10:22 AM
    Hey everyone 👋 We have some more cool news to share: we're introducing Cerbos for agentic commerce. AI agents are starting to place orders, trigger refunds, and modify subscriptions inside e-commerce systems. The question becomes: what are those agents actually allowed to do? Cerbos helps e-commerce platforms evaluate every AI agent purchase, refund, and subscription action against centralized authorization policies before money moves: • Evaluate agent actions against policies at runtime • Enforce authorization at the API boundary where agent transactions execute • Apply consistent policies across storefronts, APIs, and integrations • Maintain a clear decision trail showing which policy allowed or denied each action If you are building agent-driven commerce systems, see how authorization policies can control agent transactions. 👉 https://www.cerbos.dev/agentic-commerce
    🚀 5
    cerbie 5
    🌟 3
  • l

    Lisa Dziuba

    03/20/2026, 3:07 PM
    Happy Friday everyone 🙂 Big one today, we’re introducing Cerbos Synapse 🎉 Every authorization decision is only as good as the data behind it. Who is this user? What groups are they in? What resource are they trying to access? Most teams end up building this data plumbing themselves, repeatedly, across apps, services, and increasingly AI agents in their stack. Cerbos Synapse enriches authorization requests with identity, resource, and relationship data from your existing systems before the policy engine evaluates what to allow: ✔️ No custom enrichment middleware ✔️ Native integrations for Envoy, Kafka, Trino, and Kubernetes ✔️ Built for AI agents and non-human identities ✔️ Complete audit trail from data source to decision outcome Extensions can be written in Go or any language that compiles to WebAssembly, so you're not locked into one ecosystem. Happy to answer any questions here, or feel free to explore Cerbos Synapse yourself: https://www.cerbos.dev/product-synapse
    🚀 6
    🌟 4
    💪 4
    🙌 3
    💪🏻 1
    🙌🏻 1
  • l

    Lisa Dziuba

    03/26/2026, 4:08 PM
    👋 Hey everyone, We’ve been seeing Claude Code spread well beyond engineering. Marketing teams exploring codebases, product managers reading configs, data analysts grepping logs. But there is a gap. There is no central, enforceable way to control what those agents can actually do. Hooks exist, but they are local config, per developer, opt-in. That means no consistent enforcement across the org and no reliable way to see what agents actually did. 🎉 Today, we are introducing centralized authorization for Claude Code agents. Every tool call is intercepted and checked against policy before it runs. That gives you control over what agents are allowed to do, at the moment they act: • Allow or deny decisions on every tool call, not just monitoring • Role-based controls so engineers can use Bash while other teams stay read-only • Full audit log tied to the user behind each agent action • Policies as code, versioned, reviewed, and updated without redeploying anything Policies and audit logs are managed in Cerbos Hub, so you have one place to control access and understand what agents are doing across your org. If you want to see how it works or try it out, we’re around and happy to help: 👉 https://www.cerbos.dev/ecosystem/claude-code 👉 https://www.cerbos.dev/workshop
    cerbie 4
    💫 1
    🚀 5
    🎉 4
  • a

    Anna Paykina

    04/07/2026, 1:06 PM
    Hey community! Hope your week is going well 😊 We wanted to share our new guide + demo with you. It’s all about using Cerbos Synapse with Apache Trino. It covers how to add row-level security, column masking, and table-level access control to Trino through its existing OPA plugin. Synapse handles the protocol translation and enriches each query with user attributes from your IdP, so your Cerbos policies control what each user sees down to the row and column level. The 3-min demo shows three users running the same SELECT query and getting completely different results based on who they are. Blog +

    Demo video▾

    If you’re running Trino and have questions about the setup, drop them here :)
    💫 3
    👍 3
    🙌 3
    🙌🏻 1
    👍🏻 1
  • a

    Anna Paykina

    04/10/2026, 5:34 PM
    Hey everyone, happy Friday ☺️ We just published a new blog on the 5 authorization blind spots auditors find most often in enterprise access control. It walks through the things that come up again and again in real audits - scattered authorization logic across codebases, policies that exist on paper but no proof of enforcement, quarterly access reviews that check role labels instead of actual permissions, non-human identities running with standing privileges, and AI agents deployed without an authorization model. Each section has a “what to do now” piece with practical steps to close the gap before the next audit cycle. Hoping it’s useful for anyone working through SOC 2, ISO 27001, HIPAA, or similar frameworks, or just generally rethinking how authorization fits into their Zero Trust setup 🙂 Full blog: https://www.cerbos.dev/blog/5-authorization-blind-spots-auditors-find-and-how-to-fix-them Have a great weekend!
    🔒 3
    👍 3
    cerbie 3
  • a

    Anna Paykina

    04/14/2026, 1:44 PM
    Hey everyone! Excited to share a walkthrough on using Cerbos Synapse to add authorization to legacy applications without any code changes 🙂 Envoy sits in front of the app as a reverse proxy, handles authentication against your IdP, and calls Synapse for a policy decision on every request. The legacy app doesn’t need an SDK, doesn’t need modifications, doesn’t even know Cerbos is there. 📖 Full guide with policy examples and a phased rollout path 🎥

    Video demo▾

    showing it in action with a legacy payroll app If you’re dealing with legacy systems that have been sitting outside your authorization framework, this one’s for you!
    💥 5
    🎉 5
    cerbie 5
  • a

    Anna Paykina

    04/22/2026, 4:13 PM
    Hey community 👋 We just published a new guide on writing Cerbos authorization policies with an agent skill we’ve released. The hardest part of writing authorization policies isn’t the policy language. It’s the translation from business requirements into a precise spec of who can do what, under which conditions, on which resources. So we built an agent skill that handles the translation for you. You describe the access rules in plain English (or any language!), it asks the clarifying questions to tighten up anything vague, then generates the full policy bundle for you, including schemas, derived roles, resource policies, and tests, and validates every output against the real Cerbos compiler. If validation fails, it reads the errors and keeps fixing until the policies compile cleanly. It works in Claude Code, Cursor, Codex, OpenCode, and 10+ other agents. Install is one command: Full write-up here: https://www.cerbos.dev/blog/agent-skill-for-writing-authorization-policies
    cerbie 4
    🤖 4
    🙏 4
    👍 3
    🎉 2
  • g

    GitHub

    04/28/2026, 6:16 AM
    Release - v0.52.0 New release published by github-actions[bot] Cerbos 0.52.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.52.0.html Changelog • 2812325 Add 0.52.0 release notes (#3127) • 3f8cfc3 Add TraceBatch format for compact trace representation (#2945) • 9a8ceb5 Add ability to save Hub credentials (#3067) • 78fec1d Add build constraints (#2979) • 6e74c62 Add changelog entry for breaking OpenTelemetry changes (#2954) • d7eefbe Add pages/recipes for common questions (#3106) • 9fb62a2 Add path functions to Cerbos CEL library (#3039) • f3f464b Add permissions advisor workflow (#3007) • ad8d242 Add siteline to docs (#3093) • b9dc7e1 Add tracer.TracesToBatch (#2958) • de243ba Add verify.BundleStream (#2944) • f8a1020 Additional repository statistics (#3025) • 681bcf8 Avoid compiling constant expressions at runtime (#3005) • cbfb1b3 Avoid round-tripping attributes to JSON for schema validation (#3000) • f0e0df7 Bump brace-expansion from 2.0.2 to 2.0.3 in /npm/test/registry (#3062) • 74fa896 Bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#2975) • a3f8d30 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.96.4 to 1.97.3 in /tools (#3083) • a02dfd0 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.97.1 to 1.97.3 (#3082) • dce4632 Bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 in /tools (#3054) • 489656f Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#2980) • bf6e74a Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 in /hack/tools/changelog (#2981) • 96b53c0 Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 in /tools (#2987) • 04960ce Bump github.com/docker/cli from 27.4.1+incompatible to 29.2.0+incompatible (#3004) • a78b47a Bump github.com/go-git/go-git/v5 from 5.17.0 to 5.17.1 in /hack/tools/changelog (#3070) • 8d29a2f Bump github.com/go-git/go-git/v5 from 5.17.1 to 5.18.0 in /tools (#3109) • 10d8886 Bump github.com/go-git/go-git/v6 from 6.0.0-alpha.1 to 6.0.0-alpha.2 in /hack/tools/changelog (#3113) • f1706dd Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#3072) • 9d61b19 Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /hack/loadtest (#3073) • e9bbc5e Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /tools (#3074) • 35fd059 Bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (#3118) • d4cd21c Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 in /tools (#3104) • 6febdf3 Bump go.opentelemetry.io/otel from 1.40.0 to 1.41.0 in /api/genpb (#3121) • ebe00a5 Bump go.opentelemetry.io/otel from 1.40.0 to 1.41.0 in /hack/loadtest (#3126) • 6071f59 Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in /tools (#2986) • 73c754d Bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /tools (#3097) • <ht… cerbos/cerbos
    🚀 3
  • g

    GitHub

    05/05/2026, 11:34 AM
    Release - v0.53.0 New release published by github-actions[bot] Cerbos 0.53.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.53.0.html Changelog • 93a75a6 Add Helm release workflow and bump chart version to 0.52.1 (#3133) • 218ea22 Add v0.53.0 release notes (#3143) • 81ab26e Fix rendering of wildcard characters (#3140) • 77974a7 Migrate to
    cerbos/actions
    (#3120) • 2e8e054 Move Helm release to its own workflow (#3135) • 7cd3152 Move path functions documentation to correct place (#3139) • d72ef61 Remove JWT verification cache (#3138) • 5028a6f Remove
    voxmedia/github-action-slack-notify-build
    (#3129) • ccc98e9 Remove incorrect default tag value from Helm chart (#3131) • ea252b9 Set
    Content-Type
    to
    application/x-ndjson
    on streaming responses (#3130) • cc293e2 Update GitHub Actions deps (#3124) • 2261983 Update cerbos/actions to bb55708 (#3142) • 51ab843 Update to
    <http://github.com/ory/dockertest/v4|github.com/ory/dockertest/v4>
    (#3136) • 78d494c chore(release): Prepare release 0.53.0 • 47b23a4 chore(version): Bump version to 0.53.0 • c1d70c9 fix planner ignoring OVERRIDE_PARENT for parent DENYs (#3137) cerbos/cerbos
  • a

    Anna Paykina

    05/26/2026, 3:13 PM
    Hey everyone! 👋 hope your week is off to a good start! We just published a page on AI gateway authorization, walking through how to layer fine-grained access control on top of your AI gateway. Feel free to check it out if it’s relevant for you ☺️ AI gateways are good at telling you who’s calling but not what that caller is actually allowed to do. Once an agent starts using tools, calling an LLM, or delegating to another agent, the human behind the request tends to disappear from the audit trail, sub-agents end up inheriting more privilege than they should, and revoking access usually means rotating credentials or redeploying. The page covers what changes when every model call, tool invocation, and agent-to-agent handoff runs through the same policy layer your apps already use. You end up with one audit trail across humans, services, and agents, sub-agents that stay scoped to what the parent had, and policy changes that take effect at request time rather than at deploy time. Plus evidence trails that line up with SOC 2, ISO 27001, HIPAA, and DORA.
    🤖 3
    🚀 3
    👍 3
    cerbie 3
  • a

    Anna Paykina

    05/27/2026, 11:35 AM
    Hey community 😊 Update for those working in automotive 🚗 UNECE R155 and R156 are now type approval requirements for new vehicle types in UN 1958 markets. They require auditable evidence of who can push what firmware, to which vehicles, under which conditions. Most platforms have that logic scattered across services in different languages, which is exactly what an auditor can’t follow. We just published a guide on the authorization layer that actually produces that evidence. It walks through the
    YAML
    for a single OTA deploy action across five principals (vehicle engineer, production manager, owner, OEM partner, telematics agent), plus supplier data scoping and ECU diagnostics. Full write-up, with the allow/deny matrix and YAML per principal
    🚗 3
    👍 2
    🔒 2
  • a

    Anna Paykina

    06/08/2026, 3:05 PM
    Hey everyone 👋 Hope your week is off to a good start! If you’re running our open-source Cerbos PDP, your authorization decisions are happening thousands / millions of times a day with no easy way to see the shape of that traffic. We just shipped 🚀 Insights to change that, a new page in every Cerbos Hub workspace that aggregates the decisions flowing through your PDPs into charts and rankings, so the patterns are obvious without you going looking for them. You get allows and denies over time (hourly for the last 7 days, daily for the last 30), a count of active principals, and rankings of your busiest principals, resource kinds, and resource and action pairs. A spike in denials usually means a policy landed stricter than intended or a client is calling for something that no longer exists, and seeing it on a chart is the difference between catching it in minutes and hearing about it from a user days later. Every chart links straight back into the audit log, pre-filtered to match what you’re looking at, so you can drop into the underlying decisions without rebuilding the filter by hand. The best part is there’s nothing new to wire up. It’s built entirely on the decision data your PDPs already send to Hub, so once audit log collection is on, the page populates on its own. If your PDPs aren’t connected to Hub yet, this is the kind of thing you get when they are. Details can be found here
    cerbie 2
    ✨ 1
    🔢 1
  • a

    Anna Paykina

    06/17/2026, 11:19 AM
    Hey <!channel>! We have a 📘 🔐 new ebook out: The Authorization Maturity Model, a CISO's Benchmark for 2026 If you’ve read our How to adopt externalized authorization ebook, this is the security team equivalent. It gives CISOs: • A 4-stage model to benchmark where their authorization program actually stands • A regulator-by-regulator exposure rating across NIS2, DORA, SEC, the EU AI Act and more • And a 90-day plan to close the gaps. Written by Alex Olivier, our CPO and co-chair of OpenID AuthZEN. And if you’ve been trying to get security leadership behind a real authorization push, this is a good way in. It puts the work in the terms a CISO answers to, regulatory exposure and board-level risk, which is usually what unblocks the buy-in and budget to get started.
    🚀 3
    💫 4
    🔐 3
    👍 2
    cerbie 4
    👍🏻 1
    🙌🏻 1
    👏🏻 1
  • a

    Anna Paykina

    06/18/2026, 10:04 AM
    Hey community, some more news for you all - we just shipped an 🤖🚀* agent skill for building Cerbos Synapse extensions* Cerbos Synapse lets you shape what flows through your Policy Decision Point. Enrich a principal with attributes from a database before the decision runs, map an incoming HTTP or Envoy request onto a check, or stand up a custom endpoint under /ext/ that does exactly what your app needs. The skill builds those extensions for you. You describe what you want in plain terms, something like “enrich the principal with the user’s department from Postgres before the check runs,” and it picks the extension kind and runtime, scaffolds the files, wires the config, writes a test suite, and runs it against a local PDP. You get a working extension to drop into your own project, not a blank file. Feel free to check it out here.
    👍 3
    💡 1
  • a

    Anna Paykina

    06/30/2026, 11:16 AM
    Hey everyone 👋 hope your week’s off to a good start We just shipped the Effect matrix in Cerbos Hub. It takes the same compiled policy you already deploy and lays it out as a grid, roles down one side, actions across the top, every cell showing allowed, denied, or conditional. If you’ve ever had a product owner, a reviewer, or support ask “can this role actually do that,” you know the answer normally means reading through resource policies, derived roles, and conditions to be sure 👀_. The matrix answers it at a glance, without anyone needing to read raw policy._ You’ll find it on the Policies tab of a deployment, as a toggle between Source and Effect matrix. Conditional cells aren’t flattened into a yes or no. They’re marked conditional, and you can click in to see the exact rule and the condition behind it. It also flags the cells a wildcard rule reaches into, so a broad
    documents:*
    grant shows up as broad instead of hiding in a pattern. It’s live now for any deployment in Cerbos Hub cerbie🚀 Full write-up here
    cerbie 2
    👍 1
    🖥️ 1
    👌 1
  • a

    Anna Paykina

    07/06/2026, 11:31 AM
    Hey everyone 👋 hope your week is off to a good start We just published a guide on running an authorization POC that actually reaches production ⚙️*.* Most POCs don’t fail on the technology. They stall when success criteria only get defined at the end, so three weeks in the demo works but it’s hard to say whether that proves anything. The guide covers how to scope the POC to one real service instead of a demo app, the six questions worth answering before day one (can it model your real rules, does latency hold under real load, does the audit output satisfy compliance, and so on), who needs to be in the room while it runs, and why two to four weeks with a hard deadline beats an open-ended pilot. Full write-up here: cerbos.dev/blog/authorization-poc-guide
    🖥️ 1
    👀 1
    👍 1
    🙌 1
  • a

    Anna Paykina

    07/08/2026, 9:50 AM
    Hey everyone! For anyone at 🌍 WeAreDevelopers World Congress in Berlin this week: Alex Olivier, our co-founder and CPO, and co-chair of the OpenID AuthZEN working group, is speaking tomorrow on securing AI agents once they stop reading and start acting. Prompt instructions aren’t a security boundary, and the talk covers what to put there instead. “The day the chatbot asked for sudo” Thursday, July 9, 11:30 to 12:00, Stage 6 If you’re around and want to chat in person, DM Alex on LinkedIn and he’ll make sure you find each other: linkedin.com/in/alexolivier
    👍 1
    🤖 1
  • g

    GitHub

    07/20/2026, 9:38 AM
    Release - v0.54.0 New release published by github-actions[bot] Cerbos 0.54.0 View the full release notes at https://docs.cerbos.dev/cerbos/latest/releases/v0.54.0.html Changelog • 64d274b Auto-configure GOMEMLIMIT from the cgroup memory limit (#3259) • 3870a7d Add CI performance regression test (#3174) • 6b483c6 Add
    cerbos.audit.v1.PolicySource.Hub.EmbeddedBundle.bundle_id
    field (#3155) • 0bacbd6 Add cerbos compile-store command (#3251) • b6fb643 Add dimension filters to ruletable index key queries (#3235) • f77ba9c Add new documentation homepage and cross linking (#3264) • ffc7e76 Add proxy support for Hub client (#3221) • 9e8e948 Add role policy outputs, constants and variables (#3156) • 44dd5de Add v0.54.0 release notes (#3282) • 3fb9576 Allow disabling TLS verification for Hub client (#3220) • a39c824 Build binaries at AMD64 microarchitecture level v2 (#3218) • db8f3fb Bump fast-uri from 3.1.0 to 3.1.2 in /npm/test/registry (#3162) • 9d46168 Bump github.com/go-git/go-billy/v6 from 6.0.0-20260424211911-732291493fb8 to 6.0.0-alpha.1 (#3178) • 305bfbf Bump github.com/go-git/go-billy/v6 from 6.0.0-20260424211911-732291493fb8 to 6.0.0-alpha.1 in /hack/tools/changelog (#3177) • fc7f84f Bump golang.org/x/crypto from 0.51.0 to 0.52.0 in /hack/loadtest (#3272) • 322a56c Bump golang.org/x/crypto from 0.51.0 to 0.52.0 in /hack/tools/changelog (#3271) • 3ae505b De-duplicate and re-allocate rule table objects (#3209) • bdaf976 Disable telemetry in CI performance regression test (#3277) • 69be648 Display output errors in passing tests and JUnit report (#3202) • 54046f0 Downgrade to go1.25 (#3237) • 588fc4b Enable incremental rule table marshalling (#3270) • 1891961 Export binary path from npm packages (#3180) • 96880d9 Expose parser (#3276) • 35f56ca Extend the load-test framework to measure PDP memory demand and GC behaviour under load (#3258) • 2acd6f2 Fix E2E SDK test (#3239) • 2a7007c Fix Siteline edge function (#3186) • 79d90eb Fix npm package templates (#3181) • f09accf Fix panic in E2E blob test (#3242) • 1bda684 Fix parser bugs (#3223) • 3352262 Fix typo in performance regression check workflow (#3179) • f2c6387 Handle permission denied error from Hub API (#3248) • 9ea7f61 Ignore
    helm/*
    tags when building snapshots (#3152) • 218362c Import GPG key for Helm Secrets before installation (#3219) • 5ac3bd8 Iterable stores (#3253) • ae6972a Lazy load sparse bitmaps (#3200) • 16888ec Lock file maintenance (npm) (#3168) • 6b49993 Lock file maintenance (npm) (#3195) • 72a094b Lock file maintenance (npm) (#3226) • bed9c7d Log CEL runtime errors and record them in audit entries (#3260) • cd8a94c More compact fqnBindings dimension (#3154) • <https://github.com/cerbos/cerbos/commit/8465b2ece823a4e079… cerbos/cerbos
  • a

    Anna Paykina

    07/20/2026, 2:32 PM
    Hey everyone 👋 hope your week is off to a good start! A while back we released an agent skill that writes Cerbos authorization policies for you. You describe the access rules in plain English, it asks the clarifying questions to tighten up anything vague, then generates the full policy bundle, including schemas, derived roles, resource policies, and tests. It validates every output against the real Cerbos compiler, and if validation fails it reads the errors and keeps fixing until the policies compile cleanly. We’ve now got step-by-step guides for each tool (Claude Desktop, Claude Code, Cursor, VSCode, Codex, OpenCode, Pi, Kiro), so whichever agent you’re in, there’s a walkthrough for getting set up :)
    🤖 2
    cerbie 2
    👌 1
  • a

    Anna Paykina

    08/06/2026, 4:30 PM
    Hey everyone, hope your week is going well! We’re happy to share that we have launched a 🤝 referral program 🤝 If you introduce us to a team that becomes a paying Cerbos customer, you get $1,000. You pick how it’s paid, as account credit against your company’s next invoice, a donation to a charity of your choice in your name, or cash to you where eligible. Plenty of teams are still building authorization in-house. The logic ends up spread across every service, engineering months go into something that isn’t the product, and every permission change waits on a release. Those are the teams we’d like to reach, and most of you will spot them long before we do. Submitting takes a couple of minutes. Send a name, email, company, and title, and our team handles the rest. You hear from us when the deal closes and it is time to sort the payout. Details and full terms can be found here: cerbos.dev/referral-programme Have an awesome rest of your day 😊
    cerbie 5
    🙌 4
    👍 5