Hey everyone 👋 hope your week’s off to a good start
We just shipped the
Effect matrix in Cerbos Hub. It takes the same compiled policy you already deploy and lays it out as a grid, roles down one side, actions across the top, every cell showing allowed, denied, or conditional.
If you’ve ever had a product owner, a reviewer, or support ask “can this role actually do that,” you know the answer normally means reading through resource policies, derived roles, and conditions to be sure 👀_. The matrix answers it at a glance, without anyone needing to read raw policy._
You’ll find it on the Policies tab of a deployment, as a toggle between Source and Effect matrix. Conditional cells aren’t flattened into a yes or no. They’re marked conditional, and you can click in to see the exact rule and the condition behind it. It also flags the cells a wildcard rule reaches into, so a broad
documents:*
grant shows up as broad instead of hiding in a pattern.
It’s live now for any deployment in Cerbos Hub
cerbie🚀
Full write-up here