# Cerbos policies

There are four kinds of Cerbos policies:

## [Derived roles](https://docs.cerbos.dev/cerbos/0.38.1/policies/derived_roles)

Traditional RBAC roles are usually broad groupings with no context awareness. Derived roles are a way of augmenting those broad roles with contextual data to provide more fine-grained control at runtime. For example, a person with the broad `manager` role can be augmented to `manager_of_scranton_branch` by taking into account the geographic location (or another factor) and giving that derived role bearer extra privileges on resources that belong to the Scranton branch.

## [Resource policies](https://docs.cerbos.dev/cerbos/0.38.1/policies/resource_policies)

Defines rules for actions that can be performed on a given resource. A resource is an application-specific concept that applies to anything that requires access rules. For example, in an HR application, a resource can be as coarse-grained as a full employee record or as fine-grained as a single field in the record.

## [Principal policies](https://docs.cerbos.dev/cerbos/0.38.1/policies/principal_policies)

Defines overrides for a specific user.

## [Exported variables](https://docs.cerbos.dev/cerbos/0.38.1/policies/variables#export)

Defines variables to be reused in condition expressions in other policies.

Policies are evaluated based on the metadata passed in the request to the Cerbos PDP. See [Cerbos API](https://docs.cerbos.dev/cerbos/0.38.1/api/) for more information.
