# Cerbos policies

There are five kinds of Cerbos policies:

## [Derived roles](https://docs.cerbos.dev/cerbos/0.39.0/policies/derived_roles)
Traditional RBAC roles are usually broad groupings with no context awareness. Derived roles are a way of augmenting those broad roles with contextual data to provide more fine-grained control at runtime. For example, a person with the broad `manager` role can be augmented to `manager_of_scranton_branch` by taking into account the geographic location (or another factor) and giving that derived role bearer extra privileges on resources that belong to the Scranton branch.

## [Resource policies](https://docs.cerbos.dev/cerbos/0.39.0/policies/resource_policies)
Defines rules for actions that can be performed on a given resource. A resource is an application-specific concept that applies to anything that requires access rules. For example, in an HR application, a resource can be as coarse-grained as a full employee record or as fine-grained as a single field in the record.

## [Principal policies](https://docs.cerbos.dev/cerbos/0.39.0/policies/principal_policies)
Defines overrides for a specific user.

## [Role policies](https://docs.cerbos.dev/cerbos/0.39.0/policies/role_policies)
Define rules specific to a given role. Rules are defined as a list of permissible actions that apply to a particular resource. Role policies are evaluated before resource policies but don’t guarantee an `ALLOW` in the case of a matching rule — resource policies must also resolve to an `ALLOW` for the same request. See the dedicated [role policy documentation](https://docs.cerbos.dev/cerbos/0.39.0/policies/role_policies) for more details.

## [Exported variables](https://docs.cerbos.dev/cerbos/0.39.0/policies/variables#export)
Defines variables to be reused in condition expressions in other policies.

Policies are evaluated based on the metadata passed in the request to the Cerbos PDP. See [Cerbos API](https://docs.cerbos.dev/cerbos/0.39.0/api/) for more information.
