🔐 New: A CISO’s benchmark for authorization maturity ➔ [Download the ebook](https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark)

# Authorize LlamaIndex agent actions and data retrieval with Cerbos

Enforce policy-driven authorization on LlamaIndex agent tool calls and data connector access using Cerbos.

[Authorization for AI](/content/features-benefits-and-use-cases/ai-security/index.html)[Talk to an engineer](/content/workshop/index.html)[Agent skill for writing authZ policies](/content/blog/agent-skill-for-writing-authorization-policies/index.html)

### Tool and data authorization

Control which LlamaIndex tools and data connectors each user or role can invoke with fine-grained Cerbos policies

### Context-aware decisions

Authorize agent actions based on user identity, roles, attributes, and request context at runtime

### Audit every agent action

Every authorization decision is logged with full context, giving you a complete audit trail of agent behavior

## How Cerbos works with LlamaIndex

AI agents and tools introduce a new class of authorization challenges. They act on behalf of users, access sensitive data, and chain operations, all of which need fine-grained access control.

Cerbos provides policy-driven authorization that controls what AI systems can do, which data they can access, and on whose behalf. Policies are written in human-readable YAML and evaluated at request time.

With Cerbos and LlamaIndex, you get guardrails that scale with your AI adoption, centrally managed policies, full audit trails, and sub-millisecond decision times that don't slow down agent workflows.

[Policy-as-codeHuman-readable YAML policies managed like source code](/content/features-benefits-and-use-cases/human-readable-authorization/index.html) [Scalable PDPStateless policy decision point with sub-millisecond latency](/content/features-benefits-and-use-cases/scalability/index.html) [Centralized managementManage, test, and deploy policies from a single control plane](/content/features-benefits-and-use-cases/centralized-management/index.html)

### How Cerbos authorizes LlamaIndex agents

1. **Define policies for tool and data access**, Write YAML policies that specify which tools and data connectors each user or role can invoke based on identity, attributes, and context.
2. **Agent requests authorization before each action**, Before invoking a tool or querying a data connector, the application sends the user context, action, and target resource to the Cerbos PDP.
3. **Cerbos evaluates the request against policies**, The PDP applies fine-grained rules considering the user's identity, role, and any additional attributes you provide.
4. **Action proceeds or is blocked**, Cerbos returns an allow or deny decision. The application enforces it, with every decision logged for audit.

### Security risks of unsecured AI agents

Without authorization at every tool call, AI agents introduce risks that traditional application security doesn't cover:

- **Privilege escalation through tools.** An agent with unrestricted tool access can perform actions the delegating user isn't authorized for — reading sensitive data, modifying resources, or invoking admin operations.
- **Incomplete identity context.** Agents often carry only a partial user reference. Without the full profile, policies can't enforce department-level, role-based, or attribute-based restrictions accurately.
- **No audit trail.** Without authorization checks at each step, there's no record of what the agent did, on whose behalf, or why it was allowed — making incident investigation and compliance reporting impossible.
- **Transitive trust.** When agents chain tool calls or delegate to other agents, permissions can expand silently if each step isn't individually authorized.

### Richer agent decisions with Cerbos Synapse

When an AI agent makes an authorization call on behalf of a user, it often includes only an agent ID or partial user reference. [Cerbos Synapse](/content/product-cerbos-synapse/index.html) enriches these requests with the full user profile from your identity provider, resource metadata from your data stores, and the agent's own constraints — so the PDP receives complete context for every decision without the agent needing to assemble it.

## FAQ

### How does Cerbos authorize LlamaIndex agent actions?

Before a LlamaIndex agent invokes a tool or queries a data connector, the application sends the user context, action, and target resource to the Cerbos PDP. Cerbos evaluates fine-grained policies and returns an allow or deny decision.

### Can I restrict which data connectors an agent can access?

Yes. Cerbos policies are attribute-based, so you can restrict data connector access by role, department, data classification, or any other context you provide. Policies are written in YAML and managed outside your application code.

### Does this work with LlamaIndex RAG pipelines?

Yes. Cerbos query plans can be translated into metadata filters for vector stores, ensuring retrieval-augmented generation only returns documents the requesting user is authorized to access.

## Cerbos + LlamaIndex

- Cerbos policies govern AI agent tool access and data visibility
- Full audit trail for every AI tool call and data access
- Per-user permissions enforced across autonomous agent workflows
- Sub-millisecond policy evaluation with no agent pipeline overhead

[Book a free policy workshop](/content/workshop/index.html) [Try the Playground](/content/features-benefits-and-use-cases/cerbos-playground/index.html)
