Role Policies With Cerbos | Cerbos

🔐 New: A CISO’s benchmark for authorization maturity ➔ Download the ebook

Role policies with Cerbos

Author permissions from a role’s point of view, not just the resource, and enforce least privilege by default.

Understanding role policies

Role policies in Cerbos provide a structured approach to defining permissions based on orientations around a role that can be assigned to a user or a non-human identity. They allow teams to specify which actions a particular role can perform on various resources, facilitating clear and manageable access control without having to augment the underlying resource policies.

During access checks, Cerbos evaluates role policies that match the principal's role and scope first. If multiple role policies apply, their permissions are combined, and then this is used as a permission-narrowing mechanism to limit which actions on resources are allowed.

Precision and enhanced security

Find out more

Features, benefits & use cases

Fit Cerbos seamlessly into your tech stack

Playground

Prototype policies in your browser right now

Cerbos Hub

Implement roles & permissions in your app

Speak to an engineer

Book an intro call and learn more