Cerbos Newsletter [7 April 2022]

Hello from Cerbos!

Our April newsletter includes:


Policy Workshop

Ever wondered how to get started with your first policy, or even which policy to start with? Then reach out for a 30 minute call with one of our developers at your convenience.


Cerbos Playground

We have just released a big upgrade to http://play.cerbos.dev which allows you to prototype policies right in your browser:


Cerbos v0.15 is out!

The latest release of Cerbos includes a number of updates to make the policy authoring experience easier:


Blog highlights

This blog post shows how context-aware permissions promote anywhere-anytime access by making controls intelligent enough to sense and react to their environment. The post also looks at why and when to use context-aware permissions.

This post reviews how an authorization model plays a vital role in securing an enterprise’s sensitive data. Businesses often code additional custom logic on top of traditional access control solutions like Active Directory. However, as businesses expand, they need access controls that can scale to match their growth.

This post looks at:


Industry news

Authorization in a microservices world

The author covers how within microservices environments he goes from a simple flag to Role Based Access Controls (RBAC) and then onto Attribute Based Access Controls (ABAC). This article made it to the HackerNews frontpage and some interesting comments can be found here.

The White House zero-trust memo

DeSimone comments on and provides the so-what for the new White House memo on zero trust. An example passage from the memo: “In a zero trust architecture, every request for access should be evaluated to determine whether it is appropriate, which requires the ability to continuously evaluate any active session. If undue risk is identified, mitigations could include requiring reauthentication, limiting access until confirmation that the user requested action is appropriate, or denying access entirely.”

Why authorization is more than just enforcement

The author explains a number of access control models in this post, including the


Developer Relations Opportunity

We’ve growing very fast and need an experienced developer relations person as the face of Cerbos in the developer community. We’d love this person to engage with developers to discover and remedy pain points, produce accessible technical content and help build an inclusive community of Cerbos users.


Do you want a Cerbos t-shirt?

Good! We want to give you a t-shirt! And we also want to talk to you about Cerbos and get your feedback, both what you like and dislike, what are your primary use cases, if you are missing any particular functionality or suggestions on how you would like us to improve the product.
Please, contact us via our feedback page and we will reach out to you to book a session.


Stay connected