Cerbos Newsletter [12 Oct 2022]

Hello from Cerbos!

Our October newsletter includes :

Upgrades to Cerbos

Cerbos v0.21

The latest release of Cerbos, v0.21, includes more fine-grained control over the request limits and metadata logs as well as improvements to the Query Planner output.
Advanced server tuning knobs are now available to help users who have special deployment requirements. Most users won’t need to adjust these as the built-in defaults are suitable for most common deployment scenarios.
Users now have more control over which request metadata keys are logged to the request logs produced by the Audit logging system. Keys can be included or excluded based on your requirements. The default behavior is to not log anything.
This release also includes fixes to two edge cases found in the query planner:

Cerbos on the road

Over the next few weeks we will be attending two conferences. If you are around, please stop by and say hello. We are also giving free tickets to API World. You can claim your courtesy pass to API World here.

Blog highlights

5 Factors to weigh when building authorization architecture

A permissions layer is not something you would generally focus on when building a new software application. Your primary goal is to reach product-market-fit as quickly as possible, so you can focus on delivering the core business value and everything else takes a backseat.
In this article, learn about common patterns and the five stages of major requirement changes companies go through during their evolution from MVP to enterprise-ready.

Mapping business requirements to authorization policy

Often businesses ask the question of how to start building authorization policies for their software.
Cerbos published a 10 step detailed guide on how to build a model of your requirements and mapping them to scalable authorization policies.

Implementing Cerbos in a multi-tenant system

Many modern SaaS solutions are multi-tenant in order to streamline development, maintenance and scalability. However, this approach also creates challenges around authorization and data integrity.
Learn about how to implement an extensible multi-tenant authorization policy with Cerbos that scales.

Implementing role and attribute based access control in SQLAlchemy with Cerbos

If you maintain an application that handles any state at all, it's likely that you've had to figure out how to both store that state, as well as how to load it into the application layer and act on it in any which way your business logic requires.
Learn about how to use Cerbos and SQLAlchemy to fetch only the data that your user has access to.

Industry news

Cerbos success story: Salesroom

In our first of many more to come success stories, read about why Salesroom chose Cerbos rather than building their own in-house fine grained authorization system.
Hint: “it will cost you more than you think, even without factoring in opportunity cost.”

Thoma Bravo buys third identity company this year with $2.3B ForgeRock acquisition

The title says it all. Thoma Bravo, a leading private equity company with a 40-year history, recently acquired their third company in the IAM space. Read it on TechCrunch.

Developer Relations Opportunity

Our product adoption is growing very fast. We are looking for a developer relations manager to lead Cerbos’ developer evangelism and advocacy. We’d love this person to engage with developers to discover and remedy pain points, produce accessible technical content and help build an inclusive community of Cerbos users.
If you know amazing DevRel professionals who we should be talking to, please ask them to consider Cerbos and connect us.

Do you want a Cerbos t-shirt?

We want to give you a t-shirt! We also want to talk to you about Cerbos and get your feedback, both what you like and dislike, what are your primary use cases, if you are missing any particular functionality or have suggestions on how you would like us to improve the product.
Please, contact us via our feedback page and we will reach out to you to book a session.

Stay connected