Cerbos Playground - Prototype, test and share policies

SaaS Analytics Workspaces

This sample demonstrates how to model a SaaS application that is made up of many workspaces, for example belonging to different customers or departments.

Access is granted or denied to workspaces based on which workspaces are listed in the principal attributes of the request. This could be sourced from your authentication provider or a directory service - Cerbos can take inputs from anywhere.

Data Protection

SaaS businesses generally have a support function which needs to access a customer's workspace to help with a ticket. This is achieved through the supportRoles.yaml derived role which grants the user a support role if they are coming from either the US or EU Office IP range. By using this mechanism, support users can be scoped to only access customer accounts in their region - a common requirement in today’s data protection landscape.

Personal Information Access

Finally, an explicit PII check can be made to ensure support teams never see personal information in a customer’s account, and even certain users within a customer’s account can be granted this to meet data protection requirements.

You can test this yourself by selecting different principals in the bar to the right and check their different access levels based on their attributes.

Principal

Who is performing the action(s)?

User Example

{
  "id": "123",
  "roles": [
    "USER"
  ],
  "attr": {
    "workspaces": {
      "workspaceA": {
        "role": "OWNER"
      },
      "workspaceB": {
        "role": "MEMBER",
        "pii": true,
        "functions": {
          "view": {
            "all": true
          },
          "manage": {
            "all": false,
            "functions": [
              // additional functions can be defined here
            ]
          }
        }
      }
    }
  }
}

Resource

What is being accessed?

Workspace A (EU)

{
  "id": "workspaceA",
  "kind": "workspace",
  "policyVersion": "default",
  "attr": {
    "location": "EU"
  }
}

Actions

List of actions the principal is attempting to do with the resource

workspace Actions Result
Allowed
Denied
Allowed

Aux Data

Additional request context

Request

The HTTP request payload to Cerbos PDP

Response

The HTTP response from Cerbos PDP

Welcome to the Cerbos Playground. This environment allows you to build, test and debug authorization policies in real-time and share examples with your team. Full documentation can be found at docs.cerbos.dev