Cerbos Playground - Prototype, test and share policies
README
Finance Application Demo
To see this policy in action, check out the code example in Github. GitHub Repository
The actors are:
- Sally works in the sales department in EMEA and submits reports
- Sydney works in the sales department in the US
- John is the sales manager in EMEA
- Brock is the sales manager in US
- Joe is the finance manager, can approve all the expenses.
- Sajit is from the IT department, can do anything.
Scenario:
The expense reports sent by Sally can be approved by the finance department. Can be only seen by the regional manager that matches her region, in this case John. However, John cannot see who approved it, only Joe from finance, Sajit from IT, and Sally herself can see it.
README
Outputs Problems Tests
No policy outputs defined. Policies can return context along with the decisions - read more in the documentation..
Principal
Who is performing the action(s)?
Try the API
Sally - Sales EMEA
{
"id": "sally",
"roles": [
"USER"
],
"attr": {
"department": "SALES",
"region": "EMEA"
}
}
Resource
What is being accessed?
Expense 1
{
"id": "expense1",
"kind": "expense",
"policyVersion": "default",
"attr": {
"ownerId": "sally",
"createdAt": "2021-10-01T10:00:00.021-05:00",
"vendor": "Flux Water Gear",
"region": "EMEA",
"amount": 500,
"status": "OPEN"
}
}
Actions
List of actions the principal is attempting to do with the resource
expense Actions |
Result |
|---|---|
| Denied | |
| Allowed | |
| Denied | |
| Allowed | |
| Allowed | |
| Denied |
Aux Data
Additional request context
Request
The HTTP request payload to Cerbos PDP
Try the API
Response
The HTTP response from Cerbos PDP
Welcome to the Cerbos Playground
This environment allows you to build, test and debug authorization policies in real time and share examples with your team.
Full documentation can be found at docs.cerbos.dev