Cerbos Playground - Prototype, test and share policies

README

Finance Application Demo

To see this policy in action, check out the code example in Github. GitHub Repository

The actors are:

  1. Sally works in the sales department in EMEA and submits reports
  2. Sydney works in the sales department in the US
  3. John is the sales manager in EMEA
  4. Brock is the sales manager in US
  5. Joe is the finance manager, can approve all the expenses.
  6. Sajit is from the IT department, can do anything.

Scenario:

The expense reports sent by Sally can be approved by the finance department. Can be only seen by the regional manager that matches her region, in this case John. However, John cannot see who approved it, only Joe from finance, Sajit from IT, and Sally herself can see it.

README

Outputs Problems Tests

No policy outputs defined. Policies can return context along with the decisions - read more in the documentation..

Principal

Who is performing the action(s)?

Try the API

Sally - Sales EMEA

{
  "id": "sally",
  "roles": [
    "USER"
  ],
  "attr": {
    "department": "SALES",
    "region": "EMEA"
  }
}

Resource

What is being accessed?

Expense 1

{
  "id": "expense1",
  "kind": "expense",
  "policyVersion": "default",
  "attr": {
    "ownerId": "sally",
    "createdAt": "2021-10-01T10:00:00.021-05:00",
    "vendor": "Flux Water Gear",
    "region": "EMEA",
    "amount": 500,
    "status": "OPEN"
  }
}

Actions

List of actions the principal is attempting to do with the resource

expense Actions Result
Denied
Allowed
Denied
Allowed
Allowed
Denied

Aux Data

Additional request context

Request

The HTTP request payload to Cerbos PDP

Try the API

Response

The HTTP response from Cerbos PDP

Welcome to the Cerbos Playground

This environment allows you to build, test and debug authorization policies in real time and share examples with your team.

Full documentation can be found at docs.cerbos.dev