How the entire Cerbos platform works | Vetting checklist for MCP servers | Why acting on behalf of someone else is not a role ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser

We spent two days at Identity Week America this month. Federal agencies, defense contractors and SaaS teams came to our booth with the same problem, deciding what each identity may do. They had answered it for human users, partly answered it for workloads, and now AI agents are asking it a third time. The answer is the same one. Control over agents has to be policy based and happen at runtime, and some actions are neither allowed nor blocked, they need a person to sign off first. That has been our position for years, and M&T Bank, KeyBank and LG said it from the stage at the conference.


We wrote up how a policy can return that answer, a deny that names the sign-off that would clear it, so application code never has to work it out. For identity and security leaders, we covered why acting on behalf of someone else is not a role, how a user's identity and consent get lost when one agent hands work to another, and why that needs a fresh policy check at every handoff, plus a vetting checklist for MCP servers your teams did not write.


For builders, we showed how to run one policy at the Envoy gateway and inside the service, and how to gate agent tools outside the agent rather than in the prompt. We looked at authorizing MCP tool calls in the request path or from a hook inside the proxy, and what each can stop. We also covered stale JWT claims, and reading identity attributes live at decision time instead, and where Istio proves who a workload is but not what it may do.


For anyone wondering how the entire Cerbos platform works and how it's different from just using the open source engine (Cerbos PDP), we wrote up a side by side, what you get with each and who would get value from which.


Finally, the new Cerbos Hub interface has been launched! It gives teams less scrolling through decision logs, organization and workspace switching from any screen, a dark or light theme that follows the system, and improved accessibility. Hub can also now freeze a deployment on a known-good policy version and roll back to an earlier one.

🤝 We launched a referral program

Thank you to everyone who has sent teams our way, it is how some of our best conversations started. Know another team wrestling with authorization? Submit a referral, and if that company becomes a Cerbos customer, that is $1,000 to you. It takes two minutes. Refer a team here.

Product Updates

Cerbos Hub

 

Here’s what’s new in the Cerbos Hub interface:

  • Dark and light themes. Hub follows your system theme by default, or you can set it manually.

     

  • Switch organizations and workspaces from any screen. They now sit in a navigation bar at the top of every page, so you can move between them without leaving the page you're on.

     

  • More on each screen. Policy lists, audit logs and other common views show more rows with less scrolling.

     

  • Improved accessibility. Updated markup across the app, to current standards - for humans and agents.

Everything works the way it did, and there's nothing you need to do. You'll see the new interface the next time you sign in.


Also new since late August, a deployment can be frozen on a known-good version of its policies. Changes pushed to the linked stores are held until it is unfrozen, and the list of deployed versions now has a Roll back action on any earlier version and a Promote action on any newer one, either of which goes live on connected PDPs immediately. Frozen deployments are labelled in the deployment list so it is clear why new changes are not going out. Both are available to workspace Owners and Developers, with the detail in the release notes.

 

Learn about Cerbos Hub

Get started with Cerbos Hub

Helpful Content

[eBook] The Authorization Maturity Model: A Benchmark for 2026

 

The gap between what compliance documentation says a team's authorization program does and what actually runs in production widens every time a  service, workload or an agent is added. 

 

It usually surfaces during an audit or an incident - the worst time to find it.

 

Our new ebook, built on our work with hundreds of CISOs, public analyst research, and the latest news from industry conferences, gives security leaders a 4-stage benchmark and a self-assessment to see where their program actually stands, an exposure rating across NIS2, DORA, SEC, the EU AI Act and more, and a 90-day plan to close the gap.

 

It also covers what good looks like at each stage, and what changes once AI agents are in production.

Upcoming Events

Meet our team members and check out their talks to get valuable insights:

  • WeAreDevelopers World Congress, San José, September 24. Stop by Alex Olivier’s talk “It Passed Auth, Then Production Caught Fire”, on authorization as a reliability problem, the warning signs teams can spot before an incident, and a checklist for making authorization predictable, testable and explainable at scale.
  • ISC2 Security Congress, Gaylord Rockies, October 28. Check out Alex's talk “Identity as the Control Plane for Software Supply Chain Security”, co-presented with Vatsal Gupta of Apple, on the supply chain breaches that start with a compromised identity rather than tampered code, and how to govern human and machine identities across CI/CD without slowing engineering down.
  • Internet Identity Workshop, Mountain View, November 3 to 5. Alex will be there too. If you are attending, message him on LinkedIn if you’d like to set up a time to talk in person.

Stay connected

  • Struggling with fragmented authorization or audit readiness? → Book a free workshop

  • Explore the complete authorization management system → Cerbos Hub

  • Write policies from plain English requirements → Our agent skill

  • Set up and configure Cerbos → Documentation

  • Write a policy in the browser → Playground

  • Questions, releases and connecting with other users → Slack Community

  • More content → Build vs. buy, vendor evaluation framework, solutions to critical CISO challenges, compliance guide

  • Know a team wrestling with authorization? → Refer them and get $1,000

 

You are receiving this email because either we have met, chatted, or you've visited our website cerbos.dev and asked us to keep you up-to-date. If you have been forwarded this email, you can subscribe and receive future updates directly from us. If you prefer not to receive these updates, you can unsubscribe below, but we hope you stay!

 

 

X X
LinkedIn LinkedIn
YouTube YouTube
Email Email
GitHub Git Hub

Cerbos, 86-90 Paul Street,  London, UK, EC2A 4NE, United Kingdom.

Unsubscribe  Manage Preferences