@cerbosdevi
iAccount based inSerbia
About this account
- Account based in
- Serbia
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Authorization for enterprise software and AI.
Joined June 2021
- Tweets2K
- Following625
- Followers800
- Likes10.7K
Pinned Tweet
🚀🥳#CerbosHub has successfully transitioned from Beta to #GeneralAvailability!
Huge thank you to our community for your support, and to 500+ organizations that have put their trust into Cerbos Hub! 🧡
Find out more: bit.ly/3Ws9R55
#Cerbos #GA #Authorization
Our CPO @alexolivier will be at @WeAreDevs 🔊on why authorization spread across many services breaks at scale
Come if your permission checks live in more than one place. You'll leave with the warning signs and a checklist to fix them 🔒
wearedevelopers.com/world-co…
#WeAreDevelopers
The Cerbos PDP dashboard is now on @grafana 🎉
We rebuilt it on the #Prometheus metrics the PDP has always exposed.
Import ID 25769 and you get per-instance health, Hub connectivity, policy count, latency percentiles and restart annotations.
grafana.com/grafana/dashboar…
Cerbos retweeted
入社してから担当していた認可基盤の移行が完了したのでブログ書きました 👍
認可エンジンのCerbosを選定した理由や、
認可基盤の移行について気になる方はご覧ください!
tech.acesinc.co.jp/entry/202…
ACES moved #authorization for ACES Meet onto Cerbos and wrote up how they did it step by step.
Dual writes, a shadow run against production traffic, then cutover. Useful if you're planning the same move off in-app permission checks. Thank you @nori_nori_8! #
入社してから担当していた認可基盤の移行が完了したのでブログ書きました 👍
認可エンジンのCerbosを選定した理由や、
認可基盤の移行について気になる方はご覧ください!
tech.acesinc.co.jp/entry/202…
An #agent exports a record it shouldn't have.
The logs say a service account. Not the user, not the agent, not the sub-agent.
We wrote up why the trail goes dark at the handoff and the 4 things every hop has to log so it doesn't: 🛡️ bit.ly/4iRYEXa
#authorization #ai
Cerbos Newsletter Sept 2026 📢 bit.ly/4h1feRV
✅Takeaways from #IdentityWeek America
✅Vetting checklist for #MCP servers
✅Delegated authz
✅New Cerbos Hub interface
✅[eBook] The #Authorization Maturity Model: A Benchmark for 2026
Subscribe: bit.ly/3MGNwuW
Authorization bugs do more than leak data. At scale they become outages and stuck workflows.
Our CPO @alexolivier covers catching them early at #WeAreDevelopers World Congress, Sept 24. You'll leave with a checklist for making #authorization predictable.
wearedevelopers.com/world-co…
Same AI agent question at #IdentityWeekAmerica, whatever the badge said. Who's asking & what can it touch?
@alexolivier wrote up panel takeaways, who should own an agent, and which actions get a spend limit, a human in the loop, or a hard approval
🔗🤖 bit.ly/46e0fPx
A role can't say "read this record, only while acting for the user who owns it, only for this task, only right now."
That's why #agent #delegation needs a policy decision at every hop, not just the edge.
How per-hop #authorization works 👉 bit.ly/4yfwf1G
Most "#Keycloak alternative" lists mix four products. An authentication gateway, an OAuth server, a full #IdP and a policy engine solve different problems.
We wrote up which fits which requirement, and when swapping IdP fixes nothing: 🔗 bit.ly/4h5MBEf
#IAM
Booth 720 at Identity Week America has been busy, and it's been good to meet so many of you 😀!
@alexolivier and @emre are there for the rest of the show. Come talk permissions, policy design, or keeping AI agents inside their limits.
#IdentityWeekAmerica #IAM
Your board told you to adopt #AI agents. You're the one accountable when one does something nobody predicted.
We wrote up the 7 layers of AI agent security, the tools in each, and the layer most stacks skip.
bit.ly/4y8N7Hf
#AIsecurity #AIagents
🌎 Cerbos is at #IdentityWeek America this week, booth 720, with @emre and @alexolivier.
If roles have multiplied to the point where nobody can say who can do what, that's the conversation to have with them.
See you there!
#IdentityWeekAmerica #IAM @IdentityWeek_ID
If your #agent chain forwards the user's access token to the next hop, you're not delegating. You're #impersonating.
We wrote up what a chain that holds together looks like, a checklist to test your own design against & which standards are ready now.
🔗🛡️bit.ly/4gyFYce
Alex is on Stage 2 at @Tailscale Up tomorrow at 3:35 PM.
Stop by if you're putting agents into production.
You'll leave with a reference architecture for authorizing tool calls, policy examples you can adapt, and an adoption path that starts with visibility before enforcement.
Our CPO, @alexolivier will speak at #TailscaleUp in SF on Aug 26, on why every tool call an agent makes is a trust boundary.
Agents run at machine speed, hundreds of calls a minute. Most #authorization models assume a human clicking a UI.
tailscale.com/tailscaleup/ag…
For teams who have hit the #Istio #AuthorizationPolicy ceiling. New guide on moving ownership and tenancy rules out of middleware and into policy, running one policy set across both traffic planes, and what the extra network hops cost
bit.ly/4xAK1fD
#authorization
Guide on reading identity attributes at decision time instead of trusting #JWT claims issued at sign in. How to verify the #token at the edge, fetch current profile and group data per request, and set the staleness window per source
🔗bit.ly/45H9l7f
#authorization
Could you list every #MCP server running against your systems right now, who owns each one, and what it can reach?
At most orgs, no. And that inventory gap is the real risk, not any single server.
A practical checklist for vetting #MCPserver:
🛡️ bit.ly/46ek3lG
Most #authorization models assume the principal is the person doing the thing. That breaks the moment one person acts on behalf of another
A role carries no record of who it was granted for, so "may adjust this customer's bill" becomes "may adjust bills"
bit.ly/4xM1dyd
Cerbos Newsletter August 2026 📢 bit.ly/3SeI74L
✅What #DORA Article 9(4)(c) requires of #AI agents
✅#Agent skills for writing #authorization #policies
✅Cerbos Hub #auditLog exports
✅Cerbos PDP v0.55.0
✅Launch of referral program
Subscribe: bit.ly/3MGNwuW