Spin up an #AIagent and it needs a model to think with and tools to act with. Which model can it call? Which #MCP servers can it even open? Are the tool-call arguments inside policy?
How #agentgateway + Cerbos decide all three at the gateway: https://t.co/yObAWA6bhq
Agents follow #access, not instructions. If the policy lives inside the agent, the #agent will always talk itself past the gate.
How #IAM and security teams should be thinking about this before the #EUAIAct deadline.
https://t.co/35YayXbewa
Agents follow #access, not instructions. If the policy lives inside the agent, the #agent will always talk itself past the gate.
How #IAM and security teams should be thinking about this before the #EUAIAct deadline.
https://t.co/35YayXbewa
Identity gets the AI agent into the building. Authorization protects the vault.
@alexolivier 's #EIC2026 takeaways. Why counting agents isn't controlling them, where the decision lives, and the audit evidence the EU AI Act will ask for.
https://t.co/5RjyJ2FxRF
@nayshins@martin_casado We already built @cerbosdev for that purpose. It is designed to handle high-volume low-latency authorization with its stateless policy based approach. It works for your entire application stack and AI.
Building a multi-tenant SaaS app for enterprises? Here is a handy guide on how to properly build roles and permissions that scale for each one of your customers.
Fixed roles break when enterprises sign up for your #SaaS. Role explosion follows. Deals stall.
We just published a guide on implementing #multitenant#authorization that scales without role explosion.
🔗 Download the ebook: https://t.co/8qQ9gSkeFi
The message from #ISC2Congress 2025 is clear: policy as code is the only way forward
Continuous compliance, AI governance, and risk quantification are no longer optional
Security teams need policies that deploy and test like software
Read more🔗https://t.co/Yse2yBAASS
@ISC2
Moving to #microservices? #Authorization gets complex fast.
Our new guide covers workload identity, on-behalf-of authorization patterns, and real policy examples for securing service-to-service calls and AI agents.
#Zerotrust made practical 👉 https://t.co/FabribJi5W
Adopting externalized authorization is a big shift.
We turned lessons from helping hundreds of teams, into a 10-chapter guide covering everything from planning to rollout to governance.
📘 Get the “How to Adopt Externalized Authorization” ebook:
https://t.co/sLxBNjDwy2
#NonHumanIdentities outnumber human users by 17:1, yet they are one of the most overlooked attack vectors.
We published a new blog post breaking down the #OWASP Top 10 threats to #NHIs: What each threat is, examples of breaches, steps to mitigate them.
https://t.co/o4TpG0BKFU
Are you attending DevWorld Amsterdam?
If so - stop by booth 5C tomorrow to meet our team, talk about permission management, and take on the Cerbos game! (🤔 🏅 can you beat the top score?)
@emre@phrawzty@alexolivier#devworld#conference
Statements about stateless - what happens when architectural theory meets real-world practice? 👉 https://t.co/e48zLFoMEO
@phrawzty discusses the core principles, advantages & disadvantages, and practical concerns of #stateless#architecture#Cerbos#authorization