Cerbos Hub is a managed control plane for authorization policy administration that provides a centralized web-based interface for authoring, testing, versioning, distributing, and auditing YAML-based policies. The platform includes a web IDE with policy wizards, real-time collaborative editing, and isolated playgrounds for policy validation with fixtures, schema validation, and execution traces. It features a managed CI/CD pipeline that builds, tests, and orchestrates rollout of policies to Policy Decision Points (PDPs) across environments, with deployment management capabilities including downloadable policy bundles, effect matrix views, and embedded PDP rules for controlling bundle contents, scope filtering, and authentication requirements.
The platform aggregates decision logs from connected PDPs, capturing principals, actions, resources, policy versions, and lineage information for compliance and traceability, with audit log collection, filtering, export capabilities, and timeline visualization. It supports deployment across on-premise, cloud, serverless, edge, and browser environments, with per-tenant custom policies, dynamic policy updates, and authorization for non-human identities including workloads, microservices, and AI agents. Storage configuration provides multiple backend options including disk, git, MySQL, PostgreSQL, SQLite3, and overlay, with relational database connection pool settings and retry policies. Additional capabilities include GitHub integration for policy repository management, a JavaScript SDK for client-side integration, observability through logs and metrics, multiple workspaces, concurrent PDP support, insights and usage dashboards with aggregated decision metrics, permission-aware navigation, workspace health indicators, and enterprise options encompassing single sign-on, self-hosted deployment, configurable audit log retention, uptime service level agreements, and tiered support.