Comparison
Permisly vs Cerbos
Permisly designs the access model. Cerbos enforces it at runtime. They solve different problems — and you might need both.
Start free, no cardContext
Design and enforcement are different problems
Cerbos is a policy engine that enforces access control in your running application. Permisly is a design tool that helps you model, approve, and present the access model before it's implemented. Most teams need both: design first, then enforce.
Comparison
How they compare
| Feature | Permisly | Cerbos |
|---|---|---|
| What it does | Designs the RBAC model visually | Enforces policies at runtime |
| When you use it | Before and during implementation | During runtime in production |
| Who uses it | POs, security leads, eng leads | Backend engineers |
| Approval workflow | Built-in magic link review | External (Git, CI/CD) |
| Presenter mode | Yes — step through roles live | No |
| Share links | Zero-login viewer links | No |
| Pricing | $10 one-time | Free / Enterprise |
| Self-hosted option | Cloud only | Yes |
FAQ
Questions
Yes. Permisly designs the model, Cerbos enforces it. Many teams use a visual design tool first, then translate the model into Cerbos policies.
Start with Permisly. Design the model, get it approved, then decide whether to implement it with Cerbos, custom code, or another policy engine.
Cerbos has a free open-source edition and a paid enterprise edition. Permisly is $10 one-time — no subscription, no per-seat pricing.