TL;DR: Authorization work can stay inside the repo, with policies compiled against the real engine and tests validated before commit, according to Cerbos. Its policy skill in Claude Code shows how AI can accelerate policy writing, but human review still has to own the deny paths and the assumptions behind them.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Agent skill for writing authorization policies in Claude Code”.
Key questions
Q: How should security teams govern AI-generated authorization policies in the repo?
A: They should treat generated policies as security code, not assistant output.
Q: Why do policy generators still need human review for access control decisions?
A: Because the hardest errors are semantic, not syntactic.
Q: What breaks when authorization is not tenant-aware?
A: Global authorization models break when the same user needs different permissions in different customer contexts.
Practitioner guidance
- Define the policy review boundary Separate draft generation from approval so the agent can produce policy structure, but a human still owns deny logic, tenant boundaries, and exception handling.
- Validate policies against the target compiler Run policy compilation and tests against the real authorization engine before merge, rather than relying on syntactic review of YAML alone.
- Document the access model before prompting Write down ownership, tenant scope, and resource relationships first so the agent is constrained by the real business rules, not inferred ones.
Bottom line: Authorization policy generation inside the repo changes IAM governance from a manual admin task into a code-review and compiler-validation workflow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization authoring is moving from configuration work to governed software change. When policy creation sits inside the same repo as the application, access control becomes a first-class part of the delivery pipeline rather than a sidecar admin task. That shifts the control point from manual edits to code review, validation, and change history. For identity programmes, the implication is that policy governance now needs software-grade discipline, not just access-policy intent.
A few things that frame the scale:
- Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: What should security teams check before trusting an AI-generated policy bundle?
A: Check the assumptions the drafting session surfaced, then verify the bundle against the real compiler and test suite. If the assumptions are wrong, the generated policy can be technically correct and still be unsafe in production.
👉 Read our full editorial: Claude Code policy authoring brings authorization into the repo