Set CERBOS_HUB_DEPLOYMENT_ID, CERBOS_HUB_CLIENT_ID, and CERBOS_HUB_CLIENT_SECRET (or the equivalent hub credentials block in the config file) and double-check the deployment ID matches the environment you intend, since a wrong ID loads the wrong policies with no error. Generate client credentials with the Read only role for PDPs that just receive bundles, and save the client secret immediately because it cannot be shown again. Give each PDP a CERBOS_HUB_PDP_ID name so you can tell instances apart on the Hub monitoring page.

Context: Official docs (Service Policy Decision Points): documents a gotcha that trips agents wiring Cerbos to Cerbos Hub. A connected PDP needs three pieces of config: the deployment ID (which deployment's policies to load), plus a client ID and client secret generated from the deployment's Client credentials tab. The client secret is shown once at creation and cannot be recovered, and pointing the PDP at the wrong deployment ID silently loads a different deployment's policies.