What Is CASB (Cloud Access Security Broker)?
A Cloud Access Security Broker (CASB) is a security control point—deployed as a proxy, API integration, or gateway—that sits between an organization's users and the cloud services they use, enforcing security policies on that traffic. CASBs give IT and security teams visibility into which SaaS and cloud applications are in use (including unsanctioned ones), apply data loss prevention rules, detect anomalous access, and enforce authentication and encryption requirements. Originally built to address 'shadow IT'—employees adopting cloud apps without approval—CASBs typically operate through four pillars: visibility, data security, threat protection, and compliance. They can inspect API calls to sanctioned SaaS platforms or intercept web traffic in real time, giving organizations a consistent policy layer across many different cloud providers.
Why It Matters
CASBs were designed around human users logging into SaaS applications through a browser—but a growing share of cloud access today comes from machines: API integrations, OAuth-connected third-party apps, automation scripts, and AI agents that call SaaS APIs directly, bypassing the browser session a CASB inspects. An OAuth token granted to a connected app can read or write data in Salesforce, Google Workspace, or Microsoft 365 indefinitely, often with far broader scope than the CASB's session-based controls were built to govern. Non-human identities can outnumber human employees 45 to 1, and many of those NHIs connect to SaaS platforms directly via API keys and tokens that never pass through a CASB's inspection point. OWASP reports that 80% of identity breaches involve a non-human identity—a growing share of it through exactly this kind of API-level SaaS access that traditional CASB visibility does not cover.
How Cydenti Helps
Cydenti focuses on the machine-to-SaaS connections a CASB typically can't see: the OAuth tokens, API keys, and connected-app grants that let non-human identities read and write data in SaaS platforms outside any browser session. By continuously inventorying these tokens and their scopes, correlating them with the applications and workflows that created them, and flagging excessive or stale grants, Cydenti extends SaaS governance to cover the identity layer CASBs were never designed to monitor.
Explore →Frequently Asked Questions
Is CASB the same as CIEM?
No. CASB governs access to SaaS applications (Salesforce, Microsoft 365, Google Workspace), while CIEM governs entitlements within cloud infrastructure providers (AWS, Azure, GCP). Both address permission and access risk but at different layers—CASB at the SaaS application boundary, CIEM within cloud infrastructure IAM.
Can a CASB detect a leaked API key or OAuth token?
Generally not on its own. CASBs are built to inspect user sessions and API calls to sanctioned apps, not to inventory or monitor the lifecycle of API keys and OAuth tokens issued to non-human identities, which is why many organizations add dedicated non-human identity security to cover that gap.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h