Cloudflare CASB: Roadmap Updates and Beta Access
Last month Cloudflare launched its API-driven Cloud Access Security Broker (CASB), acquired through Vectrix, as part of the Zero Trust platform. The service scans SaaS applications for security issues spanning unauthorized user access, file exposure, misconfigurations, and shadow IT. Now, based on customer feedback, Cloudflare has shared what's next for the product and opened sign-ups for its beta program.
What's on the CASB Roadmap
Cloudflare's vision for CASB is to give IT and security teams a single, easy-to-use console for protecting data and users across all their SaaS tools. The goal is for admins to go from creating a Zero Trust account to having meaningful protection in minutes. Three upcoming features aim to address the time-consuming work of finding, understanding, and resolving security issues.
New integrations
Integrations are the method CASB uses to connect to SaaS applications via API for scanning and management. While the flow varies by third-party app, it generally follows OAuth 2.0. Cloudflare says it will keep setup simple so integrations can be completed in minutes.
The priority is protecting critical assets first. Google Workspace and GitHub integrations will be available in the beta, followed by Zoom, Slack, and Okta, with Microsoft 365 and Salesforce targeted later this year. Cloudflare plans to work closely with customers to determine which applications to integrate with next.
SaaS asset management
Tracking digital assets—users, data, folders, repos, meetings, calendars, files, settings, recordings—across multiple services is a challenge that spreadsheets handle poorly. CASB asset management centralizes visibility into data settings and user activity in one dashboard, so answering questions like "did we disable this user's account across all six services?" no longer requires logging into each one separately.
Remediation guides and automated workflows
The detect, prevent, fix model extends to detailed SaaS remediation guides that help IT admins assign issues to the right teams with context. For urgent actions, automated workflows enable one-click fixes—removing sharing permissions from a file in OneDrive, for example—from anywhere.
Cloudflare Gateway plus CASB
Combining Gateway with CASB addresses shadow IT directly. An unauthorized SaaS app detected in Gateway's shadow IT report can be converted from an unsanctioned service to a secure, integrated one in a few clicks.
What the Beta Includes
The CASB beta provides access to popular integrations like Google Workspace on day one, plus direct access to Cloudflare's product team to influence prioritization of future integrations and features. Beta invitations will go out in waves starting early next month. Access is available via the sign-up page on Cloudflare's site; those not yet ready for CASB can start with the Zero Trust platform directly.



