Cloudflare CASB General Availability: SaaS Security Visibility Without the Manual Grind
Cloudflare has officially announced the general availability of its API-driven Cloud Access Security Broker (CASB), the latest component of the company’s Zero Trust platform. As of today, IT and security administrators can connect, scan, and continuously monitor their third-party SaaS applications for security issues—a process that Cloudflare says takes just a few minutes and a handful of clicks to initiate.

The tooling supports integrations with Google Workspace, Microsoft 365, Slack, and GitHub at launch, covering use cases that range from auditing Google Drive for file oversharing to detecting misconfigurations in Microsoft 365 and uncovering shadow IT via third-party access reviews.
The Visibility Gap in Application Sprawl
Few organizations operate with fewer than ten SaaS applications these days, and many run far more. Services like Google Workspace, Microsoft 365, Slack, Salesforce, and GitHub are now the repositories for a significant portion of a company’s most sensitive operational data. The challenge for security teams is that auditing these platforms manually—tracking down every user, every file, and every sharing permission across every app—is not realistic for the vast majority of businesses.
Cloudflare designed its CASB to solve this scale problem. The product works by tapping into each vendor’s own API to scan for application-specific security issues, surfacing findings on a dashboard that tracks misconfigurations, insecure settings, file-sharing policies, shadow IT, and other practices that deviate from security best practices.
Helping Admins Answer the Tough Questions
Beyond showcasing file-sharing public exposure, administrators can use the dashboard to answer practical security questions they might not otherwise catch. For instance, the platform highlights scenarios like a critical GitHub repository accidentally flipped from Private to Public, or an IT admin working without two-factor authentication enabled.

This type of visibility goes beyond pointing out a single file that was over-shared; it surfaces misconfigurations that could expose an entire organization’s data footprint at once.
Drawing the Line on Shadow IT
Shadow IT discovery gets a newer angle here. While network-based tools such as Cloudflare Gateway can catch traffic anomalies, they are limited in what they can see. CASB offers a complementary view: it audits the authorization layer built into so-called Sign in with Google flows, providing an organized list of which third-party apps have been granted access to protected resources—something network observation alone cannot accomplish.

Completing the Zero Trust Picture
Cloudflare positions CASB not as a standalone tool but as coverage for a missing area in the Zero Trust model. Where Cloudflare Access and Gateway zero in on control and traffic visibility, and Browser Isolation and in-line DLP mitigate web-delivered threats, CASB focuses on the data at rest: which sensitive files exist, who has access to them, and what the security settings around them look like.
Getting Started
According to Cloudflare, the early beta results underscore the necessity of this kind of automation. Across beta users, CASB detected more than five million potential security issues; some organizations saw thousands of files flagged as having sharing settings that warranted review.
From a setup standpoint, CASB requires little more than a few clicks per application before findings begin populating on the service’s home page. Organizations interested in trying it can sign up for a free Zero Trust account (which includes 50 free seats) and request access via the product page. Cloudflare is also soliciting feedback via its suggestion form for which SaaS applications to prioritize with new integrations next.



