From Finding to Fix: Tying CASB Alerts to Gateway Policies
In June 2022, Cloudflare outlined a plan to connect two of its Zero Trust products: Cloudflare Gateway, its Secure Web Gateway (SWG), and CASB, its API-driven scanner for SaaS applications. The goal was straightforward: when CASB identifies a problem in apps like Google Workspace or Microsoft 365, admins should be able to quickly translate that finding into an action that stops the risky behavior at the network level.
That integration is now available. The practical effect is that generating a fine-grained HTTP policy in Gateway from a CASB discovery takes roughly three clicks. The policy is prefilled based on the specific issue found, which lets admins respond without manually constructing filter rules or hunting through logs.
Two Tools, One Workflow
CASB connects to and continuously monitors sanctioned SaaS applications for security issues such as exposed files, misconfigurations, and shadow IT. Gateway, meanwhile, sits between endpoint devices and the internet, letting teams control outbound traffic—blocking categories like gambling or social media, for example—from the Zero Trust dashboard.
Previously, IT teams could scan for issues and even see them a security dashboard, but acting on them meant a manual, reactive process. The new feature closes that loop: a CASB Finding becomes the foundation for an automated Gateway policy.
Three Use Cases for Cross-Product Policies
Stopping Personal Cloud Uploads
A common concern that surfaced during CASB beta testing was employees pushing corporate files into their personal Google Drive or OneDrive storage. Using a CASB finding, an admin can now create a Gateway policy that blocks uploads to any tenant other than the one the company uses. This prevents data exfiltration without breaking access to approved corporate storage.
Restricting Repeat Oversharers
CASB can flag users who habitually overshare files in corporate Google or Microsoft tenants—for instance, sharing with public links or external addresses. Once such a user is identified, an admin can generate a policy that blocks that specific person from further upload and download activity until the issue is reviewed and resolved. The enforcement is targeted to the user, not the entire organization.
Enforcing Approved App Allowlists
Shadow IT use cases get a similar treatment. A policy created from a CASB finding can restrict upload and download events exclusively to the SaaS apps the organization actually uses. If the business standard is Box, for example, a policy can block activity to all other file-sharing services. This confines corporate data to approved destinations without requiring broad blocking of internet access.
A Single Platform Approach
Cloudflare positions this as an example of its Zero Trust platform gaining strength from product integration rather than standalone features. The company notes that the combination of CASB's scanning capabilities and Gateway's enforcement tools is intended to give security teams more than just visibility into issues—it offers a mechanism for remediation with minimal administrative effort.



