← Back to Cloudflare One
CASB

Cloud Access Security Broker

Multimode CASB — inline + API + SaaS posture in one engine.

✓ Guided dashboard demo
Mental model

How does CASB discover SaaS use, assess posture, and protect data at rest?

Cloudflare combines near-real-time inline discovery through Gateway with periodic, read-only API integrations for SaaS posture and content findings.

Discover inlineGateway recognizes SaaS traffic, adds risk context, and surfaces Shadow IT without requiring an API integration.
Assess by APIRead-only integrations periodically inspect supported SaaS settings and content for posture or data risks.
Act through policyTeams remediate findings, approve or reject apps, and hand enforcement to Gateway or DLP controls.
Configured proof

One account shows both CASB modes: API posture and inline Shadow IT.

These are resources visible in the demo account today. API findings are periodic; Gateway discovery is near real time.

Configured proof GH

GitHub posture finding

rnobre-demo-org

organization-user-2FA-disabled

High severityActiveRead-only API

The integration detects that an organization user does not have two-factor authentication enabled. The remediation happens in GitHub, then the next CASB scan validates the posture.

Configured proof AI

ChatGPT Shadow IT

Gateway + App Library

ChatGPT traffic is recognized with application risk context, marked Unapproved, and handed to the configured Block ChatGPT Gateway policy.

Inline discoveryUnapprovedPolicy handoff

Approval status is governance metadata. Gateway policy performs the actual enforcement.

Two modes, one control plane

Inline discovery and API posture take different paths to action.

The upper lane recognizes SaaS traffic as it crosses Gateway. The lower lane periodically inspects supported SaaS through a read-only API integration. Keeping the lanes separate makes their timing and enforcement boundaries explicit.

The inline lane is near real time. API posture scans are periodic, typically every 24–48 hours.
Illustrative breadth

Where the same model can extend next.

The examples below explain product breadth; they are not configured proofs in this demo account.

AIIllustrative

AI SaaS integrations

Connect supported AI services to inspect posture and content at rest.

▤Illustrative

Public sensitive files

Find overshared files and combine content findings with DLP profiles.

☁Illustrative

Cloudy summaries

Summarize findings to accelerate investigation and remediation.

↗Illustrative

Finding webhooks

Route new findings into security operations and ticketing workflows.

Configured walkthrough

Explore both CASB modes

  1. Confirm the rnobre-demo-org integration is healthy in Cloud & SaaS integrations.
  2. Review the active GitHub 2FA finding, source remediation, and periodic verification.
  3. Explore ChatGPT Shadow IT context in App Library or Gateway HTTP logs.
  4. Compare the Unapproved governance state with the Block ChatGPT enforcement policy.
  5. Distinguish configured evidence from the illustrative expansion paths.
How to interpret the results

Keep the modes precise

  • API posture scans are periodic and out of band.
  • Gateway Shadow IT discovery is inline and near real time.
  • Marking an app Unapproved does not block it by itself.
  • CASB API integrations cover supported SaaS apps, not arbitrary internal applications.
Open in dashboard

The integrations, findings, app context, and policy behind the proofs.

Cloud & SaaS integrations ↗Confirm the GitHub integration and scan healthCASB findings ↗Review active posture and content findingsApp Library ↗Review SaaS risk and approval contextGateway HTTP policies ↗Open the Block ChatGPT enforcement rule
Built by Rodrigo Nobre with Cloudflare Workers