A cloud access security broker (CASB) is the control point between users and cloud services: it reveals which SaaS applications are actually in use, enforces policies for handling data and detects risky configurations in the services themselves.
The trigger is almost always shadow IT: business units use cloud tools the IT department knows nothing about — with company data outside any control. A CASB brings this usage to light and into orderly channels.
How does a CASB work?
Two operating modes complement each other: inline, the CASB sits in the data path — usually integrated with SWG and ZTNA in an SSE platform — and can control actions in real time: block uploads, allow downloads on managed devices, prevent risky shares. Via API it additionally connects directly to the SaaS services and inspects data at rest, shares and configurations there — such as publicly shared documents or dormant admin accounts.
Combined with data loss prevention this creates end-to-end control: who uses which service, with which data, under which conditions.
Typical CASB use cases
- Shadow IT inventory: which cloud services are really used in the company.
- Policies per service and device: company tenant allowed, private instance read-only.
- Detection of risky shares and misconfigurations in SaaS services.
- GDPR-relevant control over where personal data flows into which services.