SYSTEM Cited by 1 source
Cloudflare CASB¶
Cloudflare CASB is Cloudflare's Cloud Access Security Broker — a SaaS Security Posture Management (SSPM) product inside Cloudflare One. With a clientless integration it continuously scans connected SaaS tenants (Microsoft 365, Google Workspace, and others) and surfaces posture risks: overshared files, dormant admin keys/tokens, OAuth apps with excessive permissions. Documented at developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings.
Role¶
- Posture visibility (the original product). Detect SaaS misconfigurations "before misconfigurations became incidents."
- Remediation (the 2026 evolution). Progressed through three stages: passive alarm → manual remediation actions (fix from the dashboard, one human confirmation per finding) → automatic remediation policies (fire on detection, no human in the loop). See patterns/closed-loop-remediation.
CASB policies (automatic remediation)¶
A CASB policy is a trigger + action rule evaluated the instant a finding is detected:
- Trigger: vendor + integration (or all integrations for a vendor)
- a specific finding type.
- Actions (one or both):
- Run remediations — first-party actions Cloudflare performs directly against the SaaS integration API (e.g. revoke a public file share). Launch coverage: Microsoft 365 and Google Workspace file/folder finding types; requires upgrading the integration to read/write permissions.
- Send webhooks — POST the finding to Slack, Microsoft Teams, Jira, ServiceNow, Tines, or any custom HTTP endpoint — the hand-off to a SOC / SOAR platform.
Target: detection → completed remediation ≤ 5 minutes, versus the hours-to-days manual window.
Backend architecture¶
Built entirely on the dogfooded Cloudflare developer platform (concepts/event-driven-architecture):
- Findings engine detects a finding → enqueues an orchestration message to a Cloudflare Queue.
- A consumer Worker checks whether any policy configuration matches the incoming finding.
- On match, it creates a job and hands it to the remediations pipeline running on Cloudflare Workflows for durable, fault-tolerant execution (concepts/durable-execution) — jobs survive process restarts and retry automatically.
- Vendor API rate-limit errors are absorbed as backoff-and-retry inside the Workflow rather than dropped jobs (concepts/exponential-backoff-jitter).
Audit / compliance¶
- Admin Activity logs — policy-definition changes (created / edited / disabled, by whom, when).
- Cloud & SaaS Security policies logs (new) — runtime outcome of
each invocation: triggering finding, acted-on file, success/failure,
and specific error (e.g.
401 Unauthorized, vendor rate-limit). "The execution log is the proof of fix" for compliance — a finding tied to an automated action and timestamp.
Webhook event envelope¶
Event type casb.finding_instance.policy_dispatch (schema version: 1)
carries finding (id, severity, type_name), asset (file name, vendor,
type, url), and DLP + file metadata (access level, download counts,
full path, owner). A typed event contract for downstream SOAR consumers.
Seen in¶
- sources/2026-09-11-cloudflare-introducing-automatic-remediation-policies-with-casb — canonical wiki instance. Automatic remediation policies: the event-driven Queue → Worker-match → Workflow remediation pipeline and the passive→manual→automatic maturity progression.