Skip to content

SYSTEM Cited by 1 source

Cloudflare CASB

Cloudflare CASB is Cloudflare's Cloud Access Security Broker — a SaaS Security Posture Management (SSPM) product inside Cloudflare One. With a clientless integration it continuously scans connected SaaS tenants (Microsoft 365, Google Workspace, and others) and surfaces posture risks: overshared files, dormant admin keys/tokens, OAuth apps with excessive permissions. Documented at developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings.

Role

  • Posture visibility (the original product). Detect SaaS misconfigurations "before misconfigurations became incidents."
  • Remediation (the 2026 evolution). Progressed through three stages: passive alarm → manual remediation actions (fix from the dashboard, one human confirmation per finding) → automatic remediation policies (fire on detection, no human in the loop). See patterns/closed-loop-remediation.

CASB policies (automatic remediation)

A CASB policy is a trigger + action rule evaluated the instant a finding is detected:

  • Trigger: vendor + integration (or all integrations for a vendor)
  • a specific finding type.
  • Actions (one or both):
    • Run remediations — first-party actions Cloudflare performs directly against the SaaS integration API (e.g. revoke a public file share). Launch coverage: Microsoft 365 and Google Workspace file/folder finding types; requires upgrading the integration to read/write permissions.
    • Send webhooks — POST the finding to Slack, Microsoft Teams, Jira, ServiceNow, Tines, or any custom HTTP endpoint — the hand-off to a SOC / SOAR platform.

Target: detection → completed remediation ≤ 5 minutes, versus the hours-to-days manual window.

Backend architecture

Built entirely on the dogfooded Cloudflare developer platform (concepts/event-driven-architecture):

  1. Findings engine detects a finding → enqueues an orchestration message to a Cloudflare Queue.
  2. A consumer Worker checks whether any policy configuration matches the incoming finding.
  3. On match, it creates a job and hands it to the remediations pipeline running on Cloudflare Workflows for durable, fault-tolerant execution (concepts/durable-execution) — jobs survive process restarts and retry automatically.
  4. Vendor API rate-limit errors are absorbed as backoff-and-retry inside the Workflow rather than dropped jobs (concepts/exponential-backoff-jitter).

Audit / compliance

  • Admin Activity logs — policy-definition changes (created / edited / disabled, by whom, when).
  • Cloud & SaaS Security policies logs (new) — runtime outcome of each invocation: triggering finding, acted-on file, success/failure, and specific error (e.g. 401 Unauthorized, vendor rate-limit). "The execution log is the proof of fix" for compliance — a finding tied to an automated action and timestamp.

Webhook event envelope

Event type casb.finding_instance.policy_dispatch (schema version: 1) carries finding (id, severity, type_name), asset (file name, vendor, type, url), and DLP + file metadata (access level, download counts, full path, owner). A typed event contract for downstream SOAR consumers.

Seen in

Related

Last updated · 766 distilled / 2,225 read