By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Push SecurityPublished August 13, 2026

TL;DR: CASBs govern sanctioned cloud apps well but miss the long tail of shadow SaaS because every signup happens in the browser, where real-time adoption is visible at login, according to Push Security. The governance gap is no longer discovery alone, but controlling unmanaged identities, session risk, and AI app use before they become persistent access paths.


At a glance

What this is: This is a Push Security blog post arguing that browser telemetry exposes shadow SaaS, AI app use, and unmanaged identity activity that proxy-based CASB approaches often miss.

Why it matters: It matters to IAM and security teams because browser-based adoption creates identity, access, and third-party risk outside traditional app onboarding, inventory, and review workflows.

👉 Read Push Security's analysis of shadow SaaS discovery in the browser


Context

Cloud access security brokers were built for sanctioned applications, but they struggle when employees self-adopt SaaS and AI tools outside IT approval. In those cases, the control problem is not just application visibility, but unmanaged identity behaviour at the browser layer, where sign-up, login, and session use all happen.

That makes this topic relevant to IAM and NHI governance as well as broader cloud security. When the browser becomes the point of identity creation and application access, teams need to think about shadow SaaS, third-party risk, and unmanaged accounts as a single governance problem rather than separate detection challenges.


Key questions

Q: How should security teams govern shadow IT in SaaS environments?

A: Security teams should govern shadow IT by treating it as unmanaged access, not just unsanctioned software. Start with continuous discovery, then map each app to owners, data types, delegated scopes, and revocation paths. The control goal is to reduce hidden access paths before they become business-critical dependencies.

Q: Why do proxy-based CASBs miss so much shadow SaaS activity?

A: Proxy-based CASBs often see network traffic after the fact, but shadow SaaS adoption happens at the moment of browser-based sign-up and authentication. That means the most important identity event can occur before sanctioned discovery tools have a reliable signal. Browser visibility closes that gap by observing the session where access is actually created.

Q: What breaks when SaaS access is not tied to lifecycle controls?

A: Access persists after the business need has ended, which means former employees, stale integrations, and unused permissions can still reach data. That breaks offboarding, weakens auditability, and leaves organisations unable to prove that access was removed when the relationship changed. SaaS governance only works when termination closes the identity path, not just the HR record.

Q: What should IAM teams do when employees keep using unsanctioned AI tools?

A: Provide a sanctioned alternative, then enforce access policy through identity and browser controls rather than relying on awareness campaigns alone. If users can still connect unmanaged AI services to enterprise data, the control design is failing. IAM teams should align acceptable use, OAuth review, and revocation so policy can be enforced in practice.


Technical breakdown

Why browser telemetry changes shadow SaaS discovery

Traditional CASB models rely on API integrations, traffic proxies, or sanctioned connectors to infer application usage. That works when the app is already known, but shadow SaaS appears first at the browser during sign-up and login. Browser telemetry captures the identity event itself, including the moment an employee creates an account, authenticates, and begins using the service. The architectural shift is important because discovery moves from after-the-fact network inference to point-of-use observation.

Practical implication: inventory tools should be evaluated on whether they can observe account creation and login events, not only sanctioned app traffic.

How unmanaged identities create control gaps in SaaS and AI apps

Once employees use unsanctioned SaaS or AI tools, the organisation often loses normal lifecycle control. There may be no authoritative owner, no access review, no offboarding workflow, and no policy enforcement around data sharing or token use. In identity terms, these are unmanaged identities and sessions operating outside governance boundaries. That creates risk even when the application itself is benign, because the account, session, and data path are no longer tied to enterprise policy.

Practical implication: teams should treat unsanctioned logins as identity events requiring lifecycle control, not just as shadow IT inventory.

Why browser-based controls matter for browser-related incidents

Browser telemetry is relevant because many modern identity attacks and risky behaviours terminate in the session, not in the perimeter. Stolen credentials, compromised tokens, and risky browser extensions can all create exposure after authentication has succeeded. For IAM and security teams, that means the browser is increasingly the enforcement point for session trust, especially where SSO exists but the downstream app remains unmanaged. This is also where NHI-style governance concerns emerge, because tokens and API credentials often become the durable access layer to these tools.

Practical implication: align browser controls with session monitoring, token governance, and access policy enforcement for unmanaged services.


Threat narrative

Attacker objective: The objective is to exploit unmanaged browser-based access paths so identity, session, and data controls no longer constrain use of external services.

  1. Entry begins when employees self-adopt shadow SaaS or AI apps through a browser and create accounts outside IT control.
  2. Escalation occurs when credentials, session tokens, or browser-based trust paths are reused without lifecycle governance or visibility.
  3. Impact is the loss of policy control over data movement, third-party exposure, and unmanaged access paths that can persist beyond the original session.

NHI Mgmt Group analysis

Browser-discovered SaaS is a lifecycle problem, not just a discovery problem. If security only learns about a service after it has been approved through procurement or an API connector, it misses the moment identity is actually created. Real governance starts when the user signs up, authenticates, and begins sharing data. For practitioners, the control question is whether access can be tied back to ownership, policy, and offboarding from the first browser event.

Shadow SaaS and shadow AI belong in the same governance conversation. The article correctly shows that blocking tools does not remove demand, it just hides usage. That creates a combined identity and data-risk problem where employees can adopt services faster than governance teams can classify them. Practitioners should treat unmanaged AI apps as an extension of shadow SaaS, with the same expectations for policy, review, and containment.

Browser telemetry creates a practical control plane for unmanaged identities. In many environments, the browser is the only place where SaaS sign-up, login, and session context are visible together. That makes it a useful control point for unmanaged identities, tokens, and risky app adoption. For IAM and security teams, the question is not whether the browser replaces CASB, but whether it fills the blind spots that proxy-only discovery leaves open.

Identity governance now extends beyond owned applications into behavioural access paths. The border between sanctioned and unsanctioned access is increasingly a session boundary, not an application boundary. That means lifecycle, third-party risk, and access policy must account for how employees actually reach tools, not only which tools were approved. Practitioners should align governance with the browser-mediated path, because that is where the real control gap sits.

What this signals

Browser-mediated adoption is becoming a governance boundary. For security programmes, the practical shift is that discovery, ownership, and offboarding can no longer depend solely on sanctioned app inventories. Teams should expect more employee-led adoption of SaaS and AI tools, which means browser-based visibility will increasingly sit alongside IAM and third-party risk processes. In this context, the browser becomes an enforcement surface, not just a user interface.

Unmanaged identities now include tool accounts created outside enterprise workflows. That expands the scope of identity governance beyond classic SSO coverage. The programme implication is to align browser controls, SaaS oversight, and token handling so access does not become durable simply because the app was never formally onboarded.


For practitioners

  • Map shadow SaaS discovery to identity events Track browser sign-up and first-login events as governance triggers, then route them into inventory, ownership assignment, and review workflows.
  • Classify unmanaged AI tools with the same policy as shadow SaaS Use one control model for unsanctioned SaaS and AI apps so data handling, access review, and exception handling are applied consistently.
  • Tie browser sessions to offboarding and review Require browser-visible session data for unsanctioned services so access can be revoked or reviewed when ownership changes or risk increases.
  • Extend token governance to unmanaged services Treat browser-based tokens and embedded credentials as governance objects, not just security telemetry, and include them in lifecycle controls.

Key takeaways

  • Shadow SaaS is an identity governance problem because the account is often created before the security team ever sees the application.
  • Browser telemetry matters because it can expose unmanaged login, session, and token activity that proxy-based controls miss.
  • Teams need a single governance model for shadow SaaS and shadow AI if they want ownership, review, and offboarding to keep pace with adoption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Browser-based shadow SaaS creates access governance gaps at the point of authentication.
NIST SP 800-53 Rev 5AC-2Unmanaged accounts and app sign-ups map to account lifecycle management.
NIST Zero Trust (SP 800-207)Browser-mediated access is a zero trust boundary problem.

Use PR.AC-1 to ensure browser-observed access is tied to authenticated, policy-based ownership.


Key terms

  • Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
  • Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
  • Unmanaged identity: Any identity that can authenticate or act without being fully controlled by the organisation’s standard identity stack. That includes service accounts, API keys, tokens, and some AI agents. The risk is not just visibility loss. It is loss of ownership, lifecycle control, and reliable revocation.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.

What's in the full article

Push Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • How browser extension telemetry captures first-login and account-creation events for shadow SaaS and AI tools
  • The practical discovery workflow for turning browser observations into SaaS inventory and ownership assignment
  • Examples of browser-related incident telemetry and response signals that complement CASB and proxy data
  • The implementation trade-offs between browser visibility, sanctioned app controls, and unmanaged session governance

👉 The full Push Security post covers browser telemetry, shadow AI visibility, and the control gap in proxy-based discovery.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, secrets management, and workload identity. It helps practitioners connect identity controls to the broader security programme they operate every day.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org