TL;DR: SaaS apps now average more than 100 per organisation, and 75% of organisations plan to adopt DSPM in 2025 as data sprawl, oversharing, and compliance blind spots overwhelm perimeter-based security, according to Cyera Research. The real shift is that access control alone no longer answers where sensitive data lives, who can reach it, or how exposure changes across SaaS systems.
At a glance
What this is: Cyera's guide argues that SaaS data sprawl has outgrown perimeter-based security and that DSPM is now the practical way to restore visibility into where sensitive data lives, who can reach it, and how it moves.
Why it matters: This matters because IAM, NHI, and data security teams must govern access against actual data location and exposure, not just account permissions or app-level trust.
Context
SaaS data security now depends on understanding where sensitive information lives across federated applications, not just who has an account. When data is spread across collaboration tools, CRMs, productivity suites, and developer platforms, traditional perimeter controls lose the visibility needed to manage exposure, compliance, and misuse.
Cyera's guide treats Data Security Posture Management as the missing control layer for this environment. The underlying issue is not simply more cloud usage, but the inability of older security models to track data location, access, sharing, and misconfiguration at SaaS scale.
The article's primary IAM connection is that access governance without data context is incomplete. For teams running human IAM, NHI governance, or agentic AI controls, the question becomes how to make authorisation decisions when the same data can be copied, shared, and re-exposed across multiple SaaS systems.
Key questions
Q: What should security teams do first when SaaS data visibility is limited?
A: Start by mapping where sensitive data lives across the SaaS stack and which identities can reach it. Without that inventory, access reviews and policy enforcement are guessing. Once the major repositories and sharing paths are known, teams can prioritise the highest-risk apps, entitlements, and collaboration channels instead of trying to govern every system equally.
Q: Why does SaaS sprawl create security risk as well as cost pressure?
A: SaaS sprawl increases the number of accounts, roles, permissions, and integrations that must be governed. Each additional application adds another place where access review, approval, and offboarding can fail. The result is not just wasteful spend but a larger, harder-to-audit identity surface across business systems.
Q: What do security teams get wrong about SaaS classification?
A: They often rely on keyword scans or file names, which miss business context and generate false positives. SaaS classification works better when it considers the application, the data type, the surrounding metadata, and how the content is actually used. That reduces noise and makes the resulting policy decisions more credible.
Q: How should security teams govern access across SaaS sprawl?
A: Security teams should govern SaaS sprawl with one inventory, one policy model, and one review process that covers both human and non-human access. The practical goal is to connect application approval, entitlement review, and revocation to business ownership. Without that linkage, access governance becomes a manual cleanup exercise instead of a control system.
Technical breakdown
Why SaaS data sprawl breaks perimeter-based controls
SaaS changes the security boundary because the data no longer sits in one controlled perimeter. Information is distributed across many providers, each with its own sharing model, API surface, and administrative model, so a network-centric control plane cannot tell you where sensitive content actually resides. That creates blind spots around oversharing, misconfiguration, and cross-application movement. In practical terms, the security problem becomes one of posture and visibility, not just access enforcement.
Practical implication: move assessment from network perimeter assumptions to application-level data discovery and exposure review.
How DSPM uses SaaS APIs for discovery and classification
DSPM tools connect directly to SaaS APIs to inventory data, classify sensitive content, and map how information flows across applications. That API-driven model matters because it can observe both structured records and unstructured content without relying on endpoint agents or manual sampling. The article also highlights context-aware classification, which means the system interprets metadata and business use, not just keywords. This is what lets teams distinguish a harmless document from an exposed customer record in a live collaboration environment.
Practical implication: require SaaS-native discovery and context-aware classification before you trust any exposure report.
Why SaaS access governance needs data context
Access governance in SaaS is not just about whether an identity can log in. The harder question is what that identity can reach, copy, share, or expose once inside the application, especially when federated identities span multiple services. Cyera's guide links DSPM with IAM so teams can identify excessive permissions, risky sharing, and policy violations against specific data objects. That is a materially different control view from classic account administration because it binds entitlement decisions to actual data sensitivity and propagation paths.
Practical implication: align entitlement reviews with the sensitivity of the data an identity can reach, not with application access alone.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SaaS visibility is now a governance problem, not just a tooling gap: The core failure in SaaS-heavy environments is that identity teams can approve access without knowing where the protected data actually sits. When data spans Salesforce, Microsoft 365, Google Workspace, Slack, and developer tools, access decisions based only on app permissions no longer describe the real exposure surface. The implication is that governance must move from account-centric control to data-centric observability.
DSPM exposes the limits of shared-responsibility thinking: SaaS providers secure infrastructure, but they do not remove the customer's burden to classify, locate, and constrain sensitive data. That means the customer still owns the exposure created by oversharing, misconfiguration, and uncontrolled collaboration paths. Practitioners should read this as confirmation that cloud adoption increases the need for explicit data posture governance rather than replacing it.
Identity governance and data posture are converging: The article shows that access reviews, sharing controls, and data classification are no longer separable programmes. A permission model that cannot tell whether an identity can reach customer records, health data, or source code is incomplete by design. Teams need a unified view of entitlement, content sensitivity, and cross-app propagation if they want governance to reflect reality.
Context-aware classification is the named capability that matters most: The real shift is not merely finding more files, but understanding which files are sensitive in context and how that context changes as data moves. That creates a more actionable control model for SaaS, because policy can be attached to business meaning rather than filename heuristics. Practitioners should treat classification accuracy as a governance input, not a reporting metric.
From our research library:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
What this signals
SaaS-heavy programmes need to treat data visibility as a standing control objective, because the same identity can move across multiple applications while the underlying exposure changes. The practical shift is from periodic access review toward continuous data posture assessment, especially where collaboration tools and productivity suites amplify sharing.
Context-aware exposure mapping: This is the control gap that matters most in SaaS environments. Once data can be copied, shared, and re-saved across apps, teams need governance that follows the content rather than the container.
For identity programmes, the lesson is straightforward: access governance without data posture management leaves blind spots that neither IAM nor perimeter security can close on its own.
For practitioners
- Inventory SaaS data locations Map where sensitive data resides across collaboration tools, CRM systems, productivity suites, and development platforms before you try to tune access policy.
- Replace keyword-only classification Use context-aware classification that accounts for application metadata, business use, and data flow so you can separate true exposure from false positives.
- Tie access reviews to data sensitivity Review who can reach high-value records, shared folders, chat histories, and developer assets, then compare that access to the actual sensitivity of the content.
- Monitor cross-app propagation Track how a record, file, or message moves from one SaaS application to another so you can spot oversharing and policy violations before they become persistent exposure.
Key takeaways
- SaaS environments have turned data location and sharing into the central security problem, because access decisions alone do not reveal where sensitive information ends up.
- The article positions DSPM as the way to restore visibility across federated applications, classification workflows, and cross-app data movement.
- Identity and data governance now need to operate together, because entitlements are only meaningful when they are evaluated against the sensitivity and propagation of the underlying data.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Federated SaaS access can expose data through identities with broader reach than the business needs. |
| NHI-08 — Environment Isolation | The article highlights cross-app data movement that can blur boundaries between SaaS environments. | |
| Recommendation — Review SaaS entitlements for overprivileged non-human and service identities that can reach sensitive records. Separate SaaS data domains and restrict cross-application exposure paths for sensitive content. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The guide links DSPM to identity governance and excess access across SaaS environments. |
| Recommendation — Align entitlement reviews with sensitive-data location so authorisations reflect real exposure. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | DSPM for SaaS is positioned as a way to map identities to data access across cloud applications. |
| DSP — Data Security and Privacy | The article is fundamentally about locating, classifying, and governing sensitive SaaS data. | |
| Recommendation — Use IAM controls to connect SaaS identities, permissions, and sensitive-data exposure. Apply DSP controls to classify SaaS data and reduce oversharing across applications. | ||
Key terms
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Context-aware classification: Context-aware classification uses surrounding document meaning, not just keywords, to determine what a file or record represents. It reduces false positives and helps security teams distinguish incidental references from content that is genuinely high consequence.
- Cross-application data lineage: Cross-application data lineage is the trace of how a data object moves from one SaaS system to another. It shows whether a record started in one platform, was shared in another, and later persisted elsewhere. That visibility helps teams understand real exposure paths instead of isolated storage points.
- SaaS Access Governance: SaaS access governance is the control of who can reach cloud applications, how that access is exercised, and what conditions trigger review or restriction. It extends beyond sign-in events to include session behaviour, extension interference, and identity misuse after authentication.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org