TL;DR: CASBs govern sanctioned cloud apps well but miss the long tail of shadow SaaS because every signup happens in the browser, where real-time adoption is visible at login, according to Push Security. The governance gap is no longer discovery alone, but controlling unmanaged identities, session risk, and AI app use before they become persistent access paths.
NHIMG editorial — based on content published by Push Security: CASB / shadow SaaS analysis and browser-based discovery commentary
Questions worth separating out
Q: How should security teams govern shadow IT in SaaS environments?
A: Security teams should govern shadow IT by treating it as unmanaged access, not just unsanctioned software.
Q: Why do proxy-based CASBs miss so much shadow SaaS activity?
A: Proxy-based CASBs often see network traffic after the fact, but shadow SaaS adoption happens at the moment of browser-based sign-up and authentication.
Q: What breaks when SaaS access is not tied to lifecycle controls?
A: Access persists after the business need has ended, which means former employees, stale integrations, and unused permissions can still reach data.
Practitioner guidance
- Map shadow SaaS discovery to identity events Track browser sign-up and first-login events as governance triggers, then route them into inventory, ownership assignment, and review workflows.
- Classify unmanaged AI tools with the same policy as shadow SaaS Use one control model for unsanctioned SaaS and AI apps so data handling, access review, and exception handling are applied consistently.
- Tie browser sessions to offboarding and review Require browser-visible session data for unsanctioned services so access can be revoked or reviewed when ownership changes or risk increases.
What's in the full article
Push Security's full blog post covers the operational detail this post intentionally leaves for the source:
- How browser extension telemetry captures first-login and account-creation events for shadow SaaS and AI tools
- The practical discovery workflow for turning browser observations into SaaS inventory and ownership assignment
- Examples of browser-related incident telemetry and response signals that complement CASB and proxy data
- The implementation trade-offs between browser visibility, sanctioned app controls, and unmanaged session governance
👉 Read Push Security's analysis of shadow SaaS discovery in the browser →
Shadow SaaS in the browser: what IAM teams are missing now?
Explore further
Browser-discovered SaaS is a lifecycle problem, not just a discovery problem. If security only learns about a service after it has been approved through procurement or an API connector, it misses the moment identity is actually created. Real governance starts when the user signs up, authenticates, and begins sharing data. For practitioners, the control question is whether access can be tied back to ownership, policy, and offboarding from the first browser event.
A question worth separating out:
Q: What should IAM teams do when employees keep using unsanctioned AI tools?
A: Provide a sanctioned alternative, then enforce access policy through identity and browser controls rather than relying on awareness campaigns alone. If users can still connect unmanaged AI services to enterprise data, the control design is failing. IAM teams should align acceptable use, OAuth review, and revocation so policy can be enforced in practice.
👉 Read our full editorial: Browser-based shadow SaaS governance is still the identity blind spot