Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SaaS security controls: are vendor APIs and logs enough for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Weak customer-facing security capabilities in SaaS platforms leave security teams unable to review access, inspect logs, or validate configuration, according to Valence Security’s analysis of shared responsibility gaps. That makes vendor-provided APIs, logging, and documentation a governance requirement, not a convenience, because identity review is impossible without usable data.

NHIMG editorial — based on content published by Valence Security: An Open Letter to All SaaS Vendors: Your Customers Need You to Step Up

By the numbers:

Questions worth separating out

Q: What breaks when a SaaS platform does not expose account and configuration APIs?

A: Access governance becomes guesswork.

Q: Why do missing SaaS logs create an identity governance problem?

A: Because access review and incident response both depend on evidence.

Q: How should security teams evaluate a SaaS security vendor for enterprise use?

A: Security teams should evaluate whether the vendor fits existing governance workflows, produces audit-ready evidence, and enforces access controls that limit blast radius.

Practitioner guidance

What's in the full article

Valence Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Specific examples of SaaS platforms that fail to expose account inventories without elevated admin access
  • The draft SaaS Security Capabilities Framework baseline capabilities and how vendors are expected to implement them
  • Why missing logs break access review, investigation, and tenant-level accountability in practice

👉 Read Valence Security's blog on SaaS security capabilities and shared responsibility →

SaaS security controls: are vendor APIs and logs enough for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Customer visibility is now part of the control surface, not an optional integration. SaaS vendors often frame APIs and logs as convenience features, but the governance reality is harsher: without them, customers cannot enumerate identities, validate entitlements, or prove least privilege. That makes the platform’s exposed security surface a shared-responsibility requirement, not a usability preference. Security teams should treat missing tenant visibility as a control deficiency, not an implementation inconvenience.

A few things that frame the scale:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to 2024 Non-Human Identity Security Report.
  • Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how thin operational assurance remains.

A question worth separating out:

Q: What is the difference between SaaS configuration and SaaS governance?

A: SaaS configuration is the on or off state of a feature. SaaS governance is the policy, ownership, monitoring, and cleanup process that determines whether the feature can be used safely. A disabled setting may reduce exposure, but only governance ensures identities, content, and exceptions are managed over time.

👉 Read our full editorial: SaaS security now depends on customer-facing controls and APIs



   
ReplyQuote
Share: