Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security Why can VPNs be a poor fit for…
Cyber Security

Why can VPNs be a poor fit for SaaS visibility requirements?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 2, 2026 Domain: Cyber Security

VPNs move traffic but do not automatically create usable, user-level evidence of what happened inside cloud applications. They can add friction without improving audit quality. For SaaS-heavy operations, organisations usually need application and browser telemetry tied back to identity, rather than relying on transport-layer visibility alone.

Why This Matters for Security Teams

VPNs are often treated as a visibility control, but for SaaS estates that assumption is incomplete. A VPN can confirm that a device or user reached the network boundary, yet it rarely explains what the user did inside the application, which records were accessed, or whether the activity was legitimate. That gap matters for investigations, insider risk, and audit readiness. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls emphasises traceable logging and accountability, but those outcomes depend on telemetry from the application layer, not transport alone.

Security teams also get caught by the false comfort of “all traffic went through the VPN,” which can hide the lack of session detail, user attribution, and event correlation. In SaaS environments, identity is the control plane, and transport controls only cover part of the picture. Without browser, IdP, and application logs, teams can miss privilege misuse, token abuse, and data exposure until after an incident response has already begun. In practice, many security teams encounter the limits of VPN visibility only after a SaaS data loss review has already forced them to reconstruct events from incomplete logs.

How It Works in Practice

For saas visibility, the operational question is not whether a connection traversed a tunnel, but whether the organisation can reconstruct who did what, from where, on which device, and under which authentication context. That usually requires combining IdP sign-in logs, SaaS audit trails, browser telemetry, and sometimes endpoint signals. The goal is evidentiary richness, not just path control. CISA’s logging and monitoring guidance, together with NIST-aligned control objectives, supports this model because correlation across sources is what turns raw events into defensible records.

In practice, a stronger SaaS visibility stack tends to include:

  • Identity provider logs for authentication, MFA outcomes, and conditional access decisions.
  • SaaS audit logs for file access, sharing, admin actions, and policy changes.
  • Endpoint or browser telemetry to show session context, suspicious extensions, or download activity.
  • Centralised correlation in SIEM or SOAR so analysts can reconstruct a timeline.

This is where identity becomes central. If access is mediated through SSO, the evidence chain can be tied to the human user or NHI that obtained the session, including service accounts, automation tokens, or delegated admin activity. For NHI-heavy SaaS workflows, strong secret governance and short-lived credentials matter as much as network route enforcement. CISA’s logging and monitoring guidance is useful here because it reinforces the need to collect events at the systems that actually observe the action.

VPNs still have a role when the SaaS application is fronted by private connectivity, or when there is a requirement to constrain source IP ranges. But that is a containment measure, not a visibility strategy. These controls tend to break down when users access SaaS directly from unmanaged devices or when the organisation relies on encrypted browser sessions that never expose useful application context to the VPN.

Common Variations and Edge Cases

Tighter network control often increases user friction and operational overhead, requiring organisations to balance access simplicity against forensic quality. That tradeoff is especially visible in remote work, contractor access, and multinational environments where SaaS vendors support direct internet access by design. In those cases, adding VPN enforcement may improve perimeter consistency but still fail to produce the audit trail security teams actually need.

Best practice is evolving toward identity-centric visibility, but there is no universal standard for exactly how much browser-level telemetry is necessary. Some organisations can rely on IdP plus SaaS logs alone, while others need endpoint detection, CASB-style controls, or browser isolation to close the evidence gap. The right mix depends on data sensitivity, regulatory exposure, and whether the environment is human-user led or automation heavy.

This is also where SaaS and NHI governance intersect. If an application workflow is driven by bots, API clients, or agentic systems, a VPN will not distinguish one automation path from another. That makes secrets management, token scoping, and workload identity more important than tunnel presence. For broader identity assurance, NIST SP 800-63 Digital Identity Guidelines helps frame authentication and session assurance, while NIST control baselines remain the practical reference for logging depth. In regulated environments, the visibility requirement may need to satisfy audit and retention expectations under NIST Cybersecurity Framework 2.0 alongside internal policy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01VPN visibility gaps are a risk-management issue tied to telemetry quality.
NIST SP 800-63SP 800-63BIdentity assurance matters because SaaS evidence must tie actions to an authenticated subject.
NIST AI RMFAI-assisted SaaS and automation need governance over identity, logs, and accountability.
OWASP Non-Human Identity Top 10Non-human identities in SaaS can bypass human-centric VPN assumptions.

Treat SaaS observability as a risk decision and define what evidence must be retained and reviewed.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org