01Introduction
Much of a company's data and access now lives in SaaS: the identity provider, source control, chat and CRM. Each has hundreds of security settings, and each is configured by a different team.
02What is SSPM?
SaaS security posture management (SSPM) is a category of tools that connect to SaaS applications through their APIs, assess security settings and third-party integrations, and flag risky configurations, over-privileged users and connected apps.
It completes the posture family alongside CSPM for cloud infrastructure and DSPM for data. It sits on the customer side of the shared responsibility model for SaaS.
03How SSPM works
SSPM applies the CSPM model to business applications.
- 1.
Connect
Authorize read access to apps such as Okta, Google Workspace, Microsoft 365, GitHub, Slack and Salesforce.
- 2.
Assess settings
Check MFA enforcement, session policies, sharing defaults, admin counts and audit logging.
- 3.
Review integrations
Inventory OAuth apps and tokens connected to each platform and the scopes they hold.
- 4.
Remediate
Guide or automate fixes and track drift over time.
04Threats and risks
SaaS risk is mostly configuration and connected access.
Weak identity settings
MFA gaps and long sessions in the identity provider that guards everything else.
Over-scoped OAuth apps
Third-party integrations with read access to all mail, repositories or files.
Public sharing
Documents, channels or repositories exposed to anyone with the link.
Leaked tokens
SaaS API tokens committed to code. See secrets detection.
05How Parameter helps
Parameter doesn't replace an SSPM. It covers where SaaS access turns into cloud and code risk.
Source control exposure
Sentinel catches tokens and keys committed to GitHub before they're abused.
Identity to cloud
Cloud Security traces how federated SaaS identities map into cloud roles and what they reach.
Build pipeline risk
Supply Chain covers the packages and actions your repositories pull in.

