SaaS Security Posture Management (SSPM) is the practice of continuously scanning cloud SaaS tenants (Salesforce, Google Workspace, Slack, HR/CRM tools, and so on) for risky configuration drift — the settings that quietly slip from "secure by default" to "exposed" as admins, integrations and employees change over time.
- Public share links — a file or folder set to "anyone with the link" instead of restricted access; the single most common real-world SaaS data leak.
- MFA disabled — an account or app-wide policy that allows password-only sign-in, removing the strongest defence against credential stuffing and phishing.
- Over-privileged OAuth apps — a third-party integration granted broad scopes (read/write everything) when it only needs narrow, read-only access — a classic SaaS supply-chain risk.
- Orphaned accounts — a former employee's login that still has active permissions because offboarding never revoked it.
Run the scan to sweep every app in the portfolio, then resolve each finding with Fix — the security score (0–100) recomputes live from the remaining open, weighted-by-severity findings.