A cloud posture tool will tell you an S3 bucket is public.
It will say nothing about the SharePoint site shared with 'anyone with the link', the Microsoft 365 global admin without MFA, the stale Google Workspace guest account from a contractor who left in 2023, or the Snowflake service account holding ACCOUNTADMIN. These are the accounts attackers actually compromise — and on most platforms they are simply invisible.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Each SaaS platform is connected through a dedicated read-only connector — Microsoft Graph with OAuth 2.0, Google Admin SDK with service-account impersonation, Snowflake private-key JWT, GitHub and GitLab app tokens.
- 2
Discovery enumerates tenants, users, admin roles, sharing settings, audit-log configuration, and data-exposure surfaces without any agent or browser extension.
- 3
Findings are evaluated against 433 CIS rules — Microsoft 365 (130), GitLab (122), Google Workspace (89), Snowflake (39), SharePoint (37) and Dynamics 365 (16).
- 4
SaaS findings write into the same findings model as cloud findings, so a SaaS identity risk and a cloud identity risk appear in one queue rather than two consoles.
- 5
Because identity is shared, an Okta or Entra ID account that federates into AWS is traced through to the cloud permissions it unlocks on the attack-path graph.
Specific outputs, measurable outcomes
SaaS Security (SSPM) in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see SaaS Security (SSPM) in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.