PUBlished on
April 5, 2023
updated on
November 5, 2025

Secure Your Entire SaaS Estate with Obsidian Extend

NEHA DUGGAL & VIVEK GANTI

Security teams today face the daunting challenge of protecting sensitive business data spread across a vast IT ecosystem that comprises numerous SaaS platforms. Salesforce, Workday, Google Workspace, and Microsoft 365 are just a few of the central platforms used by organizations. But there are also several niche cloud applications deployed across an organization specific to a team, an industry, or custom developed in-house. The security of these smaller applications can be hard to manage and easy to overlook, making it challenging for organizations to assess and monitor security risks.

The granularity and variation of SaaS settings distributed across applications can quickly become overwhelming, leading to security vulnerabilities and increasing the likelihood of data breaches. Organizations need a solution that’s consolidated, automated, and scalable to secure their entire SaaS estate, including both large and niche applications.

And that’s why we are thrilled to launch ExtendTM—our solution to ‘extend’ Obsidian’s benefits to those niche applications that have so far been ignored by other security solutions.

Extend is a module built on top of the Obsidian platform that allows security teams to measure and manage security risk by surfacing application-specific configuration insights, user behavior, and activity across the entire SaaS estate. Unlike other solutions, Obsidian Extend takes a holistic approach to SaaS security, providing a consolidated and comprehensive view of the organization’s SaaS risk exposure, including smaller applications that are often ignored. Extend helps organizations reduce the likelihood of a security incident and continuously maintain adherence to regulatory compliance standards.

Supporting all applications presents a complex engineering problem

Security leaders need a solution that is able to handle a vast and varied number of SaaS applications, including both well-known platforms and custom-built applications. This requires the ability to quickly identify and onboard new applications, as well as provide visibility and control across all applications, regardless of where they are hosted. But not all applications have well documented APIs, or in some cases APIs at all. This often makes integration with them a challenge. Any solution that integrates with other applications must also be able to handle large volumes of data from these APIs, including real-time data, and provide insights and analytics based on that data.

Cover all your bases

When we set out to build a solution, we started with you: the user. Users want a single dashboard to view and monitor user activity and permissions granted across all applications used in the organization. This, without having to install, manage, configure complex SDKs.

With Obsidian Extend, we’ve set out to build the tools you need to do just that.

Get a consolidated and comprehensive view of your organization’s SaaS risk exposure: Instead of sifting through large amounts of raw data gathered from the UI/APIs of various SaaS applications in use or via SIEMs, get a consolidated and comprehensive view of your entire SaaS risk exposure—along with measurable ways to improve your posture.

No agents, no SDK. Start seeing value in 10 minutes: With Extend, you will be able to discover and scan for users, data exposed, and permissions across all federated applications within minutes. Unlike SDKs and agents which are complex to build and deploy, empower your SecOps teams to collaborate with application teams to visualize issues and remediate risks in a timely manner.

Monitor user activity across connected services: From a single interface, understand how your users are behaving in different applications. Use these analytics for robust threat detections that span your entire SaaS estate.

What’s next?

Each day this week, we launched a new product or feature that is designed to help security and governance teams measurably increase the SaaS security and compliance posture of their organizations. While the launch of Obsidian Extend is one giant leap in that direction, we are only getting started.
Security teams also need to effectively respond to SaaS security threats in near real-time and to do so, they need a complete and continuous understanding of application activity—which users and integrations are accessing their environment, what they’re doing, and when they’re behaving in a way that’s risky, unusual, or outright malicious. And they need this for all applications in their environment.

Frequently Asked Questions (FAQs)

What is Obsidian Extend and how does it improve SaaS security?

Obsidian Extend is a specialized module built on the Obsidian Security platform that enables organizations to measure and manage security risk across their entire SaaS estate, including niche and custom-built applications. It provides application-specific configuration insights, monitors user behavior, and consolidates activity data across all connected SaaS applications, offering a holistic view of your risk exposure. This comprehensive coverage helps reduce the likelihood of security incidents and ensures ongoing regulatory compliance. ---

How quickly can my organization start using Obsidian Extend, and what’s required for setup?

Obsidian Extend is designed for rapid deployment and ease of use—there's no need to install agents or develop custom SDK integrations. Most organizations can start discovering, scanning users, and monitoring permissions within 10 minutes of setup. This streamlined process allows security operations teams to see value almost immediately without complex configuration. ---

Can Obsidian Extend integrate with both popular and custom SaaS applications?

Yes, Obsidian Extend is engineered to support a wide range of SaaS applications, from well-known platforms like Salesforce and Google Workspace to niche, industry-specific, or even custom-developed in-house apps. The platform does not rely on the presence of robust APIs, making it capable of integrating and gathering insights even when limited application programming interfaces are available. ---

How does Obsidian Extend help organizations monitor user activity and permissions?

Obsidian Extend provides a unified dashboard where security teams can view and analyze user activity, permissions, and data exposure across all connected SaaS platforms. By consolidating this information, it makes it easier to track risky or unusual behavior across applications and empowers organizations to quickly remediate threats and strengthen overall security posture. ---

You May Also Like

Get Started

Start in minutes and secure your critical SaaS applications with continuous monitoring and data-driven insights.

get a demo