Skip to content
REDMAW

SaaS & Identity

Shared responsibility is not shared testing

You cannot pentest your SaaS vendors' platforms. You can, and should, test your side of the boundary.

RedMaw5 min read

Vendor platform security is covered by contracts, attestations and the vendor's own program. The customer side, covering identities, roles, service accounts, grants, integrations, sharing and configuration, is rarely tested adversarially by anyone.

The customer side of the line

  • Standing privileged roles that no longer match any job function
  • Service accounts with credentials that outlive the projects that created them
  • OAuth grants consented once and never reviewed
  • Integrations that bridge two tenants and quietly widen access
  • Sharing settings that make sensitive records reachable without authentication
  1. Compromised Identity
  2. SaaS Platform
  3. Sensitive Customer Records

Each hop validated by successful exploitation

Tags

  • saas
  • identity
  • oauth
  • shared responsibility

Keep going

Related

Further reading

Attack LibrarySaaS & Identity

OAuth Token Abuse

Tokens survive password resets. A stale grant is standing access with no owner watching it.

· 7 min read

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.