CASB
acronymcloudsecurity
Cloud Access Security Broker: the control point between users and SaaS - visibility into which cloud apps are used and policy over what flows into them.
Born to answer 'who is uploading what to which SaaS?'; now usually one letter inside SASE.
A CASB exists because the security perimeter stopped containing the data. Once business records live in software you do not run, the questions of who can reach them, from what device, and what they may do once there are no longer answerable by anything sitting on your network.
The two deployment styles have genuinely different reach. Inline, traffic passes through the broker in real time, which allows blocking as it happens but only for traffic that actually traverses that path. Out-of-band, the broker uses the provider's own API to inspect what is already stored, which finds the file shared publicly last March and can retroactively fix it, but only after the fact. Serious deployments run both, because each covers the other's blind spot.
The problem that justifies the category is shadow IT. Sanctioned applications can be configured properly; the unsanctioned ones people adopted without asking are where data actually leaks, and discovery is often the first genuine value a CASB delivers. Finding that a department has been running its workflow through an unapproved service for two years is uncomfortable, and it is exactly the finding you bought the tool to get.