# SaaS Integration Topology Produces Ungovernable Transitive Exposure

- **Artifact ID:** CHQ-SM-2026-009
- **Canonical source ID:** CHQ-ANRM-2026-007
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/memoranda/chq-sm-2026-009
- **Machine-record SHA-256:** `5d7b9ba829786cbdb2ee377851377b8b3a4a1d32e01648be537d8d8b4c729192`

## Complete structured record

```json
{
  "id": "CHQ-ANRM-2026-007",
  "aliases": [
    "CHQ-SM-2026-009"
  ],
  "title": "SaaS Integration Topology Produces Ungovernable Transitive Exposure",
  "descriptor": "SaaS Integration Topology Produces Ungovernable Transitive Exposure",
  "issued": "2026-03-13",
  "classification": "Analytical Research / Non-Advisory",
  "status": "ISSUED",
  "version": "v1.0",
  "memo_type": "ANRM",
  "authority_level": "ANALYTICAL",
  "inherits_from": "CHQ-ANRM-2026-001, CHQ-ANRM-2026-006",
  "related_artifacts": [
    "CHQ-ANRM-2026-002"
  ],
  "citable_assertion": "Bilateral SaaS integration authorization produces transitive exposure across organizational and platform boundaries that no individual participant can enumerate, observe, or govern. The exposure graph is an emergent property of the integration topology, not an artifact of any single authorization decision.",
  "purpose": "This memo records recognition of a structural condition in which bilateral SaaS integration authorization decisions produce emergent multi-party exposure that exceeds the governance perimeter of any individual authorizing organization. It does not provide recommendations, prescribe controls, or evaluate organizational decisions. Its sole function is to document recognition of the condition as of the issuance date.",
  "statement": "SaaS-to-SaaS integrations are authorized bilaterally: one organization grants one platform access to another platform. The authorization decision assumes that exposure is bounded by those two parties. This assumption is structurally false.\n\nIn August 2025, the compromise of Salesloft's Drift integration demonstrated that a single OAuth token layer created transitive exposure across organizational and platform boundaries. Attackers (tracked as UNC6395 by Google Threat Intelligence Group) compromised OAuth tokens that Drift used to connect to customers' Salesforce instances. Those tokens bypassed multi-factor authentication, persisted without expiration, and provided API-level access to Salesforce environments across multiple organizations — none of which had authorized cross-organizational access.\n\nThe exposure did not stop at Salesforce. Attackers used automated SOQL queries to harvest credentials embedded in support cases and customer records, including AWS access keys, Snowflake tokens, VPN credentials, and API secrets for Slack, Google Workspace, Azure, and OpenAI. A single integration compromise cascaded into an exposure graph spanning platforms, cloud providers, and organizational boundaries that no party had authorized or could observe.\n\nMandiant's investigation confirmed the attacker was active from March through August 2025. Detection occurred on August 19. Token revocation began August 20. A subsequent compromise through Gainsight in November 2025 demonstrated the same structural pattern through a different integration vector. The IBM X-Force Threat Intelligence Index 2026 reports that major supply chain and third-party breaches quadrupled over the preceding five years.\n\nThe condition is independent of any specific vendor, integration, or platform. It arises from the interaction between three properties: OAuth tokens create non-human identities that bypass interactive authentication controls; integration authorization is bilateral while exposure propagation is transitive; and no participant in the integration graph can enumerate, observe, or revoke the full token chain. The exposure graph is an emergent property of the topology, not a governed artifact.\n\nThis memo records recognition that SaaS integration topology produces exposure conditions that are structurally ungovernable by any individual participant.",
  "observability": "The described condition was identifiable through publicly available information, including: incident disclosures by affected organizations (Cloudflare, Zscaler, Salesloft), forensic reporting by Mandiant and Google Threat Intelligence Group, FBI Cybersecurity Advisory CSA-2025-250912, vendor post-incident statements, and independent security research. No proprietary, confidential, or non-public information was required to identify this condition.",
  "boundary": "This memo does not assess the adequacy of any organization's vendor risk management program, evaluate OAuth token governance practices, attribute fault, negligence, or responsibility, or recommend controls, architectures, or mitigations. Recognition of the condition does not imply failure to act, nor does absence of reference imply lack of awareness.",
  "reliance_language": "This memo may be referenced as an external indication that the described structural condition in SaaS integration topology was publicly observable as of the issuance date. It may be cited to establish contemporaneous recognition of the condition's existence without asserting causality, obligation, or prescriptive duty.",
  "reliance_boundary": "This document records recognition only. It does not constitute advice, instruction, or an evaluation of reasonableness.",
  "revision_history": "v1.0 (March 13, 2026): Initial issuance",
  "scope": "This memorandum examines the structural condition in which bilateral SaaS integration authorization decisions produce emergent multi-party exposure that exceeds the governance perimeter of any individual authorizing organization. The analysis is bounded by the interaction between OAuth token persistence, transitive trust propagation, and the absence of cross-organizational observability across integration graphs. The primary exhibit is the Salesloft Drift/Salesforce compromise (UNC6395, August 2025) and the subsequent Gainsight incident (November 2025). This memo does not assess the adequacy of any organization's vendor risk management program, evaluate OAuth token governance practices, attribute fault or responsibility, or recommend controls, architectures, or mitigations. Recognition of the condition does not imply failure to act, nor does absence of reference imply lack of awareness."
}
```
