Melissa Ruzzi, senior director of AI at AppOmni, notes that different departments within a company may use different SaaS applications, leading to potentially hundreds of different tools, each with unique user-defined configurations. This variety in configuration is where the security of SaaS applications lies.
See also: Supply chain attacks: Why attacks via third-party partners are increasing

Securing software as a service (SaaS) applications is challenging because typical cybersecurity controls are not designed for SaaS. The difficulty arises from the fact that the software is not owned by the user and typically runs on someone else’s infrastructure. Typical cybersecurity products are designed to work on software that is owned by the user and hosted on their infrastructure.
SaaS providers strive to maintain security within their applications, but they cannot control how those applications are used. Usage varies between users and is essentially determined by how the application is configured. This configuration represents the only inherent security available to SaaS users, and misconfiguration is the primary and most common source of insecurity.
The SaaS threat landscape is vast and ever-expanding, with more users and departments adopting additional SaaS applications. Often, these applications are downloaded and run locally without the knowledge of IT and security departments, creating shadow SaaS that can include shadow AI.
AppOmni is a cybersecurity company that offers expert assistance through its SaaS Security Posture Management (SSPM) platform, which enhances visibility, control, and reduces the risk of compromise from SaaS applications. However, the growing size and complexity of the threat surface makes this task increasingly difficult.
See also: Palo Alto: Prisma AIRS upgrade for AI agent discovery

To address these challenges, security companies, including AppOmni, are leveraging AI to enhance the efficiency and effectiveness of their services. In December 2023, AppOmni introduced AskOmni, an AI-powered SSPM assistant designed to answer users’ natural language questions about the platform.
On May 26, 2026, AppOmni launched Marlin AI, which aims to provide autonomy in addressing issues identified by the platform. AskOmni and Marlin work together, with Marlin investigating and analyzing issues while AskOmni answers users' questions about Marlin's actions.
Marlin examines the various configurations used by different users across SaaS applications used by different companies. Its framework is informed by years of SaaS experience accumulated by AppOmni, allowing it to automatically detect potentially worrisome configuration settings. For example, if it detects a multi-factor authentication (MFA) setting that is not enabled, it raises a flag.
However, the severity of this issue depends on additional factors, such as unusual activity from specific IP addresses or VPNs. Traditionally, this analysis is performed manually by human analysts, which is time-consuming. Marlin automates this process and goes a step further by suggesting remedial actions rather than simply indicating potential vulnerabilities.
See also: Reco targets AI agents' blind spots with new security feature

A growing question with new AI solutions is whether they can move from error detection to automatic error correction. For Marlin, the answer is subtle. While actions within the AppOmni platform can be automated, the response may differ when the required action extends beyond the platform. For example, if a misconfiguration is found in Salesforce, the approach may differ.
