Overview
SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.
Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.
For more information, see Reviewing the Security Posture of Your SaaS Applications.
To configure the SaaS Posture integration, you need to:
Configure the required settings in the SaaS application
Create the API connector in the CMA
A CASB license is required for SaaS Posture integrations.
配置 ChatGPT 集成
要配置ChatGPT集成,请创建一个新的密钥。
在Open AI平台中心,确定要输入到CMA的信息。
要配置ChatGPT Admin API密钥:
登录到Open AI平台中心。
在您的Open AI平台中心,导航到设置 > 数据控制。
在数据保留标签页上,启用审计日志并点击保存。
.png?sv=2026-02-06&spr=https&st=2026-10-05T07%3A16%3A38Z&se=2026-10-05T07%3A27%3A38Z&sr=c&sp=r&sig=JBeXhb6hdNIFzpcW7L%2B64mxZsgD4ymcgKcH5hipTTJg%3D)
导航到 设置 > 组织 > 管理密钥。
单击 创建新的管理密钥。
(可选)输入管理密钥的名称并更新项目,然后点击 创建管理密钥。
复制密钥,以便输入到 CMA 中。 这应该输入到访问令牌字段中。
.png?sv=2026-02-06&spr=https&st=2026-10-05T07%3A16%3A38Z&se=2026-10-05T07%3A27%3A38Z&sr=c&sp=r&sig=JBeXhb6hdNIFzpcW7L%2B64mxZsgD4ymcgKcH5hipTTJg%3D)
创建合规性API密钥
合规性API为自定义GPT和工作区级项目提供额外的姿态检查。
在您的Open AI 平台居中,导航到 身份 & 访问 > 凭证 > 管理员密钥。
单击创建新的管理员密钥。
添加以下详细信息:
名称:选择一个密钥名称
工作空间:选择用于 Cato 监控的 ChatGPT 企业工作空间
到期日:永不
权限:选择“全部”
点击提交。
复制密钥以便输入到CMA中。
确认您的工作区ID:导航到 OpenAI平台API设置
确认它与ChatGPT工作区的工作区ID在 https://chatgpt.com/admin/settings 匹配
如果工作区ID不匹配,请联系support@openai.com解决问题后再继续。复制并保存工作区ID,以便输入到CMA中。
步骤 2:在 CMA 中创建 API 连接器
在应用程序需要的集成设置之后,将详情添加到 CMA。
在CMA中创建API连接器:
从导航菜单中,点击资源 > 集成。
点击已配置集成标签页。
点击新建。
新集成面板打开。选择您要添加的SaaS应用程序。
在功能下拉菜单中选择SaaS姿态。
加入在步骤1中创建的详细信息。
访问令牌:您在步骤1中创建的API密钥
管理员令牌:您在步骤2中创建的API密钥
工作区ID:上面识别的ChatGPT企业工作区ID
点击 保存。
该应用在集成应用表格中可见,并具有已连接状态。