7 Questions for Your Obsidian Security Evaluation
.jpeg)
Six months after signing is a bad time to learn what a tool doesn't watch. Every platform in this market draws a coverage boundary somewhere, and that boundary almost never appears on the datasheet. An Obsidian Security evaluation is worth running carefully, and running it carefully means finding that boundary during the eval instead of during an audit.
Obsidian Security is a serious product with serious backing. They raised $85 million in a Series D at a $1.1 billion valuation in August 2026, from Menlo Ventures, Norwest, Greylock Partners, IVP, GV, Wing, and lead investor Crescent Cove Advisors. Snowflake, T-Mobile, Pure Storage, Trade Me, Upwork, and BigCommerce appear as customers on their site. If you're running a large SaaS estate and you want to know what's happening inside it, they belong on your list.
These seven questions are the ones we'd ask if we were the buyer. Ask them of Obsidian, of every other vendor in the eval, and of us.
Where Obsidian Security is a good fit
Be honest with yourself about the problem you're solving. If your pain is misconfigured SaaS tenants, OAuth grants nobody reviewed, over-privileged accounts in Salesforce or ServiceNow, account takeover attempts against your identity provider, or AI agents wired into Bedrock and Copilot with permissions nobody audited, Obsidian is built for exactly that. They describe SSPM, SaaS ITDR, shadow SaaS discovery, OAuth risk, supply chain security, and audit automation, plus an AI line covering AI-SPM, MCP security, agent visibility, and agent governance.
They also describe a Knowledge Graph correlating identity and activity across SaaS apps, browsers, and identity providers, and they publish scale figures: over 1.5 billion daily events processed and more than 59 million unique identities mapped. That's a real capability set. The questions below are about its edges.
1. What is the deployment model, and what has to be true before it works?
Why it matters. Deployment model determines your time to value more than any feature on the datasheet. API-connected platforms are fast to stand up but only see what the API exposes. Agent-based tools see the device but need a rollout. Proxy-based tools see traffic but need you to route traffic to them. Each has a different failure mode, and the failure mode is what you'll live with.
What good looks like. A clear answer to "what can you tell me on day one, and what requires work from my team first?" Ask how many apps have to be connected before the dashboard is useful. Ask whether anything needs to touch endpoints, and if so, who owns that rollout.
From the other end of the spectrum: dope.security is agent-based. A lightweight agent (dope.endpoint) goes on the device, traffic flies direct to the internet with no backhaul, and SSL inspection happens on-device. Outreach Health, a healthcare organization of 5,000 to 10,000 people across 34 offices in Texas, Arizona, and Massachusetts, replaced a legacy SWG and had 99% of devices secured within one week. Web access IT tickets fell 70% in 90 days, and policy changes went from days to minutes. In their words: "We didn't need a six-page deployment manual anymore. We pushed the agent, confirmed policies, and we were done." Different model, different tradeoffs. Know which one you're buying.
2. Which data sources does it need before it can tell you anything?
Why it matters. Every SaaS security platform is a function of its inputs. Obsidian names their inputs plainly: third-party app and AI configs, user activity, real-world threat signals, and browser telemetry. That's a good, honest list. It also tells you exactly where the visibility stops.
What good looks like. Get the vendor to draw the boundary for you. Obsidian publishes 200+ enterprise application integrations, including Microsoft 365, Google Workspace, Salesforce, ServiceNow, GitHub, Snowflake, Databricks, and Workday, plus AI platforms including Amazon Bedrock, Microsoft Foundry, Anthropic Claude, Google Vertex AI, OpenAI, and Microsoft Copilot.
Now take your own app inventory and mark the ones that aren't on the list. Then mark the destinations that aren't apps at all: file transfer sites, personal webmail, a random vendor portal your finance team uses once a quarter. Those aren't integrations and never will be. Ask the vendor what they see there. It's a scope line, not a defect.
3. How much of the picture depends on a connected app?
Why it matters. Obsidian's visibility comes from connected applications and telemetry, which means the picture is strongest where an app is connected. That's true of every API-first platform, and it's worth quantifying during a proof of concept. The ratio tells you how the product will behave in year two, when your app estate has changed.
What good looks like. Ask three specific things. First, which of your applications will be connected on day one, and which are not on the integration list at all. Second, what share of the findings in your proof of concept traced back to a connected app versus another input, because that ratio is your coverage curve. Third, what the console shows you about its own coverage: can an analyst open it and see which parts of the estate the platform is currently watching?
That third one is a fair question for any vendor, us included. Every tool has a coverage map, and a buyer should be able to see it. Ask for a walkthrough of the partial-coverage state, not just the fully connected demo tenant.
4. What happens to traffic that never touches a connected SaaS app?
Why it matters. This is the biggest scope question in the entire evaluation, and it's the one most likely to get skipped. A design file dropped into a partner's upload portal never touches Microsoft 365. A quarterly export synced to a personal Dropbox account never appears in a connected app's audit log. A paste into a personal ChatGPT account never touches your tenant. If the platform's view is the SaaS layer, those paths are outside it.
What good looks like. Obsidian doesn't market itself as a secure web gateway or an on-device proxy, and they shouldn't be criticized for that. So the right question isn't "can you do this?" It's "who in my stack does?" If nobody does, you have a gap, and you found it during the eval instead of during an incident.
This is where dope.security fits. dope.SWG runs the full gateway on the device: SSL inspection, URL filtering, anti-malware, and Cloud Application Control. Dopamine DLP reads what's inside an upload or a prompt while it's still moving and decides in Block, Monitor, or Off mode. That's inline enforcement on the path itself, not a report about the SaaS layer afterward.
5. What does it enforce inline, and what does it report after the fact?
Why it matters. "Detect," "prevent," and "block" get used loosely in this market. Inline enforcement means the action doesn't complete. After-the-fact means the action completed and you now have a record of it plus a remediation workflow. Both are valuable. They are not the same purchase, and they don't satisfy the same auditor.
What good looks like. Make a two-column list during the demo. Column one: what stops before it happens. Column two: what gets flagged, scored, or remediated afterward. Obsidian describes account takeover prevention, access violations, and excessive privilege management, which sit in the SaaS control plane. Ask them to place each capability you care about in one column or the other, in writing.
Then check your own requirements against it. If a regulator or a customer contract requires that a specific class of data cannot leave, a detection with a remediation workflow may not clear the bar. If your goal is reducing standing risk in your SaaS tenants, it absolutely does.
6. How does it handle personal accounts and unsanctioned destinations?
Why it matters. Shadow AI is the loudest version of this problem. The user isn't malicious. They log into personal ChatGPT because the corporate account is slower to approve, or personal Google Drive because they're in a hotel. Same domain as the sanctioned one. Different tenant.
What good looks like. Ask specifically how the product distinguishes your enterprise tenant from a personal account at the same provider, and what it can do about the difference. Discovery is one answer. Enforcement is another. They aren't interchangeable.
dope.security answers this with Cloud Application Control, which lets the enterprise tenant through and turns the personal account away at the same provider. Discovery finds the shadow account. CAC is what stops it from signing in. Dopamine DLP then auto-exempts CAC-controlled tenants from inspection, so the sanctioned path stays fast.
7. What's the total cost, in dollars and in consoles?
Why it matters. Obsidian offers a free trial and publishes a pricing page, which is more transparency than most of this market gives you. Good. Now do the harder math. Count the consoles you'll still run after this closes, plus the endpoint agents and the vendor relationships your team maintains.
What good looks like. Write down the full end state. If you buy a SaaS security platform and still run a separate gateway, a separate DLP product, and a separate set of tenant controls, that's four consoles and multiple renewals. Obsidian publishes a commissioned 192% ROI figure. Treat it as their own published claim, then build your own model with your actual console count in it.
The alternative worth pricing against: CASB Neural, AI-Powered SSPM, dope.SWG, Dopamine DLP, and Cloud Application Control in one console with one agent.
| Question | What to press on | Red flag answer |
|---|---|---|
| Deployment model | Day-one value vs. setup work | "It depends on your environment" |
| Data sources | Apps not on the integration list | Vague integration roadmap |
| Connected-app dependency | How the console reports its own coverage | No way to see current coverage |
| Non-SaaS traffic | Who in the stack covers it | No owner named for that path |
| Inline vs. after-the-fact | Written two-column list | "We prevent that" with no detail |
| Personal accounts | Tenant-level distinction | Discovery offered as enforcement |
| Total cost | Console and agent count at end state | Per-app pricing with no ceiling |
The short version of an Obsidian Security evaluation
Obsidian is strong at SaaS posture, identity threat detection, and AI agent governance. Buy it for that if that's your problem. Just make sure you know what's still uncovered when the contract is signed, because the gateway, the endpoint, and the tenant login are all still on the path your data takes.
See the rest of the path
If questions 4 and 6 made you uncomfortable, that's the useful part of this exercise. Try dope.security free, or book a 20-minute demo and we'll show you the gateway, the endpoint DLP, the SaaS posture view, and the tenant controls in one console. Bring your list. We'll answer all seven.


.jpeg)
.jpeg)

