Observe (CASB) — available today
Inviolet’scasb-netskope connector pulls Netskope egress events and ingests the ones
bound for LLM providers, so bypass volume and attribution show up in the
Shadow IT analytics view.
Set it up: Inviolet → Settings → Data Sources → Admin Connectors → New →
Netskope, then paste your credentials.
Credentials: Netskope — a REST API v2 token (Settings → Tools → REST API Clients, Read events scope) + your tenant host.
Enforce (SWG) — on request
Network enforcement packs for Netskope (block direct LLM API + consumer UIs, forcing traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which matches at the DNS layer natively — Netskope enforcement is scoped to your tenant’s capabilities. Contact us to scope a deployment.Cloudflare is the reference vendor, validated end to end (enforcement +
observability). See the Cloudflare guide for
the full pattern; the same shape applies here once your enforcement pack is built.