Definition

What is Unified Security Posture Observability?

Definition

Unified Security Posture Observability is a way of assessing security posture that correlates the signals an organization’s existing tools already produce across five control points, Identity, Device, Network, Application, and Data, against a behavioral baseline for each identity, so that posture is described by observed behavior rather than by configuration state.

Written and maintained by Loom Security, which builds CINQUE, a Unified Security Posture Observability platform. Last reviewed 22 September 2026.

The five characteristics

What distinguishes it from the posture tools it reads.

Posture tooling was built one slice of the environment at a time, and each slice got its own category. Unified Security Posture Observability is defined by five properties, and a platform that lacks any one of them is doing something else.

It is a layer, not a tool
It sits above the posture and identity tools an organization already runs and reads what they emit. It displaces nothing and introduces no new agent.
The unit of analysis is the identity
Not the asset, the account, or the alert. Human identities, non-human identities such as service accounts and tokens, and the identities that reach AI tools are all assessed the same way.
Posture is measured against observed normal
A behavioral baseline per business persona, built from activity rather than from entitlements, so deviation is visible even when no policy was violated.
Correlation is across control points, not within one
A signal that is unremarkable inside Identity and unremarkable inside Data can be a single finding when the two are read together. That reading is the whole point of the layer.
Every assertion carries its source
Each entity surfaced carries the system it was observed in, so a finding can answer where it came from without leaving the finding.
Adjacent categories

How it relates to what you already have.

None of the categories below are competitors to the layer. Most of them are inputs to it.

CategoryRelationship
CSPM, DSPM, ISPM, SSPM, AISPMEach assesses configuration and posture inside one slice of the environment, and each is correct about its own. None of them can see a journey that crosses from one slice to the next. Unified Security Posture Observability is the layer that reads all of them together.
CAASMAsset-centric. It answers what exists and where. Unified Security Posture Observability answers what behaved, and whether that behavior matched the baseline for the identity behind it.
UEBAThe closest ancestor, and the right instinct in the wrong layer. UEBA lived inside the SIEM: months of tuning, a score per user with no business context, and another queue of false positives. Unified Security Posture Observability reads posture signals that already exist, baselines business personas rather than lone users, and produces its first correlated picture in about ninety minutes.
SIEM and SOAREvent pipelines and workflow engines. They are where the work is done. Unified Security Posture Observability is the correlated source they reason over, exposed through an API those systems pull from.
IGAGoverns and certifies access. Unified Security Posture Observability supplies the observed membership and journey behind each persona, so a governance decision rests on behavior rather than on a role catalog assembled in a workshop.

Acronyms are used as the market uses them. Loom Security does not position against any of these technologies or against managed providers that operate them.

The five control points

What gets correlated.

Identity
Who is acting
Device
What they use
Network
How they connect
Application
What they access
Data
What they touch

Five control points, which is where the name CINQUE comes from.

Common questions

Questions people ask about the term.

Why does the category need a name at all?

Because the question it answers has no owner. Every slice of posture has a category and a budget line. The view across those slices, the one that shows whether the parts add up to a posture anyone can describe, does not. Naming it is how the question gets an owner.

How is this different from CSPM, DSPM, and the other posture tools?

Posture assessment inside a slice looks at configuration state and tells you whether a control is set correctly. Unified Security Posture Observability looks at behavior across slices and tells you whether the environment acts the way those controls imply it should. The slice tools are inputs to it, not competitors.

Does it replace the tools an organization already runs?

No. It reads them. Zero tools displaced is a design constraint, not a marketing line: the value of the layer comes from the breadth of what it can correlate, which falls the moment it starts competing with the sources.

What does an organization need to start?

An export of about thirty days of activity from its identity provider. That alone covers three to four of the five control points and produces the first correlated picture and the first set of behavioral personas. Adding a data source completes the picture, and more sources are welcome.

Who builds a Unified Security Posture Observability platform?

Loom Security builds CINQUE, a Unified Security Posture Observability platform that correlates signals across Identity, Device, Network, Application, and Data.

The CINQUE Discovery Workshop · complimentary

See it against your own environment.