What is our primary use case?
My main use case for Reco is that it has been a valuable part of our security and SaaS visibility stack. Over time, I have found its main value to be giving us better visibility into our SaaS environment and helping identify areas that require attention. Reco is relatively straightforward to work with, and its centralized view makes it easier to investigate issues compared with checking individual applications manually.
A specific example of how I used Reco to solve a problem and improve my workflow is when we were trying to understand an unfamiliar SaaS application in our environment. Instead of manually going through different systems to figure out who is using it and whether it needs attention, Reco gives a centralized place to start that investigation, which saves quite a bit of time, especially when dealing with a growing number of applications. For me, it is primarily the visibility that matters.
I think another benefit is the context around the visibility because it helps us decide which findings actually need attention, rather than treating everything the same.
How has it helped my organization?
The biggest positive impact Reco has had on our organization is improving our SaaS visibility and reducing the amount of manual work involved in security investigation. Previously, we had a lot of manual work going on in security audits. Before having this centralized visibility, understanding an application often means checking multiple systems, looking at access and permissions, and sometimes reaching out to different teams to understand who is using it and why. With Reco, we have a much more centralized view, allowing us to quickly investigate usage and identify the users or teams associated with an unfamiliar application instead of spending a lot of time gathering that information manually. This helps us reduce investigation time and prioritize our security efforts.
I can estimate that previously it was taking thirty minutes to forty-five minutes for messaging someone to check things, and now it reduces to five to six minutes, which is a reduction of around sixty to sixty-five percent. If we calculate it on a larger scale concerning fifteen to twenty hours, then it is a great estimation because fifty to sixty percent time saved is a lot.
What is most valuable?
The best features that Reco offers, in my opinion, are the centralized view of the SaaS applications being used across our organization. For example, if a new SaaS application starts being used by an employee, Reco helps us identify it and investigate things such as who is using it, how widely it is being used, and whether it needs to be reviewed from a security perspective. This is particularly useful because manually tracking every application across a growing organization would be time-consuming. We also use the visibility to prioritize applications or users that require attention rather than manually reviewing everything. For us, the biggest value is having centralized SaaS visibility combined with security context, which helps us reduce manual investigations and gives our security team a better understanding of our SaaS environment.
I had one incident approximately six months ago when our security team noticed that a new SaaS application, such as a project management or AI productivity tool, was being used by an employee. Previously, to investigate it, we might have had to check our identity providers to see which employees have access, look at application logs to understand usage, check with the application owner, and then manually determine whether the application should be approved. With Reco, we can start from a centralized view and quickly understand the application, who is using it, how broadly it is being used, and what security information is available around it. Instead of spending thirty or forty-five minutes collecting information from several places, we get the initial context much faster and focus on deciding whether there is an actual risk. I think this is the biggest time saving for us. It is not just that Reco puts information on one screen; it reduces the back and forth between different tools and teams during an investigation.
Whenever I use Reco, I feel safe. Governance and security are definitely important considerations, especially because SaaS environments can contain sensitive organizational user data. Understanding what data is being processed is crucial.
The breadth of coverage Reco offers for SaaS operations is strong, particularly around SaaS visibility, application discovery, and user and access context. Reco is not just showing us a list of applications; it gives us additional context that helps us understand how those applications are being used and where we may need to investigate further. For example, identifying applications across the organization to understand associated users and access helps prioritize potential security or governance issues, which becomes particularly valuable as our SaaS environment grows.
The use of eight different sensors for SaaS application discovery has made a noticeable difference for us. The main benefit is that we are not relying on a single source of information to discover SaaS applications, as different applications can show up through different signals, giving us broader coverage and making the discovery process more reliable. Having multiple sensors feed into Reco and provides a more complete picture of what is actually being used in the organization, reducing blind spots and the amount of manual discovery work for our team.
The LLM integration is interesting because the knowledge graph gives context about the relationships between users, application access, and security signals. Instead of an analyst manually connecting those dots, the AI can help explain what is happening and why something might deserve attention, significantly speeding up investigation. This is probably the biggest differentiator compared with more traditional SaaS visibility tools.
The AI agent security capability is particularly useful because AI agents are becoming another category of SaaS technology users that security teams need to understand. The biggest challenge is that agents can be connected to applications, APIs, and data sources, and sometimes have permissions to take actions on behalf of users. Discovering those connected AI agents and bringing them into the same governance process as the rest of our SaaS is quite valuable because we need to understand what is connected to what permission it has, what data it can access, and who owns it.
My impression of Reco's Device Management feature when it comes to discovering every device in our organization is quite positive, particularly from a visibility perspective. One of the challenges with device management is getting a complete and up-to-date picture of what devices are present. Reco provides centralized device visibility without maintaining separate inventories and correlating devices with users and SaaS applications manually.
What needs improvement?
I think overall Reco works well for our use case, but there are a few areas where it could become even more valuable. The biggest one would be more customizations and automations, such as having more flexibility in creating organization-specific dashboards and reports, because different security teams have different priorities. Being able to customize which metrics, applications, risks, and users we want to track would be helpful. I would also like to see more automations around remediation, such as triggering actions automatically based on predefined policies without human dependency to avoid delays.
Another improvement I wish to see is deeper integration with other security and identity tools, because the more information Reco can correlate automatically, the less time the security team has to spend moving between different systems. Overall, I would not say there is a major gap; it is more about enhancing the strong visibility Reco already provides by adding more customization, automation, and integrations.
My impression of the accuracy and reliability of Reco's AI output is that there is a lot of manual analysis the security team has to do.
For how long have I used the solution?
I have been using Reco for the last one year, and I value this service highly.
Which solution did I use previously and why did I switch?
Before using Reco, we were actually using a combination of existing identity and security tools. The main limitation was that the information was fragmented, so we could not get a complete picture from different tools, which forced us to rely on a mix of Wiz, Okta, Zscaler, and Microsoft Defender.
How was the initial setup?
Setting up Reco agents for automating tasks in our business processes is relatively straightforward, especially once the integrations and permissions are already in place. An agent could detect a SaaS application that meets certain risk criteria and then automatically notify the user owner or initiate a security review. The main thing we focus on is permission and guardrails for higher impact actions, wanting approval and auditability rather than giving the agent complete autonomy.
What was our ROI?
We have seen a positive return on investment, estimating that the initial investigation effort has dropped by roughly fifty percent. Something that previously took thirty to forty minutes might now take fifteen to twenty minutes, providing the biggest measurable efficiency gain by saving twenty to forty hours of team time to focus on something more complex or prioritized.
What's my experience with pricing, setup cost, and licensing?
We have purchased Reco through the Google Cloud Marketplace. Overall, the setup cost was straightforward because it is a SaaS, and we did not have major infrastructure costs. Most of our effort was configuring integrations, permissions, and workflows. From a licensing perspective, the main thing I look for is predictable pricing as the number of users and applications grows.
Which other solutions did I evaluate?
We evaluated several options before choosing Reco, which included comparing solutions such as Wiz, Netscope, Microsoft Defender, and assessing what we could have accomplished with our existing tools. Ultimately, we compared how well each solution could provide complete SaaS visibility.
What other advice do I have?
Reco is not deployed in a completely private cloud environment for my organization. The cloud provider we use with Reco is Google Cloud Platform, or GCP. I did not find any much deviations since our organization is a long-term user of this Google Cloud provider, and most of the services are from Google Cloud, which we trust.
My advice for others looking into using Reco is to consider that we evaluated a few alternatives before selecting it, focusing on SaaS discovery, visibility into users and access, security context, and the potential to eliminate manual investigations, which is why Reco stood out with its centralized view across different signals.
I would rate Reco around eight out of ten. I choose this rating because of the improvements I am expecting, particularly more automations and customizations. The majority of things are correct, but I think in this AI era, everything is automated, and those two things would significantly reduce time. Regarding how Reco is deployed in my organization, I took the plan.