Who accesses what.
The crux of SaaS security: the right person, on the right data, and no one else. Fine-grained management of identities, roles and access, strong authentication and locked-down sessions: the right person reaches the right data, and no one else.
Auth
OAuth, SSO, MFA.
Sessions
Tokens locked down.
Roles
Strict segregation.