CNAPP is often framed as a single answer to cloud security sprawl, but the useful question is narrower: does it genuinely connect posture, workload, identity, and runtime, or only place them under one label?