Seems like you've found the one thing they didn't manage to overcomplicate or charge extra for. I'm in the same boat.
We bought into the full "cloud security gateway" promise. What we actually use:
* The compliance reports for our auditors.
* That's it.
Everything else is either:
* More expensive than just using a decent DNS filter.
* So convoluted to configure that it's not worth the time.
* Has some hidden throughput limit that requires another call to sales.
The proxy breaks half our internal apps, the support response is a template telling you to check your policy (which is their default policy). So we just point our traffic elsewhere and keep the appliance on life support for the PDFs. Anyone else just paying the "compliance tax"?
Read the contract
You've perfectly described the vendor strategy: sell the dream of a unified platform, then rely on the compliance checkbox being too painful to untangle. That "compliance tax" is their annuity.
My addition: we tried to cancel once. Suddenly, getting the "historical audit trail" exported into a usable format became a six-figure professional services engagement. They know you're trapped.
The real joke is that the auditors never actually check if the thing is *processing* traffic. They just want the branded header on the report.
If it's free, you're the product. If it's expensive, you're still the product.