By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: IslandPublished August 22, 2025

TL;DR: Browser-layer controls can improve operational visibility, as a FinTech lending customer used Island Enterprise Browser to improve call center visibility across Salesforce.com, retire a VPN dependency, and simplify employee access while preserving auditability, according to Island. The governance lesson is that browser-layer controls can improve operational visibility, but they do not replace identity, privilege, and session governance.


At a glance

What this is: This is a brief customer story about using a browser-based control to improve visibility into call center activity across Salesforce and reduce reliance on VPN access.

Why it matters: It matters because identity and access teams need practical ways to observe employee actions in SaaS workflows without stacking more friction onto already sensitive operational environments.

By the numbers:

  • One of these tools was Salesforce Shield, an add-on module for Salesforce.com that offers granular logging but adds 30% to their subscription costs.

👉 Read Island's post on browser-based visibility for Salesforce call center operations


Context

Call center operations in regulated environments need more than simple access control. They need traceability, consistent user experience, and enough visibility to investigate mistakes or misuse without introducing unnecessary control friction. In this case, the operational problem sits at the boundary of application access, browser telemetry, and workforce governance.

The identity angle is indirect but real: when a browser becomes the control point, it can change how teams observe user behavior in SaaS applications such as Salesforce. That makes the discussion relevant to IAM and PAM practitioners who care about auditability, session context, and whether browser-layer controls complement or compete with existing identity governance processes.


Key questions

Q: How should security teams govern browser-based access to sensitive applications?

A: Treat browser-based access as part of the privileged access surface when it reaches cloud consoles, admin portals, or operational systems. Apply the same session controls, traceability, and review discipline you would expect for PAM-managed access. The goal is not to block all browsing, but to ensure the browser does not become an ungoverned path into critical systems.

Q: Why can VPNs be a poor fit for SaaS visibility requirements?

A: VPNs move traffic but do not automatically create usable, user-level evidence of what happened inside cloud applications. They can add friction without improving audit quality. For SaaS-heavy operations, organisations usually need application and browser telemetry tied back to identity, rather than relying on transport-layer visibility alone.

Q: What breaks when activity logging is fragmented across multiple tools?

A: Investigations slow down, accountability becomes harder to prove, and support teams lose a consistent record of user actions. Fragmentation also encourages duplicate controls that raise cost without materially improving governance. A single, identity-linked evidence chain is usually more useful than several partial logs.

Q: How do organisations decide when to retire a VPN in a cloud workflow?

A: Retire it only when another control clearly owns the visibility and policy outcomes the VPN was compensating for. That usually means browser-layer monitoring, application logging, and identity correlation are all in place, with documented exception handling. Otherwise the organisation may remove friction while introducing governance blind spots.


Technical breakdown

Browser-based visibility into SaaS activity

An enterprise browser can act as the observation layer for user activity inside web applications, capturing interactions that would otherwise be fragmented across endpoint logs, SaaS audit records, and network telemetry. In practice, this creates a more consistent view of what users do inside systems like Salesforce, especially when workers operate from different geographies or unmanaged networks. The mechanism is not identity enforcement by itself. It is telemetry and session control at the browser layer, which can improve oversight but still depends on upstream authentication, authorization, and governance decisions.

Practical implication: treat browser telemetry as an observability layer, not a substitute for access review, session governance, or privileged control.

Why VPN dependence often creates operational drag

VPNs centralise connectivity but often introduce friction, latency, and support burden when the goal is routine access to cloud applications. They can also blur the line between connectivity control and application visibility, because tunnelling traffic does not automatically produce meaningful user-level audit detail. When organisations rely on VPNs to compensate for weak application visibility, they may be solving for network trust rather than identity governance. That distinction matters in SaaS-heavy environments where the primary risk is often what users can do after authentication, not whether they can reach the application.

Practical implication: separate network access decisions from application-level monitoring so teams do not confuse transport control with governance.


NHI Mgmt Group analysis

Browser control is becoming an access governance layer, not just a productivity layer. The article shows how browser-mediated access can be used to observe activity in SaaS applications more consistently than a VPN-based approach. That is relevant to IAM because the browser now sits closer to the point where authentication becomes action, especially in cloud-first operations. Practitioners should treat browser controls as part of the identity control plane, not as an isolated endpoint feature.

Browser visibility gap: when SaaS activity is only visible through scattered logs, investigators lose context. The FinTech use case highlights a familiar governance problem: organisations often know a user entered Salesforce, but not enough about what happened next. That creates weak auditability for customer service operations where human error can have financial consequences. Browser-layer telemetry can reduce that gap, but only if it is tied to identity records and retained in a way that supports investigations and reviews.

VPN retirement is a signal of control simplification, not control removal. In mature programmes, reducing the number of overlapping access paths can improve both user experience and governance clarity. The risk is that teams celebrate simplification without documenting what control now owns visibility, policy enforcement, and exception handling. Practitioners should map old network controls to new browser controls before retiring anything persistent.

This use case reinforces the need to distinguish access control from activity assurance. Being able to reach Salesforce is not the same as being able to prove what happened inside it. For identity teams, that means aligning browser telemetry with least privilege, session oversight, and audit expectations rather than assuming a single control can cover all three. The useful question is not whether browser-based access works, but which governance gaps it actually closes.

Workforce SaaS governance is shifting toward session-aware observability. As more business processes move into browsers, identity programmes need stronger links between authentication, browser session evidence, and downstream application actions. That aligns with NIST Cybersecurity Framework 2.0 and access governance practices that emphasise traceability and accountability. Practitioners should expect browser-mediated controls to become part of the evidence chain for investigations and audits.

What this signals

Browser-first governance will matter more as SaaS workflows absorb customer service, finance, and operations. Teams should expect audit evidence to shift from network logs toward session-aware controls that tie browser activity to identity and application context. The practical challenge is not adding another monitoring layer, but deciding which control becomes authoritative when incidents or disputes arise.

Session evidence gap: many programmes can authenticate users but cannot reconstruct meaningful action trails inside browser-based SaaS workflows. That gap becomes expensive when call center mistakes, privilege misuse, or customer-impacting errors need investigation. Identity teams should prepare for evidence models that join browser telemetry, SaaS audit logs, and access records into a single reviewable chain.


For practitioners

  • Map browser telemetry to identity records Ensure browser activity logs can be correlated to user identity, device, and session context so audit teams can reconstruct who did what inside Salesforce and similar SaaS tools.
  • Define control ownership before retiring VPN access Document which control now provides visibility, policy enforcement, and exception handling after the VPN is removed, so gaps do not appear between network access and application oversight.
  • Preserve evidence for customer-facing workflows Retain browser and SaaS audit data long enough to investigate operational mistakes in call center processes, especially where errors could affect customer accounts or regulated decisions.
  • Review whether visibility tools overlap unnecessarily Compare Salesforce audit logging, browser telemetry, and any endpoint monitoring to remove duplicated controls where they add cost but little additional governance value.

Key takeaways

  • Browser-layer controls can improve visibility into SaaS work, but they do not replace identity governance or access review.
  • Retiring a VPN only makes sense when another control clearly owns auditability, policy enforcement, and exception handling.
  • Identity-linked browser telemetry is becoming part of the evidence chain for investigations, audits, and operational accountability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST-Cybersecurity Framework 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Browser-mediated access still depends on managed access permissions and accountability.
NIST SP 800-53 Rev 5AU-2The article centres on auditability of user actions inside SaaS workflows.
NIST-Cybersecurity Framework 2.0PR.AC-1Identity-centric access governance underpins the shift from VPN trust to browser control.

Map browser access paths to PR.AC-4 and document how session evidence ties back to user identity.


Key terms

  • Browser-mediated access: Browser-mediated access is access that is exercised through the browser rather than through a tightly controlled native client or backend workflow. It matters because many modern identity and data control failures occur after sign-in, during the live session where users interact with SaaS and AI tools.
  • Session-aware observability: A security approach that ties user actions to a specific authenticated session and retains enough context for review or investigation. In SaaS environments, this is often more useful than network logs because it shows what happened after login, not just that a connection existed.
  • Auditability: Auditability is the ability to reconstruct who or what acted, what permissions were used, and what data or tools were touched. For AI and NHI governance, it is the minimum evidence needed to investigate incidents, validate controls, and prove that autonomous actions stayed within approved scope.

What's in the full article

Island's full blog post covers the operational detail this post intentionally leaves for the source:

  • How the browser was configured as the default access path for call center employees
  • How Salesforce visibility changed once browser activity was captured at the session layer
  • Why the team could retire the VPN and what that simplified in the access stack
  • What the user experience changes meant for geographically distributed workers

👉 Island's full blog covers the browser configuration, Salesforce visibility gains, and VPN retirement details.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to broader access and audit requirements across modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org