TL;DR: Remote claims staff can be onboarded through an enterprise browser and private access layer instead of shipped workstations and legacy VPNs, reducing help desk load, hardware cost, and congestion while extending access to mobile devices, according to Island. The governance question is less about convenience than whether existing access models can still support BYOD, mobile work, and internal app routing without expanding trust.
At a glance
What this is: Island describes a remote claims-adjuster workflow that replaces workstation shipping and VPN access with browser-based delivery, private access routing, and mobile access.
Why it matters: This matters to IAM and PAM teams because it shifts access governance from device provisioning and VPN reliance toward browser-mediated access, mobility controls, and tighter application routing.
By the numbers:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
👉 Read Island’s account of browser-based access for remote claims adjusters
Context
The core issue is not just onboarding friction. It is the cost and control burden created when remote staff still need a fully managed workstation, a VPN, and manual setup before they can do useful work. In identity terms, this is a device-centric access model trying to support a highly distributed workforce, including mobile and remote claims adjusters.
Island’s example shows a broader governance pattern that many enterprises are moving toward: access is being mediated by browser control and application routing instead of endpoint ownership alone. That creates a real intersection with IAM, because the access path now becomes a policy decision as much as a device decision. For teams managing human identity, NHI, and privileged access, the lesson is that transport and session design matter just as much as authentication.
The claims-adjustment use case is not unusual for modern distributed operations. It is a representative example of where legacy VPN and shipment-based onboarding workflows no longer scale cleanly.
Key questions
Q: How should security teams handle browser sessions in cloud access governance?
A: Security teams should treat the browser session as part of the access boundary, not just a delivery mechanism. If posture tools only assess configuration, they will miss abuse that happens after login. The practical move is to combine identity, application, and session evidence so teams can tell whether a valid session is being used normally or manipulated in real time.
Q: Why does replacing a VPN with private access change IAM governance?
A: Because the control boundary moves from the network tunnel to the application and session layer. IAM teams must then think in terms of which apps, data paths, and actions are allowed, rather than whether a user is broadly inside the corporate network.
Q: What do security teams get wrong about browser-based access models?
A: They often treat the browser as a delivery shortcut rather than a policy enforcement point. If identity assurance, logging, entitlement review, and data controls are not built into the session, the organisation simply shifts the same risk into a new interface.
Q: What should organisations do first when moving remote workers off legacy VPN access?
A: Start with application inventory and user-role mapping, then define which sessions truly need internal routing. That creates a practical migration path and prevents teams from replacing a VPN with another broad trust mechanism that is harder to govern.
Technical breakdown
Browser-mediated access and enterprise control
An enterprise browser shifts the control point from the managed endpoint to the session layer. Instead of trusting the whole device, the organisation can mediate what the browser may reach, what data can be copied, and how internal applications are exposed. That is materially different from a VPN, which often expands network reach more broadly than the user actually needs. In practice, browser-mediated access can reduce the attack surface for remote workers, but only if session policies, application segmentation, and identity assurance are aligned. The control model becomes closer to least-privilege access at the session boundary than full device trust.
Practical implication: define browser session policy as an access control layer, not just as a user productivity tool.
Private access versus legacy VPN routing
Private access solutions typically route internal application traffic through a controlled path while sending public internet traffic directly over the user’s home connection. This avoids the hairpinning and congestion that often make VPNs slow during peak periods. From a security standpoint, the important point is not speed but scope: the access path can be narrowed to the applications that the worker actually needs, rather than granting broad network reach. That reduces overexposure, but it also increases the need for granular application inventory, policy enforcement, and logging. Without those, private access just replaces one tunnel with another.
Practical implication: inventory internal apps and map them to explicit access policies before replacing a VPN.
Mobile claims work and conditional access
Allowing adjusters to use smartphones or tablets for claims entry changes the identity and device assumptions behind access. Mobile access over a cellular network can be efficient, but it also removes the comfort of a fixed corporate endpoint and makes contextual controls more important. That means identity assurance, session duration, step-up authentication, and data handling controls need to reflect the mobility of the workflow. The architectural point is that the workforce is no longer anchored to one managed workstation. Governance has to follow the user and the session, not just the device image.
Practical implication: apply contextual access policies for mobile claims workflows and limit session scope to the task at hand.
NHI Mgmt Group analysis
Browser-based access is becoming an identity control plane, not merely an endpoint convenience. When organisations move work into the browser, they are implicitly shifting enforcement from device management to session governance. That matters for IAM because authentication alone does not define what the user can do once inside the session. The practical conclusion is that browser policy, application entitlements, and identity assurance now need to be designed together.
Session scope is the new trust boundary: the question is no longer whether a worker has a laptop, but what that worker can reach from a controlled browser session. This is especially relevant for distributed roles such as claims adjusters, contractors, and field users. A narrow session boundary can reduce dependency on VPNs and full workstation shipping, but only if application access and data movement are tightly governed. Practitioners should treat session scope as an enforceable access boundary, not a cosmetic layer.
Remote-work efficiency is now an identity governance problem. The article frames onboarding friction and VPN congestion as operational issues, but the underlying problem is access architecture. When identity programmes do not extend into browser session control and application routing, users experience delay while security teams absorb exception handling. The field implication is that modern access design must reconcile convenience, risk, and auditability in the same control plane.
Claims workflows show why least privilege must move closer to the runtime session. Shipping a laptop and handing out broad VPN reach creates too much persistent access for a task-based workforce. Browser-mediated access and private routing narrow that exposure, which is the right direction for human identity governance and for any future NHI-enabled workflow that depends on delegated access. Teams should see this as a signal to redesign access around task scope rather than endpoint possession.
What this signals
Browser-mediated access is becoming part of the identity control plane. For programmes that still separate endpoint management from access governance, this is where control drift starts. The immediate signal for practitioners is to align browser policy, entitlement review, and logging so session scope becomes visible and enforceable across remote and mobile work.
Task-scoped access will matter more than device ownership. As more teams support BYOD and field operations, access reviews need to ask what a user can do in a controlled session, not just whether the laptop is managed. That shift is especially important where remote workflows intersect with privileged functions or sensitive customer data.
The governance opportunity is to remove VPN-centric friction without creating a new blind spot. Organisations that can map applications to session-level policy, rather than network-wide reach, will have a cleaner path to auditability and better separation between standard and elevated access.
For practitioners
- Map remote roles to session-scoped access policies Define which claims applications, data sets, and actions each role can reach from the browser, then separate those policies from endpoint provisioning logic. Keep the policy tied to the session scope rather than the device build so BYOD and mobile access can be governed consistently.
- Replace broad VPN reach with application-specific routing Inventory internal applications and route only approved traffic through controlled paths while keeping public internet traffic separate. This reduces congestion and limits unnecessary network exposure, but only if the application inventory is maintained and reviewed regularly.
- Introduce contextual controls for mobile claims access Use step-up authentication, shorter sessions, and task-specific limits for tablets and smartphones used in the field. Mobile access should be allowed only where the workflow needs it, with logging that can reconstruct who accessed what and from where.
- Align onboarding with identity assurance, not hardware shipping Reduce dependence on shipped workstations by pairing browser-based onboarding with identity verification, entitlement checks, and automated access assignment. The operational goal is to remove avoidable friction without weakening access governance.
- Review privileged access paths in browser-mediated workflows If adjusters or support staff can reach administrative, claims-management, or customer-data functions through a controlled browser, verify that privileged functions still require separate approval and audit. Browser access should not collapse standard and elevated access into the same pathway.
Key takeaways
- The article shows that remote-work friction is often an access-architecture problem, not just a support problem.
- The material shift is from device shipping and VPN tunnelling to browser-mediated, session-scoped access.
- Practitioners should treat browser policy, application routing, and identity assurance as one governance problem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Browser-based access and private routing depend on least-privilege access governance. |
| NIST SP 800-53 Rev 5 | AC-6 | The article centers on minimizing excess access across remote work paths. |
| NIST Zero Trust (SP 800-207) | The post reflects a move from implicit network trust to controlled session access. | |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is directly implicated by browser-mediated remote work. |
Apply zero trust principles to browser sessions and require explicit verification for each protected app.
Key terms
- Enterprise Browser Security: Enterprise browser security is the practice of turning the browser into a managed control point for access, policy, and visibility. It combines isolation with governance over sessions, extensions, downloads, uploads, and application use across managed and unmanaged devices.
- Private Access: Private access is a controlled routing model for internal applications that avoids exposing them broadly on the public internet. It narrows reach to approved users and sessions, reducing dependence on general-purpose VPN access while requiring strong application inventory and policy enforcement.
- Session-Scoped Access: Session-scoped access is permission that exists only for a defined task or time window and is expected to end when the task ends. For NHI governance, it reduces lingering authority and makes AI-driven activity easier to review, revoke, and investigate when behaviour changes.
What's in the full article
Island's full post covers the operational detail this post intentionally leaves for the source:
- The remote-worker onboarding workflow that replaces shipped laptops with browser installation on existing devices
- The private access routing model that separates internal application traffic from public internet traffic
- The mobile claims workflow that lets field staff use phones or tablets to capture and enter claims data
- The operational changes that reduced help desk load, hardware cost, and VPN congestion
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, IAM, and secrets management. It helps practitioners connect identity controls to broader access design decisions across modern security programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org