TL;DR: Browser-mediated policy can narrow exposure where shared environments, contractor onboarding and cross-tenant workflows outgrow traditional perimeter controls. Teleperformance says it uses the Island Enterprise Browser to apply granular controls across 500,000 employees in 170 countries, balancing data protection, client-specific access rules, DLP and reduced VDI complexity, according to Island.
At a glance
What this is: This is an Island case study showing how Teleperformance uses browser-level controls to manage access, data loss prevention and remote work at global BPO scale.
Why it matters: It matters because BPOs, shared-service teams and contractor-heavy environments often need identity-aware controls that go beyond network access and endpoint policy alone.
By the numbers:
- Teleperformance manages call centers and human interactions for 1,400 companies, 850 of which are in the Fortune 1000.
👉 Read Island’s article on Teleperformance’s browser-based security model
Context
Teleperformance’s operating model shows why browser-mediated controls are attracting attention in distributed workforces. When a service provider supports many clients, works across acquired environments, and allows users to interact with both corporate and customer systems, the security problem is less about a single network boundary and more about controlling what each user can do in each session.
The identity angle is real here. Browser-based policy sits between human identity, contractor onboarding, and access governance, making it relevant to IAM, PAM and zero-trust programmes that need finer control than broad VPN or VDI access. For BPOs and similar shared-service organisations, this is a typical scaling problem rather than an edge case.
Key questions
Q: How should security teams control risky browser actions in shared-service environments?
A: They should define which actions are permitted inside each session, then enforce them through the browser rather than assuming network access is enough. That approach is especially useful when workers may need to view content but not post, copy, upload or export it. The goal is to reduce data leakage without blocking legitimate work.
Q: Why do outsourced workforces create harder identity governance problems?
A: Because the organisation is managing many customer contexts at once, often across different compliance expectations, platforms and trust boundaries. A user may be fully authenticated and still pose risk if their session is not constrained by client, task and data sensitivity. Identity governance has to track context, not just account status.
Q: What do organisations get wrong when replacing VDI with enterprise browsers?
A: They sometimes treat the browser as a convenience layer instead of an enforcement point. If browser sessions do not inherit identity policy, device posture, and session restrictions, the organisation has simply moved the same risk into a different interface. Replacement only works when controls move with the access path.
Q: When should teams use browser controls instead of adding more desktop infrastructure?
A: Use browser controls when the main risk is how users interact with web-delivered systems, not whether they can reach them. That is common in SaaS-heavy and client-delivery workflows. Desktop layers add value only when they improve isolation or governance, not when they make access harder to observe and manage.
Technical breakdown
How browser-level policy constrains data exfiltration
An enterprise browser can enforce rules at the interaction layer rather than relying only on network controls. That means an organisation can allow one action, such as viewing content, while blocking another, such as posting or copying data, within the same web session. This is useful when the risky behaviour is not access itself but the next action a user can take after access is granted. In practice, the browser becomes a policy enforcement point for data loss prevention and digital rights management, especially where users work inside customer portals and SaaS applications.
Practical implication: define session actions that should be allowed, blocked or audited instead of treating browser access as all-or-nothing.
Why VDI reduction changes the control model
Virtual desktop infrastructure centralises access, but it also adds cost, complexity and logon friction, especially when users must cross multiple environments. Reducing VDI does not remove the need for governance. It shifts control toward the browser, where identity, device state and allowed user actions can be enforced more directly. That matters in outsourced operations because the same worker may need to reach different customer environments without multiple desktop layers. The result is a flatter access architecture, but only if policy, logging and entitlement review are equally strong.
Practical implication: re-baseline access reviews and logging when browser access replaces layered desktop controls.
How shared-risk environments affect identity governance
In a BPO model, the organisation is not only protecting its own data. It is managing a shared risk environment with clients that have their own security and compliance expectations. That creates governance pressure across onboarding, environment separation, data handling and audit evidence. The identity issue is not just who the user is, but which customer context they are operating in at a given moment. This is where browser policy, privileged access controls and client-specific segmentation converge. Without that convergence, one user journey can create exposure across many tenants.
Practical implication: tie user identity to client context and session policy, not just to a corporate account.
Threat narrative
Attacker objective: The objective is to extract or mishandle client and corporate data through legitimate-looking access paths that evade coarse perimeter controls.
- Entry occurs through legitimate workforce access to corporate and client web applications, often from shared or hybrid environments.
- Escalation happens when a user can take higher-risk actions inside the session, such as interacting with content in ways that increase leakage pathways.
- Impact follows when sensitive data, client workflows or regulated information move beyond intended boundaries through allowed but unsafe browser actions.
NHI Mgmt Group analysis
Browser enforcement is becoming an identity control plane for outsourced workforces. In environments like BPOs, the browser is no longer just an application container. It is where session policy, client segregation and data handling rules are actually applied. That makes browser-mediated governance relevant to IAM and PAM teams, not just endpoint security teams. Practitioners should treat this as a control boundary, not a convenience layer.
Shared-risk operating models expose the weakness of account-centric governance. When one organisation serves many clients, the important question is not only whether access was authenticated. It is whether the authenticated user was constrained tightly enough for the specific customer context, action and data type. This is where IAM programmes need to move from identity proof to context-bound enforcement.
Session-level controls reduce blast radius, but only if entitlement design is equally granular. Blocking unsafe browser actions helps, yet it does not fix poor role design, excessive access or weak offboarding. The governance lesson is that browser policy can contain misuse, but it cannot compensate for stale access, over-permissioned accounts or poor lifecycle management. Practitioners should align the browser layer with identity governance rather than using it as a substitute.
Browser-based security will keep moving closer to workload and human identity governance. As more work happens in SaaS, contractor portals and customer-delivered apps, the boundary between endpoint control and identity control continues to blur. That increases the value of conditional, context-aware policy, but it also raises the bar for auditability. Teams should expect browser enforcement to become part of broader identity architecture conversations.
Granular interaction control is the right named concept for this model. The article illustrates a specific pattern where security is applied to what a user can do inside the session, not merely whether they can sign in. That pattern matters because modern risk often emerges after authentication succeeds. Practitioners should evaluate whether their controls govern interaction, not just access.
What this signals
Browser-mediated access is becoming a practical control layer for shared-service organisations, but it does not remove the need for identity lifecycle discipline. The more work moves into browser-delivered environments, the more important it becomes to align access review, offboarding and policy enforcement so that session rules and account rules do not drift apart.
Granular interaction control: this is the governance pattern that will matter more as contractor-heavy and client-facing work shifts into SaaS and browser-first workflows. The browser can reduce leakage pathways, but only if IAM, audit and endpoint teams treat it as part of the access architecture rather than a standalone convenience layer. For practitioners, the signal is clear: policy granularity is becoming a control expectation, not a niche requirement.
For practitioners
- Define session-level allowed actions List the user actions that are acceptable in client-facing workflows, such as view, copy, upload, comment or download, and map each to a policy decision. Use the browser as the enforcement point for those rules where the SaaS application itself is too coarse. This is where granular interaction control becomes operational.
- Separate corporate identity from client context Require policies that bind a user’s identity to the client environment they are serving, rather than relying on a single generic corporate login. That helps reduce accidental cross-tenant behaviour and makes audit evidence easier to interpret when multiple customer environments are involved.
- Rework offboarding across acquired environments Treat acquired business units and outsourced operating models as high-risk lifecycle zones. Inventory which identities can still reach client systems, browser-delivered apps and shared workspaces, then remove access paths that outlive the worker’s actual assignment.
- Align browser logs with IAM review cycles Feed browser policy logs into access review and exception handling so that dangerous actions can be traced back to a specific identity, device and customer context. That gives IAM and security teams a way to validate whether policy is working or merely present.
- Reduce reliance on stacked VDI layers Use browser-mediated access to simplify desktop sprawl only where you can preserve policy enforcement, segmentation and auditability. The goal is not to eliminate VDI everywhere, but to avoid adding desktop layers that obscure who accessed what and why.
Key takeaways
- Browser-based controls are being used to enforce what users can do inside a session, which is where much of the real risk now sits.
- Teleperformance’s scale shows why shared-risk environments need identity-aware policy, not just broad network access and desktop isolation.
- Practitioners should align browser policy, IAM reviews and offboarding so that granular control becomes part of governance rather than a separate tool layer.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | The article centres on granular access control across shared environments. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is essential when a browser becomes the control point for shared-service access. |
| ISO/IEC 27001:2022 | A.8.2 | Privileged access control matters where browser-mediated access reaches sensitive client systems. |
| CIS Controls v8 | CIS-5 , Account Management | Contractor onboarding and offboarding are central to the shared-risk model described. |
Apply AC-6 to restrict browser actions to the minimum necessary for each role and client context.
Key terms
- Browser-enforced policy: Browser-enforced policy is control that evaluates identity, content, and context at the point where a user interacts with an AI service. It is more precise than static blocking because it can distinguish safe interactions from risky ones while the session is still active.
- Shared-risk environment: A shared-risk environment is an operating model where one organisation’s security decisions affect many external parties, such as clients, partners or tenants. In BPO and managed-service settings, governance must account for multiple security expectations, workflows and data boundaries at the same time.
- Granular interaction control: Granular interaction control means governing the specific actions a user can take after authentication, not just whether they can log in. It focuses on blocking risky behaviours such as posting, uploading, copying or exporting data while still allowing legitimate work to continue.
- Session-level enforcement: A control model that applies security decisions to an active session, not just to the login event. It matters for privileged identities because the highest-risk abuse often happens after authentication, when access must still be monitored, constrained, or terminated based on context.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- How Teleperformance applies browser rules to specific user actions across corporate and client environments
- How the company reduced reliance on VDI while preserving access to browser-delivered applications
- How granular DLP and DRM policies are applied in practice across a global workforce
- How the approach supports compliance across multiple jurisdictions and customer requirements
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and machine identity security for practitioners who need stronger control over modern access models. It helps identity and security teams connect policy, privilege and lifecycle management across real operating environments.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org