TL;DR: Browser-layer controls can improve operational visibility, as a FinTech lending customer used Island Enterprise Browser to improve call center visibility across Salesforce.com, retire a VPN dependency, and simplify employee access while preserving auditability, according to Island. The governance lesson is that browser-layer controls can improve operational visibility, but they do not replace identity, privilege, and session governance.
NHIMG editorial — based on content published by Island: WWLW Ep. 2, the case of the mysterious call center activity
By the numbers:
- One of these tools was Salesforce Shield, an add-on module for Salesforce.com that offers granular logging but adds 30% to their subscription costs.
Questions worth separating out
Q: How should security teams govern browser-based access to sensitive applications?
A: Treat browser-based access as part of the privileged access surface when it reaches cloud consoles, admin portals, or operational systems.
Q: Why can VPNs be a poor fit for SaaS visibility requirements?
A: VPNs move traffic but do not automatically create usable, user-level evidence of what happened inside cloud applications.
Q: What breaks when activity logging is fragmented across multiple tools?
A: Investigations slow down, accountability becomes harder to prove, and support teams lose a consistent record of user actions.
Practitioner guidance
- Map browser telemetry to identity records Ensure browser activity logs can be correlated to user identity, device, and session context so audit teams can reconstruct who did what inside Salesforce and similar SaaS tools.
- Define control ownership before retiring VPN access Document which control now provides visibility, policy enforcement, and exception handling after the VPN is removed, so gaps do not appear between network access and application oversight.
- Preserve evidence for customer-facing workflows Retain browser and SaaS audit data long enough to investigate operational mistakes in call center processes, especially where errors could affect customer accounts or regulated decisions.
What's in the full article
Island's full blog post covers the operational detail this post intentionally leaves for the source:
- How the browser was configured as the default access path for call center employees
- How Salesforce visibility changed once browser activity was captured at the session layer
- Why the team could retire the VPN and what that simplified in the access stack
- What the user experience changes meant for geographically distributed workers
👉 Read Island's post on browser-based visibility for Salesforce call center operations →
Browser-based activity control for Salesforce: what teams gain?
Explore further
Browser control is becoming an access governance layer, not just a productivity layer. The article shows how browser-mediated access can be used to observe activity in SaaS applications more consistently than a VPN-based approach. That is relevant to IAM because the browser now sits closer to the point where authentication becomes action, especially in cloud-first operations. Practitioners should treat browser controls as part of the identity control plane, not as an isolated endpoint feature.
A question worth separating out:
Q: How do organisations decide when to retire a VPN in a cloud workflow?
A: Retire it only when another control clearly owns the visibility and policy outcomes the VPN was compensating for. That usually means browser-layer monitoring, application logging, and identity correlation are all in place, with documented exception handling. Otherwise the organisation may remove friction while introducing governance blind spots.
👉 Read our full editorial: Browser-based control for call center activity and Salesforce visibility