Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Browser-based controls for BPO security: what does it change for IAM?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Browser-mediated policy can narrow exposure where shared environments, contractor onboarding and cross-tenant workflows outgrow traditional perimeter controls. Teleperformance says it uses the Island Enterprise Browser to apply granular controls across 500,000 employees in 170 countries, balancing data protection, client-specific access rules, DLP and reduced VDI complexity, according to Island.

NHIMG editorial — based on content published by Island: How BPO Teleperformance Deploys Flexible, Granular Security Worldwide

By the numbers:

Questions worth separating out

Q: How should security teams control risky browser actions in shared-service environments?

A: They should define which actions are permitted inside each session, then enforce them through the browser rather than assuming network access is enough.

Q: Why do outsourced workforces create harder identity governance problems?

A: Because the organisation is managing many customer contexts at once, often across different compliance expectations, platforms and trust boundaries.

Q: What do organisations get wrong when replacing VDI with enterprise browsers?

A: They sometimes treat the browser as a convenience layer instead of an enforcement point.

Practitioner guidance

  • Define session-level allowed actions List the user actions that are acceptable in client-facing workflows, such as view, copy, upload, comment or download, and map each to a policy decision.
  • Separate corporate identity from client context Require policies that bind a user’s identity to the client environment they are serving, rather than relying on a single generic corporate login.
  • Rework offboarding across acquired environments Treat acquired business units and outsourced operating models as high-risk lifecycle zones.

What's in the full article

Island's full article covers the operational detail this post intentionally leaves for the source:

  • How Teleperformance applies browser rules to specific user actions across corporate and client environments
  • How the company reduced reliance on VDI while preserving access to browser-delivered applications
  • How granular DLP and DRM policies are applied in practice across a global workforce
  • How the approach supports compliance across multiple jurisdictions and customer requirements

👉 Read Island’s article on Teleperformance’s browser-based security model →

Browser-based controls for BPO security: what does it change for IAM?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Browser enforcement is becoming an identity control plane for outsourced workforces. In environments like BPOs, the browser is no longer just an application container. It is where session policy, client segregation and data handling rules are actually applied. That makes browser-mediated governance relevant to IAM and PAM teams, not just endpoint security teams. Practitioners should treat this as a control boundary, not a convenience layer.

A question worth separating out:

Q: When should teams use browser controls instead of adding more desktop infrastructure?

A: Use browser controls when the main risk is how users interact with web-delivered systems, not whether they can reach them. That is common in SaaS-heavy and client-delivery workflows. Desktop layers add value only when they improve isolation or governance, not when they make access harder to observe and manage.

👉 Read our full editorial: Teleperformance’s browser-based security model for global BPO risk



   
ReplyQuote
Share: