Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Enterprise browser controls in call centers: can security improve UX?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A financial asset management customer used the Enterprise Browser to pair stronger browser controls with a familiar, productivity-oriented user experience, then expand rollout from call centre teams into other departments, according to Island. The practical lesson is that security controls gain traction when they fit the work, not when they only constrain it.

NHIMG editorial — based on content published by Island: WWLW Ep. 7, the case of the happy call center users

Questions worth separating out

Q: How should teams roll out browser-based security controls without hurting adoption?

A: Start with the work pattern, not the product feature set.

Q: What breaks when browser security controls are too restrictive for end users?

A: Users begin working around the control layer, usually by shifting to unmanaged tools, personal browsers, or manual shortcuts.

Q: How do you know if browser-based access controls are actually working?

A: Look for fewer workarounds, stable or improved task completion, and consistent use of the controlled browser across target teams.

Practitioner guidance

  • Map browser controls to identity policy objectives Define which access, session, and application-entry rules the enterprise browser is meant to enforce, then align them to existing identity policy so the rollout does not create a parallel control model.
  • Treat extensions as governed dependencies Create an inventory of allowed browser extensions, the permissions they request, and the workflows they support.
  • Measure adoption alongside enforcement Track whether users actually move to the secure browser, whether support tickets decline, and whether workarounds appear in adjacent channels.

What's in the full article

Island’s full article covers the operational detail this post intentionally leaves for the source:

  • The specific homepage and extension configuration choices the team used to shape the user experience.
  • The step-by-step rollout pattern that helped the call centre move first and other departments follow.
  • The practical details behind balancing productivity gains with browser-enforced security controls.
  • The customer-story context that shows how the controls were received by end users.

👉 Read Island’s case study on secure browser controls in call centre workflows →

Enterprise browser controls in call centers: can security improve UX?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Usable controls are often the difference between policy and practice. This case reinforces a simple governance truth: security controls that interrupt workflow are less likely to be fully adopted, especially in user-facing environments. IAM, PAM, and endpoint programmes all face the same problem when enforcement is technically sound but operationally rejected. The practitioner conclusion is that control design must be measured against user completion and adoption, not just configuration correctness.

A question worth separating out:

Q: Should organisations treat browser extensions as part of identity governance?

A: Yes. Extensions operate with delegated access to browser sessions, which makes them a form of shadow identity inside the user environment. If they can reach authentication state or manipulate web content, they belong in the same governance conversation as privileged access and non-human identity controls.

👉 Read our full editorial: Browser controls and call center adoption: what this case shows



   
ReplyQuote
Share: