TL;DR: A customer support organisation replaced a non-persistent VDI with a secure workspace model that stored daily assignments in secure storage and cleared data after each shift, reducing login friction while supporting sensitive-data handling, according to Island. The governance lesson is that workspace controls should remove residual data and simplify operations without weakening access control or session boundaries.
NHIMG editorial — based on content published by Island: Updated: WWLW Ep. 3, the case of the poor content moderation experience
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should teams design secure workspaces for shift-based support operations?
A: Teams should design the workspace around the shift, not around the device.
Q: Why do non-persistent desktops often create governance problems?
A: They create governance problems when the temporary desktop becomes the only place where setup, authentication, and data handling happen.
Q: What should security teams measure in workspace modernisation projects?
A: Measure login time, session failure rates, data persistence after shift end, and the number of workarounds users adopt.
Practitioner guidance
- Map session boundaries to work boundaries Define how long a support or moderation session should exist, what data it may access, and what must be deleted at shift end.
- Separate transient workspace state from persistent work data Keep sensitive artefacts in controlled storage rather than leaving them inside the desktop or browser session.
- Review controls for shift-based and contractor-heavy operations Look for login friction, stale session data, and recovery workarounds in environments where workers rotate frequently or connect from weaker networks.
What's in the full article
Island's full post covers the operational detail this post intentionally leaves for the source:
- How the secure workspace is used to store daily work assignments across a distributed workforce.
- How data deletion after each shift is handled in the operational workflow rather than by user action.
- How the old VDI environment was decommissioned to simplify IT operations and reduce cost.
- How the user experience changed for employees working on slower network connections.
👉 Read Island's post on secure workspace replacement for VDI and shift-based data handling →
VDI replacement and secure workspace design: what teams should assess?
Explore further
Session persistence is often the hidden control gap in workforce security. Organisations tend to think in terms of authentication strength, but the real exposure in high-volume support environments is often what survives after the session ends. If work artefacts remain accessible longer than the shift that created them, the control model is already misaligned. Practitioners should evaluate whether their workspace design matches the tempo of the work, not just the sensitivity of the data.
A question worth separating out:
Q: Who should own workstation access governance across IAM, PAM, and endpoint teams?
A: Ownership should sit with identity and access governance, with endpoint teams supporting device posture and platform teams supporting session enforcement. Workstation access crosses human IAM, privileged access, and endpoint control, so accountability has to be shared but clearly assigned. The goal is one operating model for access, audit, and session state.
👉 Read our full editorial: Secure workspace replacement for VDI reduced friction and data risk