TL;DR: Remote claims staff can be onboarded through an enterprise browser and private access layer instead of shipped workstations and legacy VPNs, reducing help desk load, hardware cost, and congestion while extending access to mobile devices, according to Island. The governance question is less about convenience than whether existing access models can still support BYOD, mobile work, and internal app routing without expanding trust.
NHIMG editorial — based on content published by Island: WWLW Ep. 19, The Case of the Claims Adjusters
Questions worth separating out
Q: How should security teams handle browser sessions in cloud access governance?
A: Security teams should treat the browser session as part of the access boundary, not just a delivery mechanism.
Q: Why does replacing a VPN with private access change IAM governance?
A: Because the control boundary moves from the network tunnel to the application and session layer.
Q: What do security teams get wrong about browser-based access models?
A: They often treat the browser as a delivery shortcut rather than a policy enforcement point.
Practitioner guidance
- Map remote roles to session-scoped access policies Define which claims applications, data sets, and actions each role can reach from the browser, then separate those policies from endpoint provisioning logic.
- Replace broad VPN reach with application-specific routing Inventory internal applications and route only approved traffic through controlled paths while keeping public internet traffic separate.
- Introduce contextual controls for mobile claims access Use step-up authentication, shorter sessions, and task-specific limits for tablets and smartphones used in the field.
What's in the full article
Island's full post covers the operational detail this post intentionally leaves for the source:
- The remote-worker onboarding workflow that replaces shipped laptops with browser installation on existing devices
- The private access routing model that separates internal application traffic from public internet traffic
- The mobile claims workflow that lets field staff use phones or tablets to capture and enter claims data
- The operational changes that reduced help desk load, hardware cost, and VPN congestion
👉 Read Island’s account of browser-based access for remote claims adjusters →
VPN replacement for remote claims teams: what changes for access control?
Explore further
Browser-based access is becoming an identity control plane, not merely an endpoint convenience. When organisations move work into the browser, they are implicitly shifting enforcement from device management to session governance. That matters for IAM because authentication alone does not define what the user can do once inside the session. The practical conclusion is that browser policy, application entitlements, and identity assurance now need to be designed together.
A question worth separating out:
Q: What should organisations do first when moving remote workers off legacy VPN access?
A: Start with application inventory and user-role mapping, then define which sessions truly need internal routing. That creates a practical migration path and prevents teams from replacing a VPN with another broad trust mechanism that is harder to govern.
👉 Read our full editorial: Island’s claims adjuster workflow shows where VPN-centric access breaks