Inside the Enterprise Browser Rebuilding Security for the AI Era | Bradon Rogers, Island

13 Jul 2026 · 56 min · 22 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Braden Rogers (Island) discusses securing AI browsers and agentic workflows when they move from consumer use into enterprise environments. Key risks include prompt injection via hidden instructions in apps, agents exfiltrating corporate tokens/data to personal AI apps, and “shadow” AI extensions (claimed 18,000+). Island’s approach: keep user and agent actions inside enterprise policies by enforcing guardrails locally in the browser, consumer-browser extension, and Island Desktop (host).

Key claims

AI empowerment should be “AI-first” without abandoning regulatory/data-protection requirements; policy-based governance enables safe use of personal vs corporate AI providers; agents are “an empty chair” acting on a user’s behalf and must be confined to policy scope; visibility and audit logging provide a “virtual paper trail.”

Notable examples

an agent connecting users on a social platform while policy prevents crossing into personal boundaries; Slack becoming agentic and governed via browser/app and MCP calls.

Guests

Braden Rogers, Chief Customer Officer at Island.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Risks of AI Integration in Enterprises

0:00 to 0:55

Explore the risks associated with integrating AI browsers and agents in enterprises.

“Can you talk about the risks that are developing with AI browsers and autonomous agents as they are designed by consumers or by users, but then are being integrated into the enterprise?”

The Role of Automation in Enterprises

0:55 to 1:40

Learn how automation enables teams to create effective agents in enterprises.

“I usually start by having you introduce yourself to listeners and give as much of your background as is relevant and how you got to Island.”

AI's Impact on Workflows

2:00 to 4:54

Delve into how AI can empower users and improve their workflows in enterprises.

“and the breakneck speed with which everyone's experiencing AI.”

Managing Chaos in AI Adoption

4:54 to 8:07

Understand the challenges organizations face when adopting AI technologies.

“because I think it's this series of AI resources.”

Island's AI Integration Strategy

8:07 to 10:22

Explore how Island integrates AI into enterprise environments to enhance user experience.

“And at the end of the day, the evolution of the browser, for our original use, was consuming information and then all of a sudden it became an application delivery.”

Introducing AI Protect

10:22 to 13:04

Learn about Island's AI Protect feature and its role in safeguarding enterprise data.

“It doesn't take a lot of search through Reddit threads and things where people have experimented with these agentic browsers.”

Future of Agentic Workflows

13:04 to 14:01

Examine how Island adapts to evolving AI technologies and supports agentic workflows.

“hopping out of this seat and you see an empty chair, but the agent's doing work on my behalf.”

Understanding Modern AI Protocols

14:01 to 14:54

Learn about the challenges and protocols in AI-centric environments.

“many times in the universe of uh of of ai you also get into conversations that are you know other protocols, more modern AI centric protocols like MCP, you know, calls.”

Risks in Agentic Workflows

14:55 to 17:01

Explore the potential risks associated with agentic workflows and data security.

“People are going to push the boundaries.”

Guardrails for AI Agents

17:02 to 19:15

Discover how to enforce policies and guardrails around AI agents.

“Again, a very smooth experience, but we want to let the user also, by the way, because the agent doesn't exist independent of a user.”
Show all 22 chapters

Onboarding and User Experience with Island

19:16 to 23:04

Understand how users can easily onboard and interact with Island's tools.

“Audited and logged so that there's a virtual paper trail of everything that goes on.”

Enterprise Focus of Island

23:05 to 24:17

Learn how Island targets enterprises of all sizes for its solutions.

“I mean, you were saying that you go to the App Store and download the app.”

Deployment Methods for Island Software

24:18 to 25:57

Examine different methods for deploying Island software within organizations.

“They can use as many browsers, as many devices.”

Automation and User Workflow Optimization

25:58 to 28:10

Discover how automation can streamline workflows for enterprise users.

“There's a couple of ways to go about that.”

Observing User Workflows for AI Integration

28:10 to 33:04

Learn how observing user workflows can enhance AI capabilities in enterprise settings.

“You know, when Elon Musk, you know, has gone down the path of building autonomous vehicles, he didn't put, you know, inspection points at every intersection and watch how cars drove at every intersection.”

The Future of AI in Enterprises

33:04 to 36:36

Explore the trends in enterprise AI adoption and the potential for multi-provider ecosystems.

“So with these new products and new capabilities, where do you see this going?”

Island's Approach to Solving Tactical Problems

36:36 to 40:48

Understand Island's methodology for addressing tactical challenges with strategic solutions.

“Can we pull back a little bit and give me a little bit of the history of Island and then the chronology of the different products.”

The Status Quo in AI and Network Infrastructure

40:48 to 42:07

Examine the shortcomings of current strategies in leveraging AI within existing network infrastructures.

“Braden, what would you think I should ask from here?”

Integrating AI with Internal Resources

42:07 to 45:30

Learn how organizations can integrate AI technologies with their internal resources and applications.

“And that's really important in the AI generation, because orgs are going to have internal MCP resources.”

Scaling AI Solutions in Organizations

45:30 to 47:58

Explore the differences in AI solution implementation between small and large organizations.

“We've got customers already using it in production at scale.”

AI-Driven Insights for Policy Management

47:58 to 50:46

Discover how AI-generated insights can help organizations manage policies and vulnerabilities.

“You were talking about how Island proposes workflows and other tools to the user after observing how the user is working.”

Streamlining Operations with Island

50:46 to 55:29

Understand how Island streamlines operations and simplifies policy management through automation.

“Does that mean that there needs to be kind of a manager watching what people are doing within Island?”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Can you talk about the risks that are developing with AI browsers and autonomous agents as they are designed by consumers or by users, but then are being integrated into the enterprise? There are a lot of agentic tools that are not being developed inside the enterprise. The agent is working over an application. There's hidden instruction buried in the application. The agent goes and follows those instructions, thinking there's the human giving them instructions in the process. The agent's nothing more than me hopping out of this seat and you see an empty chair, but the agent's doing work on my behalf.

0:34And we want to have policies that are built and let the agents operate in the confines of a given policy, no more, no less, and make them live in a place where they can be enterprise ready, no matter what the AI provider is that you're using. Automation enables teams to build and run on-demand agents that operate at speed across enterprise applications. How does Island keep track of what's being built by teams in an enterprise?

1:03I usually start by having you introduce yourself to listeners and give as much of your background as is relevant and how you got to Island. and then what Island does, and then we'll start talking about keeping the agentic world safe. I mean, that seems to be one of the focuses. Yeah, thanks, Greg. I'm Braden Rogers, Chief Customer Officer with Island. The role that I play is anything that's technology and engineering-centric that's in the field that touches customers. is the world I work within every single day. Island just announced some new functionality. Can you talk about that? Yeah, 1 ,000%.

1:54First of all, it's important to acknowledge the incredible innovation that we're seeing every single day and the breakneck speed with which everyone's experiencing AI. And, you know, it's everything from people leveraging generative prompts to exchange information and to make their work more effective. And it's obviously led over into some really interesting areas around automation and agentic workflows as people have engaged it. And I think it's important to acknowledge that many of the players that are doing this work are doing some incredible work. A lot of your different providers, the big brand names that everybody knows well that are the AI players.

2:39But a lot of the work that we see from that ecosystem is very consumer driven. There's nothing wrong with that. At the end of the day, they're chasing billions of users around the world. And, you know, but at the end of the day, when you're a large financial services firm or a large healthcare provider, you certainly have concerns with these things, you know, making their way into your environment. And then also the other thing is you want users to be empowered. You want to, so you want to, you want to wrestle with this consumer need, this consumer thing. and there's some goodness really there's amazing goodness with it um and you know we certainly believe ai is here to kind of kind of help us in the future not to decimate our futures and but we want to be able to harness that and leverage that power and enable our users very effectively and for us you know there's there's an there's an avenue for that's really focused around enabling the user but most importantly is allowing cyber security have a role in one of those rare times in the universe of cybersecurity of being a true enabler.

3:43Let's weave AI into the fabric of the user's workflows and let's do it safely and let a cybersecurity team play a very deep role in that enablement. And that's what we announced yesterday with a series of capabilities focused around the universe of AI that's square in the laps of everybody in the enterprise today. Yeah. Can you talk about the risks that are developing with AI browsers and autonomous agents as they are designed by consumers or by users, but then are being integrated into the enterprise? Is that the issue really, that there are a lot of agentic tools that are not being developed inside the enterprise but are being brought into the enterprise?

4:39Or is it even for tools that the enterprise is building inside the company? Great question, Craig. I think it's important to – I'm going to go up a level real quick before we go into the agentic side. because I think it's this series of AI resources. Sometimes they're agentic resources. Sometimes they're environments where users are engaging our corporate data into a prompt. Sometimes they're developmental tools with various forms of vibe coding resources that help us speed development of applications. But there's a whole series of resources people are bringing to the table for their jobs. and you know i think it's i think it's fair to say that you know your average user can find immense value in ai as a as a bit of a cheat code for the things that were difficult in their job may you know and you know sometimes it's about the knowledge that it can bring forth that otherwise they they may not have expertise in sometimes it's about automating their workflow sometimes it's building an app that you know now now a non-technical human being can create an application that's very sophisticated.

5:47But these things are coming at the organization so fast and so furiously that the organization is faced with, you know, just because these things have a lot of promise did not mean you abandoned your fundamental requirements. If you're a financial services firm or healthcare provider or any other technology or enterprise, I should say, it didn't mean you abandoned your requirements. And by the way, they're more important than ever. Your regulatory bindings that you're having to live by. Yeah, it's even harder now to live by those bindings with this universe of chaos coming to the table. Your data protection needs that you had, you want your users engaging the sanctioned stuff, not the shadowy universe of stuff.

6:26And so at the end of the day, it's the chaos. The orgs are trying to wrestle with the chaos. But then while they're wrestling with the chaos, not turn into the no police. because, you know, I think it's a very fair statement that a lot of the world wants to be AI empowered. A lot of organizations are thinking about how do we be forward leaning? How do we think AI first? And thinking AI first is not saying no to everything for your end users. It is shepherding and weaving in the sanctioned world of AI into their workflows and empowering them to use AI as their first thought process when they go to get into something that's creative or building something or being more effective, faster at their job.

7:11And so for my universe, or at least the way I think of it is, I want to think about AI empowerment first and AI mindset first for people that are thinking that way. And how do I encourage a user who otherwise might not think that way to naturally gravitate that way because it's now in their natural workflows to make their job easier, but it's also safe. And that is, there's a number of different angles in this whole thing. There is definitely the chaos that it's the onslaught of stuff that's coming at the organization that it's hitting them before they've got their sanctioned answers and their core strategy in many cases.

7:42Yeah, explain then how Island works with the enterprise. Well, I think it's important to highlight what we built at Island prior to AI. Just, you know, if you think about the workspace for the user, the majority of the work of a user is spent day in, day out using a browser. and it's a great piece of technology. It's one of the most important pieces of tech that has been around since the advent of the internet, obviously. And at the end of the day, the evolution of the browser, for our original use, was consuming information and then all of a sudden it became an application delivery. We receive our applications in that window.

8:22Yet the mechanics of that browser are not built for that purpose. They're actually built for shopping. I mean, you think about the targeted advertising and the focus around the analytics around the end user. It's a consumer-focused need, and that's okay. It's just that we said, look, there's some potential, kinetic potential, you know, pinup in that browser. What if we can uncork that potential and transform the browser actually into an application delivery platform where we build mechanics and policy to live locally for the experience of the end user? Things like, you know, building in data protection, building in contextual awareness, building in protection for the user as they, you know, engage the broader, you know, internet.

8:59But we want to use policy locally to govern that experience and then also make the user more productive, productive in a basic way, just as a starting point. They already know how to use a web browser. We don't have to train them. So what if you could just start putting mechanics of their work right at their fingertips in the, you know, again, woven into the fabric of the browser? And that's where we started the journey. And then, you know, along comes AI and its natural habitat as a browser. You know, for much of what the user engages, AI's universe is browser centric. So as a starting point, you know, then starting for us is weaving the AI mechanics into that user's workspace so the user has seamless access, but always bound by the policies that we had in play before, the data protection elements, shepherding them to the right tenants, you know, the right corporate copilot versus personal or the right, you know, Gemini environment versus personal.

9:50Or better yet, let them go to personal, but don't let the corporate data spill over the boundary, you know, into the tabs that are the personal tenants. So all of those are, you know, kind of fundamental mechanics that is what we launched yesterday is about the empowerment of the end user to take advantage and leverage AI and then taking it a step further is taking it into areas for agentic workflows, allowing agents to have the ability to operate in the workspace of the user, but have appropriate guardrails. These are all very important foundational things. And you've certainly seen stories. It doesn't take a lot of search through Reddit threads and things where people have experimented with these agentic browsers.

10:27You see analyst firms like Gartner publishing research saying, hey, be careful. Stay away from these agentic browsers in the enterprise for now. And there's a reason for that at the end of the day. We've got to put control around it and minimize the chaos, but also, again, back to empowering users. Well, let's talk about some of the new products. AI Protect, which allows safe usage of any AI application, consumer or enterprise. How does that work? I mean, where is that a plug-in to an AI browser or is it something more horizontal? Yeah. So if you think about how the user may engage AI, they're going to engage AI in their consumer browser, their Chrome or Edge.

11:14They're going to engage AI in an enterprise browser like Island. Are they going to use localized applications such as, you know, their local clients for ChatGPT as an example or whatever the tooling may be? For us, what we announced is the ability with AI protection is to live anywhere the user lives, whether they're working in the enterprise browser, if they're working in a consumer browser, using the Island extension to assert our policies inside the consumer browser, and then using Island desktop, which is a service that lives locally on the host to assert policy outside of the browser and govern the usage of AI resources.

11:48No, again, no matter where the user's working, govern those AI resources accordingly. That's exactly what AI protect is. AI protect is really two fundamental, very foundational things for Island, but very difficult for most status quo traditional providers. It is about having visibility, understanding who's using what, and building policies. And many of those policies, while they may seem very simple, like many upstream technologies have a hard time saying, yeah, let's let users use personal Gemini. And the company data is not going to spill. There's no risk of company data. No, what they do is the strategy, which you see oftentimes, is a strategy that's like you think about the pinch points, the upstream pinch points.

12:32We're passing traffic back through a cloud and inspecting at a pinch point. Their strategy has to be a block page. They've got to block the personal stuff. That's assuming I can even identify the tenancy accordingly. But we take quite a different approach to empower the end user. if they're using their consumer browser, they're using their enterprise browser, using the local clients, let them use personal stuff, but recognize when they're using the corporate resources and bring them into the fold, into the boundary so that they can have freedom of movement. And the agents fall into the same types of flows as well.

13:03Again, the agent's nothing more than me hopping out of this seat and you see an empty chair, but the agent's doing work on my behalf. And we want to have policies that are built and let the agents operate in the confines of a given policy, no more, no less. But again, make them live in a place where they can be enterprise ready no matter what the AI provider is that you're using. So for example, Slack is becoming agentic. How would Island handle that? I guess Slack is delivered either through the browser or through an app. This desktop functionality, how does Island wrap around that? that sort of thing you know an app like slack or any other app it's gonna live in the browser it's gonna live as a local thick app and the user engages those interfaces and those interfaces could they may be making web calls over here um the thick clients can be making web calls too because a lot of times thick clients are kind of browsers in disguise as electron apps but then many times in the universe of uh of of ai you also get into conversations that are you know other protocols, more modern AI centric protocols like MCP, you know, calls.

14:15And so, you know, for us, the ability for the user to use whatever client they're using, whether it's in the browser or a fit client and asserting our policy over those things, including MCP calls at the end of the day, so that when the agent is engaging something, the agents even doing it within the permissibility scope of what it should should be doing, not falling victim to, you know, I should go over here now and go to personal Gmail and start grabbing tokens from here or taking corporate tokens from this environment over here. And, you know, those types of things that we've seen, again, that have been proof of concepts over and over again, shown around a lot of that agentic world, you know, going amok.

14:53And again, it's early. So, you know, a lot of that stuff is naturally going to be experimental with. People are going to push the boundaries. We just want to make sure that the enterprise can take advantage of that stuff, you know, today and feel safety in doing that as well. So the Slack clients, agentic workflows, just like any other agentic workflows, whether there be a browser-based agent workflow or something outside the browser is really the scope of what, you know, we're focused on tackling. So the listeners understand the risks that you're addressing. What, give some examples of what can go wrong.

15:24First of all, I think it's important to point out that, you know, going back to the conversation of that, these, a lot of these things that's focused around the consumer need. So perfect example, you've seen examples of, you know, there's, you can search a couple red thread, you'll see examples of people exploiting the agentic workflows for prompt injections, for example. The agent is working over an application. There's hidden instruction buried in the application. The agent goes and follows those instructions, thinking there's the human giving them instructions in the process. And then the next thing you know, the agent's over here grabbing, you know, tokens, you know, corporate tokens out of a Gmail account that were sent via email, and it shouldn't be doing that.

16:03But at the end of the day, it's doing it and it's following what it thinks are instructions um we've got users that are very basic level type stuff users taking corporate data launching a personal app ai app and taking corporate data over to that personal ai app in a place we don't really want it because we just lost custody of our data because now it's now it's gone into that ai provider's ecosystem um it comes from a lot of different extension ecosystem you know you've there's i think i read the other day there's like 18 ,000 plus classified extensions that are classified as AI. That's a shadowy worm of things that wind up in your environment.

16:38You don't even realize they're AI living in your environment. There's another angle we've got to think about how we govern. So there's all kinds of risks of, again, it's a lot of it's centric around the data that you have in your organization, but in the agentic world, it's also centered around what the agent may do autonomously on your behalf, thinking it's doing the right work and inadvertently doing something it shouldn't be doing. So we want to build guardrails and policies around those agents, just as we have around the end users. Again, a very smooth experience, but we want to let the user also, by the way, because the agent doesn't exist independent of a user.

17:11User sends instructions. We want to let agentic stuff be presented to the user to be able to take advantage of these things and not have to worry about the risks themselves either. How does it work under the hood? Because yeah yeah 1000 so anywhere you assert an island policy whether in the browser or whether you assert it inside of the extension or inside of island desktop again you think about the movement of of an agent the movement of the agent is moving in a very similar way akin to the end user i'll use an example yesterday i was doing some agentic work and i asked it to go to a social media platform and find and connect me to certain people that were in the sphere of a particular topical area that I wanted to learn about.

17:56And I let the agent go and do that work. At the end of the day, the agent would be bound by a policy that lives in the browser in that given example. So if the agent decided, oh, it saw some instructions to go over and take this data from here and go over the boundary to the personal stuff or some other area it shouldn't post the data to, the policy lives in play and keeps it from doing that. So the agent would still bump into the guardrail that was there for the user. And maybe we may even have more rigid guardrails for the agent for certain things as well. So the guardrails could confine the agent to specific sets of work, like only automate this one thing, but don't go out beyond the confines of that.

18:33So policy lives locally. That's really important. Lives locally in the browser for those things. Lives locally in the extension, asserting itself in the consumer browser, and lives locally in the host with Island Desktop. Again, those were all announced yesterday as well, part of the Island Enterprise platform. And then so as a result, when the agent starts asserting its will, oh, let me go touch this thick application outside the browser or touch this folder in the file system. The Island desktop is asserting its policy for the agent, just like it would a user in that particular case. And then when the client is engaging some MCP resources as well, we assert our will in that process as well.

19:08So that again, anything going into the MCP flow or coming out has been governed or at least audited at the appropriate level for those engagements. Audited and logged so that there's a virtual paper trail of everything that goes on. How is it configured? I mean, does the enterprise, how do you work with an enterprise? Yeah. Well, I think one thing that's important to point out about what we've built for the past five years, it's a very novel approach to asserting our will, our organizational will. By the way, the will is not just cybersecurity. security it's our will for productivity resources for the end user and automation resources for the end user and digital experience and stuff like that but it is a very novel approach you know you think about it you already know how to use a browser today craig if i had to onboard you in the universe of island i would tell you to go to the app store of your device of choosing or go to the island download page and download island and something tells me somewhere in your past, you've actually downloaded and installed a browser probably many times in your life.

20:16You launch Island, you log in. The org has built a policy that the moment you log in, the browser and our services instantly reach up to the cloud, grab the policy that the organization built, and boom, all of a sudden your application entitlements are provisioned for you. The policy's provisioned locally, the automation resources, et cetera, are all provisioned locally. So for you to onboard yourself as an end user, it's a self-provisioning exercise because you You need to know two things in the universe of Ireland as an end user, especially if you're self-onboarding. You need to know how to go to an app store and download an app, in this case, our browser.

20:49Second thing you need to know how to do is log into the single sign-on provider for the org that you work for. If you've ever logged into your ENTRA ID or Okta environment, you're done. All of a sudden, context, based on the positioning of the policy that the org built, is now staged for the end user. So the end user's experience is literally nothing more than engaging the familiarity of a browser. And this is why we don't require any training for the end users either because they just now see it and they go straight to work instantly wow and so island can can find and read all the the policy documents required to to govern uh agentic uses and that sort of thing yeah so you obviously the org is going to build a policy at a time the policy is going to have all this and by the way many of our island customers already have these data protection policy they've been building them working with island for years and deployed at massive scale so they built these things.

21:41And so now they've already built them. Now AI comes into the fold. You simply empower, enable the capabilities to integrate to your proper AI providers. Now AI is, the AI is elements are living slipstream right into the existing policies that the user already has. And as we continue to evolve capabilities, we'll always just evolve and begin to slipstream straight into the capabilities of the end user. And that includes even new apps in the AI universe. One of the things we announced yesterday was this area around AI publish. You want to be able to leverage resources like Vibe coding tools like Lovable and Cursor and Cloud Code, stuff like that.

22:21You want to build those apps and be able to deliver them and actually have them run and then have those apps slipped right into the island policy as people deploy the apps and deploy them at the same speed that they're deploying them in the Vibe coding tools that they're creating. So the speed is matched for deployment that is happening within the delivery. but cybersecurity policies are never abandoned in that process because it's literally slid right into the exact policies you already have because again that world is very much even though they're ai-coded apps they're web-based apps they're they look and feel web-friendly you can build thick apps but you know most people are building web-centric type apps if you know they're very rich type stuff and uh again you don't have to walk away from all the stuff you built in the past that it was important for you.

23:03Yeah, but this is a B2B product. It's not B2C. Or can it be B2C? I mean, you were saying that you go to the App Store and download the app. How do enterprises use it? Do they have a, is it by seats or, yeah. Yeah, it is definitely an enterprise focused. And I say enterprise. It's not just for the large end of town. It's for the small end of town, too. So we've got orgs that are small orgs that are getting value out of Ireland because that small org, let's say you're a small bank with 200 employees. You have the same regulatory bondings that a large, massive bank has and has to live up all the federal government requirements and maybe international requirements as well.

23:57You still have that, but you can't afford the same stack they have. You don't have the same practitioners and resources, so you need to do more with less. And we empower that for the smaller org. So it's an organizationally focused effort, not focused on consumers. Its focus is around, you know, user-based pricing at the end of the day. So it's pretty simple. You know, at the end of the day, a user can use as many apps as they want. They can use as many browsers, as many devices. That's not a consideration. It's not a concern. So we just make it really simple for people to be able to consume at the end of the day.

24:31But let's say an organization with 200 people, do you charge by seat and then you deliver an app for each of the 200 people? Or each of the 200 people downloads the app on island on their enterprise's license? How does the organization get Island into its employees' hands? Great question. So it goes one of two ways. I used the extreme example earlier when I thought about Craig going to the App Store and downloading the app. That's often what we see in the unmanaged real estate, a third-party contractor, an unmanaged device, a third-party BPO, business process outsourcer. You've outsourced your call center to a third-party entity.

25:21because you don't have the ability as an organization to force install software on somebody's machine you don't own. That breaks the laws of physics. So we give an easy way to onboard for the unmanaged, but on the managed side, you deploy like you do any other software, leveraging your existing software deployment methodologies that have been in play for years. So we just slip island into those processes. And oftentimes in many of the orgs were widely deployed. We're just part of their core build when they ship a device to somebody. Island is just part of the foundational build for those people in that case.

25:52And then the onboard themselves, they just go log into the SSO and they go to work. Automation enables teams to build and run on-demand agents that operate at speed across enterprise applications. uh does uh how does uh island uh keep track of what's what's being built uh by teams in an enterprise or is it as long as you're working on an island desktop or or in an island browser everything is automatically covered or does somebody have to submit a new agentic capability to island to be reviewed? There's a couple of ways to go about that. the most effective way is to leverage AI automation in the construct of provisioning workflows for your end users that are enterprise-grade workflows.

27:05The thing you want is you want predictability out of your workflows for your end users. You want to take, let's say, a call center worker, and you know that it takes them 10 minutes to accomplish this task when someone makes a call in for a reservation or for getting an account status. You don't want them to have to go through and learn that process. And sometimes those processes could be across three or four different apps. They got to learn. You hire the new, there's the onboarding experience that they got to learn the process. And especially if you're outsourcing to a third party, it's even more painful.

27:39It wouldn't be great if they could just push a button and it goes and accomplishes those tasks. So a big part of what we do is pre-staging the workflows that we publish. Publish those workflows to the audiences of users. And then when the user visits that part of the application, serve up reminders based on the learnings we have about that user. Like, for example, one of the things we're really heavily focused on is learning the role of the end user, understanding the nature of the end user. I use a parallel. You know, when Elon Musk, you know, has gone down the path of building autonomous vehicles, he didn't put, you know, inspection points at every intersection and watch how cars drove at every intersection.

28:27That's how the existing world of technologies, you know, when you, especially when you think about the cyber universe, would approach the problem. They would, you know, they get the pinch points, the upstream cloud proxies, and, you know, just everything's being zeroed in on a specific pinch point so it can explode outward. It'd be akin to Elon Musk trying to learn how people drive cars by putting cameras at every intersection. Didn't do that. They sat in the seat of the car. They observed how traffic works as you drive down a street because not every street is an intersection where a camera would be in the pitch point example.

Read the full transcript

28:59And so what you do is you start observing what traffic looks like, what patterns look like, how you capture that data for that learning. And then you instrument that in a way where you can now automate vehicles. There's a lot more that goes into that, obviously. We're doing the same thing. We want to do the same thing for the end users. as the end user engages apps, observe their workflows, understand what they do, because that's not a packet level engagement living up in the network somewhere. If I observe their workflows, then what I can do is learn the nature of that user, the type of work they engage.

29:32Oh, that's a nurse practitioner and we see them doing this, this, and this. Well, wouldn't it make sense for us to present to them proactively on the screen? Here's some prompts you should use to make your job easier. Oh, by the way, here's some workflows that we provisioned for the organization provision for you. So you don't have to learn the check-in process for this patient when they enter the doors of the facility. You push these buttons and it goes through the five systems to do the basic work, shrinks tasks down from five minutes of work to 30 seconds or 10 seconds. And so we get predictability out of those workflows that are reliable, that don't go off and go awry and start doing other stuff.

30:10And we leverage the agent in the process to handle the delicate parts where, you know, things in the application may have changed. Someone changed the name of a button on a screen. Your traditional automation technologies would have broken with that stuff. Leverage agent for those types of delicate tasks. But that way the agent doesn't go amok. It stays in the course of the specific task it's engaged in. And then also one of the most important things is on the back end, measure that. Because it's important to understand, are we getting benefits from these things? And if you can turn around and say, yeah, 3 ,000 call center workers use these 10 workflows repeatedly on average of 30, 40 times a day per worker, there's a lot of time savings that can come along on that stuff.

30:49If you can, on the back end, give the value of that. And that's a heavy, heavy focus is not just providing agentic workflows, but making them enterprise grade, making the enterprise ready for the right audiences of users based on the context of the user and then measuring on the back end. Is Island learning as you operate within its environment, learning your workflows and, as he said, then suggesting new workflows or more efficient workflows? Yeah, listen, if you think about the AI universe in general, one of the core things, and you hear this from many of the founders of the various providers, many of the core exec teams, they talk about their building.

31:33One provider in particular, they were just right out and said it. They're learning the profile of the end user. They're learning their workflows of the end user, but they're not focused on what I just talked about. They're focused on targeted advertising. It was stated just directly. And that's why you saw, by the way, in the Super Bowl ads, I thought it was really funny, actually, when Anthropic had those cute Super Bowl ads that were all talking about the advertising. It was really funny. But that world's all about that in the first place. We're just taking it using that type of effort for an empowerment capability for the end user to be effective at their job.

32:09And at the end of the day, again, always within the guardrails. By the way, always as well respecting the privacy of the end user, making sure that we don't run off skew of privacy concerns or issues there. So empowering that for the right audiences of users based on the right contextual situation. The user somewhere in a given geo around the world that that is not acceptable. This is everything we do in the world of Ireland from an audit logging and from an information understanding is governed by context. It's not some fixed level of audit logging that's verbose all the time. You know, this audit policy is contextually driven.

32:46So the U.S. user, we do this for them. But someone else in a different part of the world, we may anonymize something if we need to, or a different application engagement. Anonymize that one versus capture screenshots on this one. So it's very, it's delicate to meet the needs of the privacy folks that have those concerns and those privacy mandates they have to live up to, too. So with these new products and new capabilities, where do you see this going? Do you think that you're helping enterprises move deeper into AI and AI agent workflows? or is it that it's a problem that exists today that will eventually be taken care of by AI itself or different agentic platforms?

33:47Will they build this in or will they adopt islands as an API layer? Yeah, so that it's not being applied by the enterprise. Yeah, how do you see this developing? Well, it's important to point out that organizations are going to be multi-provider organizations. It is, you know, and they're already that way. They don't, sometimes they don't even know what they are. But the sanctioned universe of AI will come from a million different angles within the organization. You will have legal teams that want to use a given AI provider for that specific to their universe. You will have medical practitioners.

34:26You know, you even saw recently, you know, with ChatGPT Health as a good example of that. Anthropik had some answers for that as well. But you see different needs for different providers and different models. They all have strengths. You know, you see a lot of development audiences naturally leaning into things like Claude, for example. And so they'll be coming at the organization from 15 different angles, maybe even 20. They'll all have enterprise agreements across these things. Each one of them is going to have their own unique front door to leverage their resources. What we want to do is we want to let the organization leverage the mechanics of the island policy, build integration natively to those providers.

35:06And so when the user accesses any of those resources in their agentic workflows, in their generative work that they're doing and beyond, we want to leverage in a single interface every single one of the providers simultaneously. simultaneously that way you have one set of policies you have one set of resources you have one set of experiences for the end user and it's not the wild west anymore you put some orchestration and a little bit of organization around it as you enable the end users but i see that's where the future the future holds because orgs are going to be signing all kinds of specialized resources and they're going to have them at the end of the day but you're not going to want oh the my level of fidelity and policy is lacking over here.

35:48We all that's we're cool with that. And this one over here, we got really deep stuff. And because every one of the providers is all going to have different if you've gone into the AI providers, as a consumer, just go to the settings. They're not all the same in the settings. Some of them have different settings and capabilities and things. So but you don't want non uniformity at the end of the day when you're an organization. You know, it becomes chaos from a manageability. It's just it's it's it's unmanageable at the end of the day. You want manageability by having singular policies, singular sets of audits, singular sets of stuff, but then, you know, harness the power of every one of those providers.

36:20And that's where I see the future is as orgs begin to adopt the next one, the next one, the next one, they just integrate it right into the mechanics of Island. Uh, at the end of the day, now it's living just like the other providers are living on it. And it's all the same confines and empowerment that the other providers are living in as well. Yeah. Can we pull back a little bit and give me a little bit of the history of Island and then the chronology of the different products. And so we can see where you've moved to this most recent set of products and then talk about where you see Island going from here.

36:58Yeah, great question. So we think of everything at Island not as a technological problem. We focused on the core use cases a customer has. and then there's a set of mechanics that have to solve that use case. But philosophically speaking, we use this phrase internally quite a bit and hopefully it makes sense externally as well. We talk about being technically strategic. That sounds kind of weird to say, but let me explain a little bit. As an organization, you've got an initiative to solve a BYO problem. Well, someone says, all right, let's grab a team of people internally that are all smart and let's solve this BYO problem.

37:34So you'll set up a stack of technologies. You'll set up processes around BYO, and you'll feel good about whatever that approach was, or maybe you won't feel so good. I don't know. It depends on what you selected. But you'll solve that. Someone else comes to the table and says, hey, we've got a merger and acquisition scenario. In fact, we're acquiring companies all the time. We've got deal rooms over here, and we've got these people we're acquiring, and we've got to ship them devices and onboard them. let's go figure out process for that and the stack of technologies that and that byo initiative over here in many cases didn't do a whole lot to affect your outcome on this one these were tactical tactical and then the next thing comes along tactical again next thing along this is why you wind up with this bulk of stuff that are all disjointed because you solved the problem in a vacuum of anything that could be a strategic outcome this is a very important thing in the universe of Ireland and the enterprise browser is, is we think of it being tactically strategic.

38:33The mechanics that we needed to solve contractor for data protection, for private access needs, for accessing internal apps built natively into the browser. They were the same mechanics that I use because the policy lives locally. If I've got now got to onboard somebody to a virtual deal room, it's an emergent acquisition, those same mechanics get applied there, but I might need these additional things. So we built a handful of additional capabilities and I'm not going to go through all the chronology of Island, but all it took was some incremental capabilities because you need the data protection.

39:05You needed the contextual awareness. You needed the private access to the internal deal room resources. You just needed protected accounts, the ability to leverage injection of credentials for the user. And that was the next step for that use case. Oh, your next use case was let me eliminate my virtual desktop infrastructure. Start thinking about how I get rid of that kind of stuff because I don't love that experience. Well, think about contractors. You're onboarding the contractors today and you're often using all the things we did early in your existing contractor world outside of Ireland. You're using VDI for that.

39:36So all it took for us was incremental steps. And what I'm getting after is it lets the org tactically solve an initiative, but more with an eye toward a strategic outcome because the same exact architecture, the same exact mechanics lets you go tackle the next thing. and then the next thing and you just add an incremental thing so back to your question you asked a moment ago that leads us up to what happened yesterday with these announcements these are for us incremental things that are really important but they build upon the foundation of what we've already got and they fit naturally into that flow so it's not some artificial bolt-on that you see with you know an upstream cloud provider having to bolt on something to get actual visibility over prompts like it's not you're looking at packets you're not looking you're You don't have a presentation-level point of view, so you're having to reassemble packets artificially for that kind of stuff.

40:23So for us, these aren't bolt-ons. They're just natural next steps for that given use case that comes up. So the customer brings the next use case, and we might find all these things are replicable. It requires two additional things, and then we go construct that, and now we have an additional use case. But it's problem-centric, again, with tactical design in mind, strategic outcome in mind after you solve the tactical issue. Does that make sense? Yeah. Braden, what would you think I should ask from here? Yeah. Well, I think certainly hitting on the status quo conversation, what are some of the status quo things people use today to try to assert their will in this AI universe?

41:05And I can go there. I can go hit a number of different areas that are just where the status quo fails. Like they're just not, they're just not assembled to live in the AI universe. And so, you know, the strategy from your status quo players is often, and I said a little bit about this earlier, but the status quo is, it's a block page. I got to block you from getting to personal stuff. That is not a strategy. That is not a strategy for enablement of the user. How do you enable the agentic workflow and make it a part of their fabric and to make recommendations of prompts and things like that? If you live in the network path, you don't have it.

41:42You sit on the sideline watching this conversation. I mean, do you want to talk more about that? Or that's why I was trying to get kind of a map of islands so that I know where to focus. Well, here's why I was going there, because that lets me lean into our future work on the network side of things, the SASE universe, because then I start redefining how people leverage network resources. And that's really important in the AI generation, because orgs are going to have internal MCP resources. They're going to have their internal apps. They've got to be a part of that fabric as well. And today there's a big separation, a lot of separation between internal resources and the universe of public AI resources, et cetera.

42:21Yeah. So talk about that. So if you consider the status quo of how you would layer your existing technology stacks in an AI universe, well, your VDI infrastructure doesn't have a whole lot of play. In fact, there's almost maybe a little bit of irony of using AI in a VDI environment, the benefit of all the AI stuff and now living in this terrible experience. your upstream providers, they have a limited point of view on this because at the end of the day, it's not a packet conversation. I think of it this way, you're not going to understand the disposition of a workflow by criminal investigations.

43:06They come to a crime scene, they start picking up evidence, and they try to forensically put the pieces of the puzzle together based on the evidence they see. That takes a little bit of time and it's effort. You can be wrong you may not you know you might make mistakes but wouldn't it be a lot better if you had a camera that just showed you everything um but because you're sitting there in the network you're reassembling stuff try to reassemble the picture what happened versus sitting literally at the screen of the user observing what happened um this is why you don't see you know a lot of the networking technologies these upstream will abilities to search yourself that's why they're sitting on the sideline in these conversations with their block pages you got to block this and block that and block this that's not ai strategy um and then uh you know more more importantly as well is you got to think about how we modernize access to those resources where networking is important because you've got internal resources orgs are going to have their internal clusters many modern many really advanced orgs have their own internal clusters they can afford it but they're going to have apps and resources internally that that ai universe is going to have to play with, meaning it's going to have to engage and let AI help you in that application engagement, whether it be for automation or whether it be for just summarizing the content of a series of application elements to give you, you know, glue these pictures together across these apps.

44:22But sometimes those things will be internal. So, and those things could be MCP resources as well. So rethinking how we instrument our path to access those apps, but still letting the presentation be the fundamental point of view where we where we understand what the user is doing again back to that camera analogy you know it's it's not a we're not trying to piece together forensics here i want to observe and how do you observe you watch something and if i can watch what the user is doing i can understand what workflows they should have i can then understand they need to talk to these internal resources etc and then it's a very seamless experience again versus upstream trying to do some weird you know assertion of the unnatural in that case yeah you know there's a lot of talk about uh with with companies fielding products uh acting as customer zero or client zero i presume uh you guys are an island user as well as the company providing it can you talk about yeah i do a demo for a customer of island i show island using island i i show a lot of that um the But the good thing about what we're building and what we've demonstrated yesterday, the actual technologies, we built the technology over the course of the past year.

45:37We've got customers already using it in production at scale. We just, you know, essentially look at it this way. We kind of came out of stealth yesterday, but we already built the technology, you know, in those areas. We've got customers using those technologies in GA environments and production large scale. So, you know, the cool thing is the things we announce, there's a deliberate path in why we do it. But when we're announcing something, you're not usually customer zero at that point. Usually you're using something that's already been tried and true. We can aim you at customers that are already getting value from those things.

46:05So all of that AI stuff yesterday has got a path of customers using that stuff at scale and getting a lot of value out of it. Yeah. And is there any difference in how a company of 200 employees uses this as opposed to a company of 2 ,000 or more? I don't know if there's a difference in how they use it per se. I mean, certainly the use cases in a massive multinational org are going to be way more complex and way more broad than a company of 200 users. So the problems they may have to solve could be different. Therefore, they may apply different mechanics for different policies of application. The actual way they use the technology doesn't differ a whole lot.

46:52But the the outcome is is different for each side of the house, meaning it's different, but it's actually not much different except for the scale, the multiple. So a massive global organization, you know, for the scale and size they are, you know, you imagine if you can reduce a cluster of VDI infrastructure that you're spending$600 million a year on, maintaining hundreds of server racks and things like that. You get a lot of value out of that. The economy is scale there. But a small org probably doesn't have those racks and probably going to get that same value there, but they're going to get value in other areas.

47:27And by the way, they may get value and just reduce that one rack of VDI infrastructure they've got. and also the frustrating part of this, you know, because in those environments, you may have one IT person and that IT person is not going to be the virtualization person. They've got to be the security person. They've got to be whatever. So that jack of all trades, we've got to make their job easier as well. So there's a lot of value in both sides of the fence. It's just, but to your question, what happens in the browser, the mechanics, the tooling and resources, you know, it's similar for the small org and the large org at the end of the day.

47:57It's just the outcomes can be much grander for a large org. Yeah. You were talking about how Island proposes workflows and other tools to the user after observing how the user is working. Does it do that for policy as well? Does it review an enterprise's policies and then suggest, you know, say you don't have a policy that addresses this vulnerability or this risk? Does it do anything like that? Yeah, there's actually some really cool capabilities. This is an opportunity for AI, by the way, you know, in the universe to start observing and understanding. Something we've been using for quite a while now is the ability to have what are called insights in the product where they're AI-generated insights that look for the needle in the haystack in some cases.

49:03They may look for configuration elements in other cases. You know, you've got a duplicate policy here. Why do you have a duplicate policy here? But they essentially look for insights in a number of different areas. They look for insights in cybersecurity, in areas of digital experience, into user productivity, into data protection. So it gets in a lot of different areas. And what's happening is just bubbling up. You probably want to know about this right here. And, you know, that know about it could be how do you build a policy around the data protection because you didn't know this was happening.

49:33Or it could be just a you've got a misconfiguration over here on this on this part of your universe around MCP. You're throwing errors there and you didn't even know about it. So just heads up, warning on that. And who sees that? Because not every employee needs to see that. I could call out. So we communicate to everybody engaged in Ireland. Communication could be to the end user for certain situations because that could be the state of the privacy that you're engaging because you're governing the presentation layer. So we can communicate to the end user all kinds of different things to make their job easier because sometimes they just don't know something.

50:09And it would be great if a pop-up came up on the screen and said, do this instead. So we communicate there. But back to your question is, you know, those insights are often communicated to the practitioners who are helping build policies around the given area. And the good thing about it is you leverage RBAC at the end of the day. So different people have access to different perspectives based on the given needs. So your privacy audiences see the insights around privacy. The people that do data protection see the insights around that. And everybody gets their own part of the pie handled that is their interest area and doesn't let them get overly assertive, but lets them again, let their expertise be asserted in the place where it really truly belongs.

50:46Does that mean that there needs to be kind of a manager watching what people are doing within Island? For example, policy lapses to make sure that they're taken care of, or does it depend on the profile of the user? Does Island read that? But the island knows that this is an IT manager who's in charge of policies, safety policies. So it'll surface those things to that manager. Or is there sort of an island super user that's watching everything and directing to different people in the organization? It's a little bit of both. um you know certainly there's somebody in any technology arena that you introduce into an organization there's somebody that actually runs the stuff somebody that has to operate it um and uh so certainly there's you know a lot of times there's the champions that saw the value and island and they've got operational people that take it on um and then uh there are we try to take the administrative burden out of a lot of this stuff i mean a big part of this is letting the humans work in the natural workflows of the organization.

52:07For example, I'll use a perfect one. Oftentimes in cybersecurity, we're lacking, you know, you've built a ticketing environment. You've invested hundreds. I don't know what you've invested. I don't even want to speak to the dollars, but you've got a ticketing environment, like a ServiceNow or a Zendesk or whatever it is. You've invested in all that. And then over here, you've got admins over here manually creating exceptions in cybersecurity. Somebody opens a ticket and admin gets the notification, whoever the practitioner is, for whatever dimension of the business they're in. And they got to go log into the system over here, manually create the exception.

52:40And then they go about their work two weeks later, five weeks later, six months later. And then they got six gazillion exceptions in place and they can't even remember why they're all there. This was the old, the old, the old, you know, you think about the old firewall rules. I had orgs, I remember back in the day, orgs telling me they had 10 ,000 plus firewall rules because they don't know what they're all doing. They don't know which ones, like if you kill them all, you may kill the business. So, but in the world of Island is, you know, we also want to let the users engage the appropriate approval workflows.

53:13So tying naturally into service now, when a user bumps into a wall, you know, they bump into a page that you can't go here because policy dictates you can't go there. but you can click a request button right there in the browser, click a request button, and it kicks off the ticketing screen right in the browser. You fill out the ticket, and then all of a sudden it sends the message into the ticketing environment, and it flows through the appropriate approvers, whatever stack that looks like, and when the final approval is done, it creates the exception naturally in the browser, in the policy, in the policy engine.

53:43And if you want to put time-bound type stuff, like expire it after two weeks. Maybe I'm going to give a research team access to some unsanctioned part of the AI universe that we wouldn't normally give people to. Give them access for three weeks. It'll automatically auto expire that warning the user. This is going to auto expire. You may need to request an exception. But we try to do everything we can about your operational question. Do it in a way where the manual labor of the past is just not sitting there scaring everybody in the eyes of fundamentally having to operate this in the way that you have in the past.

54:14One last little thing. We also think of constructs when you build policies, constructs that are very novel, that when you apply them, they have the greatest level of positive impact, but the lowest level of operational overhead. Think about DLP. DLP has been an operational washing machine for ages. People constantly tuning it all day long and tweaking it. Well, we just take a different approach to it as a starting point. We leverage an application boundary as a policy construct. The application boundary just says, here's a virtual perimeter where your corporate apps live. The browser lets user move data freely in that perimeter within the appropriate policy, but the user can't take data and go over here to this tab that's personal Gmail and spill the data beyond the boundary into personal.

54:56It's a very novel construct, but we understand the disposition of the various things that are open in the browser and what the boundaries are. And as a result, I don't have to go through the minutia of constantly tweaking and tuning. We just try to think of back to your operational question. How do we operationalize this in a way where it's just lightweight on everybody that has to go through this and deal with it? And that sometimes comes in terms of the people that run it every day, the people that sometimes have to get involved in the approval processes in the mix, leveraging AI at the right times in the process, and then just novel constructs as well.

55:28Okay.

From the publisher

AI is moving faster than enterprise security systems were designed to handle. In this episode of Eye on A.I., Craig Smith speaks with Bradon Rogers, Chief Customer Officer at Island, Island about how companies are struggling to govern the rise of AI agents, browser-based workflows, and unsanctioned AI tools inside the workplace.

The conversation explores why traditional "block-and-control" security models are breaking down and how a new approach, embedding policy directly into the browser and user workflows, may offer a path forward. It also dives into emerging risks like prompt injection and autonomous agent behavior, and why enterprises are increasingly becoming multi-AI environments by default.

Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.

More from Eye On A.I.

All 266 episodes
Inside the Enterprise Browser Rebuilding Security for the AI EraEye On A.I. · 56 min
Listen in VO