The architecture is solid. The session is still largely ungoverned.
Identity, endpoint, and network tools do their job at the access layer. What happens inside the browser session after that, what data moves, what actions are taken on a privileged page, what goes into a GenAI tool, is mostly outside the control model.









