Read-only access, then: allow limited access without the ability to send messages, such as with software that disables the keyboard (but not the mouse) everywhere except the address bar, combined with monitoring.
Theoretically, a GET request is only supposed to retrieve data, but it can be (and sometimes is) also used to write data. There's no way for a screening algorithm to know the difference.
That's part of the argument for why those phone calls are so expensive...
Monitoring what someone does on the web would be possible too, of course. At least if you only let them do it for a few minutes at a time like a phone call. Monitoring someone for an hour or more of web browsing is likely to be deathly boring for the one doing the monitoring.