Client story · IT services
Secure enterprise AI deployment: How CBTS governs Claude for 2,300 employees
Before asking a single client to trust AI with real work, CBTS ran the deployment across our own business. We’ve turned our experience into a blueprint for mid-market organizations to compete at scale in an AI-driven world.
.png?width=876&height=582&name=image%20(9).png)
Industry
IT services
Scale
2,300 employees
Deployed
Anthropic Claude for Enterprise, under one governed control plane
Timeline
First 250 users in March 2026, firmwide within four months
Key outcomes
Payback on the full AI program investment
CFO-Verified
Closed-won revenue
Salesforce-Anchored
Major security incidents attributable to AI
Security-Validated
Incident containment with agentic SOC
Security-Validated
The CFO’s test
“Most AI ROI numbers don’t hold up once you ask how they were calculated. Ours do, because I don’t sign off on anything until I’ve checked it myself. Every ROI calculation ties back to actual results I can see in the P&L. This discipline ensures our AI spend is tied to actual returns.”
Shannon Mullen
Chief Financial Officer, CBTS
.png?width=608&height=532&name=Right%20(12).png)
The situation
Fast is easy. Governed is hard. Companies need both.
Mid-market organizations face particular risk from AI pilots that scale activity without organizational readiness. That gap closes when governance comes before rollout.
With a cloud-native environment that requires complete protection of its infrastructure and data, CBTS took a rigorous approach to securing and governing AI at scale before rolling out Anthropic Claude for Enterprise to all 2,300 employees.
The approach
Governance first, then scale
We became our own first client. Before we deployed anything, we worked through four questions:
- Data exposure. How do you connect AI to real systems without exposing sensitive data?
- Proof of value. How do you prove ROI when most initiatives cannot quantify value for the CFO?
- Fragmented readiness. How do you move fast when every team is figuring out AI on their own?
- Workforce trust. How do you get a workforce to trust and adopt AI at scale?
Each answer had to hold up in production, not on paper. Our CEO-sponsored, company-wide Anthropic Claude for Enterprise rollout started with 250 users in March 2026 and within four months scaled firmwide, relying on the same discipline we sell to clients: resilience, incident response, and disaster recovery automation.
Over the course of those four months, six workstreams carried the rollout, each covering a different focus and each shipping with its own controls rather than inheriting them later:
AI governance at the token level
Security policy, metered spend, and usage analytics cover every user, skill, and token. The CISO has one view of it all.
Private deployment and data boundary
Data classification decides where every workload runs. The highest-value, most sensitive work stays on infrastructure controlled by CBTS Managed Operations. Models see only what we choose to send them, and regulated content stays out of uncontrolled environments.
Cloud tenancy control
Encryption key management, audit trails, and data lineage governance are mandated. Every agent action leaves a record we can produce.
Skill Forge
This is our collection of reusable skills, each with its own governance. One person proves a way of working; the whole company runs it the next day. Nobody pays to rebuild what a colleague already solved. As models get faster and cheaper, the controls around these skills stay constant.
Forge Feed
All ROI tracking in one place — from individual projects and chats through to documented Salesforce opportunities.
Human-in-the-loop
CBTS maintains checkpoints and auditable decision trails on every agent workflow.
The CISO’s view
“Governance was not the brake on this program. It was the reason we could hit the accelerator at all. Every agent runs inside controls I can see, and nothing reaches production without clearing review.”
Chris DeBrunner
Chief Information Security Officer, CBTS
The outcome
This is how the mid-market wins with AI
1.2M
Malicious artifacts blocked by the SOC tool chain protecting the deployment
SOC Tooling Records
100%
Employee AI access running through one governed control plane — every user, skill, and token
Platform Config
100%
Production agents passing security review before deployment — median time four days
Intake Gate Records
Now we have a proven framework for giving clients an AI control plane that identifies, authenticates, and authorizes every agentic interaction in real time.
You don’t have to be a technology company to achieve similar results. In fact, our earliest and largest wins came from finance reporting, proposal response, and employee support. These are workflows that every mid-market organization runs. What’s more, it’s not just technologists contributing to Skill Forge. Our 1,300+ active builders also include sellers, finance analysts, and operations staff.
Put the CBTS blueprint to work
We have packaged our own experience into CBTS Forge AI: advisory services to identify the work worth doing, a governed control plane that shows you who is using what and at what cost, reusable skills and agents that run real workflows, and the team that operates them in production after go-live. Start with one piece or all four. Anthropic underpins our internal work, but Forge AI is model-agnostic by design. It deploys on whatever model and environment your requirements call for.

Figures reflect CBTS internal systems of record as of the reporting period. Results described are specific to the CBTS environment and are not a guarantee of outcomes in any other organization.
