THREESIXTY.
All case studies

Enterprise services (anonymized) · Security & governance

Twelve shadow agents retired. One governed surface for three business units.

When regional teams spun up their own agents, PII exposure and spend chaos followed until governance caught up.

6-week governance sprint, then ongoing MSP + ClawGuard

Shadow agents decommissioned
12
Unified policy coverage
3 business units
Mean detection-to-triage
Under 5 min
Previously: ~45 min

We stopped playing whack-a-mole in three regions. Security finally sees the same violations, and the same kill switch we do.

CISO, enterprise services

Situation

A global enterprise services firm scaled customer-ops automation faster than central IT could govern it. Regional leads deployed agents with local API keys, custom prompts, and no consistent tooling.

What was at stake

At least twelve unapproved agents handled PII across three business units. Security had no inventory; finance had no spend visibility; incident ownership was unclear when a prompt injection attempt surfaced in EMEA.

What Threesixty did

  1. Inventory and risk-tier every discovered agent, data classes, tool access, and business criticality.

  2. Centralise ClawGuard safety policies with per-machine and per-agent assignments; auto-apply policies to new registrations.

  3. Mandate approved toolchains and gateway-routed traffic; decommission or migrate shadow workloads to governed hosts.

  4. Wire violation reporting to human-in-the-loop escalation with evidence packs for SecOps review.

Technical approach

Command Center fleet inventory with ClawGuard: agent-level tool validation, gateway request/response inspection, centralised policy management. Violations surfaced with evidence suitable for SOC review. Tailscale ACLs limit lateral movement; operators reach agents on :8000 without agents reaching each other.

Results

  • All twelve shadow agents either migrated to governed infrastructure or were formally retired with sign-off.
  • Single leadership dashboard for policy coverage, violations, and spend. No more regional blind spots.
  • Duplicate tooling costs fell as teams consolidated on one approved agent stack.
  • Mean time from violation detection to triage dropped under five minutes with clear incident owners.

Related outcomes

Similar engagements by sector, service, or platform.

Ready for outcomes like these?

Start with an AI Health Audit to see where your stack will fail next, or talk to us about managed continuity, Command Center, and ClawGuard for production agent fleets.