Customer Success Playbook

Telemetry-Driven Risk Mitigation Plays

Actionable interventions for ADMs and Solutions Architects supporting enterprise customers. Use Cursor analytics and dashboard signals to detect adoption, cost, security, and competitive risks early — then run the right play before renewal or expansion conversations stall.

Audience: ADM, Solutions Architect, CS leadership
Inputs: Analytics Dashboard, Conversation Insights, billing data
Outcome: Proactive risk reduction, measurable recovery

How to Use This Page

Review telemetry weekly during pilot and monthly at scale. Each play maps a signal (what you see in the dashboard or customer conversations) to a response (specific actions with owners). Severity guides prioritization; not every signal requires escalation.

1 · Scan signals

Pull Analytics Dashboard, spend reports, and Conversation Insights. Compare to contract size and rollout phase.

2 · Match the play

Use the signal library and quick-reference matrix below. Multiple signals often share a root cause — cluster before acting.

3 · Execute & measure

Run the play with a 2–4 week recovery window. Re-check telemetry and document outcome for QBR narrative.

Pair telemetry with qualitative context

Dashboards show what changed; customer calls reveal why. A spend spike may be healthy (migration sprint) or risky (unrestricted frontier models). Always validate signals with champions and platform admins before changing guardrails.

Signal library

Cursor Telemetry Sources

Enterprise instrumentation you can use to detect risk before it shows up in renewal conversations.

Analytics Dashboard

Active users, session trends, model distribution, team-level spend, feature usage over time.

Risk lens: license utilization, engagement decay, model cost mix.

Conversation Insights

Work-type breakdown — feature development, debugging, exploration, refactoring (Enterprise).

Risk lens: stuck in exploration, no production workflows, shallow usage.

AI Code Tracking API

Per-commit AI attribution correlated with velocity, quality, and repo activity.

Risk lens: high spend with low commit impact; compliance audit gaps.

Billing & spend controls

Pooled usage burn rate, Billing Groups, Directory Group limits, spend alerts, per-user caps.

Risk lens: budget overrun, uneven adoption, power-user concentration.

Audit logs & admin events

Authentication, policy changes, Cloud Agent enablement, extension and MCP configuration.

Risk lens: shadow IT, policy drift, security incidents blocking rollout.

Product & integration signals

Cloud Agents, Bugbot, Cursor CLI, MCP servers, SCIM provisioning volume vs. active users.

Risk lens: automation under-adoption, integration requests without governance.

Severity guide

Level Definition Response SLA
LevelHigh DefinitionRenewal at risk, security/compliance blocker, or >30% pooled usage consumed in first half of term with flat adoption Response SLAExecutive alignment within 1 week; SA embedded
LevelMedium DefinitionPilot stall, cost trajectory misaligned with value, competitive evaluation underway Response SLAPlay execution within 2 weeks; weekly telemetry review
LevelLow DefinitionOptimization opportunity, uneven team adoption, education gap Response SLAChampion-led fix; ADM check-in at next QBR
Model usage

Model & Cost Risk Plays

Model choice drives most variable spend on Enterprise. Telemetry on model distribution and per-developer burn rate is your earliest warning for budget and ROI risk.

1 Frontier model over-index High

Signal: Analytics shows >40% of token spend on third-party frontier models; spend alerts firing weekly; finance questions invoice without usage growth.

Root causes: Developers defaulting to premium models; agent loops on expensive tiers; no Model Access Restrictions; lack of Composer education.

  • Pull 30-day model distribution report; segment by team and Billing Group
  • Enable Model Access Restrictions — allow Composer 2.5; gate frontier models to approved groups
  • Run 45-min model economics session: Composer 2.5 Standard for agent workflows, Fast for interactive latency
  • Publish internal guidance: when frontier models are justified (architecture spikes, novel domains)
  • Set recovery metric: frontier share <15% within 4 weeks; track in weekly ADM sync

2 High spend, low commit impact High

Signal: AI Code Tracking shows AI-assisted commits flat or declining while usage spend rises; Conversation Insights skewed to exploration/chat.

Root causes: Treating Cursor as chat-only; no agent workflows; repos lack rules/context; wrong use cases in pilot.

  • Solutions Architect runs workflow audit on top 5 spenders — map sessions to use cases
  • Re-anchor pilot on Phase 2 use cases with defined ROI signals (cycle time, PR throughput)
  • Deploy team Rules and shared .cursor conventions in high-spend repos
  • Shift defaults to Composer 2.5 Standard for multi-file agent tasks; measure cost per merged PR
  • Recovery metric: AI Code Tracking correlation with pilot KPIs improves within one sprint

3 Power-user concentration Medium

Signal: Top 10% of users account for >50% of spend; others near zero usage; Directory Group caps hit repeatedly by same individuals.

  • Identify power users — convert to champions if productive; investigate runaway agent loops if not
  • Tier spend limits: higher cap for cursor-pilot-engineering, standard cap for broad rollout groups
  • Pair under-utilizers with champions for paired programming sessions
  • Enable Dynamic Spend Limits as headcount scales to avoid manual cap drift

4 Composer under-adoption Medium

Signal: Low agent-mode sessions; developers still on legacy chat patterns; positive sentiment but no velocity metrics movement.

  • Demo agentic workflows on customer's actual repos — not generic feature tours
  • Standardize on Composer 2.5 as default; document internal "model selection cheat sheet"
  • Track agent-mode adoption rate weekly; target 60%+ of active users within 6 weeks of enablement
Cloud agents & automations

Advanced Feature & Automation Plays

Cloud Agents, Bugbot, Cursor CLI, MCP, and SCIM lifecycle automation unlock Phase 3 value — but also introduce governance and adoption risks if rolled out without telemetry-backed readiness.

1 Cloud Agents blocked or stalled Medium

Signal: Security has restricted Cloud Agents org-wide; Slack integration requested but not enabled; audit logs show policy debates; Phase 3 account with zero async agent usage.

For self-managed pool decisions and rollout, see the Self-Managed Cloud Agent Pool guide.

  • Solutions Architect leads architecture review: data flows, repo access, Privacy Mode alignment
  • Propose phased enablement — approved IdP group only (e.g. cursor-platform-admins)
  • Document approved use cases: incident triage, internal tooling, scoped refactors — not production deploys
  • Pair with Hooks and audit log streaming for compliance narrative
  • Recovery metric: pilot group running 2+ Cloud Agent workflows with documented runbooks

2 Automation stack not adopted Medium

Signal: Mature account still on Phase 1 patterns; Bugbot, CLI, MCP, Service Accounts unused; customer asks "what's next?" without progressing.

  • Map customer's SDLC — identify highest-leverage automation (PR review, CI scaffolding, ticket integration)
  • Pilot Bugbot on one high-churn repo; measure defect detection and review time
  • Evaluate Cursor CLI for platform engineering (migrations, codegen in pipelines) with restricted user list
  • Stand up approved MCP server catalog with security review workflow
  • Introduce Service Accounts for non-human automation after human workflows prove stable

3 SCIM provisioned, nobody active High

Signal: SCIM user count matches license count but weekly active users <50%; new hires provisioned without onboarding; joiner/mover/leaver works but engagement flat.

  • Distinguish provisioning success from adoption — track WAU/license ratio as primary health metric
  • Add Cursor to new-hire engineering onboarding checklist; 30-min champion-led intro within first week
  • Audit IdP groups — remove over-broad SCIM assignments until champions ready for next cohort
  • Run "why not Cursor?" survey with inactive provisioned users; address blockers (IDE policy, repo access)

4 Ungoverned automation sprawl High

Signal: Personal API keys or BYOK in use; unaudited MCP servers; Cloud Agents creating PRs outside approved repos; CLI running in CI without service account governance.

  • Disable BYOK if policy requires; redirect to pooled Enterprise usage with visibility
  • Enforce Repository Blocklist and Cloud Agent creation restrictions by group
  • Centralize MCP allowlist via admin marketplace; block unknown servers
  • Migrate CI usage to Service Accounts with rotation policy and audit log correlation
Adoption & engagement

Adoption & Renewal Risk Plays

Usage telemetry combined with champion feedback surfaces stall patterns before they become churn or downsell conversations.

1 Pilot stall High

Signal: Flat active users for 3+ weeks post go-live; mid-pilot survey scores declining; no documented wins for executive readout.

  • Reset pilot scope to 1–2 use cases with executive sponsor accountability
  • Increase ADM touch frequency to twice weekly until trajectory reverses
  • Solutions Architect office hours — unblock environment issues (SSO, repo access, proxy)
  • Capture one quantified win per week minimum for Phase 2 ROI narrative

2 Champion network decay Medium

Signal: Original pilot champions changed roles or left; enablement sessions attendance drops; internal Slack channel goes quiet.

  • Identify champion succession plan with engineering manager — minimum 2 champions per pilot squad
  • Launch internal "Cursor guild" with monthly show-and-tell; ADM facilitates first session
  • Recognize champions in QBR with leadership present — tie to promotion/career narratives where appropriate

3 Security freeze blocking expansion High

Signal: InfoSec escalation; Privacy Mode questions resurfacing; incident involving AI-generated code; expansion paused pending review.

  • Schedule joint session: security team + Solutions Architect + Trust Center walkthrough
  • Enable Cursor Blame and AI Code Tracking for attribution in incident response
  • Document control mapping: Privacy Mode, audit logs, hooks, sandbox, extension allowlists
  • Offer phased expansion with enhanced monitoring rather than full rollback

4 Value narrative gap at renewal High

Signal: 90 days to renewal; leadership cannot articulate ROI; usage is healthy but finance sees cost without productivity proof.

  • Build renewal pack: Analytics trends, AI Code Tracking outcomes, cost per developer vs. loaded salary savings
  • Include 3 customer-internal case studies with named workflows (anonymized if needed)
  • Model expansion scenarios with Composer 2.5 economics vs. status quo tooling costs
  • Align ADM + executive sponsor on expansion or right-size recommendation before procurement engages
Competitive landscape

Competitive Risk Plays

Evaluation signals often appear in telemetry (usage dip during POC) or in conversation (RFP language, Microsoft/AWS alignment). Position on agentic depth, enterprise governance, and measurable ROI — not feature checklists alone.

Competitor / alternative Common evaluation trigger Cursor differentiation Counter-play
Competitor / alternativeGitHub Copilot Common evaluation triggerMicrosoft ELA bundling; GitHub-native shops; "good enough" autocomplete Cursor differentiationAgentic multi-file edits, Composer 2.5 economics, deeper codebase context, Enterprise analytics Counter-playRun head-to-head on agent workflows and migration task; show AI Code Tracking ROI Copilot cannot match
Competitor / alternativeWindsurf / agentic IDEs Common evaluation triggerDeveloper grass-roots trial; appetite for autonomous coding agents Cursor differentiationMature Enterprise controls (SCIM, Privacy Mode, audit), ADM/SA support, pooled usage predictability Counter-playEmphasize governance gap in shadow trials; offer sanctioned pilot with guardrails instead of bans
Competitor / alternativeClaude Code / terminal agents Common evaluation triggerPlatform teams prefer CLI; Anthropic relationship; headless automation Cursor differentiationIDE-integrated context, team Rules, Cursor CLI with Enterprise policy, unified analytics Counter-playPosition Cursor CLI + Service Accounts as governed alternative; SA designs CI workflow demo
Competitor / alternativeAmazon Q Developer Common evaluation triggerAWS-all-in strategy; CodeCatalyst integration Cursor differentiationModel choice, Composer cost efficiency, cross-cloud neutrality, Conversation Insights Counter-playMap multi-cloud or polyglot reality; quantify Composer 2.5 cost vs. bundled Q inference
Competitor / alternativeSourcegraph Cody / JetBrains AI Common evaluation triggerExisting vendor relationship; IDE loyalty (IntelliJ, etc.) Cursor differentiationAgent mode depth, Cloud Agents, Bugbot, enterprise deployment at scale Counter-playFocus on pilot KPIs where agentic workflows outperform assistive completion
Competitor / alternativeBuild vs. buy (internal LLM) Common evaluation triggerAI platform team wants self-hosted models; data residency narrative Cursor differentiationTime-to-value, ongoing model R&D (Composer), Enterprise Privacy Mode, integration burden Counter-playTCO comparison including platform eng FTE; hybrid path via MCP to internal tools while keeping Cursor UX

1 Active competitive evaluation High

Signal: Parallel POC accounts; usage drop in Cursor during competitor trial; procurement RFP with feature matrix; executive mentions vendor meetings.

  • Request mutual success plan review — understand decision criteria and timeline with economic buyer
  • Accelerate measurable wins on customer's highest-pain workflows (not generic benchmarks)
  • Deliver governance pack: Trust Center, audit logs, Privacy Mode, SCIM — enterprise table stakes competitors often lack
  • Offer executive briefing with Cursor product leadership for strategic accounts
  • If loss likely: document learnings; leave door open with analytics export and migration guidance

2 Shadow AI tool sprawl Medium

Signal: Security discovers unapproved AI extensions; developers mention other tools in surveys; Cursor usage fragmented by team.

  • Partner with InfoSec on approved-tool list — position Cursor as sanctioned path with controls
  • MDM policies: Allowed Team IDs, extension allowlists, block personal accounts on corp devices
  • Address gaps driving shadow usage (JetBrains users, CLI-only workflows) with targeted enablement or CLI/remote workflows

3 "Good enough" autocomplete mindset Low

Signal: Usage concentrated in inline completion; low agent adoption; stakeholders compare Cursor to Copilot autocomplete only.

  • Reframe value: agentic SDLC (refactors, tests, migrations, incident response) — show 10x tasks not 10% faster typing
  • Live demo multi-file migration or test generation on customer codebase; tie to sprint goal
  • Publish internal benchmark: Composer 2.5 task completion time vs. manual baseline

Signal → Play Quick Reference

At-a-glance mapping for weekly telemetry reviews. Click checklist items on play sections above to track execution.

Telemetry signal Likely risk Primary play Owner
Telemetry signalFrontier models >40% of spend Likely riskBudget overrun, weak ROI story Primary playModel restrictions + Composer education OwnerADM + SA
Telemetry signalSpend up, commits flat Likely riskChat-only usage, pilot failure Primary playWorkflow audit + rules deployment OwnerSA
Telemetry signalWAU <50% of licensed seats Likely riskProvisioning without adoption Primary playOnboarding + cohort gating OwnerADM
Telemetry signalCloud Agents disabled, Slack asks Likely riskBlocked Phase 3 value Primary playPhased architecture review OwnerSA + Security
Telemetry signalZero Bugbot/CLI/MCP usage at scale Likely riskStuck at Phase 2 maturity Primary playSDLC automation mapping OwnerSA
Telemetry signal3+ weeks flat pilot MAU Likely riskExecutive readout at risk Primary playPilot reset + intensified rhythm OwnerADM
Telemetry signalChampion departures Likely riskKnowledge loss, decay Primary playGuild + succession plan OwnerADM
Telemetry signalUsage dip during external POC Likely riskCompetitive loss Primary playMutual success plan + exec briefing OwnerADM
Telemetry signalSecurity incident / freeze Likely riskExpansion blocked Primary playControl mapping + Blame/tracking OwnerSA + InfoSec
Telemetry signalRenewal without ROI narrative Likely riskDownsell or churn Primary playRenewal pack + case studies OwnerADM
Telemetry signalExploration-heavy Conversation Insights Likely riskNo production value yet Primary playUse case re-anchoring OwnerSA + Champions
Telemetry signalPersonal accounts / BYOK detected Likely riskShadow IT, compliance Primary playPolicy enforcement + Service Accounts OwnerSA + IT