1 · Scan signals
Pull Analytics Dashboard, spend reports, and Conversation Insights. Compare to contract size and rollout phase.
Actionable interventions for ADMs and Solutions Architects supporting enterprise customers. Use Cursor analytics and dashboard signals to detect adoption, cost, security, and competitive risks early — then run the right play before renewal or expansion conversations stall.
Review telemetry weekly during pilot and monthly at scale. Each play maps a signal (what you see in the dashboard or customer conversations) to a response (specific actions with owners). Severity guides prioritization; not every signal requires escalation.
Pull Analytics Dashboard, spend reports, and Conversation Insights. Compare to contract size and rollout phase.
Use the signal library and quick-reference matrix below. Multiple signals often share a root cause — cluster before acting.
Run the play with a 2–4 week recovery window. Re-check telemetry and document outcome for QBR narrative.
Dashboards show what changed; customer calls reveal why. A spend spike may be healthy (migration sprint) or risky (unrestricted frontier models). Always validate signals with champions and platform admins before changing guardrails.
Active users, session trends, model distribution, team-level spend, feature usage over time.
Risk lens: license utilization, engagement decay, model cost mix.
Work-type breakdown — feature development, debugging, exploration, refactoring (Enterprise).
Risk lens: stuck in exploration, no production workflows, shallow usage.
Per-commit AI attribution correlated with velocity, quality, and repo activity.
Risk lens: high spend with low commit impact; compliance audit gaps.
Pooled usage burn rate, Billing Groups, Directory Group limits, spend alerts, per-user caps.
Risk lens: budget overrun, uneven adoption, power-user concentration.
Authentication, policy changes, Cloud Agent enablement, extension and MCP configuration.
Risk lens: shadow IT, policy drift, security incidents blocking rollout.
Cloud Agents, Bugbot, Cursor CLI, MCP servers, SCIM provisioning volume vs. active users.
Risk lens: automation under-adoption, integration requests without governance.
| Level | Definition | Response SLA |
|---|---|---|
| LevelHigh | DefinitionRenewal at risk, security/compliance blocker, or >30% pooled usage consumed in first half of term with flat adoption | Response SLAExecutive alignment within 1 week; SA embedded |
| LevelMedium | DefinitionPilot stall, cost trajectory misaligned with value, competitive evaluation underway | Response SLAPlay execution within 2 weeks; weekly telemetry review |
| LevelLow | DefinitionOptimization opportunity, uneven team adoption, education gap | Response SLAChampion-led fix; ADM check-in at next QBR |
Signal: Analytics shows >40% of token spend on third-party frontier models; spend alerts firing weekly; finance questions invoice without usage growth.
Root causes: Developers defaulting to premium models; agent loops on expensive tiers; no Model Access Restrictions; lack of Composer education.
Signal: AI Code Tracking shows AI-assisted commits flat or declining while usage spend rises; Conversation Insights skewed to exploration/chat.
Root causes: Treating Cursor as chat-only; no agent workflows; repos lack rules/context; wrong use cases in pilot.
.cursor conventions in high-spend reposSignal: Top 10% of users account for >50% of spend; others near zero usage; Directory Group caps hit repeatedly by same individuals.
cursor-pilot-engineering, standard cap for broad rollout groupsSignal: Low agent-mode sessions; developers still on legacy chat patterns; positive sentiment but no velocity metrics movement.
Signal: Security has restricted Cloud Agents org-wide; Slack integration requested but not enabled; audit logs show policy debates; Phase 3 account with zero async agent usage.
For self-managed pool decisions and rollout, see the Self-Managed Cloud Agent Pool guide.
cursor-platform-admins)Signal: Mature account still on Phase 1 patterns; Bugbot, CLI, MCP, Service Accounts unused; customer asks "what's next?" without progressing.
Signal: SCIM user count matches license count but weekly active users <50%; new hires provisioned without onboarding; joiner/mover/leaver works but engagement flat.
Signal: Personal API keys or BYOK in use; unaudited MCP servers; Cloud Agents creating PRs outside approved repos; CLI running in CI without service account governance.
Signal: Flat active users for 3+ weeks post go-live; mid-pilot survey scores declining; no documented wins for executive readout.
Signal: Original pilot champions changed roles or left; enablement sessions attendance drops; internal Slack channel goes quiet.
Signal: InfoSec escalation; Privacy Mode questions resurfacing; incident involving AI-generated code; expansion paused pending review.
Signal: 90 days to renewal; leadership cannot articulate ROI; usage is healthy but finance sees cost without productivity proof.
| Competitor / alternative | Common evaluation trigger | Cursor differentiation | Counter-play |
|---|---|---|---|
| Competitor / alternativeGitHub Copilot | Common evaluation triggerMicrosoft ELA bundling; GitHub-native shops; "good enough" autocomplete | Cursor differentiationAgentic multi-file edits, Composer 2.5 economics, deeper codebase context, Enterprise analytics | Counter-playRun head-to-head on agent workflows and migration task; show AI Code Tracking ROI Copilot cannot match |
| Competitor / alternativeWindsurf / agentic IDEs | Common evaluation triggerDeveloper grass-roots trial; appetite for autonomous coding agents | Cursor differentiationMature Enterprise controls (SCIM, Privacy Mode, audit), ADM/SA support, pooled usage predictability | Counter-playEmphasize governance gap in shadow trials; offer sanctioned pilot with guardrails instead of bans |
| Competitor / alternativeClaude Code / terminal agents | Common evaluation triggerPlatform teams prefer CLI; Anthropic relationship; headless automation | Cursor differentiationIDE-integrated context, team Rules, Cursor CLI with Enterprise policy, unified analytics | Counter-playPosition Cursor CLI + Service Accounts as governed alternative; SA designs CI workflow demo |
| Competitor / alternativeAmazon Q Developer | Common evaluation triggerAWS-all-in strategy; CodeCatalyst integration | Cursor differentiationModel choice, Composer cost efficiency, cross-cloud neutrality, Conversation Insights | Counter-playMap multi-cloud or polyglot reality; quantify Composer 2.5 cost vs. bundled Q inference |
| Competitor / alternativeSourcegraph Cody / JetBrains AI | Common evaluation triggerExisting vendor relationship; IDE loyalty (IntelliJ, etc.) | Cursor differentiationAgent mode depth, Cloud Agents, Bugbot, enterprise deployment at scale | Counter-playFocus on pilot KPIs where agentic workflows outperform assistive completion |
| Competitor / alternativeBuild vs. buy (internal LLM) | Common evaluation triggerAI platform team wants self-hosted models; data residency narrative | Cursor differentiationTime-to-value, ongoing model R&D (Composer), Enterprise Privacy Mode, integration burden | Counter-playTCO comparison including platform eng FTE; hybrid path via MCP to internal tools while keeping Cursor UX |
Signal: Parallel POC accounts; usage drop in Cursor during competitor trial; procurement RFP with feature matrix; executive mentions vendor meetings.
Signal: Security discovers unapproved AI extensions; developers mention other tools in surveys; Cursor usage fragmented by team.
Signal: Usage concentrated in inline completion; low agent adoption; stakeholders compare Cursor to Copilot autocomplete only.
At-a-glance mapping for weekly telemetry reviews. Click checklist items on play sections above to track execution.
| Telemetry signal | Likely risk | Primary play | Owner |
|---|---|---|---|
| Telemetry signalFrontier models >40% of spend | Likely riskBudget overrun, weak ROI story | Primary playModel restrictions + Composer education | OwnerADM + SA |
| Telemetry signalSpend up, commits flat | Likely riskChat-only usage, pilot failure | Primary playWorkflow audit + rules deployment | OwnerSA |
| Telemetry signalWAU <50% of licensed seats | Likely riskProvisioning without adoption | Primary playOnboarding + cohort gating | OwnerADM |
| Telemetry signalCloud Agents disabled, Slack asks | Likely riskBlocked Phase 3 value | Primary playPhased architecture review | OwnerSA + Security |
| Telemetry signalZero Bugbot/CLI/MCP usage at scale | Likely riskStuck at Phase 2 maturity | Primary playSDLC automation mapping | OwnerSA |
| Telemetry signal3+ weeks flat pilot MAU | Likely riskExecutive readout at risk | Primary playPilot reset + intensified rhythm | OwnerADM |
| Telemetry signalChampion departures | Likely riskKnowledge loss, decay | Primary playGuild + succession plan | OwnerADM |
| Telemetry signalUsage dip during external POC | Likely riskCompetitive loss | Primary playMutual success plan + exec briefing | OwnerADM |
| Telemetry signalSecurity incident / freeze | Likely riskExpansion blocked | Primary playControl mapping + Blame/tracking | OwnerSA + InfoSec |
| Telemetry signalRenewal without ROI narrative | Likely riskDownsell or churn | Primary playRenewal pack + case studies | OwnerADM |
| Telemetry signalExploration-heavy Conversation Insights | Likely riskNo production value yet | Primary playUse case re-anchoring | OwnerSA + Champions |
| Telemetry signalPersonal accounts / BYOK detected | Likely riskShadow IT, compliance | Primary playPolicy enforcement + Service Accounts | OwnerSA + IT |
These plays complement the structured rollout — not replace it.