TL;DR
The situation
At Happy Returns, a leading reverse logistics company, developers and engineers were rapidly deploying AI agents and frontier models across their systems. While executive leadership established a progressive mandate—allowing developers to leverage the power of AI while figuring out a way to control it—the security team lacked the visual telemetry and governance structures needed to monitor and manage these rapid deployments.
The decision
Rather than blocking AI adoption, Happy Returns chose to deploy Backslash Security’s agentic endpoint capabilities. This allowed the company to gain instant visibility into AI usage on developer workstations, transition to a secure-enablement model, and implement automated policies and guardrails to keep AI-native workflows under control.
The outcome
Happy Returns executed a full-scale deployment across all Mac and Windows endpoints and was fully up and running in less than 30 days. The security team now utilizes Backslash’s centralized guardrails to block unapproved models, monitor risky AI behaviors, and maintain clear visibility into the corporate ecosystem, ensuring robust security without stalling developer productivity.
Background & Objectives
Happy Returns is a pioneer in the reverse logistics industry, specializing in “no-box, no-label” returns to make returns easy for consumers. In alignment with their commitment to operational efficiency and innovation, the company’s executive leadership established a clear, forward-leaning policy: permit software engineers and developers to use cutting-edge AI agents and frontier models, let them explore and decide what tools they want to use, but establish a robust mechanism to manage, govern, and control them.
To execute this directive, the information security function, led by Phillip Walsh, Director & Head of Information Security, set out to implement a security governance framework. The objective was to empower developers to safely innovate with agentic AI while providing the security team with the necessary telemetry and guardrails to mitigate any operational or security risks.
The Challenge: Governance and Technical Risk
As Happy Returns developers rapidly adopted AI agents and frontier models, the scale of deployment immediately surpassed initial expectations. Based on early signals from the corporate network, Phillip Walsh recognized that establishing proper governance was going to be “a lot more than I planned on.”
The company faced several distinct challenges:
- Lack of Visibility: Engineers were independently deploying a variety of AI models and agents across their workstations. Without centralized telemetry, the security team had no visual oversight into what AI applications were active, what developers were doing, or how they were interacting with internal systems.
- Rapid and Decentralized Proliferation: AI agents and frontier models were being introduced into the environment at an unprecedented pace, making manual security assessments and inventory tracking impossible.
- Governance Enforcement: To comply with the executive mandate, the security team needed a seamless, non-intrusive way to govern AI usage, separate safe behaviors from risky behaviors, and restrict unauthorized models without creating friction in the engineering workflow.
The Solution Strategy
To address these challenges, Happy Returns rejected traditional restrictive security approaches. Instead, they deployed Backslash Security across all corporate endpoints.
The key components of the solution strategy included:
- Comprehensive Endpoint Coverage: Happy Returns completed a full-scale deployment of Backslash’s endpoint capabilities across all Mac and Windows workstations, capturing telemetry directly where code was being generated and AI agents were active.
- Rapid Deployment and Partnership: Working in close collaboration with the Backslash engineering and product teams, Happy Returns completed their deployment and was fully operational in less than 30 days.
- Dynamic Guardrails and Policies: Walsh’s team leveraged Backslash’s built-in rule base to establish granular guardrails. These policies allowed the security team to specify exactly which frontier models and AI agents are authorized for use, while automatically blocking unapproved, high-risk, or deprecated models.
Operational Outcome
By partnering with Backslash Security, Happy Returns established full control over its AI endpoint ecosystem in record time. The security team achieved several key operational milestones:
- Sub-30-Day Time-to-Value: The entire platform was fully running in under 30 days, delivering a seamless deployment experience with direct support from Backslash.
- Active Risk Monitoring and Governance: Phillip Walsh can now easily pull rules on Backslash’s guardrails to review active policies. The centralized dashboard provides a clear log of blocked models and tracks the frequency of risky behaviors in the rule base, proving immediate and tangible value to executive stakeholders.
- Forward-Looking Security Posture: With comprehensive visuals of the corporate ecosystem, the security team is equipped to guard immediate threats while maintaining a forward look into the future of their AI environment.
- Collaborative Engineering Partnership: The deployment fostered a strong, bi-directional partnership between Happy Returns and the Backslash engineering and product teams. Through continuous back-and-forth communication, Backslash integrated user feedback directly into their product roadmap, delivering rapid feature releases that are highly tailored to Happy Returns’ evolving AI ecosystem.
“We did a full-scale deployment across all our Mac and Windows endpoints and were fully running in under 30 days. It’s not a complicated process—Backslash gives you great telemetry so you can see exactly what’s inside your system. Taking it step-by-step to guard what we can right now while having a forward look into the future has shown great value.” — Phillip Walsh, Director & Head of Information Security, Happy Returns
Security Posture Comparison
| Pain Point |
Before Backslash |
After Backslash |
| Ecosystem Visibility |
No telemetry on endpoint AI usage; blind spots regarding which AI agents and frontier models are running. |
Comprehensive visuals and telemetry across all Mac and Windows endpoints to see what everyone is doing. |
| Model & Agent Governance |
Uncontrolled and rapid deployment of unapproved frontier models and AI agents by engineers. |
Centralized rule base and guardrails that enforce authorized models and automatically restrict unapproved ones. |
| Risky Behavior Tracking |
Inability to track, log, or measure risky AI behaviors or unauthorized tools on developer machines. |
Real-time monitoring and reporting of risky behaviors directly within the rule base to demonstrate security value. |
| Deployment & Integration |
Anticipated high friction and long setup times to manage decentralized endpoint AI usage. |
Rapid, friction-free deployment that was fully operational in 30 days or less. |
| Strategic Adaptability |
Reactive security approach that struggles to keep up with the fast-moving AI landscape. |
Proactive, forward-looking posture supported by a tight product partnership and highly useful, rapid feature releases. |