How Zuora governs AI adoption without slowing it down
Mark Gill leads IT services, infrastructure, and security at Zuora, where IT owns the budget for AI used across the business. In this conversation he walks through the governance and prioritization process his team built to move from AI experimentation to real adoption, the security rules that keep that experimentation safe, and why he thinks the promise of immediate ROI is the most common mistake.
· Mark Gill
Why it matters
When every team can spin up an AI tool in an afternoon, the constraint stops being whether you can build something. It becomes whether the thing you built is worth running, and whether it can reach data it should not.
Zuora’s answer is a governance process that runs before deployment. Champions from every business unit meet weekly, argue for their priorities, and the ideas with the clearest ROI move forward. Underneath that sits a set of security boundaries that hold whether someone is using sanctioned tooling or vibe coding on their own machine. Access is scoped to what a person can already authenticate for, and no agent anywhere is allowed to write critical data into a production system.
The payoff is a program that can still move fast toward 10x and 100x goals, because the discipline is doing the filtering rather than a backlog of half-tested ideas.
→ See how Tray governs agent access
In their words
What does moving from AI experimentation to real AI adoption actually look like?
For us, it was about measuring, figuring out how to measure ROI, and establishing a governance and prioritization process for use cases. We couldn’t just allow everybody to deploy ideas or vibe-coded solutions. We have established a set of champions across all of our business units at Zuora, and they come together on a weekly basis and talk about what their priorities are, what’s important, and then we work really hard to grab the ones that deliver the most ROI for us. We have an established governance process that we follow.
What did you learn from that experience?
We wanted input from all of the different groups in the company, from sales, from global services, from customer success. We wanted them all to be a part of it, but when you’re trying to capture ROI, that’s the hard part. How do you measure the success of all the different ideas that come to the table? Some of them will come to the table in a very passionate way, like this is a really great idea, but when you dissect it and really talk it through, it might not be near as valuable to the company as something coming from another team. So we wanted the group to be able to say, here’s our priority with our Zuora hat on.
What role does IT play in making AI successful across the business?
The majority of the AI in the enterprise, what’s used within operations at Zuora, the entire budget is owned by IT. We take ownership and responsibility for driving the choice, driving the commercials, and then driving the deployment. When we have new tooling available, we plan the exposure, the information flow, the communications to everyone. We usually provide ramp-up sessions to everyone, so everybody’s aware of what tools they have.
Once they start operating, we provide sessions in the form of the champions that we just talked about, or ongoing coffee talks or brown bag sessions where people can come and ask questions. Then we help teams actually deploy the ideas, depending on the tooling that they’re building it in, and in some cases we help them move on to new ideas.
How do you balance AI experimentation with security and governance?
Everybody experimenting on their own, if they’re using the tools we’ve provided, those tools are already set up to where the authentication only allows them access to data that they already only have access to in the landscape, so they can’t get deeper than that. If they’re vibe coding on their own machine, they don’t get any extended access to data beyond the tooling that they have.
We don’t allow access without approval and review to any data beyond what they can authenticate for. And we also don’t allow any of our agents anywhere to write critical data into any of our systems. That’s a rule that everybody already knows. There are multiple mechanisms that we’re using to control that.
"We also don't allow any of our agents anywhere to write critical data into any of our systems. That's a rule that everybody already knows."
What conventional wisdom about AI do you think is wrong?
I think everybody thinks they’re gonna get immediate ROI, and that actually doesn’t happen very often at all. You’ve gotta be governed and specific and disciplined about the solutions that you’re solving with AI. Just deploying AI and expecting it to actually make a difference doesn’t happen. You actually have to participate in the process. I see a lot of people who go, we’re gonna implement AI and we won’t need all these people, or we can change what we’re doing. It doesn’t happen that quickly.
"Everybody thinks they're gonna get immediate ROI, and that actually doesn't happen very often at all."
What excites you about what Tray is building?
I’m excited about MCP gateway. I’m excited about the new MCP tools that are coming. I’m really excited about Tray MCP within Claude Code. That will change the way we build workflows. That’ll change the way we deliver change to all of our business partners. I’m super excited about that because we’re trying to get ourselves to 10x and 100x of what we were doing last quarter, and I think that’s really gonna enable us to do that.
Govern agent access before it becomes a problem
The discipline behind Zuora's move from AI experiments to real adoption.
Read Zuora's story →