TELUS is one of Canada's largest telecommunications and technology companies, operating across telecommunications, health, and agriculture, historically as four distinct organizations (TELUS Communications Inc., TELUS Health, TELUS Agriculture, and TELUS International, since repatriated into TCI), each with its own governance structure and SaaS footprint. Adam Smith leads the CAPS team (Cloud infrastructure, API Program, and Security), which spans API infrastructure, developer experience, and the security tooling that includes Cloudflare and Obsidian, as well as IT asset management. Cam Sawatzky leads the team responsible for edge protection and CDN via Cloudflare, and for SaaS security posture, a practice built in large part around Obsidian.
TELUS's SaaS estate had grown the way most large, federated enterprises' do: organically, and largely without central oversight. Individual business units and admins purchased and configured tools on their own, some federated, some paid for on a personal credit card, accumulating into a footprint north of a hundred distinct applications. Each of TELUS's four historic organizations maintained its own SaaS tools, its own governance, and in many cases its own CSO.
Obsidian's introduction to TELUS wasn't the product of a competitive bake-off, it was the product of proven results. Obsidian was originally brought in to help TELUS Agriculture's team improve its posture following the Snowflake incident. As other teams inside TELUS began to hear about the impact, adoption spread organically: the team managing Google Workspace ran its own proof of concept, then onboarded Obsidian for its first tier of SaaS tools. From there, what began as isolated, org-specific usage became the foundation for a company-wide SaaS security program.
The value was clear enough, fast enough, that it changed how TELUS thought about budget for the program entirely.
For a lean team supporting a global, multi-org SaaS estate, the value of Obsidian shows up most clearly in the first hours after a new supply chain threat breaks. When a new attack, most recently, a Shai-Hulud-style incident is publicly disclosed, TELUS doesn't need to chase down individual SaaS admins one by one to check exposure.
By the time I wake up and start work, my team is already often able to see if we're impacted by a supply chain attack. ... [With the most recent one] I woke up and we'd already communicated it out and identified the couple of key areas to look into."
That speed replaces what would otherwise be a slow, manual scramble across dozens of admins with a single, centralized answer and it changes the emotional experience of an incident as much as the technical one.
There's always that initial panic and anxiety about the unknown. I feel like, to a large extent, we bring some clarity into that chaos and say: rest assured, here's a clear picture of what's going on."
Google Workspace is TELUS's largest SaaS deployment by user count, roughly 80,000 seats spread across Canada, the U.S., the Philippines, Australia, South Africa, and Europe. It's also where TELUS's Obsidian usage is most mature. The team meets with its Obsidian TAM on a regular cadence to work through posture improvements, monitors for shadow SaaS and unnecessary spend, and evaluates which native Google Workspace capabilities are safe to unlock for employees versus which ones (like unrestricted third-party integrations) represent unacceptable risk.
That maturity also produced a tangible financial outcome. In a single review wave, TELUS's Obsidian team categorized third-party Google Workspace connections into roughly ten categories and cross-referenced them against existing enterprise contracts, surfacing redundant, individually expensed tools that overlapped with agreements TELUS already had in place. The exercise identified real license cost savings and became the business case that helped the team secure an unlimited SaaS security budget going forward.
The strategic side of TELUS's SaaS security program, onboarding new applications and running posture improvement is run by a very lean team. Detection, alerting, and 24/7 monitoring sit with TELUS's SOC and threat intelligence teams, who rely heavily on Obsidian's data as part of their own workflows.
The amount of value we're able to get out of it, because of the amount of automation that's in there, is really good. In a challenging time around staffing, it's been able to stay on its feet with a very small team."
TELUS's SaaS security program is still consolidating, moving from four historically independent organizations toward more centralized, enterprise-wide governance. As that consolidation continues, and as agentic AI adds a new and faster-moving layer of risk on top of an already sprawling SaaS estate, TELUS sees the same discipline that brought consistency to Google Workspace and reined in GitHub as the model for what comes next.