Customers

Inside Tampa General Hospital's Approach to Governing Agent Adoption

Tampa General Hospital operates six hospitals and several hundred clinics and surgery centers across the state of Florida. As the health system's Chief Information Security Officer, James Bowie is responsible for security across that entire footprint, including a SaaS environment that touches nearly every clinical and administrative workflow.

Like most healthcare organizations, Tampa General has watched AI move from experimental to embedded across its applications faster than governance could keep pace. That gap became impossible to ignore after a single, unplanned discovery.

Industry
Hospitals and Health Care
Company size
15,000
USE case
AI Governance and Shadow Apps
Ready to start?
Get a demo

The Discovery That Changed the Approach

The shift started with a routine question. Tampa General's deputy CISO asked Bowie whether the organization had signed a contract with a particular vendor. It hadn't, and no assessment had ever been run on it.

The team traced how the application had made its way into a user's inbox and found no clear answer. Pulling on that thread surfaced a broader pattern: employees across the organization had signed up for a range of unsanctioned applications and AI-enabled tools on their own, often without realizing AI was built into them at all. Tampa General's existing security tools hadn't flagged any of it, because nothing had been installed or attached in a way legacy detection methods were built to catch.

The scope of the problem made it clear that Tampa General needed a purpose-built solution for third-party AI and SaaS visibility.

What Reco's Deployment Revealed

Tampa General already had a reasonably mature AI governance program in place before evaluating Reco, with buy-in from leadership across the organization. Based on that foundation, Bowie expected the deployment to surface a modest number of previously unknown applications.

The actual scope of exposure was significantly larger than anticipated. The findings spanned far more of the organization's third-party footprint than the team's earlier manual inventory had suggested, and represented a different category of risk than a traditional network vulnerability: risk distributed across dozens of applications that staff had adopted independently, each with its own access to organizational data. The security team worked through the findings systematically, prioritizing the highest-risk exposures first.

Bringing Leadership Into the Conversation

Visibility on its own doesn't reduce risk. Turning that visibility into organizational change required Bowie to bring the findings directly to Tampa General Hospital's leadership.

Bowie presented the data to a leadership forum of roughly a thousand people, framing the exposure in terms the room could act on: the convenience of an unsanctioned tool did not outweigh a risk he quantified at $150 million to the organization. He walked through specific applications different departments had adopted, many of which had embedded AI capabilities that weren't apparent to the people using them.

The Reco dashboard was central to making the case. A single view let Bowie show any department leader exactly what their team had introduced into their ecosystem, turning an abstract risk into something concrete and ownable. According to Bowie, that exercise shifted the conversation from resistance to accountability across the leadership team.

Moving From Blocking AI to Governing It

Tampa General's security team recognized early that blocking AI outright wasn't a sustainable strategy. Staff wanted to use these tools, and restricting adoption entirely would have put the security team at odds with the rest of the organization.

Reco enabled the team to take a different approach: catalog every application and agent in use, determine which to approve, and redirect employees toward vetted alternatives when they reached for something unsanctioned. Instead of a flat denial, the security team could point users to an approved, secured option that met the same need.

"The most impactful thing was being able to show that dashboard and say: here's the sprawl this has created. Every time this happens, it makes the job harder."

James Bowie,
CISO Tampa General Hospital

Upskilling the Security Team

AI-related work now accounts for roughly half of the security team's workload, a significant increase for a team that was already stretched before AI adoption accelerated.

Rather than treating this as pure overhead, Tampa General used it as a training opportunity. The team set aside dedicated time to build an agent from scratch, including the use case, deployment, and a working interface, then had other team members attempt to break it. That exercise gave the team hands-on familiarity with how agents are built and where they're vulnerable, and the organization has continued to repeat the cycle since. The result is a team that understands AI well enough to secure it, rather than one working from theory alone.

Why Tampa General Hospital Chose Reco

At the time of evaluation, Tampa General Hospital found no other vendor able to address the full scope of its third-party AI and SaaS visibility requirements. The proof of concept was, in Bowie's words, a deciding factor in the selection.

One specific integration Tampa General needed did not yet exist in the platform. Rather than placing the request on a roadmap for a future release, Reco delivered it within two days via Reco Factory, before the contract was finalized. Deployment itself was completed in a matter of minutes.

Looking Ahead

Bowie sees the hospital’s partnership with Reco continuing to evolve alongside the broader challenge of agent ecosystem security, an area he views as still largely unsolved across the industry. Based on ongoing conversations with Reco's product team, Tampa General expects to help shape an approach that allows healthcare organizations to secure agents without preventing their teams from using them.

About Reco

Reco is the leader in agent Ecosyetm security — eliminating the security gap driven by SaaS sprawl. The Reco Platform connects to your entire third-party environment, maps every relationship and action, and gives your team the context to act. New SaaS and agent integrations can be built in hours, enabling teams to keep innovating safely.

Book a demo today

Read More Customer Stories

5 min read
July 11, 2025

Banco BS2 Uses Reco to Gain Visibility into SaaS Security During Mergers & Acquisitions

Banco BS2 is a Brazilian digital bank that's often involved with mergers and acquisitions of other financial institutions. Banco BS2 uses Reco to gain visibility into the security posture of the company they are merging with or acquiring. Douglas Ferreira, Chief Information Security Officer at Banco BS2, shares why he chose Reco for SaaS Security and the benefits for his organization.
5 min read
July 10, 2025

BHG Financial Uses Reco for In-Depth SSPM and Governance

BHG Financial is a financial services company that provides financial solutions to professionals, small business owners, and financial institutions. They use Reco to ensure in-depth SaaS security posture management and governance of their SaaS ecosystem. Fred Hamilton, Chief Information Security Officer at BHG Financial, explains why he chose Reco for SaaS Security and the benefits for his organization.
Read More
Watch Now
5 min read
July 9, 2025

Ruby Life Achieved Executive Buy-In and Obtained Budget for SaaS Security

Ruby Life's CISO successfully secured budget for Reco by strategically aligning with both technical and business stakeholders, demonstrating how SaaS security would enable safe AI adoption and drive revenue growth rather than just mitigate risks. Learn how this approach helped the mid-size company gain executive support by connecting security investments to concrete business outcomes like compliance, customer retention, and competitive advantage.
Read More
Watch Now

Your agents are already running. Do you know what they're doing?

Request a demo