Most consulting firms publish the wins. We do too, but we also published the one where our own recommendation didn't survive contact with the client, because that story is more useful than another clean win would have been, and because a firm that only ever shows you its successes hasn't shown you enough to trust it.
Here are all four, with the real numbers.
The one that looked clean and still wasn't
A European D365 F&SC estate, about 700 licensed users, security that was genuinely among the best-configured we've assessed. No sloppy roles, no obvious villain. Monthly cost: $105,000. Comparing what was granted against what people actually did in the system, not what looked reasonable on paper, brought that down to about $65,000 a month, a 35 to 37 percent reduction, plus roughly a dozen roles flagged for segregation-of-duties conflicts nobody had previously found. Full details: A 35% License Savings in a D365 Estate With Nothing Obvious to Cut.
The one where automation did the deployment, not just the analysis
Roughly 150 licensed users, a fairly ordinary security picture. What made this one different is what happened after the analysis: the optimal security model was generated as importable configuration and deployed in about ninety minutes, not built by hand over weeks. Monthly cost dropped from a projected $43,000 to about $32,000, a 25 percent reduction. The harder part, as it turned out, wasn't the deployment itself, it was the framework of organization assignments, view references, and policy relationships that had to be carried over deliberately so the new roles didn't lose anything the old ones quietly depended on. Full details: We Rebuilt a Client's D365 Security Model in 90 Minutes. The Hard Part Was Everything Else.
The one where the numbers worked and we said no anyway
This is the one we'd rather you read before you hire anyone in this space, including us. A large, integration-heavy estate with nearly a thousand users produced a genuinely optimal security redesign, mathematically speaking. It would have cut the monthly bill from $72,000 to $40,000, a 44 percent reduction. It also would have produced roughly a hundred security roles, which made it unmaintainable for the administrators who'd have to live with it every day. The client turned it down, and they were right to. We rebuilt the methodology because of what that engagement taught us: a security design nobody can reason about isn't a design, it's a liability with a spreadsheet attached. Full details: We Cut a Client's D365 License Bill by 44%. They Turned It Down.
Anyone can show you a savings percentage. Showing you the one where the savings percentage wasn't the whole answer is the part that's actually hard to fake.
The one with no savings number at all
Not every engagement in this series is about cutting an existing bill. One was a mentoring engagement on a brand-new, greenfield D365 F&SC implementation, roughly thirty security roles, built from a clean requirements sheet with no legacy drift behind it. Running a segregation-of-duties analysis anyway, a day before user acceptance testing, found over a thousand conflicts hiding inside those thirty roles. There's no before-and-after dollar figure here, because the fix happened before go-live instead of after, which is exactly the point: the same telemetry-driven approach that finds six-figure overspend in a mature estate also works as prevention, before the expensive version of the same problem ever gets the chance to exist. Full details: Thirty Roles. A Thousand Conflicts. One Day Before UAT.
Why we publish it this way
Anonymized case studies with specific, checkable numbers aren't the flashiest form of proof. A named client with a big round percentage would read better on a slide. But the numbers above are real, tied to real engagements, and one of them describes our own recommendation getting turned down for a reason we ultimately agreed with. That's a harder story to tell than four wins in a row, and it's the reason we tell it.
Four engagements, four different shapes of the same underlying discipline: trace the license requirement to the security configuration actually driving it, check it against real usage, and be honest about what the evidence supports, even when that means walking back your own first answer.