Aller au contenu principal
Image principale de l’étude de cas : High-speed rail: IRYO brings Claude into its software development cycle, on its own Anthropic organisation

Histoire de réussite

High-speed rail: IRYO brings Claude into its software development cycle, on its own Anthropic organisation

  • Rail
  • Software development
  • AI governance
  • Corporate AI

Thinkia implemented the software development process at IRYO, with a 57% reduction in development effort, on an Anthropic organisation that belongs to the operator. Thinkia also runs the FinOps of that consumption, at cost and with no margin on tokens.

  • 57% Reduction in development effort after implementing the process

Context

IRYO was where most large European companies found themselves in 2026: its people had started using AI assistants, and the company had no way of saying who used what, under which terms, at what cost or with which data. The first corporate account had been opened informally by a manager on a personal payment method, and lapsed when the card expired. That is the real starting point: not a lack of appetite for AI, but the absence of a control plane underneath it.

For an operator whose service is defined by punctuality and safety, that gap is not only a finance problem. Unsupervised assistant use means corporate content leaving through channels with no data processing agreement, credentials nobody can revoke when a person leaves, and no auditable record of who did what.

And the default alternative — a blanket corporate licence administered centrally by IT — is slow, fits badly with how teams actually work, and turns every seat change into a ticket.

Collaboration

The development process, implemented

The centre of gravity of this engagement is software development. Claude is not a general assistant handed to the workforce and left there: Thinkia implemented the software development process itself at IRYO, with Claude Code as the environment where that work happens. Teams specify, build and review inside a governed cycle, and the delivery method travels with it — so the same governance that applies to the code applies to the AI that helps produce it. For an operator working under rail safety and availability obligations, that is a requirement rather than a preference.

On an organisation that belongs to the operator

Underneath sits the part that makes the rest defensible: delegated self-management over the customer’s own Anthropic organisation.

Thinkia holds the commercial relationship with Anthropic, provisions IRYO’s organisation, verifies the domain and sets the global spend limits. From there, administrators appointed by the operator add and remove users and keys within those limits, without asking anyone’s permission. Thinkia watches global spend, warns as limits approach, and escalates platform incidents to Anthropic through to closure.

The governance frame is explicit rather than implied: corporate identity through SSO/SAML with domain verification and least-privilege roles; named API keys per user and per project, with scheduled rotation and immediate revocation on every departure; spend limits per organisation and per user, with threshold alerts and blocking on anomalous consumption patterns; a signed DPA and the guarantee that the operator’s prompts and outputs are not used to train models; and a change log of every administrative action, available for the customer’s own review.

The commercial design is the part that makes it work: Thinkia takes no margin on token consumption. Usage is billed at cost and verified by the customer’s own administrators in a dashboard that separates fixed seats from variable API usage and mirrors each provider invoice. What the operator sees is what is actually paid.

The products are Claude for Work — Team seats, which include Claude Code — and an Anthropic API organisation with keys per user and per project.

And the FinOps of that consumption

Thinkia also runs the FinOps of IRYO’s AI consumption: tracking spend against the declared limits, attributing it by team and by project, flagging anomalous patterns before they become an invoice, and reconciling every line against what the provider actually charged. It is the discipline that keeps the previous section from being a set of good intentions — a spend limit only means something if somebody watches it, explains the variance and acts on it.

And it is run without a conflict of interest: Thinkia takes no margin on the tokens it is optimising. Consumption is billed at cost, so reducing it costs Thinkia nothing and gains the operator everything.

Outcome

What it gives the operator: a software development process implemented and running, with teams working with Claude inside a governed cycle rather than through personal accounts and improvised tooling. An Anthropic organisation that belongs to IRYO rather than to its supplier, so the relationship survives any change of supplier. And the FinOps of that consumption run by someone with no incentive to let it grow. A single answer, with an owner, to “who uses Claude here, for what, and at what cost” — where before there was an informal account on a personal payment method that lapsed in silence. Corporate AI use inside the company’s own security perimeter, with a compliance posture that is contractual rather than assumed: signed DPA, no training on the operator’s content, minimum retention. Spend that cannot run away, so AI cost becomes a line finance can plan rather than a surprise it discovers. Consumption billed at cost and reconciled line by line against the provider invoice, in a dashboard the customer audits rather than takes on trust. And speed without losing control: a new team has access in minutes rather than a procurement cycle, while provisioning, policy and oversight stay with a single owner.

The result: a 57% reduction in development effort after the process was implemented.

What is not on this page: the adoption and spend figures live inside the FinOps reporting and are not published here. This is a 2026 contract and the deployment continues.

Case metrics correspond to specific projects and do not constitute a promise of results; each context produces its own range.