Blink Security Automation — Confidential

accretive — Customer Success Report

Generated 2026-10-05 | accretive-value-report.md
2026-10-05Report Date
253Total Playbooks
20Unique Workflows (12m)
55,459Actions Automated (12m)
$14,264Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

253
Total playbooks built
all non-deleted workflows
45
Active playbooks
currently enabled
20
Unique workflows executed (12m)
distinct workflows that ran
55,459
Actions automated (12m)
completed action steps
308.1h
Hours saved (12m)
@ 20s per action
$14,264
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 964 Palo Alto CVE & security advisories ingested and converted to Jira tickets — zero analyst effort required - 80 new hire Active Directory accounts enabled on schedule (40 U.S. + 40 HU/RO) - 40 daily firewall policy override compliance reports generated from Panorama - 19 backup failure events automatically detected, classified, and routed - 18 SentinelOne threat detections auto-ticketed across U.S. and Hungary environments - 16 VPN disconnections executed across Palo Alto and Cisco FTD infrastructure (admin + self-service) - 8 MFA re-enrollment actions enforced for Hungary-region users

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Palo Alto CVE & Security Advisory Tracking
  • 964Palo Alto CVE & security advisory tickets auto-created
78.8%
1
1 active
Employee Onboarding — AD Account Activation
  • 40New hire AD accounts enabled (U.S.)
  • 40New hire AD accounts enabled (HU/RO)
6.6%
3
3 active
Firewall Policy Compliance Monitoring
  • 40Firewall policy override compliance reports delivered
3.3%
1
1 active
Backup Failure Monitoring & Alerting
  • 19Backup failure events detected & routed
3.3%
1
1 active
SentinelOne Threat Detection & Case Management
  • 12SentinelOne threats auto-ticketed (Hungary)
  • 6SentinelOne threats auto-ticketed (U.S.)
1.6%
5
5 active
VPN Session Enforcement & Self-Service
  • 9VPN sessions force-disconnected (admin-initiated)
  • 6Self-service VPN disconnection requests completed
5.6%
6
6 active
MFA & Password Lifecycle Management
  • 8MFA re-enrollments enforced (Hungary users)
0.7%
4
4 active
IT Self-Service & Helpdesk
  • 1VPN kick requests processed (Teams-initiated)
0.2%
3
3 active
Identity & HR Attribute Management
  • 1Employee title changes automated
0.0%
2
2 active
Employee Offboarding & Termination0 executions
0.0%
2
2 active
Teams Guest Access Review0 executions
0.0%
2
2 active
Risky User Monitoring0 executions
0.0%
1
1 active
Wazuh SIEM Detection Engineering0 executions
0.0%
1
1 active
IT Asset & Network Inventory0 executions
0.0%
2
2 active
Development / Sandbox0 executions
0.0%
7
6 active
Total1,218 executions100%
41
40 active

Use Case Growth Over Time

212 unique playbooks  |  15 operational use cases  |  1,218 total executions (12m)  |  2025-03 to 2026-06
Toggle:
Toggle:

03Integration Ecosystem

Development / Sandbox
Microsoft Teams NetBox
Risky User Monitoring
Microsoft Entra ID Microsoft Teams
Employee Onboarding — AD Account Activation
Jira Data Center NetBox Active Directory Active Directory On-Prem Email
SentinelOne Threat Detection & Case Management
VirusTotal Microsoft Teams SentinelOne Jira Data Center
VPN Session Enforcement & Self-Service
SentinelOne Jira Data Center NetBox
Teams Guest Access Review
Microsoft Graph Jira Data Center
MFA & Password Lifecycle Management
Microsoft Entra ID Microsoft Teams Microsoft Graph Jira Data Center Active Directory On-Prem
Backup Failure Monitoring & Alerting
Microsoft Teams
IT Self-Service & Helpdesk
Microsoft Entra ID Active Directory On-Prem Jira Data Center Microsoft Teams Confluence Data Center
Identity & HR Attribute Management
Microsoft Entra ID Active Directory On-Prem Microsoft Teams Jira Data Center
IT Asset & Network Inventory
NetBox
Firewall Policy Compliance Monitoring
Jira Data Center
Employee Offboarding & Termination
Active Directory On-Prem NetBox Microsoft Teams Microsoft Entra ID PagerDuty Jira Data Center
Palo Alto CVE & Security Advisory Tracking
Jira

04Key Observations

✓  Strengths

Strengths

Vulnerability tracking at scale. The Palo Alto RSS ingestion playbook is the highest-volume automation at 964 executions — running every hour to capture CVEs and security advisories. This represents a meaningful reduction in analyst overhead for vendor advisory monitoring and ensures zero advisories are missed.

Multi-region, timezone-aware IAM. The organization operates across U.S., Hungary, and Romania and has built corresponding IAM automation for each region. New hire AD activation, MFA enforcement, title changes, and offboarding all have separate Hungary-scoped variants, showing mature operational segmentation.

Layered VPN enforcement. The VPN disconnection system is well-architected: a NetBox-driven device inventory feeds a parallel orchestrator that fans out to both Cisco FTD and Palo Alto platforms simultaneously. The addition of a self-service path reduces IT intervention for routine disconnection requests.

Comprehensive offboarding blueprint. The SelfService Termination playbook covers the full offboarding checklist in a single workflow: on-prem AD disable, Entra disable + session revoke, VPN kick, IP cleanup (NetBox), and Jira audit ticket. This is a strong foundation even though it has not yet run in production.

Dual EDR environments. Separate SentinelOne playbooks for U.S. and Hungary environments (18 total executions) show that the threat detection pipeline is active across both geographic footprints.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Offboarding not yet in production. The SelfService Termination workflow has 0 executions despite being fully built. Activating it would bring the full IAM lifecycle under automation and reduce the risk of incomplete offboarding steps.

MFA and password reset workflows underutilized. Reset Password and Re-Require MFA (All Users) have 0 executions; the Hungary-scoped MFA variant has only 8. These workflows appear ready — driving adoption through IT team enablement could increase usage significantly.

Guest access review not yet run. Teams Guest Accounting is built and complete but shows 0 executions. Running this quarterly would generate an audit-ready access review report and address a common compliance gap.

Risky User Monitoring not operationalized. The Gather Risky Users playbook exists but has not run. Scheduling it daily or connecting it to an Entra risk event would turn a dormant capability into an active identity threat detection signal.

Wazuh SIEM coverage not yet scheduled. The detection engineering playbook covers 10+ Wazuh alert categories but has not been scheduled. Converting it to a scheduled daily or weekly run would provide continuous SIEM health and coverage reporting.

SentinelOne triage on-demand not wired to the event pipeline. The On-Demand triage variant (SentinelOne Alert Triage Final On-Demand) has 0 executions. Connecting it to the event-driven S1 webhook pipeline as an escalation handler would complete the automated triage → analyst review → containment loop.

Integration Ecosystem

Integration Use Cases
Microsoft Entra ID / Active Directory Onboarding, Offboarding, MFA enforcement, Risky user monitoring, Title changes
Microsoft Teams VPN enforcement, MFA/password reset, Offboarding, Threat alerts, HR changes, Helpdesk
Jira Data Center CVE ticketing, Onboarding, S1 case creation, Offboarding, MFA audit, Title changes
SentinelOne Threat detection & case management, VPN–EDR gap analysis
Palo Alto Networks (Panorama / SSH) VPN enforcement, Firewall policy compliance
Cisco FTD (SSH) VPN enforcement
NetBox (IPAM/DCIM) VPN IP onboarding, Offboarding cleanup, Asset inventory
Splunk Firewall compliance queries, VPN login analysis
Wazuh SIEM detection engineering
Microsoft Graph Guest access review, Teams enumeration, Entra session revoke
Confluence Data Center Knowledge base search (helpdesk)
Blink Web Forms Asset serial number intake
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 New Agent Enterprise IT 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Enterprise IT0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Demo Dash 00

Webforms

Forms
6
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 SN Collector 00
2 What user would you like to edit? 00
3 Title 00
4 Which User would you like to Terminate 00
5 header 00
D Full Use Case Analysis 15 use cases | 1,218 executions (12m)

Business KPIs

Metric Count Playbook
Palo Alto CVE & security advisory tickets auto-created 964 Create Jira Tickets from PAN Security RSS
New hire AD accounts enabled (U.S.) 40 Enable U.S. New Hire AD account
New hire AD accounts enabled (HU/RO) 40 Enable HU or RO New Hire AD account
Firewall policy override compliance reports delivered 40 Daily Report on Panorama Policy Override Requiring Review
Backup failure events detected & routed 19 Failed Backup
SentinelOne threats auto-ticketed (Hungary) 12 S1 Hungary - Threat Detected Alert and Ticket Submission
VPN sessions force-disconnected (admin-initiated) 9 Disconnect Someone from VPN - Run This
MFA re-enrollments enforced (Hungary users) 8 Re-Require MFA - Hungary Users
SentinelOne threats auto-ticketed (U.S.) 6 S1 Threat Detected Alert and Ticket Submission
Self-service VPN disconnection requests completed 6 Self Service Disconnect Myself from VPN
Employee title changes automated 1 Change Title - Hungary Users
VPN kick requests processed (Teams-initiated) 1 VPN kicker (Kick user off of VPN)
In the last 12 months, Blink automated: - 964 Palo Alto CVE & security advisories ingested and converted to Jira tickets — zero analyst effort required - 80 new hire Active Directory accounts enabled on schedule (40 U.S. + 40 HU/RO) - 40 daily firewall policy override compliance reports generated from Panorama - 19 backup failure events automatically detected, classified, and routed - 18 SentinelOne threat detections auto-ticketed across U.S. and Hungary environments - 16 VPN disconnections executed across Palo Alto and Cisco FTD infrastructure (admin + self-service) - 8 MFA re-enrollment actions enforced for Hungary-region users

Use Case Summary

# Use Case Category Subcategory Playbooks Executions (12 mo)
1 Palo Alto CVE & Security Advisory Tracking Vulnerability Mgmt CVE lookup & remediation 1 964
2 Employee Onboarding — AD Account Activation IAM Employee onboarding 3 80
3 Firewall Policy Compliance Monitoring GRC Security metrics & reporting 1 40
4 Backup Failure Monitoring & Alerting Other IT/OT & network infra monitoring 1 19
5 SentinelOne Threat Detection & Case Management SOC EDR containment & response 5 18
6 VPN Session Enforcement & Self-Service IAM JIT & temporary access 9 16
7 MFA & Password Lifecycle Management IAM Password & credential lifecycle 4 8
8 IT Self-Service & Helpdesk Other IT helpdesk & ticket routing 3 1
9 Identity & HR Attribute Management IAM Identity lifecycle automation 2 1
10 Employee Offboarding & Termination IAM Employee offboarding 3 0
11 Teams Guest Access Review IAM Access review & group mgmt 3 0
12 Risky User Monitoring SOC Identity threat response 1 0
13 Wazuh SIEM Detection Engineering SOC SIEM & log pipeline monitoring 1 0
14 IT Asset & Network Inventory Other IT/OT & network infra monitoring 2 0
15 Development / Sandbox — — 7 0
Total 46 1,147

Use Cases

1. Palo Alto CVE & Security Advisory Tracking

Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation

Description: Automatically ingests the Palo Alto Networks security RSS feed on an hourly schedule, parses each new CVE and advisory, and creates a corresponding Jira ticket. This eliminates the manual work of monitoring vendor advisories and ensures every published vulnerability is immediately tracked in the organization's ticketing system.

Business problem solved: Security teams routinely miss or delay acting on vendor CVE feeds because manual monitoring is error-prone and slow. This playbook guarantees every Palo Alto advisory is captured, catalogued, and assigned — at the moment it is published.

Integrations: HTTP (RSS/XML fetch), Jira Data Center

Playbook Trigger Executions (12 mo) Category Subcategory
Create Jira Tickets from PAN Security RSS Scheduled (hourly) 964 Vulnerability Mgmt CVE lookup & remediation

2. Employee Onboarding — AD Account Activation

Category: IAM | Subcategory: Employee onboarding, Identity sync & directory mgmt

Description: Enables new hire Active Directory accounts on their start date for both U.S. and European (Hungary/Romania) timezones. A scheduled daily job checks Jira for new hire tickets and activates the corresponding AD account at the appropriate local business time. A companion workflow handles VPN IP assignment and Netbox registration during onboarding.

Business problem solved: Delayed account activation on a new hire's first day creates a poor employee experience and productivity loss. These playbooks ensure accounts go live exactly when needed — in the correct timezone — without requiring an IT admin to manually action each ticket.

Integrations: Jira Data Center, Active Directory (on-prem / WinRM), Microsoft Graph, NetBox

Playbook Trigger Executions (12 mo) Category Subcategory
Enable U.S. New Hire AD account Scheduled (daily, 00:15 PT) 40 IAM Employee onboarding
Enable HU or RO New Hire AD account Scheduled (daily, 00:15 CET) 40 IAM Employee onboarding
Jira Ingestion Employee VPN IP Onboarding On-demand 0 IAM Employee onboarding, Identity sync & directory mgmt

3. Firewall Policy Compliance Monitoring

Category: GRC | Subcategory: Security metrics & reporting, PCI & regulatory monitoring

Description: Runs a daily Splunk query against Palo Alto Panorama configuration logs to identify firewall rules with local policy overrides — rules that deviate from the centrally managed Panorama templates. When overrides are detected, a formatted report is delivered to the security team for review.

Business problem solved: Local firewall rule overrides are a common audit finding and a sign that policy governance is breaking down. This playbook provides daily visibility into policy drift so the network security team can remediate deviations before they become compliance gaps.

Integrations: Splunk (HTTP/Ad Hoc query), Jira Data Center

Playbook Trigger Executions (12 mo) Category Subcategory
Daily Report on Panorama Policy Override Requiring Review Scheduled (daily, 08:30) 40 GRC Security metrics & reporting, PCI & regulatory monitoring

4. Backup Failure Monitoring & Alerting

Category: Other | Subcategory: IT/OT & network infra monitoring

Description: Listens for inbound webhook events from the backup platform. When an event containing a backup failure keyword is received, the playbook classifies and routes the alert for IT operations response.

Business problem solved: Undetected backup failures are a silent disaster risk — they often go unnoticed until a restore attempt fails. This event-driven playbook ensures every backup failure generates an immediate, actionable alert rather than disappearing into a log.

Integrations: Custom Webhook (backup platform)

Playbook Trigger Executions (12 mo) Category Subcategory
Failed Backup Event (custom webhook) 19 Other IT/OT & network infra monitoring

5. SentinelOne Threat Detection & Case Management

Category: SOC | Subcategory: EDR containment & response, Case mgmt & SOAR

Description: End-to-end automated response pipeline for SentinelOne endpoint threats. When S1 detects a threat (via webhook), the playbook deduplicates against existing Jira tickets, creates a new case if needed, and optionally escalates for analyst review via Teams interactivity. Separate variants cover U.S. and Hungary S1 environments. Additional playbooks support analyst-initiated triage review and host isolation lift.

Business problem solved: Manual threat triage creates alert fatigue and delays response. These playbooks ensure every S1 threat is immediately logged as a Jira ticket, duplicate alerts are suppressed, and analysts are only interrupted when genuine escalation is warranted.

Integrations: SentinelOne, Jira Data Center, Microsoft Teams, Microsoft Outlook (email webhook), VirusTotal (IOC enrichment implied)

Playbook Trigger Executions (12 mo) Category Subcategory
S1 Hungary - Threat Detected Alert and Ticket Submission Event (custom webhook) 12 SOC EDR containment & response, Case mgmt & SOAR
S1 Threat Detected Alert and Ticket Submission Event (custom webhook) 6 SOC EDR containment & response, Case mgmt & SOAR
SentinelOne Alert Triage Final On-Demand On-demand 0 SOC EDR containment & response, Alert enrichment / IOC lookup
SentinelOne Host via Email Notification Event (Outlook webhook) 0 SOC Phishing detection & response, EDR containment & response
SentinelOne Lift Host Isolation On-demand 0 SOC EDR containment & response

6. VPN Session Enforcement & Self-Service

Category: IAM | Subcategory: JIT & temporary access, Identity lifecycle automation

Description: A multi-component system for enforcing VPN session termination across both Palo Alto and Cisco FTD firewall platforms. The primary orchestrator queries NetBox for all active VPN firewall devices, spawns parallel helper subflows per device, and collects results. A self-service variant allows employees to disconnect themselves from VPN (e.g., before an IT action). An additional analytical workflow cross-references Splunk VPN login data against the SentinelOne agent inventory to surface devices on VPN without EDR coverage.

Business problem solved: Terminating a user's VPN session during an incident, offboarding, or policy violation requires coordinating across multiple heterogeneous firewall platforms. Manual execution is slow and error-prone. These playbooks reduce a multi-step, multi-device operation to a single automated action.

Integrations: NetBox, Palo Alto Networks (SSH/Paramiko), Cisco FTD (SSH/Paramiko), Blink (cross-automation call), SentinelOne, Splunk, Microsoft Teams

Playbook Trigger Executions (12 mo) Category Subcategory
Disconnect Someone from VPN - Run This On-demand 9 IAM JIT & temporary access
Self Service Disconnect Myself from VPN On-demand 6 IAM JIT & temporary access
Disconnect Someone from VPN - Helper Cisco FTD Subflow 36 IAM JIT & temporary access
Disconnect Someone from VPN - Helper Palo Alto Subflow 54 IAM JIT & temporary access
VPN kicker (Kick user off of VPN) On-demand (Teams) 1 IAM JIT & temporary access
VPN without S1 On-demand 0 Other Endpoint hygiene & MDM ops
VPN without S1 copy On-demand 0 Other Endpoint hygiene & MDM ops
Disconnect Someone from VPN - Helper Palo Alto *(workspace 2)* Subflow 0 IAM JIT & temporary access
Disconnect Someone from VPN - Helper Cisco FTD *(workspace 2)* Subflow 0 IAM JIT & temporary access

7. MFA & Password Lifecycle Management

Category: IAM | Subcategory: Password & credential lifecycle, Identity lifecycle automation

Description: A set of Teams-driven self-service workflows enabling IT administrators or security staff to re-enforce MFA requirements and reset passwords for users in Hungary and global scopes. Each workflow validates the runner's identity, prompts for the target user via Teams, performs verification steps, then executes the credential action in Active Directory. A re-require MFA variant additionally lists and revokes existing MFA methods before forcing re-registration.

Business problem solved: MFA bypass, credential compromise, and account lockout resolution are high-frequency IT operations that consume significant analyst time when handled manually. These playbooks give authorized staff a guided, audited self-service path via Microsoft Teams.

Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center

Playbook Trigger Executions (12 mo) Category Subcategory
Re-Require MFA - Hungary Users On-demand (Teams) 8 IAM Password & credential lifecycle
Re-Require MFA - All Users On-demand (Teams) 0 IAM Password & credential lifecycle
Reset Password - Hungary Users On-demand (Teams) 0 IAM Password & credential lifecycle
Reset Password - All Users On-demand (Teams) 0 IAM Password & credential lifecycle

8. IT Self-Service & Helpdesk

Category: Other | Subcategory: IT helpdesk & ticket routing

Description: A collection of employee-facing self-service automations. Account unlock allows a user to unlock their own AD account without opening a ticket. A Confluence search assistant enables analysts to search the knowledge base via a Teams conversation and receive article links. An ADManager Plus notification relay sends real-time user provisioning events from ADManager Plus into Teams.

Business problem solved: Low-complexity, high-frequency IT requests (account unlocks, knowledge-base lookups) consume helpdesk capacity disproportionate to their value. These playbooks route self-resolvable requests directly to the user, reducing ticket volume and wait times.

Integrations: Active Directory (Microsoft Graph), WinRM, Jira Data Center, Confluence Data Center, Microsoft Teams, Custom Webhook (ADManager Plus)

Playbook Trigger Executions (12 mo) Category Subcategory
VPN kicker (Kick user off of VPN) On-demand (Teams) 1 Other IT helpdesk & ticket routing
Unlock my computer account On-demand 0 Other IT helpdesk & ticket routing
Search confluence for related articles On-demand (Teams) 0 Other IT helpdesk & ticket routing

*Note: VPN kicker is also counted in Use Case 6 (VPN Session Enforcement). It appears here because its primary invocation path is a Teams-initiated helpdesk action.*

9. Identity & HR Attribute Management

Category: IAM | Subcategory: Identity lifecycle automation

Description: Automates job title changes in Active Directory via Teams interactivity. The workflow validates that the requester is an authorized manager, retrieves the target user's AD record, applies the new title via WinRM, and opens a Jira ticket as an audit record. A Hungary-scoped and an all-users variant exist.

Business problem solved: Title changes are a frequent HR event that require an IT admin touchpoint to update Active Directory — introducing delays and manual error risk. These playbooks let authorized managers self-serve the change with a full audit trail.

Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center

Playbook Trigger Executions (12 mo) Category Subcategory
Change Title - Hungary Users On-demand (Teams) 1 IAM Identity lifecycle automation
Title Change On-demand (Teams) 0 IAM Identity lifecycle automation

10. Employee Offboarding & Termination

Category: IAM | Subcategory: Employee offboarding, Full employee lifecycle

Description: A comprehensive employee termination workflow that disables the AD account on-prem, resets the password in both on-prem AD and Entra ID, revokes active Entra sessions, kicks the user from VPN (calling the VPN enforcement use case), modifies the AD description field to record the termination, and creates a Jira audit ticket — all within a single Teams-guided interaction. A NetBox cleanup companion workflow releases the user's assigned VPN IP from the address range.

Business problem solved: Employee termination requires coordinated action across identity systems, VPN, and ITSM. Gaps in any step create security risk (live credentials, active VPN sessions). This playbook enforces a repeatable, complete offboarding checklist with an audit trail.

Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center, NetBox, Blink (cross-automation for VPN kick)

Playbook Trigger Executions (12 mo) Category Subcategory
SelfService Termination - Hungary On-demand (Teams) 0 IAM Employee offboarding, Full employee lifecycle
Netbox Clean-Up Post Termination On-demand 0 IAM Employee offboarding
SelfService Termination Test - Hungary copy *(test variant)* On-demand 0 IAM Employee offboarding

11. Teams Guest Access Review

Category: IAM | Subcategory: Access review & group mgmt, RBAC review & access mgmt

Description: Audits all guest accounts in Microsoft Entra ID, maps each guest to the Teams channels they have access to, identifies the owners of those channels, and sends access review emails to each owner with an attached CSV report. A Jira ticket is created per review cycle. The workflow uses Microsoft Graph API and MSAL for token acquisition to enumerate Teams membership at scale.

Business problem solved: External guest accounts accumulate in Microsoft Teams over time, often outliving the business relationship. Without periodic review, this creates a data exposure risk and a compliance gap. This playbook automates the access review cycle that would otherwise require manual admin effort.

Integrations: Microsoft Entra ID (Graph API), Microsoft Teams (Graph API), Jira Data Center, Email (Python SMTP)

Playbook Trigger Executions (12 mo) Category Subcategory
Teams Guest Accounting On-demand 0 IAM Access review & group mgmt
Teams Guest Accounting BETA On-demand 0 IAM Access review & group mgmt
Teams Guest Accounting_Subroutine1 *(subflow)* Subflow 0 IAM Access review & group mgmt

12. Risky User Monitoring

Category: SOC | Subcategory: Identity threat response

Description: Queries Microsoft Entra ID for users flagged as "risky" (elevated sign-in risk score), stores results in a Blink table for tracking, and surfaces the data via Teams message. A Jira webhook can also trigger the query on-demand.

Business problem solved: Entra ID identity risk signals (impossible travel, leaked credentials, unfamiliar sign-ins) are often unactioned because they require proactive log review. This playbook surfaces risky users in the analyst's primary communication channel and persists the data for trend analysis.

Integrations: Microsoft Entra ID (Active Directory), Microsoft Teams, Blink Tables, Jira (webhook trigger)

Playbook Trigger Executions (12 mo) Category Subcategory
Gather Risky Users via Teams Event (Jira webhook) 0 SOC Identity threat response

13. Wazuh SIEM Detection Engineering

Category: SOC | Subcategory: SIEM & log pipeline monitoring, Threat hunting & detection

Description: A detection engineering playbook that queries the Wazuh SIEM and Wazuh Indexer across 10+ detection categories: disconnected agents, critical alerts (levels 12–15), SSH logins, new user creation, sensitive group additions, scheduled task modifications, LSASS dump attempts, and suspicious parent process creation. Results are formatted for analyst review.

Business problem solved: Building and validating detection coverage across a Wazuh deployment requires repeated manual queries across multiple log indices. This playbook codifies the detection engineering workflow, enabling systematic coverage checks and tuning.

Integrations: Wazuh (REST API, Indexer/OpenSearch API)

Playbook Trigger Executions (12 mo) Category Subcategory
Wazuh Detection Engineering On-demand 0 SOC SIEM & log pipeline monitoring, Threat hunting & detection

14. IT Asset & Network Inventory

Category: Other | Subcategory: IT/OT & network infra monitoring

Description: A two-part asset lifecycle system. The SN Intake Form presents a web form for staff to record serial numbers against purchase orders as hardware arrives; each submission is processed into NetBox. A companion daily scheduled job performs a NetBox true-up, synchronizing the serial number table with current NetBox records to capture device changes.

Business problem solved: Accurate hardware asset tracking requires real-time data entry at receipt and ongoing reconciliation against the authoritative IPAM/DCIM system. Manual processes create stale records and audit risk. These playbooks automate both data capture and daily reconciliation.

Integrations: Blink Web Forms, NetBox

Playbook Trigger Executions (12 mo) Category Subcategory
SN Intake Form Event (Web Form) 0 Other IT/OT & network infra monitoring
SN to Netbox Daily True-Up Scheduled (daily) 0 Other IT/OT & network infra monitoring

15. Development / Sandbox

The following workflows are test, prototype, or infrastructure-level automations with no production executions in the last 12 months.

Playbook Notes Category Subcategory
Say Hi to Jeff Teams connectivity test Other IT helpdesk & ticket routing
Netbox Test NetBox API connectivity test Other IT/OT & network infra monitoring
Getting Started - Hello World Platform orientation Other DevOps & release automation
MSFT Outlook Webhook New Email Simulation Webhook simulation for S1 email triage SOC Phishing detection & response
Error handler Global error event listener (stub) Other DevOps & release automation
Netbox Search Ad-hoc NetBox lookup utility Other IT/OT & network infra monitoring
Teams Test Jira → Teams notification test Other IT helpdesk & ticket routing
ADManager Plus ADManager Plus webhook → Teams relay IAM Identity sync & directory mgmt

Key Observations

Strengths

Vulnerability tracking at scale. The Palo Alto RSS ingestion playbook is the highest-volume automation at 964 executions — running every hour to capture CVEs and security advisories. This represents a meaningful reduction in analyst overhead for vendor advisory monitoring and ensures zero advisories are missed.

Multi-region, timezone-aware IAM. The organization operates across U.S., Hungary, and Romania and has built corresponding IAM automation for each region. New hire AD activation, MFA enforcement, title changes, and offboarding all have separate Hungary-scoped variants, showing mature operational segmentation.

Layered VPN enforcement. The VPN disconnection system is well-architected: a NetBox-driven device inventory feeds a parallel orchestrator that fans out to both Cisco FTD and Palo Alto platforms simultaneously. The addition of a self-service path reduces IT intervention for routine disconnection requests.

Comprehensive offboarding blueprint. The SelfService Termination playbook covers the full offboarding checklist in a single workflow: on-prem AD disable, Entra disable + session revoke, VPN kick, IP cleanup (NetBox), and Jira audit ticket. This is a strong foundation even though it has not yet run in production.

Dual EDR environments. Separate SentinelOne playbooks for U.S. and Hungary environments (18 total executions) show that the threat detection pipeline is active across both geographic footprints.

Gaps & Opportunities

Offboarding not yet in production. The SelfService Termination workflow has 0 executions despite being fully built. Activating it would bring the full IAM lifecycle under automation and reduce the risk of incomplete offboarding steps.

MFA and password reset workflows underutilized. Reset Password and Re-Require MFA (All Users) have 0 executions; the Hungary-scoped MFA variant has only 8. These workflows appear ready — driving adoption through IT team enablement could increase usage significantly.

Guest access review not yet run. Teams Guest Accounting is built and complete but shows 0 executions. Running this quarterly would generate an audit-ready access review report and address a common compliance gap.

Risky User Monitoring not operationalized. The Gather Risky Users playbook exists but has not run. Scheduling it daily or connecting it to an Entra risk event would turn a dormant capability into an active identity threat detection signal.

Wazuh SIEM coverage not yet scheduled. The detection engineering playbook covers 10+ Wazuh alert categories but has not been scheduled. Converting it to a scheduled daily or weekly run would provide continuous SIEM health and coverage reporting.

SentinelOne triage on-demand not wired to the event pipeline. The On-Demand triage variant (SentinelOne Alert Triage Final On-Demand) has 0 executions. Connecting it to the event-driven S1 webhook pipeline as an escalation handler would complete the automated triage → analyst review → containment loop.

Integration Ecosystem

Integration Use Cases
Microsoft Entra ID / Active Directory Onboarding, Offboarding, MFA enforcement, Risky user monitoring, Title changes
Microsoft Teams VPN enforcement, MFA/password reset, Offboarding, Threat alerts, HR changes, Helpdesk
Jira Data Center CVE ticketing, Onboarding, S1 case creation, Offboarding, MFA audit, Title changes
SentinelOne Threat detection & case management, VPN–EDR gap analysis
Palo Alto Networks (Panorama / SSH) VPN enforcement, Firewall policy compliance
Cisco FTD (SSH) VPN enforcement
NetBox (IPAM/DCIM) VPN IP onboarding, Offboarding cleanup, Asset inventory
Splunk Firewall compliance queries, VPN login analysis
Wazuh SIEM detection engineering
Microsoft Graph Guest access review, Teams enumeration, Entra session revoke
Confluence Data Center Knowledge base search (helpdesk)
Blink Web Forms Asset serial number intake
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.