01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Palo Alto CVE & Security Advisory Tracking |
| 78.8% | 1 1 active |
| Employee Onboarding — AD Account Activation |
| 6.6% | 3 3 active |
| Firewall Policy Compliance Monitoring |
| 3.3% | 1 1 active |
| Backup Failure Monitoring & Alerting |
| 3.3% | 1 1 active |
| SentinelOne Threat Detection & Case Management |
| 1.6% | 5 5 active |
| VPN Session Enforcement & Self-Service |
| 5.6% | 6 6 active |
| MFA & Password Lifecycle Management |
| 0.7% | 4 4 active |
| IT Self-Service & Helpdesk |
| 0.2% | 3 3 active |
| Identity & HR Attribute Management |
| 0.0% | 2 2 active |
| Employee Offboarding & Termination | 0 executions | 0.0% | 2 2 active |
| Teams Guest Access Review | 0 executions | 0.0% | 2 2 active |
| Risky User Monitoring | 0 executions | 0.0% | 1 1 active |
| Wazuh SIEM Detection Engineering | 0 executions | 0.0% | 1 1 active |
| IT Asset & Network Inventory | 0 executions | 0.0% | 2 2 active |
| Development / Sandbox | 0 executions | 0.0% | 7 6 active |
| Total | 1,218 executions | 100% | 41 40 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Vulnerability tracking at scale. The Palo Alto RSS ingestion playbook is the highest-volume automation at 964 executions — running every hour to capture CVEs and security advisories. This represents a meaningful reduction in analyst overhead for vendor advisory monitoring and ensures zero advisories are missed.
Multi-region, timezone-aware IAM. The organization operates across U.S., Hungary, and Romania and has built corresponding IAM automation for each region. New hire AD activation, MFA enforcement, title changes, and offboarding all have separate Hungary-scoped variants, showing mature operational segmentation.
Layered VPN enforcement. The VPN disconnection system is well-architected: a NetBox-driven device inventory feeds a parallel orchestrator that fans out to both Cisco FTD and Palo Alto platforms simultaneously. The addition of a self-service path reduces IT intervention for routine disconnection requests.
Comprehensive offboarding blueprint. The SelfService Termination playbook covers the full offboarding checklist in a single workflow: on-prem AD disable, Entra disable + session revoke, VPN kick, IP cleanup (NetBox), and Jira audit ticket. This is a strong foundation even though it has not yet run in production.
Dual EDR environments. Separate SentinelOne playbooks for U.S. and Hungary environments (18 total executions) show that the threat detection pipeline is active across both geographic footprints.
###
Gaps & Opportunities
Offboarding not yet in production. The SelfService Termination workflow has 0 executions despite being fully built. Activating it would bring the full IAM lifecycle under automation and reduce the risk of incomplete offboarding steps.
MFA and password reset workflows underutilized. Reset Password and Re-Require MFA (All Users) have 0 executions; the Hungary-scoped MFA variant has only 8. These workflows appear ready — driving adoption through IT team enablement could increase usage significantly.
Guest access review not yet run. Teams Guest Accounting is built and complete but shows 0 executions. Running this quarterly would generate an audit-ready access review report and address a common compliance gap.
Risky User Monitoring not operationalized. The Gather Risky Users playbook exists but has not run. Scheduling it daily or connecting it to an Entra risk event would turn a dormant capability into an active identity threat detection signal.
Wazuh SIEM coverage not yet scheduled. The detection engineering playbook covers 10+ Wazuh alert categories but has not been scheduled. Converting it to a scheduled daily or weekly run would provide continuous SIEM health and coverage reporting.
SentinelOne triage on-demand not wired to the event pipeline. The On-Demand triage variant (SentinelOne Alert Triage Final On-Demand) has 0 executions. Connecting it to the event-driven S1 webhook pipeline as an escalation handler would complete the automated triage → analyst review → containment loop.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| Microsoft Entra ID / Active Directory | Onboarding, Offboarding, MFA enforcement, Risky user monitoring, Title changes |
| Microsoft Teams | VPN enforcement, MFA/password reset, Offboarding, Threat alerts, HR changes, Helpdesk |
| Jira Data Center | CVE ticketing, Onboarding, S1 case creation, Offboarding, MFA audit, Title changes |
| SentinelOne | Threat detection & case management, VPN–EDR gap analysis |
| Palo Alto Networks (Panorama / SSH) | VPN enforcement, Firewall policy compliance |
| Cisco FTD (SSH) | VPN enforcement |
| NetBox (IPAM/DCIM) | VPN IP onboarding, Offboarding cleanup, Asset inventory |
| Splunk | Firewall compliance queries, VPN login analysis |
| Wazuh | SIEM detection engineering |
| Microsoft Graph | Guest access review, Teams enumeration, Entra session revoke |
| Confluence Data Center | Knowledge base search (helpdesk) |
| Blink Web Forms | Asset serial number intake |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | New Agent | Enterprise IT | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Enterprise IT | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Demo Dash | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | SN Collector | 0 | 0 |
| 2 | What user would you like to edit? | 0 | 0 |
| 3 | Title | 0 | 0 |
| 4 | Which User would you like to Terminate | 0 | 0 |
| 5 | header | 0 | 0 |
D Full Use Case Analysis 15 use cases | 1,218 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Palo Alto CVE & security advisory tickets auto-created | 964 | Create Jira Tickets from PAN Security RSS |
| New hire AD accounts enabled (U.S.) | 40 | Enable U.S. New Hire AD account |
| New hire AD accounts enabled (HU/RO) | 40 | Enable HU or RO New Hire AD account |
| Firewall policy override compliance reports delivered | 40 | Daily Report on Panorama Policy Override Requiring Review |
| Backup failure events detected & routed | 19 | Failed Backup |
| SentinelOne threats auto-ticketed (Hungary) | 12 | S1 Hungary - Threat Detected Alert and Ticket Submission |
| VPN sessions force-disconnected (admin-initiated) | 9 | Disconnect Someone from VPN - Run This |
| MFA re-enrollments enforced (Hungary users) | 8 | Re-Require MFA - Hungary Users |
| SentinelOne threats auto-ticketed (U.S.) | 6 | S1 Threat Detected Alert and Ticket Submission |
| Self-service VPN disconnection requests completed | 6 | Self Service Disconnect Myself from VPN |
| Employee title changes automated | 1 | Change Title - Hungary Users |
| VPN kick requests processed (Teams-initiated) | 1 | VPN kicker (Kick user off of VPN) |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks | Executions (12 mo) |
|---|---|---|---|---|---|
| 1 | Palo Alto CVE & Security Advisory Tracking | Vulnerability Mgmt | CVE lookup & remediation | 1 | 964 |
| 2 | Employee Onboarding — AD Account Activation | IAM | Employee onboarding | 3 | 80 |
| 3 | Firewall Policy Compliance Monitoring | GRC | Security metrics & reporting | 1 | 40 |
| 4 | Backup Failure Monitoring & Alerting | Other | IT/OT & network infra monitoring | 1 | 19 |
| 5 | SentinelOne Threat Detection & Case Management | SOC | EDR containment & response | 5 | 18 |
| 6 | VPN Session Enforcement & Self-Service | IAM | JIT & temporary access | 9 | 16 |
| 7 | MFA & Password Lifecycle Management | IAM | Password & credential lifecycle | 4 | 8 |
| 8 | IT Self-Service & Helpdesk | Other | IT helpdesk & ticket routing | 3 | 1 |
| 9 | Identity & HR Attribute Management | IAM | Identity lifecycle automation | 2 | 1 |
| 10 | Employee Offboarding & Termination | IAM | Employee offboarding | 3 | 0 |
| 11 | Teams Guest Access Review | IAM | Access review & group mgmt | 3 | 0 |
| 12 | Risky User Monitoring | SOC | Identity threat response | 1 | 0 |
| 13 | Wazuh SIEM Detection Engineering | SOC | SIEM & log pipeline monitoring | 1 | 0 |
| 14 | IT Asset & Network Inventory | Other | IT/OT & network infra monitoring | 2 | 0 |
| 15 | Development / Sandbox | — | — | 7 | 0 |
| Total | 46 | 1,147 |
Use Cases
1. Palo Alto CVE & Security Advisory Tracking
Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation
Description: Automatically ingests the Palo Alto Networks security RSS feed on an hourly schedule, parses each new CVE and advisory, and creates a corresponding Jira ticket. This eliminates the manual work of monitoring vendor advisories and ensures every published vulnerability is immediately tracked in the organization's ticketing system.
Business problem solved: Security teams routinely miss or delay acting on vendor CVE feeds because manual monitoring is error-prone and slow. This playbook guarantees every Palo Alto advisory is captured, catalogued, and assigned — at the moment it is published.
Integrations: HTTP (RSS/XML fetch), Jira Data Center
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Create Jira Tickets from PAN Security RSS | Scheduled (hourly) | 964 | Vulnerability Mgmt | CVE lookup & remediation |
2. Employee Onboarding — AD Account Activation
Category: IAM | Subcategory: Employee onboarding, Identity sync & directory mgmt
Description: Enables new hire Active Directory accounts on their start date for both U.S. and European (Hungary/Romania) timezones. A scheduled daily job checks Jira for new hire tickets and activates the corresponding AD account at the appropriate local business time. A companion workflow handles VPN IP assignment and Netbox registration during onboarding.
Business problem solved: Delayed account activation on a new hire's first day creates a poor employee experience and productivity loss. These playbooks ensure accounts go live exactly when needed — in the correct timezone — without requiring an IT admin to manually action each ticket.
Integrations: Jira Data Center, Active Directory (on-prem / WinRM), Microsoft Graph, NetBox
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Enable U.S. New Hire AD account | Scheduled (daily, 00:15 PT) | 40 | IAM | Employee onboarding |
| Enable HU or RO New Hire AD account | Scheduled (daily, 00:15 CET) | 40 | IAM | Employee onboarding |
| Jira Ingestion Employee VPN IP Onboarding | On-demand | 0 | IAM | Employee onboarding, Identity sync & directory mgmt |
3. Firewall Policy Compliance Monitoring
Category: GRC | Subcategory: Security metrics & reporting, PCI & regulatory monitoring
Description: Runs a daily Splunk query against Palo Alto Panorama configuration logs to identify firewall rules with local policy overrides — rules that deviate from the centrally managed Panorama templates. When overrides are detected, a formatted report is delivered to the security team for review.
Business problem solved: Local firewall rule overrides are a common audit finding and a sign that policy governance is breaking down. This playbook provides daily visibility into policy drift so the network security team can remediate deviations before they become compliance gaps.
Integrations: Splunk (HTTP/Ad Hoc query), Jira Data Center
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Daily Report on Panorama Policy Override Requiring Review | Scheduled (daily, 08:30) | 40 | GRC | Security metrics & reporting, PCI & regulatory monitoring |
4. Backup Failure Monitoring & Alerting
Category: Other | Subcategory: IT/OT & network infra monitoring
Description: Listens for inbound webhook events from the backup platform. When an event containing a backup failure keyword is received, the playbook classifies and routes the alert for IT operations response.
Business problem solved: Undetected backup failures are a silent disaster risk — they often go unnoticed until a restore attempt fails. This event-driven playbook ensures every backup failure generates an immediate, actionable alert rather than disappearing into a log.
Integrations: Custom Webhook (backup platform)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Failed Backup | Event (custom webhook) | 19 | Other | IT/OT & network infra monitoring |
5. SentinelOne Threat Detection & Case Management
Category: SOC | Subcategory: EDR containment & response, Case mgmt & SOAR
Description: End-to-end automated response pipeline for SentinelOne endpoint threats. When S1 detects a threat (via webhook), the playbook deduplicates against existing Jira tickets, creates a new case if needed, and optionally escalates for analyst review via Teams interactivity. Separate variants cover U.S. and Hungary S1 environments. Additional playbooks support analyst-initiated triage review and host isolation lift.
Business problem solved: Manual threat triage creates alert fatigue and delays response. These playbooks ensure every S1 threat is immediately logged as a Jira ticket, duplicate alerts are suppressed, and analysts are only interrupted when genuine escalation is warranted.
Integrations: SentinelOne, Jira Data Center, Microsoft Teams, Microsoft Outlook (email webhook), VirusTotal (IOC enrichment implied)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| S1 Hungary - Threat Detected Alert and Ticket Submission | Event (custom webhook) | 12 | SOC | EDR containment & response, Case mgmt & SOAR |
| S1 Threat Detected Alert and Ticket Submission | Event (custom webhook) | 6 | SOC | EDR containment & response, Case mgmt & SOAR |
| SentinelOne Alert Triage Final On-Demand | On-demand | 0 | SOC | EDR containment & response, Alert enrichment / IOC lookup |
| SentinelOne Host via Email Notification | Event (Outlook webhook) | 0 | SOC | Phishing detection & response, EDR containment & response |
| SentinelOne Lift Host Isolation | On-demand | 0 | SOC | EDR containment & response |
6. VPN Session Enforcement & Self-Service
Category: IAM | Subcategory: JIT & temporary access, Identity lifecycle automation
Description: A multi-component system for enforcing VPN session termination across both Palo Alto and Cisco FTD firewall platforms. The primary orchestrator queries NetBox for all active VPN firewall devices, spawns parallel helper subflows per device, and collects results. A self-service variant allows employees to disconnect themselves from VPN (e.g., before an IT action). An additional analytical workflow cross-references Splunk VPN login data against the SentinelOne agent inventory to surface devices on VPN without EDR coverage.
Business problem solved: Terminating a user's VPN session during an incident, offboarding, or policy violation requires coordinating across multiple heterogeneous firewall platforms. Manual execution is slow and error-prone. These playbooks reduce a multi-step, multi-device operation to a single automated action.
Integrations: NetBox, Palo Alto Networks (SSH/Paramiko), Cisco FTD (SSH/Paramiko), Blink (cross-automation call), SentinelOne, Splunk, Microsoft Teams
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Disconnect Someone from VPN - Run This | On-demand | 9 | IAM | JIT & temporary access |
| Self Service Disconnect Myself from VPN | On-demand | 6 | IAM | JIT & temporary access |
| Disconnect Someone from VPN - Helper Cisco FTD | Subflow | 36 | IAM | JIT & temporary access |
| Disconnect Someone from VPN - Helper Palo Alto | Subflow | 54 | IAM | JIT & temporary access |
| VPN kicker (Kick user off of VPN) | On-demand (Teams) | 1 | IAM | JIT & temporary access |
| VPN without S1 | On-demand | 0 | Other | Endpoint hygiene & MDM ops |
| VPN without S1 copy | On-demand | 0 | Other | Endpoint hygiene & MDM ops |
| Disconnect Someone from VPN - Helper Palo Alto *(workspace 2)* | Subflow | 0 | IAM | JIT & temporary access |
| Disconnect Someone from VPN - Helper Cisco FTD *(workspace 2)* | Subflow | 0 | IAM | JIT & temporary access |
7. MFA & Password Lifecycle Management
Category: IAM | Subcategory: Password & credential lifecycle, Identity lifecycle automation
Description: A set of Teams-driven self-service workflows enabling IT administrators or security staff to re-enforce MFA requirements and reset passwords for users in Hungary and global scopes. Each workflow validates the runner's identity, prompts for the target user via Teams, performs verification steps, then executes the credential action in Active Directory. A re-require MFA variant additionally lists and revokes existing MFA methods before forcing re-registration.
Business problem solved: MFA bypass, credential compromise, and account lockout resolution are high-frequency IT operations that consume significant analyst time when handled manually. These playbooks give authorized staff a guided, audited self-service path via Microsoft Teams.
Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Re-Require MFA - Hungary Users | On-demand (Teams) | 8 | IAM | Password & credential lifecycle |
| Re-Require MFA - All Users | On-demand (Teams) | 0 | IAM | Password & credential lifecycle |
| Reset Password - Hungary Users | On-demand (Teams) | 0 | IAM | Password & credential lifecycle |
| Reset Password - All Users | On-demand (Teams) | 0 | IAM | Password & credential lifecycle |
8. IT Self-Service & Helpdesk
Category: Other | Subcategory: IT helpdesk & ticket routing
Description: A collection of employee-facing self-service automations. Account unlock allows a user to unlock their own AD account without opening a ticket. A Confluence search assistant enables analysts to search the knowledge base via a Teams conversation and receive article links. An ADManager Plus notification relay sends real-time user provisioning events from ADManager Plus into Teams.
Business problem solved: Low-complexity, high-frequency IT requests (account unlocks, knowledge-base lookups) consume helpdesk capacity disproportionate to their value. These playbooks route self-resolvable requests directly to the user, reducing ticket volume and wait times.
Integrations: Active Directory (Microsoft Graph), WinRM, Jira Data Center, Confluence Data Center, Microsoft Teams, Custom Webhook (ADManager Plus)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| VPN kicker (Kick user off of VPN) | On-demand (Teams) | 1 | Other | IT helpdesk & ticket routing |
| Unlock my computer account | On-demand | 0 | Other | IT helpdesk & ticket routing |
| Search confluence for related articles | On-demand (Teams) | 0 | Other | IT helpdesk & ticket routing |
*Note: VPN kicker is also counted in Use Case 6 (VPN Session Enforcement). It appears here because its primary invocation path is a Teams-initiated helpdesk action.*
9. Identity & HR Attribute Management
Category: IAM | Subcategory: Identity lifecycle automation
Description: Automates job title changes in Active Directory via Teams interactivity. The workflow validates that the requester is an authorized manager, retrieves the target user's AD record, applies the new title via WinRM, and opens a Jira ticket as an audit record. A Hungary-scoped and an all-users variant exist.
Business problem solved: Title changes are a frequent HR event that require an IT admin touchpoint to update Active Directory — introducing delays and manual error risk. These playbooks let authorized managers self-serve the change with a full audit trail.
Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Change Title - Hungary Users | On-demand (Teams) | 1 | IAM | Identity lifecycle automation |
| Title Change | On-demand (Teams) | 0 | IAM | Identity lifecycle automation |
10. Employee Offboarding & Termination
Category: IAM | Subcategory: Employee offboarding, Full employee lifecycle
Description: A comprehensive employee termination workflow that disables the AD account on-prem, resets the password in both on-prem AD and Entra ID, revokes active Entra sessions, kicks the user from VPN (calling the VPN enforcement use case), modifies the AD description field to record the termination, and creates a Jira audit ticket — all within a single Teams-guided interaction. A NetBox cleanup companion workflow releases the user's assigned VPN IP from the address range.
Business problem solved: Employee termination requires coordinated action across identity systems, VPN, and ITSM. Gaps in any step create security risk (live credentials, active VPN sessions). This playbook enforces a repeatable, complete offboarding checklist with an audit trail.
Integrations: Microsoft Entra ID (Graph API), Active Directory on-prem (WinRM), Microsoft Teams, Jira Data Center, NetBox, Blink (cross-automation for VPN kick)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| SelfService Termination - Hungary | On-demand (Teams) | 0 | IAM | Employee offboarding, Full employee lifecycle |
| Netbox Clean-Up Post Termination | On-demand | 0 | IAM | Employee offboarding |
| SelfService Termination Test - Hungary copy *(test variant)* | On-demand | 0 | IAM | Employee offboarding |
11. Teams Guest Access Review
Category: IAM | Subcategory: Access review & group mgmt, RBAC review & access mgmt
Description: Audits all guest accounts in Microsoft Entra ID, maps each guest to the Teams channels they have access to, identifies the owners of those channels, and sends access review emails to each owner with an attached CSV report. A Jira ticket is created per review cycle. The workflow uses Microsoft Graph API and MSAL for token acquisition to enumerate Teams membership at scale.
Business problem solved: External guest accounts accumulate in Microsoft Teams over time, often outliving the business relationship. Without periodic review, this creates a data exposure risk and a compliance gap. This playbook automates the access review cycle that would otherwise require manual admin effort.
Integrations: Microsoft Entra ID (Graph API), Microsoft Teams (Graph API), Jira Data Center, Email (Python SMTP)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Teams Guest Accounting | On-demand | 0 | IAM | Access review & group mgmt |
| Teams Guest Accounting BETA | On-demand | 0 | IAM | Access review & group mgmt |
| Teams Guest Accounting_Subroutine1 *(subflow)* | Subflow | 0 | IAM | Access review & group mgmt |
12. Risky User Monitoring
Category: SOC | Subcategory: Identity threat response
Description: Queries Microsoft Entra ID for users flagged as "risky" (elevated sign-in risk score), stores results in a Blink table for tracking, and surfaces the data via Teams message. A Jira webhook can also trigger the query on-demand.
Business problem solved: Entra ID identity risk signals (impossible travel, leaked credentials, unfamiliar sign-ins) are often unactioned because they require proactive log review. This playbook surfaces risky users in the analyst's primary communication channel and persists the data for trend analysis.
Integrations: Microsoft Entra ID (Active Directory), Microsoft Teams, Blink Tables, Jira (webhook trigger)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Gather Risky Users via Teams | Event (Jira webhook) | 0 | SOC | Identity threat response |
13. Wazuh SIEM Detection Engineering
Category: SOC | Subcategory: SIEM & log pipeline monitoring, Threat hunting & detection
Description: A detection engineering playbook that queries the Wazuh SIEM and Wazuh Indexer across 10+ detection categories: disconnected agents, critical alerts (levels 12–15), SSH logins, new user creation, sensitive group additions, scheduled task modifications, LSASS dump attempts, and suspicious parent process creation. Results are formatted for analyst review.
Business problem solved: Building and validating detection coverage across a Wazuh deployment requires repeated manual queries across multiple log indices. This playbook codifies the detection engineering workflow, enabling systematic coverage checks and tuning.
Integrations: Wazuh (REST API, Indexer/OpenSearch API)
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| Wazuh Detection Engineering | On-demand | 0 | SOC | SIEM & log pipeline monitoring, Threat hunting & detection |
14. IT Asset & Network Inventory
Category: Other | Subcategory: IT/OT & network infra monitoring
Description: A two-part asset lifecycle system. The SN Intake Form presents a web form for staff to record serial numbers against purchase orders as hardware arrives; each submission is processed into NetBox. A companion daily scheduled job performs a NetBox true-up, synchronizing the serial number table with current NetBox records to capture device changes.
Business problem solved: Accurate hardware asset tracking requires real-time data entry at receipt and ongoing reconciliation against the authoritative IPAM/DCIM system. Manual processes create stale records and audit risk. These playbooks automate both data capture and daily reconciliation.
Integrations: Blink Web Forms, NetBox
| Playbook | Trigger | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|
| SN Intake Form | Event (Web Form) | 0 | Other | IT/OT & network infra monitoring |
| SN to Netbox Daily True-Up | Scheduled (daily) | 0 | Other | IT/OT & network infra monitoring |
15. Development / Sandbox
The following workflows are test, prototype, or infrastructure-level automations with no production executions in the last 12 months.
| Playbook | Notes | Category | Subcategory |
|---|---|---|---|
| Say Hi to Jeff | Teams connectivity test | Other | IT helpdesk & ticket routing |
| Netbox Test | NetBox API connectivity test | Other | IT/OT & network infra monitoring |
| Getting Started - Hello World | Platform orientation | Other | DevOps & release automation |
| MSFT Outlook Webhook New Email Simulation | Webhook simulation for S1 email triage | SOC | Phishing detection & response |
| Error handler | Global error event listener (stub) | Other | DevOps & release automation |
| Netbox Search | Ad-hoc NetBox lookup utility | Other | IT/OT & network infra monitoring |
| Teams Test | Jira → Teams notification test | Other | IT helpdesk & ticket routing |
| ADManager Plus | ADManager Plus webhook → Teams relay | IAM | Identity sync & directory mgmt |
Key Observations
Strengths
Vulnerability tracking at scale. The Palo Alto RSS ingestion playbook is the highest-volume automation at 964 executions — running every hour to capture CVEs and security advisories. This represents a meaningful reduction in analyst overhead for vendor advisory monitoring and ensures zero advisories are missed.
Multi-region, timezone-aware IAM. The organization operates across U.S., Hungary, and Romania and has built corresponding IAM automation for each region. New hire AD activation, MFA enforcement, title changes, and offboarding all have separate Hungary-scoped variants, showing mature operational segmentation.
Layered VPN enforcement. The VPN disconnection system is well-architected: a NetBox-driven device inventory feeds a parallel orchestrator that fans out to both Cisco FTD and Palo Alto platforms simultaneously. The addition of a self-service path reduces IT intervention for routine disconnection requests.
Comprehensive offboarding blueprint. The SelfService Termination playbook covers the full offboarding checklist in a single workflow: on-prem AD disable, Entra disable + session revoke, VPN kick, IP cleanup (NetBox), and Jira audit ticket. This is a strong foundation even though it has not yet run in production.
Dual EDR environments. Separate SentinelOne playbooks for U.S. and Hungary environments (18 total executions) show that the threat detection pipeline is active across both geographic footprints.
Gaps & Opportunities
Offboarding not yet in production. The SelfService Termination workflow has 0 executions despite being fully built. Activating it would bring the full IAM lifecycle under automation and reduce the risk of incomplete offboarding steps.
MFA and password reset workflows underutilized. Reset Password and Re-Require MFA (All Users) have 0 executions; the Hungary-scoped MFA variant has only 8. These workflows appear ready — driving adoption through IT team enablement could increase usage significantly.
Guest access review not yet run. Teams Guest Accounting is built and complete but shows 0 executions. Running this quarterly would generate an audit-ready access review report and address a common compliance gap.
Risky User Monitoring not operationalized. The Gather Risky Users playbook exists but has not run. Scheduling it daily or connecting it to an Entra risk event would turn a dormant capability into an active identity threat detection signal.
Wazuh SIEM coverage not yet scheduled. The detection engineering playbook covers 10+ Wazuh alert categories but has not been scheduled. Converting it to a scheduled daily or weekly run would provide continuous SIEM health and coverage reporting.
SentinelOne triage on-demand not wired to the event pipeline. The On-Demand triage variant (SentinelOne Alert Triage Final On-Demand) has 0 executions. Connecting it to the event-driven S1 webhook pipeline as an escalation handler would complete the automated triage → analyst review → containment loop.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| Microsoft Entra ID / Active Directory | Onboarding, Offboarding, MFA enforcement, Risky user monitoring, Title changes |
| Microsoft Teams | VPN enforcement, MFA/password reset, Offboarding, Threat alerts, HR changes, Helpdesk |
| Jira Data Center | CVE ticketing, Onboarding, S1 case creation, Offboarding, MFA audit, Title changes |
| SentinelOne | Threat detection & case management, VPN–EDR gap analysis |
| Palo Alto Networks (Panorama / SSH) | VPN enforcement, Firewall policy compliance |
| Cisco FTD (SSH) | VPN enforcement |
| NetBox (IPAM/DCIM) | VPN IP onboarding, Offboarding cleanup, Asset inventory |
| Splunk | Firewall compliance queries, VPN login analysis |
| Wazuh | SIEM detection engineering |
| Microsoft Graph | Guest access review, Teams enumeration, Entra session revoke |
| Confluence Data Center | Knowledge base search (helpdesk) |
| Blink Web Forms | Asset serial number intake |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.