01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1 — Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response | 1 executions | 0.0% | 51 51 active |
| Use Case 2 — Cloud Security Alert Triage & Ownership Coordination (Wiz) |
| 0.6% | 7 7 active |
| Use Case 3 — EDR Containment & Response (CrowdStrike) | 27,942 executions | 45.3% | 5 5 active |
| Use Case 4 — SIEM Feed Curation — Okta Exclusion List Sync |
| 0.1% | 1 1 active |
| Use Case 5 — Security Ticket Sync — Jira SecOps to Linear | 0 executions | 0.0% | 0 0 active |
| Use Case 6 — Password & Credential Utility | 0 executions | 0.0% | 1 1 active |
| Use Case 7 — Full Employee Lifecycle Automation | 0 executions | 0.0% | 3 3 active |
| Use Case 8 — Linear ↔ Notion Project & Roadmap Sync |
| 23.2% | 10 10 active |
| Use Case 9 — AI-Assisted PRD-to-Ticket Creation | 38 executions | 0.1% | 2 2 active |
| Use Case 10 — Feature/Content Submission Review & PM Notification |
| 0.4% | 5 5 active |
| Use Case 11 — Meeting & Leadership Cadence Reminders |
| 0.1% | 1 1 active |
| Use Case 12 — Email-to-Spreadsheet Data Capture |
| 3.2% | 1 1 active |
| Use Case 13 — Helpdesk Ticket Sync (Zendesk → Notion) | 0 executions | 0.0% | 2 1 active |
| Use Case 14 — Slack Channel Concierge — Deal Desk & Billing Routing |
| 6.5% | 4 4 active |
| Use Case 15 — Sales Bookings & Performance Tracking |
| 0.8% | 2 2 active |
| Use Case 16 — Off-Hours / On-Call Escalation Notifications |
| 0.1% | 3 3 active |
| Use Case 17 — HR & Culture Automation |
| 1.5% | 4 2 active |
| Use Case 18 — Data Protection Complaint Intake | 3 executions | 0.0% | 1 1 active |
| Use Case 19 — License & Subscription Management Notifications |
| 0.0% | 1 1 active |
| Use Case 20 — Engineering Changelog Broadcasting | 3 executions | 0.0% | 1 1 active |
| Total | 50,405 executions | 100% | 105 102 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Real production impact in endpoint containment. Between the scheduled CrowdStrike - Auto Isolate job (19,200 executions) and the new webhook-triggered CrowdStrike - Auto Isolate - Webhook (7,134 executions), AlphaSense automated 26,334 endpoint isolations in 12 months — by far the single highest-value security automation in the tenant, now running both on a schedule and in real time off live detections.
Deep engineering/PM tooling integration. The Linear ↔ Notion sync pipelines and PRD-to-Linear AI pipeline together processed over 14,400 executions, showing Blink is embedded in AlphaSense's daily product and engineering workflow, not just security.
A fully architected, production-ready SOC platform. The 51-playbook SOAR framework (Use Case 1) covers observable extraction, enrichment across 8+ security tools, deduplication, and automated phishing/malware response. It is structurally complete and simply needs a live alert feed to go into production.
Cloud security ownership routing is built and ready. The Wiz + FireHydrant + Port.io integration (Use Case 2) is configured to automatically route cloud threats to the correct owning team — a capability many security teams still do by hand.
AI is already in the workflow, not just a pilot. The PRD-to-Linear (Claude) and "+1" recognition workflows show AlphaSense using Claude for real, recurring business tasks.
###
Gaps & Opportunities
Core SOC pipeline shows zero executions. Process Alert and its enrichment/response chain (Use Case 1) haven't run in the last 12 months. Activating the live alert feed would immediately convert this built platform into measurable analyst time savings.
Cloud threat triage (Wiz) is mostly idle. Outside of the 144-execution owner-coordination flow, the remaining 7 Wiz playbooks in Use Case 2 show 0 executions — the alert-ingestion and inventory side of the pipeline appears disconnected from a live feed.
No dedicated vulnerability-scanning or CVE workflows. Given AlphaSense's CrowdStrike/Wiz/Chronicle footprint, there's no playbook for vuln scan ingestion, CVE lookup/remediation, or scan-lifecycle automation — the closest analog (Linear Ticket Create) is a Jira poll-sync, not a scan pipeline.
Several duplicate/unlabeled workflows increase maintenance overhead. "Get Notion User ID from Email" exists in three copies (Use Case 8), and multiple playbooks are still named "New Workflow" or "New Workflow 1" with no distinguishing name (Use Cases 2, 12, 13, 14, 17) — consolidating or renaming these would reduce confusion about which is canonical.
A polling-based workflow inflates raw execution counts. Linear Ticket Create shows 21,523 executions, but it polls Jira every 5 minutes regardless of whether a new issue exists — the number reflects poll cycles, not tickets created, and should not be read as a business-volume metric as-is.
One unused tutorial workflow. "Getting Started - Hello World" (workspace 445403f0) is Blink's onboarding sample and has never been run — expected for a sandbox, but worth cleaning up if that workspace is otherwise inactive.
Integration Ecosystem
| Domain | Integrations in Use |
|---|---|
| Security | CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Whois · Wiz · FireHydrant · Port.io · Google Chronicle/SecOps · Artemis Security |
| Identity | Okta · Microsoft Entra ID (Active Directory) · Google Workspace · GitHub · Slack |
| Productivity & DevOps | Linear · Notion · Jira · GitLab · Google Calendar · Google Sheets · Gmail |
| AI | Anthropic (Claude) |
| Communication | Slack · Microsoft Outlook |
| Business Systems | Salesforce · Zendesk · Google Forms |
| Infrastructure | HTTP webhooks · Bash · Python |
A Case Management 5 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management V9 | 5 | 5 | 0 | N/A |
B AI Agents 2 active | 11 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Wiz Findings Expert | Security DxR | 6 | 0 | 650,598 |
| 2 | Wiz GraphQL Agent | Security DxR | 5 | 0 | 3,241,209 |
| 3 | Agent Blink | Case Management V9 | 0 | 0 | 0 |
| 4 | Secops | Security DxR | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Security DxR | 11 |
| Case Management V9 | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | TPM | 0 | 0 |
| 2 | TPM | 0 | 0 |
| 3 | Test | 0 | 0 |
| 4 | ViZ | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 19 use cases | 61,657 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Compromised endpoints automatically isolated | 26,334 | CrowdStrike - Auto Isolate (19,200) + CrowdStrike - Auto Isolate - Webhook (7,134) |
| Inbound emails processed and logged automatically | 2,170 | List Gmail Messages and Send Results via Email |
| Product roadmap updates synced from Linear to Notion | 1,936 | Project updates testing |
| Engineering tickets synced from Linear to Notion | 780 | Linear to Notion Database |
| SA skills-feedback entries logged from Slack to Notion | 719 | SA Skills Feedback - Slack to Notion |
| Sales bookings captured automatically from inbound email | 340 | Collect Bookings |
| Hiring-manager feedback surveys sent | 228 | HM Survey Trigger |
| Flagged-ticket alerts routed to Slack | 221 | Flag Requests Tickets notifications |
| Deal desk inquiries triaged in Slack | 159 | Deal Desk Slack Channel |
| Cloud security alerts routed to the correct resource owner | 144 | Wiz Threat User/Resource Owner Coordination |
| Driver & deprecation project updates synced to Notion | 80 | Linear Driver Projects to Notion Sync (40) + Linear AS Features/Products/Components Deprecation Projects to Notion Sync (40) |
| Leadership meeting reminders sent | 40 | GTM Leadership Pulse: Meeting Reminders |
| Okta exclusion-list updates pushed to SIEM (Chronicle) | 40 | Okta Exclusion List to Google Chronicle/SecOps Exclusion Table |
| Sales call leaderboard reports published to Slack | 28 | Print Call Leaderboard |
| Off-hours production incidents escalated to on-call | 27 | Off Hours Notification - Production |
| PRDs auto-converted into Linear tickets via AI | 20 | PRD to Linear with Claude (19) + PRD to Linear with Claude: CONTENT (1) |
| Software license expiration alerts sent | 12 | Send License Expiration Emails |
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12mo) |
|---|---|---|---|---|
| 1 | Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response | SOC | 51 | 0* |
| 2 | Cloud Security Alert Triage & Ownership Coordination (Wiz) | Cloud Security | 8 | 144 |
| 3 | EDR Containment & Response (CrowdStrike) | SOC | 5 | 27,071 |
| 4 | SIEM Feed Curation — Okta Exclusion List Sync | SOC | 1 | 40 |
| 5 | Security Ticket Sync — Jira SecOps to Linear | Vulnerability Mgmt | 1 | 21,523 |
| 6 | Password & Credential Utility | IAM | 1 | 0 |
| 7 | Full Employee Lifecycle Automation | IAM | 3 | 0 |
| 8 | Linear ↔ Notion Project & Roadmap Sync | Other | 10 | 14,395 |
| 9 | AI-Assisted PRD-to-Ticket Creation | Other | 2 | 20 |
| 10 | Feature/Content Submission Review & PM Notification | Other | 5 | 235 |
| 11 | Meeting & Leadership Cadence Reminders | Other | 1 | 40 |
| 12 | Email-to-Spreadsheet Data Capture | Other | 2 | 2,170 |
| 13 | Helpdesk Ticket Sync (Zendesk → Notion) | Other | 2 | 0 |
| 14 | Slack Channel Concierge — Deal Desk & Billing Routing | Other | 5 | 209 |
| 15 | Sales Bookings & Performance Tracking | Other | 2 | 368 |
| 16 | Off-Hours / On-Call Escalation Notifications | Other | 3 | 27 |
| 17 | HR & Culture Automation | GRC | 4 | 959 |
| 18 | Data Protection Complaint Intake | GRC | 1 | 0 |
| 19 | License & Subscription Management Notifications | Other | 1 | 12 |
| 20 | Engineering Changelog Broadcasting | Other | 1 | 0 |
_\* SOC platform is fully built and configured; execution counts are 0, indicating the platform is in pre-production or standing by for a live alert feed._
Use Cases
Use Case 1 — Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response
Category: SOC
Subcategories: Agentic SOC · Case mgmt & SOAR · Alert enrichment / IOC lookup · EDR containment & response · Phishing detection & response · Identity threat response
Description:
A complete, self-contained SOAR platform covering the full alert lifecycle: alerts are ingested and deduplicated, observables (IP, hash, URL, email, username, agent ID) are automatically enriched across eight external security tools, and enriched cases are routed to automated phishing/malware response and CrowdStrike endpoint containment. Recovery and utility playbooks keep the case-management data model healthy (stale-case closure, relation cleanup, similarity search, unprocessed-alert recovery).
Business problem solved:
Removes analyst time spent on repetitive triage, enrichment, and cross-tool pivoting. Every incoming alert is automatically contextualized, deduplicated against existing cases, and routed to the correct response action without human intervention.
Integrations: Blink Case Management · CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Okta · Google Workspace · Microsoft Entra ID (Active Directory) · GitHub · Slack · Microsoft Outlook · Whois
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Process Alert | 0 | Primary alert orchestrator — extracts observables, dedupes cases, triggers enrichment & response |
| Subflow - Response - Main Router | 0 | Routes enriched cases to the correct response playbook |
| Response Subflow - Phishing | 0 | Automated phishing response via Microsoft Outlook |
| Response Subflow - Malware | 0 | Automated malware containment and remediation routing |
| Subflow - Enrich Observables - Main Router | 0 | Dispatches each observable to the correct enrichment subflow |
| Enrich - Hash - VT | 0 | Hash enrichment via VirusTotal |
| Enrich - Hash - Crowdstrike | 0 | Hash enrichment via CrowdStrike |
| Get Hash Info Using VirusTotal | 0 | On-demand hash lookup via VirusTotal |
| Get Hash Info Using Crowdstrike | 0 | On-demand hash lookup via CrowdStrike indicators |
| Enrich - IP - VT | 0 | IP enrichment via VirusTotal |
| Enrich - IP - IPDB | 0 | IP enrichment via AbuseIPDB |
| Enrich - IP or Domain - Whois | 0 | IP/domain enrichment via Whois |
| Enrich IP or Domain Using Whois | 0 | On-demand IP/domain Whois lookup |
| Enrich - URL - VT | 0 | URL enrichment via VirusTotal |
| Enrich - URL - URLScan | 0 | URL enrichment via URLScan |
| Analyze URL with URLScan | 0 | On-demand URL analysis via URLScan |
| Secure URL Screenshot Capture | 0 | Captures a sandboxed screenshot of a suspicious URL |
| Enrich - Agent ID - Crowdstrike | 0 | Endpoint device lookup via CrowdStrike agent ID |
| Enrich - Username or Email - Okta | 0 | Identity enrichment via Okta |
| Get User Information Using Okta | 0 | On-demand Okta user lookup |
| Okta Search for User Activity | 0 | Pulls Okta login/activity logs for a user |
| Enrich - Username or Email - Google Workspace | 0 | Identity enrichment via Google Workspace |
| Get User Information Using Google Workspace | 0 | On-demand Google Workspace user lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Identity enrichment via Microsoft Entra ID |
| Get User Information Using Microsoft Entra ID | 0 | On-demand Entra ID lookup incl. risky-user status |
| Enrich - Username - Github | 0 | Identity enrichment via GitHub |
| Get User Information Using Github | 0 | On-demand GitHub user lookup |
| Enrich - Email Address - Slack | 0 | Identity enrichment via Slack |
| Get User Information on Email Address Using Slack | 0 | On-demand Slack user lookup by email |
| Get End of Life Date for a Product | 0 | Looks up EOL date for a software/hardware product |
| Run Dig Command | 0 | DNS lookup utility for investigations |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Sets/checks device quarantine state in CrowdStrike |
| CrowdStrike RTR to a Single Host | 0 | Runs Real Time Response commands on one host |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs Real Time Response commands across multiple hosts |
| Subflow - Update Enrichment Data | 0 | Writes enrichment verdicts back to the observable record |
| Utility - Update Enrichment | 0 | On-demand enrichment refresh for a given alert payload |
| Recovery - Enrich Non-Enriched Observables | 0 | Sweeps for observables missing enrichment and reprocesses them |
| Recovery - Handle Unprocessed Alerts | 0 | Sweeps for alerts stuck mid-pipeline and reprocesses them |
| Subflow - Missing Alert Template Notification | 0 | Notifies when no matching alert template is found |
| Table Action - Validate Observables Extraction Template | 0 | Validates extraction templates against historical alerts |
| Utility - List Alert Observable Relations | 0 | Lists all observables linked to an alert |
| Utility - List Observable Alert Relations | 0 | Lists all alerts linked to an observable |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates an observable-alert relationship |
| Utility - Delete Observable Relation | 0 | Removes a specific observable-alert relationship |
| Utility - Find Similar Cases Based on Observables | 0 | Calculates case similarity scores from shared observables |
| Utility - Close Stale Cases | 0 | Auto-closes cases with no activity in 30+ days |
| Error Handling - Send Error Notification Email | 0 | Emails the SOC team when a platform workflow errors |
| Simulate Multiple Alerts from Different Sources | 0 | Test-data generator for multi-source alert scenarios |
| Simulate Crowdstrike Alert | 0 | Test-data generator for CrowdStrike alert scenarios |
| USE WITH CARE - Reset Case Management Environment | 0 | Wipes case-management test tables (destructive utility) |
| Artemis Security Workflow | 0 | Parses Artemis security-scanner webhook alerts and posts formatted alerts to Slack |
Use Case 2 — Cloud Security Alert Triage & Ownership Coordination (Wiz)
Category: Cloud Security
Subcategories: CSPM ingest & triage · Cloud asset coverage & inventory
Description:
Ingests Wiz cloud security alerts and cloud resource inventory, then automatically identifies the engineer or team responsible for the affected asset by querying FireHydrant's on-call roster and Port.io's service catalog — cutting the time between "alert fires" and "right owner engaged."
Business problem solved:
Cloud security alerts are only actionable once routed to the team that owns the resource. This eliminates the manual lookup step engineers currently do by hand.
Integrations: Wiz · FireHydrant · Port.io · Blink Agents
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Wiz Threat User/Resource Owner Coordination | 144 | Webhook-triggered — matches a Wiz threat to the responsible user/resource owner |
| New Workflow | 0 | Polls Wiz every 5 minutes for new alerts |
| Wiz Alert Triage (Scheduled Search - every 10 mins) | 0 | Scheduled Wiz query sweep for triage |
| Wiz GraphQL Query | 0 | On-demand raw Wiz GraphQL query utility |
| AGENT - Wiz GraphQL Workflow | 0 | Blink agent wrapper for natural-language Wiz querying |
| Use Case 1 | 0 | Pulls cloud resource inventory from Wiz |
| Subflow - FireHydrant - Find Owner | 0 | Looks up the on-call owning team in FireHydrant |
| Subflow - Port.io - Find Owner | 0 | Looks up the owning team via the Port.io service catalog |
Use Case 3 — EDR Containment & Response (CrowdStrike)
Category: SOC
Subcategories: EDR containment & response
Description:
A production endpoint-containment pipeline: a scheduled job automatically isolates compromised hosts in CrowdStrike, a webhook-triggered flow isolates hosts in real time the moment CrowdStrike raises a non-informational detection, an on-demand subflow handles ad-hoc isolation requests, a tenant-wide error handler posts any workflow failure to Slack for the security engineering team, and a generic webhook intake logs external events for this pipeline.
Business problem solved:
Automates the highest-value EDR action — endpoint isolation — removing the delay of a human triggering containment by hand. Isolation now runs both on a schedule and instantly off live CrowdStrike detections, while giving the team a single Slack feed for both containment activity and workflow health.
Integrations: CrowdStrike · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| CrowdStrike - Auto Isolate | 19,200 | Scheduled job that automatically isolates compromised endpoints |
| CrowdStrike - Auto Isolate - Webhook | 7,134 | Webhook-triggered — isolates the endpoint in real time when CrowdStrike raises a non-informational detection |
| Mate Webhook | 666 | Webhook intake for the "Mate" integration feeding this pipeline |
| DxR Default Error Handling | 54 | Tenant-wide error handler — posts any workflow failure to Slack |
| Subflow - Endpoint Isolation | 17 | On-demand endpoint isolation subflow |
Use Case 4 — SIEM Feed Curation — Okta Exclusion List Sync
Category: SOC
Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation
Description:
On a schedule, pulls the current Okta exclusion list and pushes it into Google Chronicle/SecOps' exclusion table, keeping the SIEM's noise-suppression rules aligned with the identity system of record.
Business problem solved:
Manually keeping SIEM exclusion lists synchronized with identity-provider data is a common, easily-dropped maintenance task; this keeps it current automatically.
Integrations: Okta · Google Chronicle/SecOps
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Okta Exclusion List to Google Chronicle/SecOps Exclusion Table | 40 | Scheduled sync of the Okta exclusion list into Chronicle/SecOps |
Use Case 5 — Security Ticket Sync — Jira SecOps to Linear
Category: Vulnerability Mgmt
Subcategories: Vuln lifecycle, prioritize, ticket
Description:
Polls Jira for new issues in the SECOPS/SEM projects and mirrors qualifying issues into Linear, so the security team can prioritize and track remediation work in the same tool engineering uses.
Business problem solved:
Keeps security remediation tickets visible to engineering without requiring analysts to manually re-key Jira findings into Linear.
Integrations: Jira · Linear
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Linear Ticket Create | 21,523 | Polls Jira every 5 minutes for new SECOPS/SEM issues and mirrors qualifying ones to Linear |
_Note: this playbook polls on a fixed 5-minute interval, so its execution count reflects poll cycles rather than one-to-one ticket creation — it is intentionally excluded from the Business KPI table above._
Use Case 6 — Password & Credential Utility
Category: IAM
Subcategories: Password & credential lifecycle
Description:
An on-demand utility that generates a random, policy-compliant password for use in other identity workflows (e.g., account resets, provisioning).
Business problem solved:
Provides a reusable, secure password-generation building block instead of ad hoc scripting.
Integrations: None (native utility)
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Random Password Generator | 0 | Generates a random password on demand |
Use Case 7 — Full Employee Lifecycle Automation
Category: IAM
Subcategories: Full employee lifecycle
Description:
Slack-triggered workflows that capture new-hire, role-change, and departure events and notify the right internal channel, forming the front door of AlphaSense's identity lifecycle process.
Business problem solved:
Ensures IT/security are reliably notified the moment an employee joins, changes role, or leaves — the trigger point for provisioning, access changes, and de-provisioning.
Integrations: Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| New Hire | 0 | Captures new-hire submissions and notifies via Slack |
| Role Change | 0 | Captures role-change submissions and notifies via Slack |
| Submit Departure | 0 | Captures departure submissions and notifies via Slack |
Use Case 8 — Linear ↔ Notion Project & Roadmap Sync
Category: Other
Subcategories: DevOps & release automation
Description:
Keeps Notion project and roadmap databases synchronized with Linear issues, initiatives, driver projects, and deprecation tracking — covering both webhook-driven and scheduled full syncs — so product and engineering teams don't maintain the same data in two tools by hand.
Business problem solved:
Removes the manual, error-prone work of duplicating Linear status into Notion for stakeholders who live in Notion.
Integrations: Linear · Notion
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Get Notion User ID from Email | 11,599 | Utility — resolves a Notion user ID from an email address, called by the sync workflows below |
| Project updates testing | 1,936 | Triggered on new Linear project updates — writes summaries into Notion |
| Linear to Notion Database | 780 | Webhook-triggered Linear issue → Notion database sync |
| Linear Driver Projects to Notion Sync | 40 | Scheduled full sync of Linear driver projects to Notion |
| Linear AS Features/Products/Components Deprecation Projects to Notion Sync | 40 | Scheduled sync of deprecation-tracking projects to Notion |
| Get Notion User ID from Email copy | 0 | Unused duplicate of the user-ID lookup utility |
| Get Notion User ID from Email copy copy | 0 | Unused duplicate of the user-ID lookup utility |
| Clean up Notion Project Database | 0 | On-demand cleanup of stale Notion project records |
| Project updater | 0 | Triggered on new Notion pages — updates the linked Linear project |
| Project updater copy | 0 | On-demand variant of the project updater |
Use Case 9 — AI-Assisted PRD-to-Ticket Creation
Category: Other
Subcategories: DevOps & release automation
Description:
Uses Anthropic's Claude to read a submitted PRD and convert it directly into structured Linear tickets — one instance for the product team, one for the content team.
Business problem solved:
Cuts the manual effort of translating a requirements doc into properly-structured engineering/content tickets.
Integrations: Anthropic (Claude) · Linear
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| PRD to Linear with Claude | 19 | Converts a submitted PRD into Linear tickets using Claude |
| PRD to Linear with Claude: CONTENT | 1 | Content-team variant of the PRD-to-Linear pipeline |
Use Case 10 — Feature/Content Submission Review & PM Notification
Category: Other
Subcategories: DevOps & release automation · IT helpdesk & ticket routing
Description:
Handles the review lifecycle for feature/content flag requests: a Salesforce AV-flag review creates Linear tickets and notifies the PM, submitters get a Slack DM when their request needs more info or is rejected, and any Linear ticket tagged with the "flag request" label triggers a Slack notification to the team.
Business problem solved:
Keeps PMs and requesters informed at each stage of a feature request's lifecycle without manual status updates.
Integrations: Slack · Linear · Salesforce
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Flag Requests Tickets notifications | 221 | Notifies Slack when a Linear ticket is tagged as a flag request |
| Send DM to PM on new submission | 7 | DMs the owning PM when a new submission arrives |
| Notion SF AV Flag Review: Create Linear tickets and notify PM | 6 | Converts a Salesforce AV-flag review into Linear tickets and notifies the PM |
| Rejected | 1 | Sends a rejection notification via Slack |
| Send DM to PM requesting more info | 0 | DMs the PM when a submission needs more information |
Use Case 11 — Meeting & Leadership Cadence Reminders
Category: Other
Subcategories: SaaS / IT administration
Description:
Checks Google Calendar on a schedule and sends Slack reminders ahead of recurring GTM leadership meetings.
Business problem solved:
Reduces missed or under-prepared leadership meetings without anyone having to manually track the calendar.
Integrations: Google Calendar · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| GTM Leadership Pulse: Meeting Reminders | 40 | Scheduled Google Calendar check with Slack reminder for leadership meetings |
Use Case 12 — Email-to-Spreadsheet Data Capture
Category: Other
Subcategories: SaaS / IT administration
Description:
Watches Gmail for new messages, extracts message data, and appends structured rows to a Google Sheet for downstream reporting.
Business problem solved:
Creates a queryable log of inbound email activity without manual data entry into spreadsheets.
Integrations: Gmail · Google Sheets · Google Workspace
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| List Gmail Messages and Send Results via Email | 2,170 | Triggered on new Gmail messages — extracts data and logs to Google Sheets |
| New Workflow 1 | 0 | On-demand variant of the Gmail-to-Sheets capture |
Use Case 13 — Helpdesk Ticket Sync (Zendesk → Notion)
Category: Other
Subcategories: IT helpdesk & ticket routing
Description:
Triggered on new Zendesk tickets, looks up ticket/organization context and writes a structured entry into a Notion database.
Business problem solved:
Bridges customer-support ticketing (Zendesk) with internal knowledge management (Notion) without manual copy-paste.
Integrations: Zendesk · Notion
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| New Workflow 1 | 0 | New Zendesk ticket → Notion database entry |
| New Workflow 1 (greig.fields@alpha-sense.com) | 0 | User-specific variant of the Zendesk → Notion sync |
Use Case 14 — Slack Channel Concierge — Deal Desk & Billing Routing
Category: Other
Subcategories: Financial & fraud operations
Description:
Listens for new (non-thread-reply) messages posted in the Deal Desk and Billing Slack channels and triages them automatically, reducing manual channel-monitoring by the finance/deal-desk team.
Business problem solved:
Ensures the first message in a deal-desk or billing question thread is triaged immediately instead of waiting on a human to notice it.
Integrations: Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Deal Desk Slack Channel | 159 | Triages new top-level messages in the Deal Desk Slack channel |
| New Workflow | 20 | Same top-level-message triage pattern, deployed to another channel |
| Billing Slack Channel- Test | 24 | Test-environment version of the billing channel triage |
| Billing Slack Channel- Prod | 5 | Production billing-channel triage |
| Test Slack | 1 | Early-stage test workflow — normalizes an incoming Slack event and creates a case; prototype, shares this workspace with the triage flows above |
Use Case 15 — Sales Bookings & Performance Tracking
Category: Other
Subcategories: Customer registry & FinOps auto
Description:
Monitors Gmail for booking-confirmation emails and logs each one to a tracking table, then publishes a Slack leaderboard of booking/call activity.
Business problem solved:
Removes manual tracking of sales bookings and gives the team a self-updating leaderboard that drives accountability.
Integrations: Gmail · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Collect Bookings | 340 | Monitors Gmail for booking confirmations and logs to a tracking table |
| Print Call Leaderboard | 28 | Publishes a Slack leaderboard of booking/call activity |
Use Case 16 — Off-Hours / On-Call Escalation Notifications
Category: Other
Subcategories: IT/OT & network infra monitoring
Description:
Webhook-triggered, per-environment (production/staging/development) off-hours alerting that formats the incoming event and interactively pages the on-call responder via Slack.
Business problem solved:
Ensures off-hours incidents reach the right on-call responder within seconds, without a manual escalation chain, and keeps environments separated so prod incidents aren't lost in dev/staging noise.
Integrations: Slack · HTTP (environment webhooks)
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Off Hours Notification - Production | 27 | Off-hours alert routing for the production environment |
| Off Hours Notification - Development | 0 | Off-hours alert routing for the development environment |
| Off Hours Notification - Staging | 0 | Off-hours alert routing for the staging environment |
Use Case 17 — HR & Culture Automation
Category: GRC
Subcategories: AI / HR compliance automation
Description:
A set of people-operations automations: hiring-manager feedback surveys are emailed automatically, Solutions-Architect skills feedback captured in Slack is logged to Notion, and a Slack "+1" slash-command lets employees log peer recognition (with an Anthropic-assisted lookup and Salesforce context) straight into Notion.
Business problem solved:
Automates recurring HR/enablement admin — feedback collection and peer recognition — that would otherwise rely on someone remembering to send a form or copy notes into a shared doc.
Integrations: Gmail · Slack · Notion · Salesforce · Anthropic (Claude)
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| SA Skills Feedback - Slack to Notion | 719 | Logs SA skills feedback (via Slack emoji reaction) to Notion |
| HM Survey Trigger | 228 | Sends hiring-manager feedback survey emails |
| New Workflow | 12 | Slack-triggered — logs an entry to Notion |
| +1 | 0 | Slack slash-command for peer recognition, logged to Notion |
Use Case 18 — Data Protection Complaint Intake
Category: GRC
Subcategories: DSAR & privacy automation
Description:
Triggered when a Google Forms data-protection complaint form is submitted, this sends an email alert so the privacy team can respond within required timelines.
Business problem solved:
Ensures data-protection/DSAR-adjacent complaints reach the privacy team immediately rather than sitting in a forms inbox.
Integrations: Google Forms
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Data Protection Complaint Form Alert | 0 | Emails the privacy team on a new complaint-form submission |
Use Case 19 — License & Subscription Management Notifications
Category: Other
Subcategories: SaaS / IT administration
Description:
Sends proactive email alerts ahead of software license expirations.
Business problem solved:
Prevents lapsed licenses/subscriptions by giving stakeholders advance warning instead of discovering the lapse after the fact.
Integrations: None captured (email/scripting)
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Send License Expiration Emails | 12 | Emails stakeholders ahead of software license expirations |
Use Case 20 — Engineering Changelog Broadcasting
Category: Other
Subcategories: DevOps & release automation
Description:
Triggered on new GitLab merges, posts a formatted changelog entry to Slack.
Business problem solved:
Keeps engineering stakeholders informed of what shipped without anyone manually summarizing merges.
Integrations: GitLab · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| DFS Changelog | 0 | Posts a GitLab-merge changelog entry to Slack |
Key Observations
Strengths
Real production impact in endpoint containment. Between the scheduled CrowdStrike - Auto Isolate job (19,200 executions) and the new webhook-triggered CrowdStrike - Auto Isolate - Webhook (7,134 executions), AlphaSense automated 26,334 endpoint isolations in 12 months — by far the single highest-value security automation in the tenant, now running both on a schedule and in real time off live detections.
Deep engineering/PM tooling integration. The Linear ↔ Notion sync pipelines and PRD-to-Linear AI pipeline together processed over 14,400 executions, showing Blink is embedded in AlphaSense's daily product and engineering workflow, not just security.
A fully architected, production-ready SOC platform. The 51-playbook SOAR framework (Use Case 1) covers observable extraction, enrichment across 8+ security tools, deduplication, and automated phishing/malware response. It is structurally complete and simply needs a live alert feed to go into production.
Cloud security ownership routing is built and ready. The Wiz + FireHydrant + Port.io integration (Use Case 2) is configured to automatically route cloud threats to the correct owning team — a capability many security teams still do by hand.
AI is already in the workflow, not just a pilot. The PRD-to-Linear (Claude) and "+1" recognition workflows show AlphaSense using Claude for real, recurring business tasks.
Gaps & Opportunities
Core SOC pipeline shows zero executions. Process Alert and its enrichment/response chain (Use Case 1) haven't run in the last 12 months. Activating the live alert feed would immediately convert this built platform into measurable analyst time savings.
Cloud threat triage (Wiz) is mostly idle. Outside of the 144-execution owner-coordination flow, the remaining 7 Wiz playbooks in Use Case 2 show 0 executions — the alert-ingestion and inventory side of the pipeline appears disconnected from a live feed.
No dedicated vulnerability-scanning or CVE workflows. Given AlphaSense's CrowdStrike/Wiz/Chronicle footprint, there's no playbook for vuln scan ingestion, CVE lookup/remediation, or scan-lifecycle automation — the closest analog (Linear Ticket Create) is a Jira poll-sync, not a scan pipeline.
Several duplicate/unlabeled workflows increase maintenance overhead. "Get Notion User ID from Email" exists in three copies (Use Case 8), and multiple playbooks are still named "New Workflow" or "New Workflow 1" with no distinguishing name (Use Cases 2, 12, 13, 14, 17) — consolidating or renaming these would reduce confusion about which is canonical.
A polling-based workflow inflates raw execution counts. Linear Ticket Create shows 21,523 executions, but it polls Jira every 5 minutes regardless of whether a new issue exists — the number reflects poll cycles, not tickets created, and should not be read as a business-volume metric as-is.
One unused tutorial workflow. "Getting Started - Hello World" (workspace 445403f0) is Blink's onboarding sample and has never been run — expected for a sandbox, but worth cleaning up if that workspace is otherwise inactive.
Integration Ecosystem
| Domain | Integrations in Use |
|---|---|
| Security | CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Whois · Wiz · FireHydrant · Port.io · Google Chronicle/SecOps · Artemis Security |
| Identity | Okta · Microsoft Entra ID (Active Directory) · Google Workspace · GitHub · Slack |
| Productivity & DevOps | Linear · Notion · Jira · GitLab · Google Calendar · Google Sheets · Gmail |
| AI | Anthropic (Claude) |
| Communication | Slack · Microsoft Outlook |
| Business Systems | Salesforce · Zendesk · Google Forms |
| Infrastructure | HTTP webhooks · Bash · Python |
E New Integrations (detail) 7 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| alphasense | 2lo_auth | my_http_custom_2_legged_oauth_2_0_authentication_connection | 2026-09-09 |
| alphasense | google-drive | my_google_drive_connection | 2026-09-09 |
| alphasense | slack | my_slack_connection_1 | 2026-09-09 |
| alphasense | google-sheets | my_google_sheets_connection | 2026-09-02 |
| alphasense | zendesk | revops_zendesk_connection | 2026-08-31 |
| alphasense | gmail | my_gmail_connection | 2026-08-31 |
| alphasense | gmail | my_gmail_connection | 2026-08-27 |