Blink Security Automation — Confidential

alphasense — Customer Success Report

Generated 2026-09-10 | alphasense-value-report.md
2026-09-10Report Date
263Total Playbooks
62Unique Workflows (12m)
2,988,668Actions Automated (12m)
$768,690Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

263
Total playbooks built
all non-deleted workflows
115
Active playbooks
currently enabled
62
Unique workflows executed (12m)
distinct workflows that ran
2,988,668
Actions automated (12m)
completed action steps
16,603.7h
Hours saved (12m)
@ 20s per action
$768,690
Money saved (12m)
@ $100K avg salary
8
New active workflows (last 30d)
recently created & enabled
5
Total cases managed
5 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
2
Active AI agents
of 4 total
11
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 26,334 compromised endpoints automatically isolated in CrowdStrike — zero-touch containment - 2,170 inbound emails processed and logged without manual data entry - 1,936 product roadmap updates synced from Linear to Notion in real time - 780 engineering tickets propagated to the Notion knowledge base with zero manual effort - 719 SA skills-feedback entries captured from Slack straight into Notion - 340 sales bookings captured automatically from inbound email - 228 hiring-manager feedback surveys sent without manual follow-up - 144 cloud security alerts automatically routed to the correct resource owner

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1 — Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response1 executions
0.0%
51
51 active
Use Case 2 — Cloud Security Alert Triage & Ownership Coordination (Wiz)
  • 144Cloud security alerts routed to the correct resource owner
0.6%
7
7 active
Use Case 3 — EDR Containment & Response (CrowdStrike)27,942 executions
45.3%
5
5 active
Use Case 4 — SIEM Feed Curation — Okta Exclusion List Sync
  • 40Okta exclusion-list updates pushed to SIEM (Chronicle)
0.1%
1
1 active
Use Case 5 — Security Ticket Sync — Jira SecOps to Linear0 executions
0.0%
0
0 active
Use Case 6 — Password & Credential Utility0 executions
0.0%
1
1 active
Use Case 7 — Full Employee Lifecycle Automation0 executions
0.0%
3
3 active
Use Case 8 — Linear ↔ Notion Project & Roadmap Sync
  • 1,936Product roadmap updates synced from Linear to Notion
  • 780Engineering tickets synced from Linear to Notion
23.2%
10
10 active
Use Case 9 — AI-Assisted PRD-to-Ticket Creation38 executions
0.1%
2
2 active
Use Case 10 — Feature/Content Submission Review & PM Notification
  • 221Flagged-ticket alerts routed to Slack
0.4%
5
5 active
Use Case 11 — Meeting & Leadership Cadence Reminders
  • 40Leadership meeting reminders sent
0.1%
1
1 active
Use Case 12 — Email-to-Spreadsheet Data Capture
  • 2,170Inbound emails processed and logged automatically
3.2%
1
1 active
Use Case 13 — Helpdesk Ticket Sync (Zendesk → Notion)0 executions
0.0%
2
1 active
Use Case 14 — Slack Channel Concierge — Deal Desk & Billing Routing
  • 159Deal desk inquiries triaged in Slack
6.5%
4
4 active
Use Case 15 — Sales Bookings & Performance Tracking
  • 340Sales bookings captured automatically from inbound email
  • 28Sales call leaderboard reports published to Slack
0.8%
2
2 active
Use Case 16 — Off-Hours / On-Call Escalation Notifications
  • 27Off-hours production incidents escalated to on-call
0.1%
3
3 active
Use Case 17 — HR & Culture Automation
  • 719SA skills-feedback entries logged from Slack to Notion
  • 228Hiring-manager feedback surveys sent
1.5%
4
2 active
Use Case 18 — Data Protection Complaint Intake3 executions
0.0%
1
1 active
Use Case 19 — License & Subscription Management Notifications
  • 12Software license expiration alerts sent
0.0%
1
1 active
Use Case 20 — Engineering Changelog Broadcasting3 executions
0.0%
1
1 active
Total50,405 executions100%
105
102 active

Use Case Growth Over Time

177 unique playbooks  |  19 operational use cases  |  61,657 total executions (12m)  |  2024-09 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Use Case 1 — Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Microsoft Outlook Email Google Workspace GitHub Microsoft Entra ID Slack
Use Case 8 — Linear ↔ Notion Project & Roadmap Sync
Notion Linear
Use Case 2 — Cloud Security Alert Triage & Ownership Coordination (Wiz)
Wiz AWS Azure GCP Shodan GreyNoise Censys FireHydrant Agents Slack Jira Okta Port
Use Case 17 — HR & Culture Automation
Notion Linear Slack Salesforce Anthropic OpenAI Greenhouse Email Gmail Google Drive GitHub
Use Case 13 — Helpdesk Ticket Sync (Zendesk → Notion)
Notion Linear Gmail Google Sheets Zendesk Slack Email CrowdStrike
Use Case 12 — Email-to-Spreadsheet Data Capture
Gmail Google Sheets
Use Case 11 — Meeting & Leadership Cadence Reminders
Google Calendar Slack
Use Case 4 — SIEM Feed Curation — Okta Exclusion List Sync
Okta Chronicle
Use Case 9 — AI-Assisted PRD-to-Ticket Creation
Notion Linear Anthropic Slack
Use Case 3 — EDR Containment & Response (CrowdStrike)
CrowdStrike Slack Jira
Use Case 16 — Off-Hours / On-Call Escalation Notifications
Slack
Use Case 15 — Sales Bookings & Performance Tracking
Gmail Slack
Use Case 10 — Feature/Content Submission Review & PM Notification
Slack Notion Linear Anthropic
Use Case 20 — Engineering Changelog Broadcasting
Slack
Use Case 14 — Slack Channel Concierge — Deal Desk & Billing Routing
Slack Salesforce Anthropic
Use Case 7 — Full Employee Lifecycle Automation
Slack
Use Case 19 — License & Subscription Management Notifications
Gmail
Use Case 18 — Data Protection Complaint Intake
Google Forms Email

04Key Observations

✓  Strengths

Strengths

Real production impact in endpoint containment. Between the scheduled CrowdStrike - Auto Isolate job (19,200 executions) and the new webhook-triggered CrowdStrike - Auto Isolate - Webhook (7,134 executions), AlphaSense automated 26,334 endpoint isolations in 12 months — by far the single highest-value security automation in the tenant, now running both on a schedule and in real time off live detections.

Deep engineering/PM tooling integration. The Linear ↔ Notion sync pipelines and PRD-to-Linear AI pipeline together processed over 14,400 executions, showing Blink is embedded in AlphaSense's daily product and engineering workflow, not just security.

A fully architected, production-ready SOC platform. The 51-playbook SOAR framework (Use Case 1) covers observable extraction, enrichment across 8+ security tools, deduplication, and automated phishing/malware response. It is structurally complete and simply needs a live alert feed to go into production.

Cloud security ownership routing is built and ready. The Wiz + FireHydrant + Port.io integration (Use Case 2) is configured to automatically route cloud threats to the correct owning team — a capability many security teams still do by hand.

AI is already in the workflow, not just a pilot. The PRD-to-Linear (Claude) and "+1" recognition workflows show AlphaSense using Claude for real, recurring business tasks.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Core SOC pipeline shows zero executions. Process Alert and its enrichment/response chain (Use Case 1) haven't run in the last 12 months. Activating the live alert feed would immediately convert this built platform into measurable analyst time savings.

Cloud threat triage (Wiz) is mostly idle. Outside of the 144-execution owner-coordination flow, the remaining 7 Wiz playbooks in Use Case 2 show 0 executions — the alert-ingestion and inventory side of the pipeline appears disconnected from a live feed.

No dedicated vulnerability-scanning or CVE workflows. Given AlphaSense's CrowdStrike/Wiz/Chronicle footprint, there's no playbook for vuln scan ingestion, CVE lookup/remediation, or scan-lifecycle automation — the closest analog (Linear Ticket Create) is a Jira poll-sync, not a scan pipeline.

Several duplicate/unlabeled workflows increase maintenance overhead. "Get Notion User ID from Email" exists in three copies (Use Case 8), and multiple playbooks are still named "New Workflow" or "New Workflow 1" with no distinguishing name (Use Cases 2, 12, 13, 14, 17) — consolidating or renaming these would reduce confusion about which is canonical.

A polling-based workflow inflates raw execution counts. Linear Ticket Create shows 21,523 executions, but it polls Jira every 5 minutes regardless of whether a new issue exists — the number reflects poll cycles, not tickets created, and should not be read as a business-volume metric as-is.

One unused tutorial workflow. "Getting Started - Hello World" (workspace 445403f0) is Blink's onboarding sample and has never been run — expected for a sandbox, but worth cleaning up if that workspace is otherwise inactive.

Integration Ecosystem

Domain Integrations in Use
Security CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Whois · Wiz · FireHydrant · Port.io · Google Chronicle/SecOps · Artemis Security
Identity Okta · Microsoft Entra ID (Active Directory) · Google Workspace · GitHub · Slack
Productivity & DevOps Linear · Notion · Jira · GitLab · Google Calendar · Google Sheets · Gmail
AI Anthropic (Claude)
Communication Slack · Microsoft Outlook
Business Systems Salesforce · Zendesk · Google Forms
Infrastructure HTTP webhooks · Bash · Python
Appendices
A Case Management 5 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
5
5 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 5 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management V9 5 5 0 N/A
B AI Agents 2 active | 11 tasks (12m)

AI Agents

Active Agents
2
of 4 total
Tasks Executed (12m)
11
0 in last 30d
Data Usage (12m)
3,891,807
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Wiz Findings Expert Security DxR 6 0 650,598
2 Wiz GraphQL Agent Security DxR 5 0 3,241,209
3 Agent Blink Case Management V9 0 0 0
4 Secops Security DxR 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Security DxR11
Case Management V90
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
4
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 TPM 00
2 TPM 00
3 Test 00
4 ViZ 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 19 use cases | 61,657 executions (12m)

Business KPIs

Metric Count Playbook
Compromised endpoints automatically isolated 26,334 CrowdStrike - Auto Isolate (19,200) + CrowdStrike - Auto Isolate - Webhook (7,134)
Inbound emails processed and logged automatically 2,170 List Gmail Messages and Send Results via Email
Product roadmap updates synced from Linear to Notion 1,936 Project updates testing
Engineering tickets synced from Linear to Notion 780 Linear to Notion Database
SA skills-feedback entries logged from Slack to Notion 719 SA Skills Feedback - Slack to Notion
Sales bookings captured automatically from inbound email 340 Collect Bookings
Hiring-manager feedback surveys sent 228 HM Survey Trigger
Flagged-ticket alerts routed to Slack 221 Flag Requests Tickets notifications
Deal desk inquiries triaged in Slack 159 Deal Desk Slack Channel
Cloud security alerts routed to the correct resource owner 144 Wiz Threat User/Resource Owner Coordination
Driver & deprecation project updates synced to Notion 80 Linear Driver Projects to Notion Sync (40) + Linear AS Features/Products/Components Deprecation Projects to Notion Sync (40)
Leadership meeting reminders sent 40 GTM Leadership Pulse: Meeting Reminders
Okta exclusion-list updates pushed to SIEM (Chronicle) 40 Okta Exclusion List to Google Chronicle/SecOps Exclusion Table
Sales call leaderboard reports published to Slack 28 Print Call Leaderboard
Off-hours production incidents escalated to on-call 27 Off Hours Notification - Production
PRDs auto-converted into Linear tickets via AI 20 PRD to Linear with Claude (19) + PRD to Linear with Claude: CONTENT (1)
Software license expiration alerts sent 12 Send License Expiration Emails
In the last 12 months, Blink automated: - 26,334 compromised endpoints automatically isolated in CrowdStrike — zero-touch containment - 2,170 inbound emails processed and logged without manual data entry - 1,936 product roadmap updates synced from Linear to Notion in real time - 780 engineering tickets propagated to the Notion knowledge base with zero manual effort - 719 SA skills-feedback entries captured from Slack straight into Notion - 340 sales bookings captured automatically from inbound email - 228 hiring-manager feedback surveys sent without manual follow-up - 144 cloud security alerts automatically routed to the correct resource owner

Use Case Summary

# Use Case Category Playbooks Executions (12mo)
1 Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response SOC 51 0*
2 Cloud Security Alert Triage & Ownership Coordination (Wiz) Cloud Security 8 144
3 EDR Containment & Response (CrowdStrike) SOC 5 27,071
4 SIEM Feed Curation — Okta Exclusion List Sync SOC 1 40
5 Security Ticket Sync — Jira SecOps to Linear Vulnerability Mgmt 1 21,523
6 Password & Credential Utility IAM 1 0
7 Full Employee Lifecycle Automation IAM 3 0
8 Linear ↔ Notion Project & Roadmap Sync Other 10 14,395
9 AI-Assisted PRD-to-Ticket Creation Other 2 20
10 Feature/Content Submission Review & PM Notification Other 5 235
11 Meeting & Leadership Cadence Reminders Other 1 40
12 Email-to-Spreadsheet Data Capture Other 2 2,170
13 Helpdesk Ticket Sync (Zendesk → Notion) Other 2 0
14 Slack Channel Concierge — Deal Desk & Billing Routing Other 5 209
15 Sales Bookings & Performance Tracking Other 2 368
16 Off-Hours / On-Call Escalation Notifications Other 3 27
17 HR & Culture Automation GRC 4 959
18 Data Protection Complaint Intake GRC 1 0
19 License & Subscription Management Notifications Other 1 12
20 Engineering Changelog Broadcasting Other 1 0

_\* SOC platform is fully built and configured; execution counts are 0, indicating the platform is in pre-production or standing by for a live alert feed._

Use Cases

Use Case 1 — Agentic SOC Automation Framework — Alert Enrichment, Case Mgmt & Response

Category: SOC

Subcategories: Agentic SOC · Case mgmt & SOAR · Alert enrichment / IOC lookup · EDR containment & response · Phishing detection & response · Identity threat response

Description:

A complete, self-contained SOAR platform covering the full alert lifecycle: alerts are ingested and deduplicated, observables (IP, hash, URL, email, username, agent ID) are automatically enriched across eight external security tools, and enriched cases are routed to automated phishing/malware response and CrowdStrike endpoint containment. Recovery and utility playbooks keep the case-management data model healthy (stale-case closure, relation cleanup, similarity search, unprocessed-alert recovery).

Business problem solved:

Removes analyst time spent on repetitive triage, enrichment, and cross-tool pivoting. Every incoming alert is automatically contextualized, deduplicated against existing cases, and routed to the correct response action without human intervention.

Integrations: Blink Case Management · CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Okta · Google Workspace · Microsoft Entra ID (Active Directory) · GitHub · Slack · Microsoft Outlook · Whois

Playbooks

Playbook Executions Role
Process Alert 0 Primary alert orchestrator — extracts observables, dedupes cases, triggers enrichment & response
Subflow - Response - Main Router 0 Routes enriched cases to the correct response playbook
Response Subflow - Phishing 0 Automated phishing response via Microsoft Outlook
Response Subflow - Malware 0 Automated malware containment and remediation routing
Subflow - Enrich Observables - Main Router 0 Dispatches each observable to the correct enrichment subflow
Enrich - Hash - VT 0 Hash enrichment via VirusTotal
Enrich - Hash - Crowdstrike 0 Hash enrichment via CrowdStrike
Get Hash Info Using VirusTotal 0 On-demand hash lookup via VirusTotal
Get Hash Info Using Crowdstrike 0 On-demand hash lookup via CrowdStrike indicators
Enrich - IP - VT 0 IP enrichment via VirusTotal
Enrich - IP - IPDB 0 IP enrichment via AbuseIPDB
Enrich - IP or Domain - Whois 0 IP/domain enrichment via Whois
Enrich IP or Domain Using Whois 0 On-demand IP/domain Whois lookup
Enrich - URL - VT 0 URL enrichment via VirusTotal
Enrich - URL - URLScan 0 URL enrichment via URLScan
Analyze URL with URLScan 0 On-demand URL analysis via URLScan
Secure URL Screenshot Capture 0 Captures a sandboxed screenshot of a suspicious URL
Enrich - Agent ID - Crowdstrike 0 Endpoint device lookup via CrowdStrike agent ID
Enrich - Username or Email - Okta 0 Identity enrichment via Okta
Get User Information Using Okta 0 On-demand Okta user lookup
Okta Search for User Activity 0 Pulls Okta login/activity logs for a user
Enrich - Username or Email - Google Workspace 0 Identity enrichment via Google Workspace
Get User Information Using Google Workspace 0 On-demand Google Workspace user lookup
Enrich - Username or Email - Microsoft Entra ID 0 Identity enrichment via Microsoft Entra ID
Get User Information Using Microsoft Entra ID 0 On-demand Entra ID lookup incl. risky-user status
Enrich - Username - Github 0 Identity enrichment via GitHub
Get User Information Using Github 0 On-demand GitHub user lookup
Enrich - Email Address - Slack 0 Identity enrichment via Slack
Get User Information on Email Address Using Slack 0 On-demand Slack user lookup by email
Get End of Life Date for a Product 0 Looks up EOL date for a software/hardware product
Run Dig Command 0 DNS lookup utility for investigations
Manage Endpoint Quarantine Status in Crowdstrike 0 Sets/checks device quarantine state in CrowdStrike
CrowdStrike RTR to a Single Host 0 Runs Real Time Response commands on one host
CrowdStrike RTR to a Batch of Hosts 0 Runs Real Time Response commands across multiple hosts
Subflow - Update Enrichment Data 0 Writes enrichment verdicts back to the observable record
Utility - Update Enrichment 0 On-demand enrichment refresh for a given alert payload
Recovery - Enrich Non-Enriched Observables 0 Sweeps for observables missing enrichment and reprocesses them
Recovery - Handle Unprocessed Alerts 0 Sweeps for alerts stuck mid-pipeline and reprocesses them
Subflow - Missing Alert Template Notification 0 Notifies when no matching alert template is found
Table Action - Validate Observables Extraction Template 0 Validates extraction templates against historical alerts
Utility - List Alert Observable Relations 0 Lists all observables linked to an alert
Utility - List Observable Alert Relations 0 Lists all alerts linked to an observable
Utility - Set Or Update Observable Relation 0 Creates or updates an observable-alert relationship
Utility - Delete Observable Relation 0 Removes a specific observable-alert relationship
Utility - Find Similar Cases Based on Observables 0 Calculates case similarity scores from shared observables
Utility - Close Stale Cases 0 Auto-closes cases with no activity in 30+ days
Error Handling - Send Error Notification Email 0 Emails the SOC team when a platform workflow errors
Simulate Multiple Alerts from Different Sources 0 Test-data generator for multi-source alert scenarios
Simulate Crowdstrike Alert 0 Test-data generator for CrowdStrike alert scenarios
USE WITH CARE - Reset Case Management Environment 0 Wipes case-management test tables (destructive utility)
Artemis Security Workflow 0 Parses Artemis security-scanner webhook alerts and posts formatted alerts to Slack

Use Case 2 — Cloud Security Alert Triage & Ownership Coordination (Wiz)

Category: Cloud Security

Subcategories: CSPM ingest & triage · Cloud asset coverage & inventory

Description:

Ingests Wiz cloud security alerts and cloud resource inventory, then automatically identifies the engineer or team responsible for the affected asset by querying FireHydrant's on-call roster and Port.io's service catalog — cutting the time between "alert fires" and "right owner engaged."

Business problem solved:

Cloud security alerts are only actionable once routed to the team that owns the resource. This eliminates the manual lookup step engineers currently do by hand.

Integrations: Wiz · FireHydrant · Port.io · Blink Agents

Playbooks

Playbook Executions Role
Wiz Threat User/Resource Owner Coordination 144 Webhook-triggered — matches a Wiz threat to the responsible user/resource owner
New Workflow 0 Polls Wiz every 5 minutes for new alerts
Wiz Alert Triage (Scheduled Search - every 10 mins) 0 Scheduled Wiz query sweep for triage
Wiz GraphQL Query 0 On-demand raw Wiz GraphQL query utility
AGENT - Wiz GraphQL Workflow 0 Blink agent wrapper for natural-language Wiz querying
Use Case 1 0 Pulls cloud resource inventory from Wiz
Subflow - FireHydrant - Find Owner 0 Looks up the on-call owning team in FireHydrant
Subflow - Port.io - Find Owner 0 Looks up the owning team via the Port.io service catalog

Use Case 3 — EDR Containment & Response (CrowdStrike)

Category: SOC

Subcategories: EDR containment & response

Description:

A production endpoint-containment pipeline: a scheduled job automatically isolates compromised hosts in CrowdStrike, a webhook-triggered flow isolates hosts in real time the moment CrowdStrike raises a non-informational detection, an on-demand subflow handles ad-hoc isolation requests, a tenant-wide error handler posts any workflow failure to Slack for the security engineering team, and a generic webhook intake logs external events for this pipeline.

Business problem solved:

Automates the highest-value EDR action — endpoint isolation — removing the delay of a human triggering containment by hand. Isolation now runs both on a schedule and instantly off live CrowdStrike detections, while giving the team a single Slack feed for both containment activity and workflow health.

Integrations: CrowdStrike · Slack

Playbooks

Playbook Executions Role
CrowdStrike - Auto Isolate 19,200 Scheduled job that automatically isolates compromised endpoints
CrowdStrike - Auto Isolate - Webhook 7,134 Webhook-triggered — isolates the endpoint in real time when CrowdStrike raises a non-informational detection
Mate Webhook 666 Webhook intake for the "Mate" integration feeding this pipeline
DxR Default Error Handling 54 Tenant-wide error handler — posts any workflow failure to Slack
Subflow - Endpoint Isolation 17 On-demand endpoint isolation subflow

Use Case 4 — SIEM Feed Curation — Okta Exclusion List Sync

Category: SOC

Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation

Description:

On a schedule, pulls the current Okta exclusion list and pushes it into Google Chronicle/SecOps' exclusion table, keeping the SIEM's noise-suppression rules aligned with the identity system of record.

Business problem solved:

Manually keeping SIEM exclusion lists synchronized with identity-provider data is a common, easily-dropped maintenance task; this keeps it current automatically.

Integrations: Okta · Google Chronicle/SecOps

Playbooks

Playbook Executions Role
Okta Exclusion List to Google Chronicle/SecOps Exclusion Table 40 Scheduled sync of the Okta exclusion list into Chronicle/SecOps

Use Case 5 — Security Ticket Sync — Jira SecOps to Linear

Category: Vulnerability Mgmt

Subcategories: Vuln lifecycle, prioritize, ticket

Description:

Polls Jira for new issues in the SECOPS/SEM projects and mirrors qualifying issues into Linear, so the security team can prioritize and track remediation work in the same tool engineering uses.

Business problem solved:

Keeps security remediation tickets visible to engineering without requiring analysts to manually re-key Jira findings into Linear.

Integrations: Jira · Linear

Playbooks

Playbook Executions Role
Linear Ticket Create 21,523 Polls Jira every 5 minutes for new SECOPS/SEM issues and mirrors qualifying ones to Linear

_Note: this playbook polls on a fixed 5-minute interval, so its execution count reflects poll cycles rather than one-to-one ticket creation — it is intentionally excluded from the Business KPI table above._

Use Case 6 — Password & Credential Utility

Category: IAM

Subcategories: Password & credential lifecycle

Description:

An on-demand utility that generates a random, policy-compliant password for use in other identity workflows (e.g., account resets, provisioning).

Business problem solved:

Provides a reusable, secure password-generation building block instead of ad hoc scripting.

Integrations: None (native utility)

Playbooks

Playbook Executions Role
Random Password Generator 0 Generates a random password on demand

Use Case 7 — Full Employee Lifecycle Automation

Category: IAM

Subcategories: Full employee lifecycle

Description:

Slack-triggered workflows that capture new-hire, role-change, and departure events and notify the right internal channel, forming the front door of AlphaSense's identity lifecycle process.

Business problem solved:

Ensures IT/security are reliably notified the moment an employee joins, changes role, or leaves — the trigger point for provisioning, access changes, and de-provisioning.

Integrations: Slack

Playbooks

Playbook Executions Role
New Hire 0 Captures new-hire submissions and notifies via Slack
Role Change 0 Captures role-change submissions and notifies via Slack
Submit Departure 0 Captures departure submissions and notifies via Slack

Use Case 8 — Linear ↔ Notion Project & Roadmap Sync

Category: Other

Subcategories: DevOps & release automation

Description:

Keeps Notion project and roadmap databases synchronized with Linear issues, initiatives, driver projects, and deprecation tracking — covering both webhook-driven and scheduled full syncs — so product and engineering teams don't maintain the same data in two tools by hand.

Business problem solved:

Removes the manual, error-prone work of duplicating Linear status into Notion for stakeholders who live in Notion.

Integrations: Linear · Notion

Playbooks

Playbook Executions Role
Get Notion User ID from Email 11,599 Utility — resolves a Notion user ID from an email address, called by the sync workflows below
Project updates testing 1,936 Triggered on new Linear project updates — writes summaries into Notion
Linear to Notion Database 780 Webhook-triggered Linear issue → Notion database sync
Linear Driver Projects to Notion Sync 40 Scheduled full sync of Linear driver projects to Notion
Linear AS Features/Products/Components Deprecation Projects to Notion Sync 40 Scheduled sync of deprecation-tracking projects to Notion
Get Notion User ID from Email copy 0 Unused duplicate of the user-ID lookup utility
Get Notion User ID from Email copy copy 0 Unused duplicate of the user-ID lookup utility
Clean up Notion Project Database 0 On-demand cleanup of stale Notion project records
Project updater 0 Triggered on new Notion pages — updates the linked Linear project
Project updater copy 0 On-demand variant of the project updater

Use Case 9 — AI-Assisted PRD-to-Ticket Creation

Category: Other

Subcategories: DevOps & release automation

Description:

Uses Anthropic's Claude to read a submitted PRD and convert it directly into structured Linear tickets — one instance for the product team, one for the content team.

Business problem solved:

Cuts the manual effort of translating a requirements doc into properly-structured engineering/content tickets.

Integrations: Anthropic (Claude) · Linear

Playbooks

Playbook Executions Role
PRD to Linear with Claude 19 Converts a submitted PRD into Linear tickets using Claude
PRD to Linear with Claude: CONTENT 1 Content-team variant of the PRD-to-Linear pipeline

Use Case 10 — Feature/Content Submission Review & PM Notification

Category: Other

Subcategories: DevOps & release automation · IT helpdesk & ticket routing

Description:

Handles the review lifecycle for feature/content flag requests: a Salesforce AV-flag review creates Linear tickets and notifies the PM, submitters get a Slack DM when their request needs more info or is rejected, and any Linear ticket tagged with the "flag request" label triggers a Slack notification to the team.

Business problem solved:

Keeps PMs and requesters informed at each stage of a feature request's lifecycle without manual status updates.

Integrations: Slack · Linear · Salesforce

Playbooks

Playbook Executions Role
Flag Requests Tickets notifications 221 Notifies Slack when a Linear ticket is tagged as a flag request
Send DM to PM on new submission 7 DMs the owning PM when a new submission arrives
Notion SF AV Flag Review: Create Linear tickets and notify PM 6 Converts a Salesforce AV-flag review into Linear tickets and notifies the PM
Rejected 1 Sends a rejection notification via Slack
Send DM to PM requesting more info 0 DMs the PM when a submission needs more information

Use Case 11 — Meeting & Leadership Cadence Reminders

Category: Other

Subcategories: SaaS / IT administration

Description:

Checks Google Calendar on a schedule and sends Slack reminders ahead of recurring GTM leadership meetings.

Business problem solved:

Reduces missed or under-prepared leadership meetings without anyone having to manually track the calendar.

Integrations: Google Calendar · Slack

Playbooks

Playbook Executions Role
GTM Leadership Pulse: Meeting Reminders 40 Scheduled Google Calendar check with Slack reminder for leadership meetings

Use Case 12 — Email-to-Spreadsheet Data Capture

Category: Other

Subcategories: SaaS / IT administration

Description:

Watches Gmail for new messages, extracts message data, and appends structured rows to a Google Sheet for downstream reporting.

Business problem solved:

Creates a queryable log of inbound email activity without manual data entry into spreadsheets.

Integrations: Gmail · Google Sheets · Google Workspace

Playbooks

Playbook Executions Role
List Gmail Messages and Send Results via Email 2,170 Triggered on new Gmail messages — extracts data and logs to Google Sheets
New Workflow 1 0 On-demand variant of the Gmail-to-Sheets capture

Use Case 13 — Helpdesk Ticket Sync (Zendesk → Notion)

Category: Other

Subcategories: IT helpdesk & ticket routing

Description:

Triggered on new Zendesk tickets, looks up ticket/organization context and writes a structured entry into a Notion database.

Business problem solved:

Bridges customer-support ticketing (Zendesk) with internal knowledge management (Notion) without manual copy-paste.

Integrations: Zendesk · Notion

Playbooks

Playbook Executions Role
New Workflow 1 0 New Zendesk ticket → Notion database entry
New Workflow 1 (greig.fields@alpha-sense.com) 0 User-specific variant of the Zendesk → Notion sync

Use Case 14 — Slack Channel Concierge — Deal Desk & Billing Routing

Category: Other

Subcategories: Financial & fraud operations

Description:

Listens for new (non-thread-reply) messages posted in the Deal Desk and Billing Slack channels and triages them automatically, reducing manual channel-monitoring by the finance/deal-desk team.

Business problem solved:

Ensures the first message in a deal-desk or billing question thread is triaged immediately instead of waiting on a human to notice it.

Integrations: Slack

Playbooks

Playbook Executions Role
Deal Desk Slack Channel 159 Triages new top-level messages in the Deal Desk Slack channel
New Workflow 20 Same top-level-message triage pattern, deployed to another channel
Billing Slack Channel- Test 24 Test-environment version of the billing channel triage
Billing Slack Channel- Prod 5 Production billing-channel triage
Test Slack 1 Early-stage test workflow — normalizes an incoming Slack event and creates a case; prototype, shares this workspace with the triage flows above

Use Case 15 — Sales Bookings & Performance Tracking

Category: Other

Subcategories: Customer registry & FinOps auto

Description:

Monitors Gmail for booking-confirmation emails and logs each one to a tracking table, then publishes a Slack leaderboard of booking/call activity.

Business problem solved:

Removes manual tracking of sales bookings and gives the team a self-updating leaderboard that drives accountability.

Integrations: Gmail · Slack

Playbooks

Playbook Executions Role
Collect Bookings 340 Monitors Gmail for booking confirmations and logs to a tracking table
Print Call Leaderboard 28 Publishes a Slack leaderboard of booking/call activity

Use Case 16 — Off-Hours / On-Call Escalation Notifications

Category: Other

Subcategories: IT/OT & network infra monitoring

Description:

Webhook-triggered, per-environment (production/staging/development) off-hours alerting that formats the incoming event and interactively pages the on-call responder via Slack.

Business problem solved:

Ensures off-hours incidents reach the right on-call responder within seconds, without a manual escalation chain, and keeps environments separated so prod incidents aren't lost in dev/staging noise.

Integrations: Slack · HTTP (environment webhooks)

Playbooks

Playbook Executions Role
Off Hours Notification - Production 27 Off-hours alert routing for the production environment
Off Hours Notification - Development 0 Off-hours alert routing for the development environment
Off Hours Notification - Staging 0 Off-hours alert routing for the staging environment

Use Case 17 — HR & Culture Automation

Category: GRC

Subcategories: AI / HR compliance automation

Description:

A set of people-operations automations: hiring-manager feedback surveys are emailed automatically, Solutions-Architect skills feedback captured in Slack is logged to Notion, and a Slack "+1" slash-command lets employees log peer recognition (with an Anthropic-assisted lookup and Salesforce context) straight into Notion.

Business problem solved:

Automates recurring HR/enablement admin — feedback collection and peer recognition — that would otherwise rely on someone remembering to send a form or copy notes into a shared doc.

Integrations: Gmail · Slack · Notion · Salesforce · Anthropic (Claude)

Playbooks

Playbook Executions Role
SA Skills Feedback - Slack to Notion 719 Logs SA skills feedback (via Slack emoji reaction) to Notion
HM Survey Trigger 228 Sends hiring-manager feedback survey emails
New Workflow 12 Slack-triggered — logs an entry to Notion
+1 0 Slack slash-command for peer recognition, logged to Notion

Use Case 18 — Data Protection Complaint Intake

Category: GRC

Subcategories: DSAR & privacy automation

Description:

Triggered when a Google Forms data-protection complaint form is submitted, this sends an email alert so the privacy team can respond within required timelines.

Business problem solved:

Ensures data-protection/DSAR-adjacent complaints reach the privacy team immediately rather than sitting in a forms inbox.

Integrations: Google Forms

Playbooks

Playbook Executions Role
Data Protection Complaint Form Alert 0 Emails the privacy team on a new complaint-form submission

Use Case 19 — License & Subscription Management Notifications

Category: Other

Subcategories: SaaS / IT administration

Description:

Sends proactive email alerts ahead of software license expirations.

Business problem solved:

Prevents lapsed licenses/subscriptions by giving stakeholders advance warning instead of discovering the lapse after the fact.

Integrations: None captured (email/scripting)

Playbooks

Playbook Executions Role
Send License Expiration Emails 12 Emails stakeholders ahead of software license expirations

Use Case 20 — Engineering Changelog Broadcasting

Category: Other

Subcategories: DevOps & release automation

Description:

Triggered on new GitLab merges, posts a formatted changelog entry to Slack.

Business problem solved:

Keeps engineering stakeholders informed of what shipped without anyone manually summarizing merges.

Integrations: GitLab · Slack

Playbooks

Playbook Executions Role
DFS Changelog 0 Posts a GitLab-merge changelog entry to Slack

Key Observations

Strengths

Real production impact in endpoint containment. Between the scheduled CrowdStrike - Auto Isolate job (19,200 executions) and the new webhook-triggered CrowdStrike - Auto Isolate - Webhook (7,134 executions), AlphaSense automated 26,334 endpoint isolations in 12 months — by far the single highest-value security automation in the tenant, now running both on a schedule and in real time off live detections.

Deep engineering/PM tooling integration. The Linear ↔ Notion sync pipelines and PRD-to-Linear AI pipeline together processed over 14,400 executions, showing Blink is embedded in AlphaSense's daily product and engineering workflow, not just security.

A fully architected, production-ready SOC platform. The 51-playbook SOAR framework (Use Case 1) covers observable extraction, enrichment across 8+ security tools, deduplication, and automated phishing/malware response. It is structurally complete and simply needs a live alert feed to go into production.

Cloud security ownership routing is built and ready. The Wiz + FireHydrant + Port.io integration (Use Case 2) is configured to automatically route cloud threats to the correct owning team — a capability many security teams still do by hand.

AI is already in the workflow, not just a pilot. The PRD-to-Linear (Claude) and "+1" recognition workflows show AlphaSense using Claude for real, recurring business tasks.

Gaps & Opportunities

Core SOC pipeline shows zero executions. Process Alert and its enrichment/response chain (Use Case 1) haven't run in the last 12 months. Activating the live alert feed would immediately convert this built platform into measurable analyst time savings.

Cloud threat triage (Wiz) is mostly idle. Outside of the 144-execution owner-coordination flow, the remaining 7 Wiz playbooks in Use Case 2 show 0 executions — the alert-ingestion and inventory side of the pipeline appears disconnected from a live feed.

No dedicated vulnerability-scanning or CVE workflows. Given AlphaSense's CrowdStrike/Wiz/Chronicle footprint, there's no playbook for vuln scan ingestion, CVE lookup/remediation, or scan-lifecycle automation — the closest analog (Linear Ticket Create) is a Jira poll-sync, not a scan pipeline.

Several duplicate/unlabeled workflows increase maintenance overhead. "Get Notion User ID from Email" exists in three copies (Use Case 8), and multiple playbooks are still named "New Workflow" or "New Workflow 1" with no distinguishing name (Use Cases 2, 12, 13, 14, 17) — consolidating or renaming these would reduce confusion about which is canonical.

A polling-based workflow inflates raw execution counts. Linear Ticket Create shows 21,523 executions, but it polls Jira every 5 minutes regardless of whether a new issue exists — the number reflects poll cycles, not tickets created, and should not be read as a business-volume metric as-is.

One unused tutorial workflow. "Getting Started - Hello World" (workspace 445403f0) is Blink's onboarding sample and has never been run — expected for a sandbox, but worth cleaning up if that workspace is otherwise inactive.

Integration Ecosystem

Domain Integrations in Use
Security CrowdStrike · VirusTotal · AbuseIPDB · URLScan · Whois · Wiz · FireHydrant · Port.io · Google Chronicle/SecOps · Artemis Security
Identity Okta · Microsoft Entra ID (Active Directory) · Google Workspace · GitHub · Slack
Productivity & DevOps Linear · Notion · Jira · GitLab · Google Calendar · Google Sheets · Gmail
AI Anthropic (Claude)
Communication Slack · Microsoft Outlook
Business Systems Salesforce · Zendesk · Google Forms
Infrastructure HTTP webhooks · Bash · Python
E New Integrations (detail) 7 added in last 30d

New Integrations Added - Last 30 Days

7 new connections
TenantIntegrationConnection NameAdded
alphasense 2lo_auth my_http_custom_2_legged_oauth_2_0_authentication_connection 2026-09-09
alphasense google-drive my_google_drive_connection 2026-09-09
alphasense slack my_slack_connection_1 2026-09-09
alphasense google-sheets my_google_sheets_connection 2026-09-02
alphasense zendesk revops_zendesk_connection 2026-08-31
alphasense gmail my_gmail_connection 2026-08-31
alphasense gmail my_gmail_connection 2026-08-27