Blink Security Automation — Confidential

Altana — Customer Success Report

Generated 2026-09-10 | altana-value-report.md
2026-09-10Report Date
97Total Playbooks
10Unique Workflows (12m)
20,808Actions Automated (12m)
$5,352Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

97
Total playbooks built
all non-deleted workflows
68
Active playbooks
currently enabled
10
Unique workflows executed (12m)
distinct workflows that ran
20,808
Actions automated (12m)
completed action steps
115.6h
Hours saved (12m)
@ 20s per action
$5,352
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 8 total
3
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 11 new employees onboarded end-to-end — from Greenhouse hire event through BambooHR record creation, document upload, and IT ticket generation - 25 endpoint migrations completed — coordinating Okta identity, Jamf device management, and access provisioning across user endpoints - 285 AI triage insight updates posted — event-driven webhook automation routing and posting AI-generated triage insights from Abstract

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Employee Onboarding
  • 11New employees onboarded end-to-end
1.4%
3
2 active
IT Endpoint Migration
  • 25Endpoint migrations completed
2.2%
1
1 active
SOC Alert Ingestion & Case Processing
  • 285AI triage insight updates posted
40.1%
12
12 active
Alert Enrichment & IOC Lookup0 executions
0.0%
30
30 active
Incident Response & EDR0 executions
0.0%
6
6 active
Case Management Utilities0 executions
0.0%
9
9 active
Development / Test0 executions
0.0%
2
0 active
Credential & Vault Management66 executions
4.6%
4
4 active
Total689 executions100%
67
64 active

Use Case Growth Over Time

80 unique playbooks  |  8 operational use cases  |  1,426 total executions (12m)  |  2025-09 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

Employee Onboarding
Anthropic BambooHR Greenhouse
Development / Test
Jamf Okta Slack Jira Email Splunk VirusTotal Gemini OpenAI Google Sheets FedEx Gmail SentinelOne IPinfo
IT Endpoint Migration
Okta Jamf
SOC Alert Ingestion & Case Processing
CrowdStrike Email Linear
Incident Response & EDR
Microsoft Outlook CrowdStrike
Alert Enrichment & IOC Lookup
CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan GitHub Slack
Case Management Utilities
Email
Credential & Vault Management
1Password

04Key Observations

✓  Strengths

Strengths

Active IAM and endpoint automation: The employee onboarding and endpoint migration workflows are live, integrated across Greenhouse, BambooHR, Okta, and Jamf, and leveraging Claude AI for data extraction — a strong indicator of mature, production-grade automation in the People Ops and IT domains.

Well-structured SOC platform foundation: The security workspace contains a complete, architecturally sound SOAR platform: alert ingestion from six sources, a unified case processing pipeline with observable extraction and deduplication, 30 enrichment subflows covering all major observable types, incident response playbooks for the two highest-volume alert categories, and a full suite of case management utilities. This represents significant build investment.

Broad integration coverage for enrichment: The enrichment library covers identity (Okta, Google Workspace, Entra ID, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), and endpoint (CrowdStrike) — a well-rounded IOC context stack.

AI-augmented onboarding: Use of Anthropic Claude for address component extraction and work location determination in the NHO flow demonstrates early adoption of AI-native automation beyond simple API chaining.

SOC pipeline receiving live events: The AI triage webhook integration (285 executions) shows the SOC pipeline is actively ingesting events, demonstrating that the platform architecture is operational and capable of handling production-scale alert volumes.

###

△  Gaps & Growth Opportunities

Gaps

EXAMPLE ingestion sources not yet connected: The six vendor-specific ingest workflows (Wiz, Defender, CrowdStrike, Falcon LogScale, Azure, CloudTrail) remain named "EXAMPLE" with zero executions. Connecting these to live alert feeds would immediately expand automated coverage across the full security stack and compound value from the existing enrichment and response library.

No cloud security or GRC coverage: The entire Cloud Security, Vulnerability Management, and GRC categories have zero playbooks. These are common expansion areas for security teams that have established a SOC foundation.

Phishing response incomplete: The phishing response subflow checks KnowBe4 campaign headers but does not proceed to remediation steps (e.g., pulling the email from other inboxes, blocking the sender, notifying affected users). The malware response subflow similarly routes on remediation status but has no downstream containment logic beyond CrowdStrike isolation.

Duplicate utility patterns: Several enrichment areas have both a "Get User Information Using X" and an "Enrich - Username - X" variant with overlapping functionality. Consolidating these would reduce maintenance surface.

Integration Ecosystem

Domain Integrations in Use
Identity & MDM Okta, Microsoft Entra ID, Google Workspace, Jamf, Entitle
HR & Recruiting BambooHR, Greenhouse
Credentials & Secrets 1Password
EDR & Threat Intel CrowdStrike (detection + RTR), VirusTotal, AbuseIPDB, URLScan
Cloud & SIEM Wiz, Microsoft Defender for Cloud Apps, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail
Collaboration Slack, Microsoft Outlook
Developer GitHub
AI Anthropic (Claude)
Core Platform Blink Case Management, Blink Tables
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 3 tasks (12m)

AI Agents

Active Agents
1
of 8 total
Tasks Executed (12m)
3
0 in last 30d
Data Usage (12m)
72,175
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Expel incident Analyzer InfoSec 3 0 72,175
2 Agent Blink Case Management Example 0 0 0
3 Agent Blink People Privileged 0 0 0
4 Agent Blink Case Management 0 0 0
5 Agent Blink InfoSec 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
InfoSec3
Case Management Example0
People Privileged0
Case Management0
Accounting0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 8 use cases | 1,426 executions (12m)

Business KPIs

Metric Count Playbook
New employees onboarded end-to-end 11 Kick off NHO
Endpoint migrations completed 25 Enable Iru Migration
AI triage insight updates posted 285 Post AI Triage Abstract Insight Updates
In the last 12 months, Blink automated: - 11 new employees onboarded end-to-end — from Greenhouse hire event through BambooHR record creation, document upload, and IT ticket generation - 25 endpoint migrations completed — coordinating Okta identity, Jamf device management, and access provisioning across user endpoints - 285 AI triage insight updates posted — event-driven webhook automation routing and posting AI-generated triage insights from Abstract

Use Case Summary

# Use Case Category Playbooks Active
1 Employee Onboarding IAM 2 2
2 IT Endpoint Migration Other 1 1
3 SOC Alert Ingestion & Case Processing SOC 12 1
4 Alert Enrichment & IOC Lookup SOC 30 0
5 Incident Response & EDR SOC 6 0
6 Case Management Utilities SOC 9 0
7 Development / Test Other 4 0
8 Credential & Vault Management IAM 4 4
Total 68 8

_Active = at least one execution in the last 12 months_

Use Cases

1. Employee Onboarding

Description: Automates the complete new hire onboarding journey from offer acceptance to system provisioning. A Greenhouse hire event triggers the full workflow, which uses Claude AI to parse structured address and location data, creates the employee record in BambooHR, sets employment status and job leveling, uploads the offer packet and resume, and creates an IT provisioning ticket.

Business problem: New hire onboarding requires coordinating across recruiting, HRIS, and IT systems — a manual process prone to delays and data entry errors that degrades day-one employee experience.

Integrations: Greenhouse, BambooHR, Anthropic (Claude), HTTP (IT ticketing), Blink Tables

Playbook Executions Role
Kick off NHO 11 Trigger — fires on Greenhouse hire_candidate webhook; orchestrates the full NHO flow
Create new employee 11 Subflow — AI address parsing, BambooHR record creation, document uploads, IT ticket creation

2. IT Endpoint Migration

Description: Automates the Iru endpoint migration process for individual users, coordinating identity verification in Okta, device lookup in Jamf, mobile device enrollment checks, managed Chrome provisioning, and migration enablement across enrolled computers.

Business problem: Endpoint migration projects require multi-system coordination (identity, MDM, access) that is time-consuming to execute manually at scale and prone to missed steps.

Integrations: Okta, Jamf, Entitle (via HTTP)

Playbook Executions Role
Enable Iru Migration 25 On-demand — validates identity, enumerates devices, provisions managed Chrome, enables migration on all Jamf-enrolled computers

3. SOC Alert Ingestion & Case Processing

Description: A full SOAR-style alert processing pipeline. Ingestion playbooks pull alerts from six security tools into Blink Case Management; the core Process Alert workflow handles observable extraction, case deduplication, enrichment orchestration, and automated response routing. Simulation playbooks support analyst training and pipeline testing. A live event-driven webhook integration posts AI-generated triage insights from Abstract into the pipeline.

Business problem: Security teams receive high volumes of alerts from disparate tools that must be triaged, correlated, and enriched consistently — a manual process that creates analyst fatigue and slow response times.

Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail, Blink Case Management, Abstract (webhook)

Playbook Executions Role
Post AI Triage Abstract Insight Updates 285 Ingest — event-driven; receives AI triage insights from Abstract via custom webhook, checks source, and routes updates into the pipeline
Process Alert 0 Core pipeline — event-driven; extracts observables, deduplicates cases, triggers enrichment, routes to response
EXAMPLE Ingest - Wiz 0 Ingest — Wiz issue polling → case creation
EXAMPLE Ingest - Microsoft Defender For Cloud Apps 0 Ingest — Defender for Cloud Apps alert polling → case creation
EXAMPLE Ingest - CrowdStrike Falcon LogScale -- 0 Ingest — Falcon LogScale webhook → case creation
EXAMPLE Ingest - CrowdStrike 0 Ingest — CrowdStrike webhook with alert detail enrichment → case creation
EXAMPLE Ingest - Azure 0 Ingest — Azure Monitor event polling → case creation
EXAMPLE Ingest - AWS CloudTrail 0 Ingest — AWS CloudTrail event polling → case creation
Recovery - Handle Unprocessed Alerts 0 Recovery — reprocesses alerts that failed the main pipeline
Subflow - Missing Alert Template Notification 0 Subflow — notifies on alerts that lack an extraction template
Simulate Multiple Alerts from Different Sources 0 Testing — injects synthetic alerts from multiple vendors for pipeline validation
Simulate Crowdstrike Alert 0 Testing — injects a random CrowdStrike example alert for pipeline testing

4. Alert Enrichment & IOC Lookup

Description: A comprehensive library of enrichment subflows that automatically populate observable context across identities, endpoints, IPs, URLs, and file hashes from multiple threat intelligence and identity sources. A central router dispatches observables to the appropriate enrichment subflow based on type.

Business problem: Analysts manually looking up IOC context across CrowdStrike, Okta, VirusTotal, and other tools during triage accounts for a large share of alert handling time; automated enrichment reduces time-to-context significantly.

Integrations: CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, AbuseIPDB, VirusTotal, URLScan, Slack, GitHub, Bash (whois, dig)

Playbook Executions Role
Subflow - Enrich Observables - Main Router 0 Router — dispatches observables to type-specific enrichment subflows
Utility - Update Enrichment 0 Wrapper — triggers the enrichment router
Recovery - Enrich Non-Enriched Observables 0 Recovery — re-enriches observables that were not enriched during alert processing
Subflow - Update Enrichment Data 0 Subflow — writes enrichment verdict and data back to a case observable
Enrich - Agent ID - Crowdstrike 0 Enrich — resolves CrowdStrike agent ID to device details
Enrich - Username or Email - Okta 0 Enrich — looks up user profile and status in Okta
Get User Information Using Okta 0 Utility — standalone Okta user lookup
Enrich - Username or Email - Google Workspace 0 Enrich — looks up user in Google Workspace
Get User Information Using Google Workspace 0 Utility — standalone Google Workspace user lookup
Enrich - Username or Email - Microsoft Entra ID 0 Enrich — looks up user and risky user status in Entra ID
Get User Information Using Microsoft Entra ID 0 Utility — standalone Entra ID user lookup with risk status
Enrich - Username - Github 0 Enrich — looks up GitHub user profile
Get User Information Using Github 0 Utility — standalone GitHub user lookup
Enrich - Email Address - Slack 0 Enrich — resolves email to Slack user profile
Get User Information on Email Address Using Slack 0 Utility — standalone Slack user lookup by email
Okta Search for User Activity 0 Enrich — retrieves Okta activity logs for a user over a date range
Enrich - IP - IPDB 0 Enrich — AbuseIPDB reputation check for IP observables
Enrich - IP - VT 0 Enrich — VirusTotal IP reputation and verdict
Enrich - IP or Domain - Whois 0 Enrich — Whois lookup for IP/domain observables
Enrich IP or Domain Using Whois 0 Utility — standalone Whois lookup
Enrich - URL - VT 0 Enrich — VirusTotal URL scan and verdict
Enrich - URL - URLScan 0 Enrich — URLScan submission and verdict
Analyze URL with URLScan 0 Utility — standalone URLScan analysis
Secure URL Screenshot Capture 0 Enrich — captures a screenshot of a URL for visual inspection
Enrich - Hash - VT 0 Enrich — VirusTotal hash lookup with configurable verdict threshold
Enrich - Hash - Crowdstrike 0 Enrich — CrowdStrike endpoint search by hash
Get Hash Info Using Crowdstrike 0 Utility — standalone CrowdStrike indicator lookup by hash
Get Hash Info Using VirusTotal 0 Utility — standalone VirusTotal hash search
Get End of Life Date for a Product 0 Enrich — retrieves EOL/EOS dates for software products and versions
Run Dig Command 0 Utility — DNS dig lookup for domains

5. Incident Response & EDR

Description: Automated response playbooks for the two primary incident types — phishing and malware — plus a main response router that dispatches based on case type. CrowdStrike RTR playbooks enable analysts to execute remote commands or quarantine/un-quarantine endpoints directly from cases.

Business problem: Manual incident response workflows are slow and inconsistent; automated triage and containment reduce dwell time and free analysts for higher-value investigation.

Integrations: Microsoft Outlook, CrowdStrike (RTR), Blink Case Management

Playbook Executions Role
Subflow - Response - Main Router 0 Router — dispatches cases to phishing or malware response subflow based on case type
Response Subflow - Phishing 0 Response — retrieves original email, checks for KnowBe4 campaign headers, routes accordingly
Response Subflow - Malware 0 Response — evaluates malware remediation status and routes to appropriate action
Manage Endpoint Quarantine Status in Crowdstrike 0 Containment — isolates or lifts isolation of a CrowdStrike-managed device
CrowdStrike RTR to a Single Host 0 Containment — executes RTR command against a single CrowdStrike-managed host
CrowdStrike RTR to a Batch of Hosts 0 Containment — executes RTR command across a batch of CrowdStrike-managed hosts

6. Case Management Utilities

Description: A set of utility and maintenance playbooks that keep the case management environment healthy — closing stale cases, managing observable-to-alert relationships, finding similar cases based on shared observables, and providing error notification infrastructure for the broader SOC pipeline.

Business problem: Case management systems accumulate stale and orphaned data over time; automated hygiene workflows keep the environment accurate and actionable without manual curation.

Integrations: Blink Case Management, Email

Playbook Executions Role
Utility - Close Stale Cases 0 Utility — closes cases open with no update for over a month
Utility - Find Similar Cases Based on Observables 0 Utility — calculates similarity score between cases based on shared observables
Utility - Set Or Update Observable Relation 0 Utility — creates or updates the relation between an observable and an alert
Utility - Delete Observable Relation 0 Utility — removes a relation between an observable and an alert
Utility - List Observable Alert Relations 0 Utility — lists all alerts related to a given observable
Utility - List Alert Observable Relations 0 Utility — lists all observables related to a given alert
Table Action - Validate Observables Extraction Template 0 Utility — validates that an alert matches an existing extraction template
Error Handling - Send Error Notification Email 0 Infrastructure — sends error notification emails for pipeline failures
USE WITH CARE - Reset Case Management Environment 0 Maintenance — purges all cases, alerts, observables, attachments, and tasks (destructive)

7. Development / Test

Description: Empty or test workflows with no production logic. Includes stub workflows and a working directory test automation.

Playbook Executions Notes
New Workflow 0 Empty stub
New Workflow 1 0 Empty stub
New Workflow 0 In-development webhook receiver (Abstract Insight trigger)
Working Directory Testing 0 Platform test — Python and Bash in a working directory context

8. Credential & Vault Management

Description: Automates 1Password vault and group lifecycle management for IT operations. On-demand playbooks allow IT administrators to add or remove users from 1Password groups and manage vault access permissions, while utility workflows enumerate existing vaults and their assigned managers for access review.

Business problem: Managing access to shared password vaults and security groups in 1Password manually creates delays and risks out-of-sync permissions as team membership changes; automated workflows ensure consistent provisioning and reduce IT overhead.

Integrations: 1Password

Playbook Executions Role
Manage 1Password Groups 19 On-demand — adds or removes a user from a specified 1Password group
List 1Password Vaults 18 Utility — enumerates all 1Password vaults in the tenant
Manage 1Password Vaults 1 On-demand — adds or removes user access permissions on a specified 1Password vault
List 1Password Vault Managers 1 Utility — lists all managers assigned to a specified 1Password vault

Key Observations

Strengths

Active IAM and endpoint automation: The employee onboarding and endpoint migration workflows are live, integrated across Greenhouse, BambooHR, Okta, and Jamf, and leveraging Claude AI for data extraction — a strong indicator of mature, production-grade automation in the People Ops and IT domains.

Well-structured SOC platform foundation: The security workspace contains a complete, architecturally sound SOAR platform: alert ingestion from six sources, a unified case processing pipeline with observable extraction and deduplication, 30 enrichment subflows covering all major observable types, incident response playbooks for the two highest-volume alert categories, and a full suite of case management utilities. This represents significant build investment.

Broad integration coverage for enrichment: The enrichment library covers identity (Okta, Google Workspace, Entra ID, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), and endpoint (CrowdStrike) — a well-rounded IOC context stack.

AI-augmented onboarding: Use of Anthropic Claude for address component extraction and work location determination in the NHO flow demonstrates early adoption of AI-native automation beyond simple API chaining.

SOC pipeline receiving live events: The AI triage webhook integration (285 executions) shows the SOC pipeline is actively ingesting events, demonstrating that the platform architecture is operational and capable of handling production-scale alert volumes.

Gaps

EXAMPLE ingestion sources not yet connected: The six vendor-specific ingest workflows (Wiz, Defender, CrowdStrike, Falcon LogScale, Azure, CloudTrail) remain named "EXAMPLE" with zero executions. Connecting these to live alert feeds would immediately expand automated coverage across the full security stack and compound value from the existing enrichment and response library.

No cloud security or GRC coverage: The entire Cloud Security, Vulnerability Management, and GRC categories have zero playbooks. These are common expansion areas for security teams that have established a SOC foundation.

Phishing response incomplete: The phishing response subflow checks KnowBe4 campaign headers but does not proceed to remediation steps (e.g., pulling the email from other inboxes, blocking the sender, notifying affected users). The malware response subflow similarly routes on remediation status but has no downstream containment logic beyond CrowdStrike isolation.

Duplicate utility patterns: Several enrichment areas have both a "Get User Information Using X" and an "Enrich - Username - X" variant with overlapping functionality. Consolidating these would reduce maintenance surface.

Integration Ecosystem

Domain Integrations in Use
Identity & MDM Okta, Microsoft Entra ID, Google Workspace, Jamf, Entitle
HR & Recruiting BambooHR, Greenhouse
Credentials & Secrets 1Password
EDR & Threat Intel CrowdStrike (detection + RTR), VirusTotal, AbuseIPDB, URLScan
Cloud & SIEM Wiz, Microsoft Defender for Cloud Apps, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail
Collaboration Slack, Microsoft Outlook
Developer GitHub
AI Anthropic (Claude)
Core Platform Blink Case Management, Blink Tables
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.