01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Employee Onboarding |
| 1.4% | 3 2 active |
| IT Endpoint Migration |
| 2.2% | 1 1 active |
| SOC Alert Ingestion & Case Processing |
| 40.1% | 12 12 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 30 30 active |
| Incident Response & EDR | 0 executions | 0.0% | 6 6 active |
| Case Management Utilities | 0 executions | 0.0% | 9 9 active |
| Development / Test | 0 executions | 0.0% | 2 0 active |
| Credential & Vault Management | 66 executions | 4.6% | 4 4 active |
| Total | 689 executions | 100% | 67 64 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Active IAM and endpoint automation: The employee onboarding and endpoint migration workflows are live, integrated across Greenhouse, BambooHR, Okta, and Jamf, and leveraging Claude AI for data extraction — a strong indicator of mature, production-grade automation in the People Ops and IT domains.
Well-structured SOC platform foundation: The security workspace contains a complete, architecturally sound SOAR platform: alert ingestion from six sources, a unified case processing pipeline with observable extraction and deduplication, 30 enrichment subflows covering all major observable types, incident response playbooks for the two highest-volume alert categories, and a full suite of case management utilities. This represents significant build investment.
Broad integration coverage for enrichment: The enrichment library covers identity (Okta, Google Workspace, Entra ID, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), and endpoint (CrowdStrike) — a well-rounded IOC context stack.
AI-augmented onboarding: Use of Anthropic Claude for address component extraction and work location determination in the NHO flow demonstrates early adoption of AI-native automation beyond simple API chaining.
SOC pipeline receiving live events: The AI triage webhook integration (285 executions) shows the SOC pipeline is actively ingesting events, demonstrating that the platform architecture is operational and capable of handling production-scale alert volumes.
###
Gaps
EXAMPLE ingestion sources not yet connected: The six vendor-specific ingest workflows (Wiz, Defender, CrowdStrike, Falcon LogScale, Azure, CloudTrail) remain named "EXAMPLE" with zero executions. Connecting these to live alert feeds would immediately expand automated coverage across the full security stack and compound value from the existing enrichment and response library.
No cloud security or GRC coverage: The entire Cloud Security, Vulnerability Management, and GRC categories have zero playbooks. These are common expansion areas for security teams that have established a SOC foundation.
Phishing response incomplete: The phishing response subflow checks KnowBe4 campaign headers but does not proceed to remediation steps (e.g., pulling the email from other inboxes, blocking the sender, notifying affected users). The malware response subflow similarly routes on remediation status but has no downstream containment logic beyond CrowdStrike isolation.
Duplicate utility patterns: Several enrichment areas have both a "Get User Information Using X" and an "Enrich - Username - X" variant with overlapping functionality. Consolidating these would reduce maintenance surface.
Integration Ecosystem
| Domain | Integrations in Use |
|---|---|
| Identity & MDM | Okta, Microsoft Entra ID, Google Workspace, Jamf, Entitle |
| HR & Recruiting | BambooHR, Greenhouse |
| Credentials & Secrets | 1Password |
| EDR & Threat Intel | CrowdStrike (detection + RTR), VirusTotal, AbuseIPDB, URLScan |
| Cloud & SIEM | Wiz, Microsoft Defender for Cloud Apps, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail |
| Collaboration | Slack, Microsoft Outlook |
| Developer | GitHub |
| AI | Anthropic (Claude) |
| Core Platform | Blink Case Management, Blink Tables |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 3 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Expel incident Analyzer | InfoSec | 3 | 0 | 72,175 |
| 2 | Agent Blink | Case Management Example | 0 | 0 | 0 |
| 3 | Agent Blink | People Privileged | 0 | 0 | 0 |
| 4 | Agent Blink | Case Management | 0 | 0 | 0 |
| 5 | Agent Blink | InfoSec | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| InfoSec | 3 |
| Case Management Example | 0 |
| People Privileged | 0 |
| Case Management | 0 |
| Accounting | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 8 use cases | 1,426 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| New employees onboarded end-to-end | 11 | Kick off NHO |
| Endpoint migrations completed | 25 | Enable Iru Migration |
| AI triage insight updates posted | 285 | Post AI Triage Abstract Insight Updates |
Use Case Summary
| # | Use Case | Category | Playbooks | Active |
|---|---|---|---|---|
| 1 | Employee Onboarding | IAM | 2 | 2 |
| 2 | IT Endpoint Migration | Other | 1 | 1 |
| 3 | SOC Alert Ingestion & Case Processing | SOC | 12 | 1 |
| 4 | Alert Enrichment & IOC Lookup | SOC | 30 | 0 |
| 5 | Incident Response & EDR | SOC | 6 | 0 |
| 6 | Case Management Utilities | SOC | 9 | 0 |
| 7 | Development / Test | Other | 4 | 0 |
| 8 | Credential & Vault Management | IAM | 4 | 4 |
| Total | 68 | 8 |
_Active = at least one execution in the last 12 months_
Use Cases
1. Employee Onboarding
Description: Automates the complete new hire onboarding journey from offer acceptance to system provisioning. A Greenhouse hire event triggers the full workflow, which uses Claude AI to parse structured address and location data, creates the employee record in BambooHR, sets employment status and job leveling, uploads the offer packet and resume, and creates an IT provisioning ticket.
Business problem: New hire onboarding requires coordinating across recruiting, HRIS, and IT systems — a manual process prone to delays and data entry errors that degrades day-one employee experience.
Integrations: Greenhouse, BambooHR, Anthropic (Claude), HTTP (IT ticketing), Blink Tables
| Playbook | Executions | Role |
|---|---|---|
| Kick off NHO | 11 | Trigger — fires on Greenhouse hire_candidate webhook; orchestrates the full NHO flow |
| Create new employee | 11 | Subflow — AI address parsing, BambooHR record creation, document uploads, IT ticket creation |
2. IT Endpoint Migration
Description: Automates the Iru endpoint migration process for individual users, coordinating identity verification in Okta, device lookup in Jamf, mobile device enrollment checks, managed Chrome provisioning, and migration enablement across enrolled computers.
Business problem: Endpoint migration projects require multi-system coordination (identity, MDM, access) that is time-consuming to execute manually at scale and prone to missed steps.
Integrations: Okta, Jamf, Entitle (via HTTP)
| Playbook | Executions | Role |
|---|---|---|
| Enable Iru Migration | 25 | On-demand — validates identity, enumerates devices, provisions managed Chrome, enables migration on all Jamf-enrolled computers |
3. SOC Alert Ingestion & Case Processing
Description: A full SOAR-style alert processing pipeline. Ingestion playbooks pull alerts from six security tools into Blink Case Management; the core Process Alert workflow handles observable extraction, case deduplication, enrichment orchestration, and automated response routing. Simulation playbooks support analyst training and pipeline testing. A live event-driven webhook integration posts AI-generated triage insights from Abstract into the pipeline.
Business problem: Security teams receive high volumes of alerts from disparate tools that must be triaged, correlated, and enriched consistently — a manual process that creates analyst fatigue and slow response times.
Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail, Blink Case Management, Abstract (webhook)
| Playbook | Executions | Role |
|---|---|---|
| Post AI Triage Abstract Insight Updates | 285 | Ingest — event-driven; receives AI triage insights from Abstract via custom webhook, checks source, and routes updates into the pipeline |
| Process Alert | 0 | Core pipeline — event-driven; extracts observables, deduplicates cases, triggers enrichment, routes to response |
| EXAMPLE Ingest - Wiz | 0 | Ingest — Wiz issue polling → case creation |
| EXAMPLE Ingest - Microsoft Defender For Cloud Apps | 0 | Ingest — Defender for Cloud Apps alert polling → case creation |
| EXAMPLE Ingest - CrowdStrike Falcon LogScale -- | 0 | Ingest — Falcon LogScale webhook → case creation |
| EXAMPLE Ingest - CrowdStrike | 0 | Ingest — CrowdStrike webhook with alert detail enrichment → case creation |
| EXAMPLE Ingest - Azure | 0 | Ingest — Azure Monitor event polling → case creation |
| EXAMPLE Ingest - AWS CloudTrail | 0 | Ingest — AWS CloudTrail event polling → case creation |
| Recovery - Handle Unprocessed Alerts | 0 | Recovery — reprocesses alerts that failed the main pipeline |
| Subflow - Missing Alert Template Notification | 0 | Subflow — notifies on alerts that lack an extraction template |
| Simulate Multiple Alerts from Different Sources | 0 | Testing — injects synthetic alerts from multiple vendors for pipeline validation |
| Simulate Crowdstrike Alert | 0 | Testing — injects a random CrowdStrike example alert for pipeline testing |
4. Alert Enrichment & IOC Lookup
Description: A comprehensive library of enrichment subflows that automatically populate observable context across identities, endpoints, IPs, URLs, and file hashes from multiple threat intelligence and identity sources. A central router dispatches observables to the appropriate enrichment subflow based on type.
Business problem: Analysts manually looking up IOC context across CrowdStrike, Okta, VirusTotal, and other tools during triage accounts for a large share of alert handling time; automated enrichment reduces time-to-context significantly.
Integrations: CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, AbuseIPDB, VirusTotal, URLScan, Slack, GitHub, Bash (whois, dig)
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Enrich Observables - Main Router | 0 | Router — dispatches observables to type-specific enrichment subflows |
| Utility - Update Enrichment | 0 | Wrapper — triggers the enrichment router |
| Recovery - Enrich Non-Enriched Observables | 0 | Recovery — re-enriches observables that were not enriched during alert processing |
| Subflow - Update Enrichment Data | 0 | Subflow — writes enrichment verdict and data back to a case observable |
| Enrich - Agent ID - Crowdstrike | 0 | Enrich — resolves CrowdStrike agent ID to device details |
| Enrich - Username or Email - Okta | 0 | Enrich — looks up user profile and status in Okta |
| Get User Information Using Okta | 0 | Utility — standalone Okta user lookup |
| Enrich - Username or Email - Google Workspace | 0 | Enrich — looks up user in Google Workspace |
| Get User Information Using Google Workspace | 0 | Utility — standalone Google Workspace user lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Enrich — looks up user and risky user status in Entra ID |
| Get User Information Using Microsoft Entra ID | 0 | Utility — standalone Entra ID user lookup with risk status |
| Enrich - Username - Github | 0 | Enrich — looks up GitHub user profile |
| Get User Information Using Github | 0 | Utility — standalone GitHub user lookup |
| Enrich - Email Address - Slack | 0 | Enrich — resolves email to Slack user profile |
| Get User Information on Email Address Using Slack | 0 | Utility — standalone Slack user lookup by email |
| Okta Search for User Activity | 0 | Enrich — retrieves Okta activity logs for a user over a date range |
| Enrich - IP - IPDB | 0 | Enrich — AbuseIPDB reputation check for IP observables |
| Enrich - IP - VT | 0 | Enrich — VirusTotal IP reputation and verdict |
| Enrich - IP or Domain - Whois | 0 | Enrich — Whois lookup for IP/domain observables |
| Enrich IP or Domain Using Whois | 0 | Utility — standalone Whois lookup |
| Enrich - URL - VT | 0 | Enrich — VirusTotal URL scan and verdict |
| Enrich - URL - URLScan | 0 | Enrich — URLScan submission and verdict |
| Analyze URL with URLScan | 0 | Utility — standalone URLScan analysis |
| Secure URL Screenshot Capture | 0 | Enrich — captures a screenshot of a URL for visual inspection |
| Enrich - Hash - VT | 0 | Enrich — VirusTotal hash lookup with configurable verdict threshold |
| Enrich - Hash - Crowdstrike | 0 | Enrich — CrowdStrike endpoint search by hash |
| Get Hash Info Using Crowdstrike | 0 | Utility — standalone CrowdStrike indicator lookup by hash |
| Get Hash Info Using VirusTotal | 0 | Utility — standalone VirusTotal hash search |
| Get End of Life Date for a Product | 0 | Enrich — retrieves EOL/EOS dates for software products and versions |
| Run Dig Command | 0 | Utility — DNS dig lookup for domains |
5. Incident Response & EDR
Description: Automated response playbooks for the two primary incident types — phishing and malware — plus a main response router that dispatches based on case type. CrowdStrike RTR playbooks enable analysts to execute remote commands or quarantine/un-quarantine endpoints directly from cases.
Business problem: Manual incident response workflows are slow and inconsistent; automated triage and containment reduce dwell time and free analysts for higher-value investigation.
Integrations: Microsoft Outlook, CrowdStrike (RTR), Blink Case Management
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Response - Main Router | 0 | Router — dispatches cases to phishing or malware response subflow based on case type |
| Response Subflow - Phishing | 0 | Response — retrieves original email, checks for KnowBe4 campaign headers, routes accordingly |
| Response Subflow - Malware | 0 | Response — evaluates malware remediation status and routes to appropriate action |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Containment — isolates or lifts isolation of a CrowdStrike-managed device |
| CrowdStrike RTR to a Single Host | 0 | Containment — executes RTR command against a single CrowdStrike-managed host |
| CrowdStrike RTR to a Batch of Hosts | 0 | Containment — executes RTR command across a batch of CrowdStrike-managed hosts |
6. Case Management Utilities
Description: A set of utility and maintenance playbooks that keep the case management environment healthy — closing stale cases, managing observable-to-alert relationships, finding similar cases based on shared observables, and providing error notification infrastructure for the broader SOC pipeline.
Business problem: Case management systems accumulate stale and orphaned data over time; automated hygiene workflows keep the environment accurate and actionable without manual curation.
Integrations: Blink Case Management, Email
| Playbook | Executions | Role |
|---|---|---|
| Utility - Close Stale Cases | 0 | Utility — closes cases open with no update for over a month |
| Utility - Find Similar Cases Based on Observables | 0 | Utility — calculates similarity score between cases based on shared observables |
| Utility - Set Or Update Observable Relation | 0 | Utility — creates or updates the relation between an observable and an alert |
| Utility - Delete Observable Relation | 0 | Utility — removes a relation between an observable and an alert |
| Utility - List Observable Alert Relations | 0 | Utility — lists all alerts related to a given observable |
| Utility - List Alert Observable Relations | 0 | Utility — lists all observables related to a given alert |
| Table Action - Validate Observables Extraction Template | 0 | Utility — validates that an alert matches an existing extraction template |
| Error Handling - Send Error Notification Email | 0 | Infrastructure — sends error notification emails for pipeline failures |
| USE WITH CARE - Reset Case Management Environment | 0 | Maintenance — purges all cases, alerts, observables, attachments, and tasks (destructive) |
7. Development / Test
Description: Empty or test workflows with no production logic. Includes stub workflows and a working directory test automation.
| Playbook | Executions | Notes |
|---|---|---|
| New Workflow | 0 | Empty stub |
| New Workflow 1 | 0 | Empty stub |
| New Workflow | 0 | In-development webhook receiver (Abstract Insight trigger) |
| Working Directory Testing | 0 | Platform test — Python and Bash in a working directory context |
8. Credential & Vault Management
Description: Automates 1Password vault and group lifecycle management for IT operations. On-demand playbooks allow IT administrators to add or remove users from 1Password groups and manage vault access permissions, while utility workflows enumerate existing vaults and their assigned managers for access review.
Business problem: Managing access to shared password vaults and security groups in 1Password manually creates delays and risks out-of-sync permissions as team membership changes; automated workflows ensure consistent provisioning and reduce IT overhead.
Integrations: 1Password
| Playbook | Executions | Role |
|---|---|---|
| Manage 1Password Groups | 19 | On-demand — adds or removes a user from a specified 1Password group |
| List 1Password Vaults | 18 | Utility — enumerates all 1Password vaults in the tenant |
| Manage 1Password Vaults | 1 | On-demand — adds or removes user access permissions on a specified 1Password vault |
| List 1Password Vault Managers | 1 | Utility — lists all managers assigned to a specified 1Password vault |
Key Observations
Strengths
Active IAM and endpoint automation: The employee onboarding and endpoint migration workflows are live, integrated across Greenhouse, BambooHR, Okta, and Jamf, and leveraging Claude AI for data extraction — a strong indicator of mature, production-grade automation in the People Ops and IT domains.
Well-structured SOC platform foundation: The security workspace contains a complete, architecturally sound SOAR platform: alert ingestion from six sources, a unified case processing pipeline with observable extraction and deduplication, 30 enrichment subflows covering all major observable types, incident response playbooks for the two highest-volume alert categories, and a full suite of case management utilities. This represents significant build investment.
Broad integration coverage for enrichment: The enrichment library covers identity (Okta, Google Workspace, Entra ID, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), and endpoint (CrowdStrike) — a well-rounded IOC context stack.
AI-augmented onboarding: Use of Anthropic Claude for address component extraction and work location determination in the NHO flow demonstrates early adoption of AI-native automation beyond simple API chaining.
SOC pipeline receiving live events: The AI triage webhook integration (285 executions) shows the SOC pipeline is actively ingesting events, demonstrating that the platform architecture is operational and capable of handling production-scale alert volumes.
Gaps
EXAMPLE ingestion sources not yet connected: The six vendor-specific ingest workflows (Wiz, Defender, CrowdStrike, Falcon LogScale, Azure, CloudTrail) remain named "EXAMPLE" with zero executions. Connecting these to live alert feeds would immediately expand automated coverage across the full security stack and compound value from the existing enrichment and response library.
No cloud security or GRC coverage: The entire Cloud Security, Vulnerability Management, and GRC categories have zero playbooks. These are common expansion areas for security teams that have established a SOC foundation.
Phishing response incomplete: The phishing response subflow checks KnowBe4 campaign headers but does not proceed to remediation steps (e.g., pulling the email from other inboxes, blocking the sender, notifying affected users). The malware response subflow similarly routes on remediation status but has no downstream containment logic beyond CrowdStrike isolation.
Duplicate utility patterns: Several enrichment areas have both a "Get User Information Using X" and an "Enrich - Username - X" variant with overlapping functionality. Consolidating these would reduce maintenance surface.
Integration Ecosystem
| Domain | Integrations in Use |
|---|---|
| Identity & MDM | Okta, Microsoft Entra ID, Google Workspace, Jamf, Entitle |
| HR & Recruiting | BambooHR, Greenhouse |
| Credentials & Secrets | 1Password |
| EDR & Threat Intel | CrowdStrike (detection + RTR), VirusTotal, AbuseIPDB, URLScan |
| Cloud & SIEM | Wiz, Microsoft Defender for Cloud Apps, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail |
| Collaboration | Slack, Microsoft Outlook |
| Developer | GitHub |
| AI | Anthropic (Claude) |
| Core Platform | Blink Case Management, Blink Tables |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.