Blink Security Automation — Confidential

ASSUTA — Customer Success Report

Generated 2026-09-10 | assuta-value-report.md
2026-09-10Report Date
64Total Playbooks
25Unique Workflows (12m)
401,015Actions Automated (12m)
$103,142Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

64
Total playbooks built
all non-deleted workflows
20
Active playbooks
currently enabled
25
Unique workflows executed (12m)
distinct workflows that ran
401,015
Actions automated (12m)
completed action steps
2,227.9h
Hours saved (12m)
@ 20s per action
$103,142
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
Note: No automated executions were recorded for any workflow in the last 12 months. The automation library appears to be in a build or pre-production phase — workflows are fully configured but have not yet been activated at production scale. KPIs will populate once workflows are promoted to active use.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Network Threat Containment via Palo Alto FW EDL0 executions
0.0%
6
6 active
Endpoint Detection & Response0 executions
0.0%
3
3 active
Identity & Access Management0 executions
0.0%
1
1 active
Notification Infrastructure0 executions
0.0%
3
3 active
Data & Table Management0 executions
0.0%
2
2 active
Development / Uncategorized0 executions
0.0%
1
1 active
Total0 executions100%
16
16 active

Use Case Growth Over Time

31 unique playbooks  |  6 operational use cases  |  0 total executions (12m)  |  2024-02 to 2024-10
Toggle:
Toggle:

03Integration Ecosystem

Notification Infrastructure
Email Twilio
Endpoint Detection & Response
Cortex XDR Email
Data & Table Management
Google Sheets
Network Threat Containment via Palo Alto FW EDL
VirusTotal Zendesk
Identity & Access Management
Microsoft Entra ID

04Key Observations

✓  Strengths

Strengths

  1. Well-scoped network containment pipeline. The EDL automation is the most complete use case — covering single and bulk IP blocking, whitelist management, and full bi-directional Zendesk integration (event in, ticket comment out, SMS notification). This is a meaningful SOC automation that eliminates manual firewall edits under incident pressure.
  1. Zendesk as SOC ticketing hub. The webhook-triggered architecture cleanly routes Zendesk incidents to automated response actions, establishing a solid SOAR pattern that can be extended to additional response types without reworking the entry point.
  1. Approval gates on sensitive actions. Endpoint isolation (Cortex XDR - Isolate Endpoint) and user enable/disable (Microsoft Entra ID - Enable or Disable User) both require an approve input, indicating deliberate human-in-the-loop design for high-impact actions — a sign of mature automation governance.
  1. Reusable notification layer. SMS and email flows are built as independent, callable utilities rather than embedded per-playbook. This keeps notification logic DRY and makes future changes (e.g., swapping SMTP providers) a single-point update.
  1. Whitelist-aware containment. IP blocking and user disable actions both check against Blink Tables whitelists before acting, preventing automation from accidentally blocking legitimate infrastructure or users.

###

△  Gaps & Growth Opportunities

Gaps

  1. Zero production executions. No workflow has recorded any execution in the last 12 months. The full library is configured but dormant — activating these automations is the single highest-priority action to realize business value from this investment.
  1. Staging/production workspace drift. Several playbooks are duplicated across two workspaces (assuta_cortex_xdr vs. assuta_staging-assuta_cortex_xdr). Without a structured promotion process, these copies will diverge over time, creating a maintenance and correctness risk. A clear staging → production promotion path should be established.
  1. No event-driven or scheduled automation. Every playbook except the Zendesk webhook is on_demand. There are no alert-driven, schedule-driven, or SIEM-connected automations, which means no autonomous SOC response without a human manually triggering a workflow.
  1. Narrow IAM scope. The IAM use case covers only Entra ID account enable/disable and session revocation. Missing: full employee offboarding orchestration, access reviews, role assignments, JIT/temporary access, and Active Directory-native lifecycle management.
  1. No vulnerability management or GRC coverage. The library has no vulnerability scanning, compliance monitoring, audit reporting, or regulatory workflow automation — categories that commonly represent high-volume, high-value automation opportunities.
  1. No alert enrichment or threat intel lookups. Despite having Cortex XDR integrated, there are no workflows for automatic alert enrichment, IOC lookup, or threat intelligence ingestion — steps that typically precede containment decisions.

Integration Ecosystem

Integration Role in Current Workflows
Cortex XDR Endpoint isolation, malware scan, AD user management via script, endpoint lookup
Microsoft Entra ID User account enable/disable, session revocation
Palo Alto Firewall (EDL via SMB) IP block list management
Zendesk Incident routing (webhook trigger), ticket commenting
SMTP Email notification delivery
Google Sheets / Workspace Reference data import
Blink Tables IP whitelists, user allow-lists, routing reference data
SMS Urgent alert notification for blocked IPs
Active Directory User management (via Cortex XDR script execution)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 6 use cases | 0 executions (12m)

Business KPIs

Note: No automated executions were recorded for any workflow in the last 12 months. The automation library appears to be in a build or pre-production phase — workflows are fully configured but have not yet been activated at production scale. KPIs will populate once workflows are promoted to active use.

*No execution-based metrics are available for this period.*

Use Case Summary

Use Case Category Subcategories Playbooks
Network Threat Containment via Palo Alto FW EDL SOC Case mgmt & SOAR, Threat intel ingest & curation 6
Endpoint Detection & Response SOC EDR containment & response 5
Identity & Access Management IAM Identity lifecycle automation, Password & credential lifecycle 3
Notification Infrastructure Other IT helpdesk & ticket routing 3
Data & Table Management Other SaaS / IT administration 2
Development / Uncategorized Other SaaS / IT administration 1

Total: 20 playbooks across 6 use cases (includes duplicates across staging and production workspaces)

Use Cases

1. Network Threat Containment via Palo Alto FW EDL

Description: Automates the blocking of malicious IP addresses at the Palo Alto firewall by maintaining an External Dynamic List (EDL), triggered both manually and through Zendesk incident tickets. Includes whitelist validation and bi-directional Zendesk ticket updates.

Business problem: Security analysts must act quickly when malicious IPs are identified — manual firewall rule edits are slow and error-prone. This pipeline automates containment from the moment an incident is raised in Zendesk, with notification via SMS and a documented audit trail back into the ticket.

Integrations: Palo Alto Firewall (EDL via SMB), Zendesk, Blink Tables, SMS

Playbook Executions (12 mo.) Category Subcategory
Zendesk Webhook 0 SOC Case mgmt & SOAR
PaloAlto FW - Add single IP to EDL - Incidents From Zendesk 0 SOC Case mgmt & SOAR, Threat intel ingest & curation
PaloAlto FW - Add multi IPs to EDL - Incidents From Zendesk 0 SOC Case mgmt & SOAR, Threat intel ingest & curation
PaloAlto FW - Add IPs to EDL file 0 SOC Threat intel ingest & curation
PaloAlto FW - Remove manually IPs from EDL file 0 SOC Threat intel ingest & curation
Adding IP manually into White-list IP's 0 SOC Threat intel ingest & curation

2. Endpoint Detection & Response

Description: Automates endpoint containment and investigation via Cortex XDR — covering endpoint isolation with email notification, malware scanning, AD endpoint lookup, and enabling/disabling AD user accounts directly from the XDR platform via script execution.

Business problem: When a threat is detected on an endpoint, analysts must contain it before lateral movement occurs. Manual isolation and AD account management introduce critical delay; these playbooks automate the full response chain with approval gates for high-impact actions and status reporting back to the team.

Integrations: Cortex XDR, Active Directory (via XDR Script Library), SMTP

Playbook Executions (12 mo.) Category Subcategory
Cortex XDR - Isolate Endpoint and Notify by Email 0 SOC EDR containment & response
Cortex XDR - Malware Scan 0 SOC EDR containment & response
Cortex XDR - Run Script - Enable or Disable AD User 0 SOC EDR containment & response
Cortex XDR - Run Script - Get AD Endpoint *(production)* 0 SOC EDR containment & response
Cortex XDR - Run Script - Get AD Endpoint *(staging)* 0 SOC EDR containment & response

3. Identity & Access Management

Description: Automates user account lifecycle actions in Microsoft Entra ID — enabling and disabling accounts with whitelist-based validation, plus revoking all active sessions for a user — both with approval gates.

Business problem: During incidents or offboarding, time-sensitive identity actions (account disable, session invalidation) must execute immediately and consistently. Manual portal operations introduce lag and skip validation steps; these playbooks enforce input validation, whitelist checks, and structured approval before any account action is taken.

Integrations: Microsoft Entra ID, Blink Tables

Playbook Executions (12 mo.) Category Subcategory
Microsoft Entra ID - Enable or Disable User *(production)* 0 IAM Identity lifecycle automation
Microsoft Entra ID - Enable or Disable User *(staging)* 0 IAM Identity lifecycle automation
Microsoft Entra ID - Revoke User Session 0 IAM Password & credential lifecycle

4. Notification Infrastructure

Description: Reusable notification subflows providing email delivery (SMTP and table-driven) and bulk SMS, used as building blocks by security response playbooks throughout the library.

Business problem: Security workflows need consistent, multi-channel alerting — email to stakeholders for audit trails, SMS for urgent time-sensitive escalations. These utilities standardize notification delivery and avoid duplicating integration logic across playbooks.

Integrations: SMTP, SMS provider, Blink Tables

Playbook Executions (12 mo.) Category Subcategory
Assuta - Send Email from Table 0 Other IT helpdesk & ticket routing
SMTP - Send Email 0 Other IT helpdesk & ticket routing
Send - SMS to list of destinations 0 Other IT helpdesk & ticket routing

5. Data & Table Management

Description: Utility playbooks for managing Blink table content — importing structured data from Google Sheets and inspecting table state — used to keep reference data (IP whitelists, user allow-lists) current for downstream security workflows.

Business problem: Security workflows depend on Blink Tables for dynamic reference data that changes over time (e.g., IP whitelists, approved user lists). These playbooks allow the security team to refresh that data from upstream sources without manual intervention in the Blink UI.

Integrations: Google Sheets, Google Workspace, Blink Tables

Playbook Executions (12 mo.) Category Subcategory
Import CSVs to Table 0 Other SaaS / IT administration
Show Table Content 0 Other SaaS / IT administration

6. Development / Uncategorized

Description: Unfinished or test playbooks not yet promoted to a production use case.

Playbook Executions (12 mo.) Category Subcategory
New Workflow 0 Other SaaS / IT administration

Key Observations

Strengths

  1. Well-scoped network containment pipeline. The EDL automation is the most complete use case — covering single and bulk IP blocking, whitelist management, and full bi-directional Zendesk integration (event in, ticket comment out, SMS notification). This is a meaningful SOC automation that eliminates manual firewall edits under incident pressure.
  1. Zendesk as SOC ticketing hub. The webhook-triggered architecture cleanly routes Zendesk incidents to automated response actions, establishing a solid SOAR pattern that can be extended to additional response types without reworking the entry point.
  1. Approval gates on sensitive actions. Endpoint isolation (Cortex XDR - Isolate Endpoint) and user enable/disable (Microsoft Entra ID - Enable or Disable User) both require an approve input, indicating deliberate human-in-the-loop design for high-impact actions — a sign of mature automation governance.
  1. Reusable notification layer. SMS and email flows are built as independent, callable utilities rather than embedded per-playbook. This keeps notification logic DRY and makes future changes (e.g., swapping SMTP providers) a single-point update.
  1. Whitelist-aware containment. IP blocking and user disable actions both check against Blink Tables whitelists before acting, preventing automation from accidentally blocking legitimate infrastructure or users.

Gaps

  1. Zero production executions. No workflow has recorded any execution in the last 12 months. The full library is configured but dormant — activating these automations is the single highest-priority action to realize business value from this investment.
  1. Staging/production workspace drift. Several playbooks are duplicated across two workspaces (assuta_cortex_xdr vs. assuta_staging-assuta_cortex_xdr). Without a structured promotion process, these copies will diverge over time, creating a maintenance and correctness risk. A clear staging → production promotion path should be established.
  1. No event-driven or scheduled automation. Every playbook except the Zendesk webhook is on_demand. There are no alert-driven, schedule-driven, or SIEM-connected automations, which means no autonomous SOC response without a human manually triggering a workflow.
  1. Narrow IAM scope. The IAM use case covers only Entra ID account enable/disable and session revocation. Missing: full employee offboarding orchestration, access reviews, role assignments, JIT/temporary access, and Active Directory-native lifecycle management.
  1. No vulnerability management or GRC coverage. The library has no vulnerability scanning, compliance monitoring, audit reporting, or regulatory workflow automation — categories that commonly represent high-volume, high-value automation opportunities.
  1. No alert enrichment or threat intel lookups. Despite having Cortex XDR integrated, there are no workflows for automatic alert enrichment, IOC lookup, or threat intelligence ingestion — steps that typically precede containment decisions.

Integration Ecosystem

Integration Role in Current Workflows
Cortex XDR Endpoint isolation, malware scan, AD user management via script, endpoint lookup
Microsoft Entra ID User account enable/disable, session revocation
Palo Alto Firewall (EDL via SMB) IP block list management
Zendesk Incident routing (webhook trigger), ticket commenting
SMTP Email notification delivery
Google Sheets / Workspace Reference data import
Blink Tables IP whitelists, user allow-lists, routing reference data
SMS Urgent alert notification for blocked IPs
Active Directory User management (via Cortex XDR script execution)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.