01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1: IT Helpdesk Automation via Zendesk | 196 executions | 25.7% | 1 1 active |
| Use Case 2: Identity Lifecycle Management | 376 executions | 49.3% | 3 3 active |
| Use Case 3: Identity Threat Response | 176 executions | 23.1% | 3 3 active |
| Total | 748 executions | 100% | 7 7 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
- Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
- Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.
###
Gaps
- Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
- Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
- No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
- Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | Core — all IAM and identity threat response workflows |
| Zendesk | Event trigger for helpdesk routing |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 3 use cases | 762 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| IT support tickets routed & processed via Zendesk | 193 | Webhook from Zendesk |
| MFA resets completed without IT intervention | 185 | Microsoft Entra ID - MFA Reset |
| Password resets completed end-to-end | 175 | Microsoft Entra ID - Password Reset |
| User sessions revoked in response to security events | 172 | Microsoft Entra ID - Revoke User Session |
| User accounts enabled or disabled | 8 | Microsoft Entra ID - Enable/Disable User |
Use Case Summary
| Use Case | Category | Total Playbooks | Active Playbooks (executions > 0) |
|---|---|---|---|
| IT Helpdesk Automation via Zendesk | Other | 1 | 1 |
| Identity Lifecycle Management | IAM | 4 | 3 |
| Identity Threat Response | SOC | 3 | 1 |
Use Cases
Use Case 1: IT Helpdesk Automation via Zendesk
Description: Zendesk tickets are ingested as webhook events and routed into Blink workflows for automated resolution. This serves as the integration layer connecting the IT helpdesk ticketing system to downstream identity management actions.
Business problem solved: Eliminates the manual triage step where helpdesk agents read Zendesk tickets and hand off identity-related requests to IT admins. Incoming requests are captured and dispatched automatically, reducing response latency and analyst toil.
Integrations: Zendesk (webhook trigger)
Category: Other — IT helpdesk & ticket routing
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Webhook from Zendesk | 193 | Event (custom webhook) | Other | IT helpdesk & ticket routing |
Use Case 2: Identity Lifecycle Management
Description: On-demand automations that handle the full range of routine Entra ID operations — resetting MFA methods, resetting passwords, enabling or disabling accounts, and looking up user details. These workflows validate inputs, execute the action against Microsoft Entra ID, and return a structured status output.
Business problem solved: Routine identity operations (password resets, MFA resets, account state changes) are among the highest-volume helpdesk requests in any enterprise. Automating them eliminates manual admin steps, reduces wait times for end users, and frees IT staff for higher-value work.
Integrations: Microsoft Entra ID (active-directory connector)
Category: IAM — Password & credential lifecycle, Identity lifecycle automation, Identity sync & directory mgmt
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Microsoft Entra ID - MFA Reset | 185 | On demand | IAM | Password & credential lifecycle |
| Microsoft Entra ID - Password Reset | 175 | On demand | IAM | Password & credential lifecycle |
| Microsoft Entra ID - Enable/Disable User | 8 | On demand | IAM | Identity lifecycle automation |
| Microsoft Entra ID - Get User *(subflow)* | 14 | On demand | IAM | Identity sync & directory mgmt |
Use Case 3: Identity Threat Response
Description: On-demand security response automations targeting compromised or at-risk Entra ID accounts — revoking active sessions, confirming user compromise status, and resolving flagged user risks. Session revocation is the most active workflow in this group.
Business problem solved: When an account is suspected of compromise, speed of containment determines blast radius. Automating session revocation and risk resolution lets security teams respond in seconds rather than minutes, without requiring an admin to manually navigate the Entra ID portal under pressure.
Integrations: Microsoft Entra ID (active-directory connector)
Category: SOC — Identity threat response
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Microsoft Entra ID - Revoke User Session | 172 | On demand | SOC | Identity threat response |
| Microsoft Entra ID - Confirm User Compromise | 0 | On demand | SOC | Identity threat response |
| Microsoft Entra ID - Resolve User Risk | 0 | On demand | SOC | Identity threat response |
Key Observations
Strengths
- High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
- Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
- Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.
Gaps
- Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
- Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
- No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
- Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | Core — all IAM and identity threat response workflows |
| Zendesk | Event trigger for helpdesk routing |
1. Business KPIs — Last 12 Months
| Metric | Count | Playbook |
|---|---|---|
| IT support tickets routed & processed via Zendesk | 193 | Webhook from Zendesk |
| MFA resets completed without IT intervention | 185 | Microsoft Entra ID - MFA Reset |
| Password resets completed end-to-end | 175 | Microsoft Entra ID - Password Reset |
| User sessions revoked in response to security events | 172 | Microsoft Entra ID - Revoke User Session |
| User accounts enabled or disabled | 8 | Microsoft Entra ID - Enable/Disable User |
2. Use Case Summary
| Use Case | Category | Total Playbooks | Active Playbooks (executions > 0) |
|---|---|---|---|
| IT Helpdesk Automation via Zendesk | Other | 1 | 1 |
| Identity Lifecycle Management | IAM | 4 | 3 |
| Identity Threat Response | SOC | 3 | 1 |
3. Use Cases
Use Case 1: IT Helpdesk Automation via Zendesk
Description: Zendesk tickets are ingested as webhook events and routed into Blink workflows for automated resolution. This serves as the integration layer connecting the IT helpdesk ticketing system to downstream identity management actions.
Business problem solved: Eliminates the manual triage step where helpdesk agents read Zendesk tickets and hand off identity-related requests to IT admins. Incoming requests are captured and dispatched automatically, reducing response latency and analyst toil.
Integrations: Zendesk (webhook trigger)
Category: Other — IT helpdesk & ticket routing
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Webhook from Zendesk | 193 | Event (custom webhook) | Other | IT helpdesk & ticket routing |
Use Case 2: Identity Lifecycle Management
Description: On-demand automations that handle the full range of routine Entra ID operations — resetting MFA methods, resetting passwords, enabling or disabling accounts, and looking up user details. These workflows validate inputs, execute the action against Microsoft Entra ID, and return a structured status output.
Business problem solved: Routine identity operations (password resets, MFA resets, account state changes) are among the highest-volume helpdesk requests in any enterprise. Automating them eliminates manual admin steps, reduces wait times for end users, and frees IT staff for higher-value work.
Integrations: Microsoft Entra ID (active-directory connector)
Category: IAM — Password & credential lifecycle, Identity lifecycle automation, Identity sync & directory mgmt
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Microsoft Entra ID - MFA Reset | 185 | On demand | IAM | Password & credential lifecycle |
| Microsoft Entra ID - Password Reset | 175 | On demand | IAM | Password & credential lifecycle |
| Microsoft Entra ID - Enable/Disable User | 8 | On demand | IAM | Identity lifecycle automation |
| Microsoft Entra ID - Get User *(subflow)* | 14 | On demand | IAM | Identity sync & directory mgmt |
Use Case 3: Identity Threat Response
Description: On-demand security response automations targeting compromised or at-risk Entra ID accounts — revoking active sessions, confirming user compromise status, and resolving flagged user risks. Session revocation is the most active workflow in this group.
Business problem solved: When an account is suspected of compromise, speed of containment determines blast radius. Automating session revocation and risk resolution lets security teams respond in seconds rather than minutes, without requiring an admin to manually navigate the Entra ID portal under pressure.
Integrations: Microsoft Entra ID (active-directory connector)
Category: SOC — Identity threat response
| Playbook | Executions (12 mo) | Trigger Type | Category | Subcategory |
|---|---|---|---|---|
| Microsoft Entra ID - Revoke User Session | 172 | On demand | SOC | Identity threat response |
| Microsoft Entra ID - Confirm User Compromise | 0 | On demand | SOC | Identity threat response |
| Microsoft Entra ID - Resolve User Risk | 0 | On demand | SOC | Identity threat response |
4. Key Observations
Strengths
- High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
- Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
- Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.
Gaps
- Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
- Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
- No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
- Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | Core — all IAM and identity threat response workflows |
| Zendesk | Event trigger for helpdesk routing |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.