Blink Security Automation — Confidential

HIQA — Customer Success Report

Generated 2026-09-10 | hiqa-value-report.md
2026-09-10Report Date
17Total Playbooks
1Unique Workflows (12m)
130,764Actions Automated (12m)
$33,633Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

17
Total playbooks built
all non-deleted workflows
1
Active playbooks
currently enabled
1
Unique workflows executed (12m)
distinct workflows that ran
130,764
Actions automated (12m)
completed action steps
726.5h
Hours saved (12m)
@ 20s per action
$33,633
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: *(No automation executions were recorded in this period. The single deployed workflow has not yet run in production.)*

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Azure Hybrid Infrastructure Control0 executions
0.0%
1
0 active
Total0 executions100%
1
0 active

Use Case Growth Over Time

6 unique playbooks  |  1 operational use cases  |  0 total executions (12m)  |  2024-03 to 2024-08
Toggle:
Toggle:

03Integration Ecosystem

Azure Hybrid Infrastructure Control
Azure

04Key Observations

✓  Strengths

Strengths

  • Azure ARC integration is in place. The foundational connection to Azure ARC hybrid machine management is configured and connected (hiqa_hiqa_prod_sub01), which positions the team to extend this workflow into richer asset inventory and remediation patterns.
  • Conditional logic is present. The workflow already includes branching on machine state, demonstrating the pattern needed for more sophisticated response automation.

###

△  Gaps & Growth Opportunities

Gaps

  • Zero production executions. The single deployed workflow has not run in the last 12 months. This strongly suggests it was built for a one-off or exploratory use case and has not been adopted into a repeatable operational process, or that it is pending rollout.
  • Extremely limited workflow coverage. With only one workflow in the dataset, HIQA has not yet adopted Blink across the broader security and IT automation surface. Peer customers at a similar stage typically have 10–50+ active workflows spanning SOC triage, IAM lifecycle, and vulnerability management.
  • No SOC or IAM automation. There are no workflows covering alert triage, phishing response, identity lifecycle, or access review — all high-ROI categories for a healthcare/public-sector organization handling sensitive data.
  • No GRC or compliance automation. Organizations subject to healthcare compliance frameworks (e.g., GDPR, ISO 27001, HSE requirements) typically benefit heavily from automated compliance evidence collection and control monitoring.

Integration Ecosystem

Integration Usage
Azure (ARC) 1 workflow

The integration footprint is minimal. Expanding to Azure AD / Entra ID, endpoint management (Defender, Intune), and ticketing (ServiceNow, Jira) would unlock the most common high-value use cases.

Recommended Next Steps

  1. Confirm deployment status of the Azure ARC workflow — if it is live but simply hasn't been triggered, instrument a scheduled or event-driven trigger.
  2. Identify the top 3 manual security processes the team runs today (e.g., user offboarding, alert investigation, vulnerability reporting) and target those for automation first.
  3. Explore IAM lifecycle automation — employee onboarding/offboarding is typically the fastest path to measurable ROI in organizations of HIQA's profile.
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 1 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
— — No playbooks with recorded executions in the last 12 months
In the last 12 months, Blink automated: *(No automation executions were recorded in this period. The single deployed workflow has not yet run in production.)*

Use Case Summary

Use Case Category Playbooks
Azure Hybrid Infrastructure Control Cloud Security 1

Total playbooks: 1

Total executions (last 12 months): 0

Use Cases

Azure Hybrid Infrastructure Control

Description: On-demand command execution and status inspection across Azure ARC-managed hybrid machines. Enables operators to query machine state and act on the result without direct shell access to the endpoint.

Business problem solved: Provides a governed, auditable mechanism to retrieve status from and execute commands on hybrid cloud machines enrolled in Azure ARC, removing the need for direct RDP/SSH sessions and adding conditional branching logic around machine state.

Category: Cloud Security

Subcategory: Cloud asset coverage & inventory

Integrations: Azure (Azure ARC / Hybrid Machines)

Trigger: On-demand (manual invocation with Action and Hostname inputs)

Playbooks

Playbook Executions (12 mo) Workflow ID
Azure ARC - Run Command 0 a0c0284d

Workflow logic summary:

  1. Accepts Action and Hostname as inputs
  2. Calls azure.GetHybridMachine to retrieve the machine's current status from the Azure ARC control plane
  3. Branches on machine state via internal.ifCondition
  4. Prints result

Key Observations

Strengths

  • Azure ARC integration is in place. The foundational connection to Azure ARC hybrid machine management is configured and connected (hiqa_hiqa_prod_sub01), which positions the team to extend this workflow into richer asset inventory and remediation patterns.
  • Conditional logic is present. The workflow already includes branching on machine state, demonstrating the pattern needed for more sophisticated response automation.

Gaps

  • Zero production executions. The single deployed workflow has not run in the last 12 months. This strongly suggests it was built for a one-off or exploratory use case and has not been adopted into a repeatable operational process, or that it is pending rollout.
  • Extremely limited workflow coverage. With only one workflow in the dataset, HIQA has not yet adopted Blink across the broader security and IT automation surface. Peer customers at a similar stage typically have 10–50+ active workflows spanning SOC triage, IAM lifecycle, and vulnerability management.
  • No SOC or IAM automation. There are no workflows covering alert triage, phishing response, identity lifecycle, or access review — all high-ROI categories for a healthcare/public-sector organization handling sensitive data.
  • No GRC or compliance automation. Organizations subject to healthcare compliance frameworks (e.g., GDPR, ISO 27001, HSE requirements) typically benefit heavily from automated compliance evidence collection and control monitoring.

Integration Ecosystem

Integration Usage
Azure (ARC) 1 workflow

The integration footprint is minimal. Expanding to Azure AD / Entra ID, endpoint management (Defender, Intune), and ticketing (ServiceNow, Jira) would unlock the most common high-value use cases.

Recommended Next Steps

  1. Confirm deployment status of the Azure ARC workflow — if it is live but simply hasn't been triggered, instrument a scheduled or event-driven trigger.
  2. Identify the top 3 manual security processes the team runs today (e.g., user offboarding, alert investigation, vulnerability reporting) and target those for automation first.
  3. Explore IAM lifecycle automation — employee onboarding/offboarding is typically the fastest path to measurable ROI in organizations of HIQA's profile.

1. Business KPIs — Last 12 Months

Metric Count Playbook
— — No playbooks with recorded executions in the last 12 months
In the last 12 months, Blink automated: *(No automation executions were recorded in this period. The single deployed workflow has not yet run in production.)*

2. Use Case Summary

Use Case Category Playbooks
Azure Hybrid Infrastructure Control Cloud Security 1

Total playbooks: 1

Total executions (last 12 months): 0

3. Use Cases

Azure Hybrid Infrastructure Control

Description: On-demand command execution and status inspection across Azure ARC-managed hybrid machines. Enables operators to query machine state and act on the result without direct shell access to the endpoint.

Business problem solved: Provides a governed, auditable mechanism to retrieve status from and execute commands on hybrid cloud machines enrolled in Azure ARC, removing the need for direct RDP/SSH sessions and adding conditional branching logic around machine state.

Category: Cloud Security

Subcategory: Cloud asset coverage & inventory

Integrations: Azure (Azure ARC / Hybrid Machines)

Trigger: On-demand (manual invocation with Action and Hostname inputs)

Playbooks

Playbook Executions (12 mo) Workflow ID
Azure ARC - Run Command 0 a0c0284d

Workflow logic summary:

  1. Accepts Action and Hostname as inputs
  2. Calls azure.GetHybridMachine to retrieve the machine's current status from the Azure ARC control plane
  3. Branches on machine state via internal.ifCondition
  4. Prints result

4. Key Observations

Strengths

  • Azure ARC integration is in place. The foundational connection to Azure ARC hybrid machine management is configured and connected (hiqa_hiqa_prod_sub01), which positions the team to extend this workflow into richer asset inventory and remediation patterns.
  • Conditional logic is present. The workflow already includes branching on machine state, demonstrating the pattern needed for more sophisticated response automation.

Gaps

  • Zero production executions. The single deployed workflow has not run in the last 12 months. This strongly suggests it was built for a one-off or exploratory use case and has not been adopted into a repeatable operational process, or that it is pending rollout.
  • Extremely limited workflow coverage. With only one workflow in the dataset, HIQA has not yet adopted Blink across the broader security and IT automation surface. Peer customers at a similar stage typically have 10–50+ active workflows spanning SOC triage, IAM lifecycle, and vulnerability management.
  • No SOC or IAM automation. There are no workflows covering alert triage, phishing response, identity lifecycle, or access review — all high-ROI categories for a healthcare/public-sector organization handling sensitive data.
  • No GRC or compliance automation. Organizations subject to healthcare compliance frameworks (e.g., GDPR, ISO 27001, HSE requirements) typically benefit heavily from automated compliance evidence collection and control monitoring.

Integration Ecosystem

Integration Usage
Azure (ARC) 1 workflow

The integration footprint is minimal. Expanding to Azure AD / Entra ID, endpoint management (Defender, Intune), and ticketing (ServiceNow, Jira) would unlock the most common high-value use cases.

Recommended Next Steps

  1. Confirm deployment status of the Azure ARC workflow — if it is live but simply hasn't been triggered, instrument a scheduled or event-driven trigger.
  2. Identify the top 3 manual security processes the team runs today (e.g., user offboarding, alert investigation, vulnerability reporting) and target those for automation first.
  3. Explore IAM lifecycle automation — employee onboarding/offboarding is typically the fastest path to measurable ROI in organizations of HIQA's profile.
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.