01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Employee Offboarding Automation |
| 84.9% | 6 6 active |
| Identity Threat Detection & Response |
| 0.0% | 5 5 active |
| Alert Enrichment & IOC Investigation |
| 0.0% | 28 28 active |
| SOAR Case Management Platform | 3 executions | 5.7% | 27 27 active |
| EDR Containment & Endpoint Response | 0 executions | 0.0% | 3 3 active |
| Network Infrastructure Hygiene |
| 0.0% | 7 7 active |
| Security Documentation & Audit Trail |
| 9.4% | 3 3 active |
| Privileged Access Management Integration | 0 executions | 0.0% | 3 3 active |
| Store Identity & Access Administration |
| 0.0% | 2 2 active |
| Total | 53 executions | 100% | 84 84 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
IAM offboarding is the production anchor. The employee offboarding use case has the highest execution volume (24 runs across 4 active playbooks) and the tightest integration footprint — Freshservice → Blink → AD/Entra/UKG. The webhook-triggered Create Offboarding Job running 12 times indicates a real operational dependency on Blink for identity lifecycle management.
Identity threat response is fully operational. The MSFT risky-user workflow cluster (Get Risky User Details, Dismiss User Risk, List Sign-Ins) shows consistent use across 9 executions in the measurement window. The presence of a Jira change-request automation in the same workspace suggests a structured remediation workflow is in place.
Broad enrichment library built, ready to activate. 28 distinct enrichment playbooks span 12 integration sources — CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, Slack, GitHub, Whois, dig. This is a production-ready enrichment layer that accelerates SOAR activation significantly.
Self-documenting automation practice. The weekly documentation workflow publishing to SharePoint is a differentiated governance practice — few organizations auto-document their automation logic for audit. 5 runs indicate this has been consistently running since deployment.
###
Gaps & Opportunities
SOAR platform built but not ingesting live alerts. 28 case management playbooks — including 6 source ingestion templates (CrowdStrike, Defender for Cloud Apps, Azure, AWS CloudTrail, Wiz), the full deduplication/enrichment/response pipeline — show zero executions. The infrastructure is fully built; the gap is activating the ingest connectors with production alert sources. This represents significant latent value ready to unlock.
EDR containment playbooks are dormant. CrowdStrike RTR capabilities (single host, batch, quarantine) are built but unused. These should be wired into the malware response subflow or made available as case actions to enable automated containment in the existing SOAR pipeline.
PAM integration has moved past proof-of-concept but is not yet running in production. Delinea now backs two real provisioning workflows — EDI SFTP account creation and Token2 MFA seed provisioning into Entra ID — beyond the original test playbook, but all three show zero executions. Operationalizing these would eliminate hardcoded credentials and manual MFA seeding from onboarding workflows, a low-effort, high-security-value maturity step.
Store network and identity provisioning is built but not yet activated. Seven new playbooks — pulling store records from Microsoft SQL Server and using them to provision Netbox sites/locations/subnets, Entra ID administrative units, and password-reset group membership — form a complete new-store provisioning pipeline. Only one playbook (password-reset group membership) has recorded executions so far; the rest are likely awaiting the next store opening or rollout milestone to trigger.
No phishing or cloud security coverage active. The phishing response subflow and all cloud security ingestion (Wiz, Azure, AWS CloudTrail) show zero executions. Given that Binnys has Wiz and CrowdStrike in the environment, activating those ingest triggers is a near-term expansion opportunity.
Integration Ecosystem
| Integration | Use Cases | Status |
|---|---|---|
| Microsoft Entra ID | IAM, SOC | Active |
| Active Directory (WinRM) | IAM, SOC | Active |
| Freshservice | IAM | Active |
| UKG Pro HCM | IAM | Active |
| Microsoft Defender for Endpoint | SOC | Active |
| Microsoft Teams | SOC | Active |
| Jira | SOC / GRC | Active |
| DNS Dumpster / PowerShell DNS | Other | Active |
| SharePoint | GRC | Active |
| CrowdStrike Falcon | SOC | Built, inactive |
| VirusTotal | SOC | Built, inactive |
| AbuseIPDB | SOC | Built, inactive |
| URLScan | SOC | Built, inactive |
| Okta | SOC | Built, inactive |
| Google Workspace | SOC | Built, inactive |
| Slack | SOC | Built, inactive |
| GitHub | SOC | Built, inactive |
| Wiz | Cloud Security | Built, inactive |
| AWS CloudTrail | SOC | Built, inactive |
| Azure Monitor | SOC | Built, inactive |
| Microsoft Defender for Cloud Apps | SOC | Built, inactive |
| Delinea Secret Server | IAM | Built, inactive |
| Blink API | GRC | Active |
| Netbox | Other | Built, inactive |
| Microsoft SQL Server | Other | Built, inactive |
| SSH | IAM | Built, inactive |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 18 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Jimmy | POC | 18 | 0 | 514,896 |
| 2 | Agent Blink | HR_Workspace | 0 | 0 | 0 |
| 3 | Agent Blink | POC | 0 | 0 | 0 |
| 4 | DNS Zone Cleanup (Demo - Mocked) | andrew.black@blinkops.com | 0 | 0 | 0 |
| 5 | New Agent | HR_Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| POC | 18 |
| HR_Workspace | 0 |
| andrew.black@blinkops.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Offboarding table | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 9 use cases | 53 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Employee offboardings automated end-to-end | 12 | Create Offboarding Job |
| Endpoint device status checks (AD + Defender) | 10 | AD - Get Device Status, Defender - Get Machine Info |
| Weekly automation documentation reports published | 5 | Weekly Documentation |
| Risky user identities investigated in Entra ID | 4 | MSFT - Get Risky User Details |
| Compromised user sessions revoked & risk flags cleared | 3 | MSFT - Dismiss User Risk |
| Security change requests auto-created in Jira | 3 | Jira - Create Change Request Ticket |
| DNS zone audits & stale record cleanups | 3 | DNS - List Zone Records, DNS - Delete Stale Record |
| SOC escalation alerts dispatched to Teams | 1 | Teams - Send SOC Escalation Alert |
| Store password-reset group memberships maintained | 2 | Maintain Members of Store Password Reset Groups |
Use Case Summary
| # | Use Case | Category | Playbooks | Active Playbooks | Total Executions |
|---|---|---|---|---|---|
| 1 | Employee Offboarding Automation | IAM | 6 | 4 | 24 |
| 2 | Identity Threat Detection & Response | SOC | 5 | 4 | 11 |
| 3 | Alert Enrichment & IOC Investigation | SOC | 29 | 2 | 10 |
| 4 | SOAR Case Management Platform | SOC | 28 | 0 | 0 |
| 5 | EDR Containment & Endpoint Response | SOC | 3 | 0 | 0 |
| 6 | Network Infrastructure Hygiene | Other | 7 | 2 | 3 |
| 7 | Security Documentation & Audit Trail | GRC | 3 | 1 | 5 |
| 8 | Privileged Access Management Integration | IAM | 3 | 0 | 0 |
| 9 | Store Identity & Access Administration | IAM | 2 | 1 | 2 |
| Total | 86 | 14 | 55 |
Use Cases
1. Employee Offboarding Automation
Category: IAM
Subcategories: Employee offboarding, Identity lifecycle automation, Identity sync & directory mgmt
Description: End-to-end automation of employee offboarding, triggered by a Freshservice ITSM ticket and orchestrated across Active Directory, Microsoft Entra ID, and UKG Pro HCM. Blink deactivates accounts, terminates sessions, verifies SSO status, and manages scheduled batch offboarding jobs without manual IT intervention.
Business problem solved: Manual offboarding across disparate HR and identity systems is error-prone, slow, and creates security risk when access is not revoked promptly after an employee's departure.
Integrations: Freshservice, Active Directory (WinRM + PowerShell), Microsoft Entra ID, UKG Pro HCM, Blink Tables
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| Create Offboarding Job | 12 | Employee offboarding |
| Run_Scheduled_Employee_Offboard_Jobs | 3 | Employee offboarding |
| Subflow - Offboard User AD and Entra Tasks | 6 | Employee offboarding |
| UKG - Get Employee SSO Status | 3 | Identity sync & directory mgmt |
| Clone Fresh Service Ticket | 0 | Employee offboarding |
| Manage MyStaff Groups | 0 | Access review & group mgmt |
2. Identity Threat Detection & Response
Category: SOC
Subcategories: Identity threat response, Alert enrichment / IOC lookup, Case mgmt & SOAR
Description: Detects and responds to identity-based threats in Microsoft Entra ID — investigating risky user flags, pulling sign-in logs, revoking active sessions, dismissing risk after remediation, and escalating confirmed incidents to Teams and Jira. Provides an automated first-response loop for compromised account scenarios.
Business problem solved: Identity-based attacks are the leading entry point for breaches. Without automation, analysts must manually cross-reference Entra risky-user signals, pull sign-in history, revoke sessions, and file change tickets — a process that can take hours per incident.
Integrations: Microsoft Entra ID, Microsoft Teams, Jira
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| MSFT - Get Risky User Details | 4 | Identity threat response |
| MSFT - Dismiss User Risk | 3 | Identity threat response |
| Jira - Create Change Request Ticket | 3 | Case mgmt & SOAR |
| MSFT - List User Sign-Ins | 2 | Alert enrichment / IOC lookup |
| Teams - Send SOC Escalation Alert | 1 | Case mgmt & SOAR |
3. Alert Enrichment & IOC Investigation
Category: SOC
Subcategories: Alert enrichment / IOC lookup, EDR containment & response
Description: A comprehensive library of enrichment playbooks that automatically look up indicators of compromise — IPs, hashes, URLs, domains, email addresses, and usernames — across CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, Slack, and GitHub. Also includes device status lookups against Active Directory and Microsoft Defender for Endpoint. These playbooks serve as the enrichment backbone for the SOAR platform.
Business problem solved: Manual IOC investigation requires analysts to context-switch across 8–12 consoles per alert. This enrichment library automates the data-gathering phase so analysts receive pre-populated context rather than starting from scratch.
Integrations: Active Directory, Microsoft Defender for Endpoint, CrowdStrike Falcon, VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, Microsoft Entra ID, Slack, GitHub, Whois, dig/DNS
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| AD - Get Device Status | 5 | Alert enrichment / IOC lookup |
| Defender - Get Machine Info | 5 | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Alert enrichment / IOC lookup |
| Enrich - Username - Github | 0 | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | 0 | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 0 | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Github | 0 | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | 0 | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | 0 | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | Alert enrichment / IOC lookup |
| Okta Search for User Activity | 0 | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | Alert enrichment / IOC lookup |
4. SOAR Case Management Platform
Category: SOC
Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring, Phishing detection & response, EDR containment & response
Description: A full Blink-native SOAR platform encompassing alert ingestion from six sources, observable extraction and deduplication, automated enrichment routing, phishing and malware response subflows, and a library of case management utilities. Provides the operational backbone for tier-1 SOC triage with zero executions in the measurement window — indicating the platform is built and configured but awaiting production alert volume activation.
Business problem solved: Building a custom SOAR without a dedicated platform requires expensive licensing and long implementation cycles. This use case demonstrates a fully self-built SOAR running entirely on Blink, covering the complete alert-to-case lifecycle.
Integrations: Blink Case Management, CrowdStrike Falcon, Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, Wiz, Microsoft Outlook, Email
5. EDR Containment & Endpoint Response
Category: SOC
Subcategories: EDR containment & response
Description: Playbooks for remote endpoint containment and command execution via CrowdStrike Falcon Real Time Response (RTR). Supports both single-host and bulk-host quarantine/de-quarantine operations and ad-hoc command execution over live sessions.
Business problem solved: Containment of compromised endpoints requires rapid, repeatable action that bypasses manual console access. These playbooks enable one-click or automated quarantine directly from a case without requiring direct CrowdStrike console access.
Integrations: CrowdStrike Falcon (RTR)
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | EDR containment & response |
6. Network Infrastructure Hygiene
Category: Other
Subcategories: IT/OT & network infra monitoring
Description: Automates DNS zone auditing and stale record remediation, and provisions store-location network infrastructure in Netbox (IPAM/DCIM) — pulling store records from Microsoft SQL Server into Blink Tables and using them to create corresponding sites, locations, and IP subnets in Netbox. Together these playbooks keep DNS and network documentation synchronized with the authoritative store database as locations are added or change.
Business problem solved: Stale DNS records are a persistent hygiene issue that can be exploited for subdomain takeovers or create confusion in incident investigations, and manually creating Netbox sites/locations/subnets for each store is a repetitive, error-prone task. Automating both keeps network infrastructure records accurate without manual upkeep.
Integrations: DNS Dumpster, PowerShell / WinRM, Netbox, Microsoft SQL Server, Blink Tables
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| DNS - List Zone Records | 2 | IT/OT & network infra monitoring |
| DNS - Delete Stale Record | 1 | IT/OT & network infra monitoring |
| Populate GSE_Stores Table | 0 | IT/OT & network infra monitoring |
| Create Sites in Netbox | 0 | IT/OT & network infra monitoring |
| Create Locations in Netbox | 0 | IT/OT & network infra monitoring |
| Update Location IDs | 0 | IT/OT & network infra monitoring |
| Create IP Subnets in Netbox | 0 | IT/OT & network infra monitoring |
7. Security Documentation & Audit Trail
Category: GRC
Subcategories: Security metrics & reporting, DevSecOps compliance
Description: A scheduled weekly automation that inventories all Blink workflows modified in the prior week, extracts their YAML definitions, converts them to human-readable documentation, and publishes the output to SharePoint. Provides a continuous, tamper-evident audit trail of automation logic changes for compliance and governance purposes.
Business problem solved: Security automation logic is often undocumented, creating audit risk and knowledge gaps during staff transitions or regulatory reviews. This use case produces automated, version-tracked documentation on a fixed schedule without analyst involvement.
Integrations: Blink API, SharePoint
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| Weekly Documentation | 5 | Security metrics & reporting |
| Create Documentation in sharepoint | 0 | Security metrics & reporting |
| Get Playbook Yaml | 0 | Security metrics & reporting |
8. Privileged Access Management Integration
Category: IAM
Subcategories: Privileged account mgmt, Password & credential lifecycle
Description: Integration with Delinea Secret Server (PAM vault) for retrieving and storing privileged credentials. Beyond the initial test connection, this now includes generating and vaulting SFTP service-account passwords for EDI trading-partner access (with matching SSH provisioning and rsyslog configuration), and retrieving vaulted Token2 hardware OTP seed files to provision multi-factor authenticators directly into Microsoft Entra ID.
Business problem solved: Hardcoded credentials in automation are a critical security risk. Integrating Delinea allows automated workflows to retrieve secrets at runtime from a managed vault and push credentials or MFA seeds into downstream systems (SSH/SFTP servers, Entra ID) without manual handling, enforcing least-privilege and full audit logging of credential access.
Integrations: Delinea Secret Server, WinRM, SSH, Microsoft Entra ID
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| Test Delinea | 0 | Privileged account mgmt |
| Create EDI SFTP Account | 0 | Privileged account mgmt |
| Add Token2 Seeds to Entra | 0 | Password & credential lifecycle |
9. Store Identity & Access Administration
Category: IAM
Subcategories: Identity lifecycle automation, Access review & group mgmt
Description: Automates the identity and access scaffolding required to stand up a new store location — creating a dedicated Microsoft Entra ID administrative unit per store and maintaining group membership for store-level password-reset delegation. Runs alongside the Netbox network provisioning pipeline to fully provision a new store's identity footprint from a single store record.
Business problem solved: As Binny's opens or updates store locations, IT and identity administrators must manually create delegated administrative scopes and manage local password-reset group membership per site — a repetitive, error-prone task when done by hand across dozens of retail locations.
Integrations: Microsoft Entra ID, Blink Tables
| Playbook | Executions (12 mo.) | Subcategory |
|---|---|---|
| Set up Administrative Units for Stores | 0 | Identity lifecycle automation |
| Maintain Members of Store Password Reset Groups | 2 | Access review & group mgmt |
Key Observations
Strengths
IAM offboarding is the production anchor. The employee offboarding use case has the highest execution volume (24 runs across 4 active playbooks) and the tightest integration footprint — Freshservice → Blink → AD/Entra/UKG. The webhook-triggered Create Offboarding Job running 12 times indicates a real operational dependency on Blink for identity lifecycle management.
Identity threat response is fully operational. The MSFT risky-user workflow cluster (Get Risky User Details, Dismiss User Risk, List Sign-Ins) shows consistent use across 9 executions in the measurement window. The presence of a Jira change-request automation in the same workspace suggests a structured remediation workflow is in place.
Broad enrichment library built, ready to activate. 28 distinct enrichment playbooks span 12 integration sources — CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, Slack, GitHub, Whois, dig. This is a production-ready enrichment layer that accelerates SOAR activation significantly.
Self-documenting automation practice. The weekly documentation workflow publishing to SharePoint is a differentiated governance practice — few organizations auto-document their automation logic for audit. 5 runs indicate this has been consistently running since deployment.
Gaps & Opportunities
SOAR platform built but not ingesting live alerts. 28 case management playbooks — including 6 source ingestion templates (CrowdStrike, Defender for Cloud Apps, Azure, AWS CloudTrail, Wiz), the full deduplication/enrichment/response pipeline — show zero executions. The infrastructure is fully built; the gap is activating the ingest connectors with production alert sources. This represents significant latent value ready to unlock.
EDR containment playbooks are dormant. CrowdStrike RTR capabilities (single host, batch, quarantine) are built but unused. These should be wired into the malware response subflow or made available as case actions to enable automated containment in the existing SOAR pipeline.
PAM integration has moved past proof-of-concept but is not yet running in production. Delinea now backs two real provisioning workflows — EDI SFTP account creation and Token2 MFA seed provisioning into Entra ID — beyond the original test playbook, but all three show zero executions. Operationalizing these would eliminate hardcoded credentials and manual MFA seeding from onboarding workflows, a low-effort, high-security-value maturity step.
Store network and identity provisioning is built but not yet activated. Seven new playbooks — pulling store records from Microsoft SQL Server and using them to provision Netbox sites/locations/subnets, Entra ID administrative units, and password-reset group membership — form a complete new-store provisioning pipeline. Only one playbook (password-reset group membership) has recorded executions so far; the rest are likely awaiting the next store opening or rollout milestone to trigger.
No phishing or cloud security coverage active. The phishing response subflow and all cloud security ingestion (Wiz, Azure, AWS CloudTrail) show zero executions. Given that Binnys has Wiz and CrowdStrike in the environment, activating those ingest triggers is a near-term expansion opportunity.
Integration Ecosystem
| Integration | Use Cases | Status |
|---|---|---|
| Microsoft Entra ID | IAM, SOC | Active |
| Active Directory (WinRM) | IAM, SOC | Active |
| Freshservice | IAM | Active |
| UKG Pro HCM | IAM | Active |
| Microsoft Defender for Endpoint | SOC | Active |
| Microsoft Teams | SOC | Active |
| Jira | SOC / GRC | Active |
| DNS Dumpster / PowerShell DNS | Other | Active |
| SharePoint | GRC | Active |
| CrowdStrike Falcon | SOC | Built, inactive |
| VirusTotal | SOC | Built, inactive |
| AbuseIPDB | SOC | Built, inactive |
| URLScan | SOC | Built, inactive |
| Okta | SOC | Built, inactive |
| Google Workspace | SOC | Built, inactive |
| Slack | SOC | Built, inactive |
| GitHub | SOC | Built, inactive |
| Wiz | Cloud Security | Built, inactive |
| AWS CloudTrail | SOC | Built, inactive |
| Azure Monitor | SOC | Built, inactive |
| Microsoft Defender for Cloud Apps | SOC | Built, inactive |
| Delinea Secret Server | IAM | Built, inactive |
| Blink API | GRC | Active |
| Netbox | Other | Built, inactive |
| Microsoft SQL Server | Other | Built, inactive |
| SSH | IAM | Built, inactive |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.