Blink Security Automation — Confidential

binnys — Customer Success Report

Generated 2026-09-10 | binnys-value-report.md
2026-09-10Report Date
167Total Playbooks
32Unique Workflows (12m)
1,486Actions Automated (12m)
$382Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

167
Total playbooks built
all non-deleted workflows
144
Active playbooks
currently enabled
32
Unique workflows executed (12m)
distinct workflows that ran
1,486
Actions automated (12m)
completed action steps
8.3h
Hours saved (12m)
@ 20s per action
$382
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 6 total
18
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 12 employee offboardings triggered and orchestrated end-to-end - 10 endpoint device status checks across Active Directory and Microsoft Defender - 5 weekly security automation documentation reports published to SharePoint - 4 risky user identities investigated in Microsoft Entra ID - 3 compromised user sessions revoked and risk flags cleared - 3 security change requests auto-created in Jira - 3 DNS zone audits and stale record cleanups completed - 2 store password-reset group memberships maintained across store locations - 1 SOC escalation alert dispatched to Microsoft Teams

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Employee Offboarding Automation
  • 12Employee offboardings automated end-to-end
84.9%
6
6 active
Identity Threat Detection & Response
  • 4Risky user identities investigated in Entra ID
  • 3Compromised user sessions revoked & risk flags cleared
  • 3Security change requests auto-created in Jira
0.0%
5
5 active
Alert Enrichment & IOC Investigation
  • 10Endpoint device status checks (AD + Defender)
0.0%
28
28 active
SOAR Case Management Platform3 executions
5.7%
27
27 active
EDR Containment & Endpoint Response0 executions
0.0%
3
3 active
Network Infrastructure Hygiene
  • 3DNS zone audits & stale record cleanups
0.0%
7
7 active
Security Documentation & Audit Trail
  • 5Weekly automation documentation reports published
9.4%
3
3 active
Privileged Access Management Integration0 executions
0.0%
3
3 active
Store Identity & Access Administration
  • 2Store password-reset group memberships maintained
0.0%
2
2 active
Total53 executions100%
84
84 active

Use Case Growth Over Time

98 unique playbooks  |  9 operational use cases  |  53 total executions (12m)  |  2026-03 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

SOAR Case Management Platform
CrowdStrike Microsoft Outlook Email
Alert Enrichment & IOC Investigation
CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan GitHub Slack Microsoft Defender For Endpoints
EDR Containment & Endpoint Response
CrowdStrike
Privileged Access Management Integration
Delinea SSH Microsoft Graph
Employee Offboarding Automation
Microsoft Entra ID Freshservice Microsoft Teams Web Form UKG Pro HCM
Security Documentation & Audit Trail
SharePoint Agents
Identity Threat Detection & Response
Microsoft Entra ID Jira Microsoft Teams
Network Infrastructure Hygiene
Infoblox Cloud Services Portal DNS Dumpster Microsoft SQL Server NetBox
Store Identity & Access Administration
Microsoft Entra ID Microsoft Graph

04Key Observations

✓  Strengths

Strengths

IAM offboarding is the production anchor. The employee offboarding use case has the highest execution volume (24 runs across 4 active playbooks) and the tightest integration footprint — Freshservice → Blink → AD/Entra/UKG. The webhook-triggered Create Offboarding Job running 12 times indicates a real operational dependency on Blink for identity lifecycle management.

Identity threat response is fully operational. The MSFT risky-user workflow cluster (Get Risky User Details, Dismiss User Risk, List Sign-Ins) shows consistent use across 9 executions in the measurement window. The presence of a Jira change-request automation in the same workspace suggests a structured remediation workflow is in place.

Broad enrichment library built, ready to activate. 28 distinct enrichment playbooks span 12 integration sources — CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, Slack, GitHub, Whois, dig. This is a production-ready enrichment layer that accelerates SOAR activation significantly.

Self-documenting automation practice. The weekly documentation workflow publishing to SharePoint is a differentiated governance practice — few organizations auto-document their automation logic for audit. 5 runs indicate this has been consistently running since deployment.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

SOAR platform built but not ingesting live alerts. 28 case management playbooks — including 6 source ingestion templates (CrowdStrike, Defender for Cloud Apps, Azure, AWS CloudTrail, Wiz), the full deduplication/enrichment/response pipeline — show zero executions. The infrastructure is fully built; the gap is activating the ingest connectors with production alert sources. This represents significant latent value ready to unlock.

EDR containment playbooks are dormant. CrowdStrike RTR capabilities (single host, batch, quarantine) are built but unused. These should be wired into the malware response subflow or made available as case actions to enable automated containment in the existing SOAR pipeline.

PAM integration has moved past proof-of-concept but is not yet running in production. Delinea now backs two real provisioning workflows — EDI SFTP account creation and Token2 MFA seed provisioning into Entra ID — beyond the original test playbook, but all three show zero executions. Operationalizing these would eliminate hardcoded credentials and manual MFA seeding from onboarding workflows, a low-effort, high-security-value maturity step.

Store network and identity provisioning is built but not yet activated. Seven new playbooks — pulling store records from Microsoft SQL Server and using them to provision Netbox sites/locations/subnets, Entra ID administrative units, and password-reset group membership — form a complete new-store provisioning pipeline. Only one playbook (password-reset group membership) has recorded executions so far; the rest are likely awaiting the next store opening or rollout milestone to trigger.

No phishing or cloud security coverage active. The phishing response subflow and all cloud security ingestion (Wiz, Azure, AWS CloudTrail) show zero executions. Given that Binnys has Wiz and CrowdStrike in the environment, activating those ingest triggers is a near-term expansion opportunity.

Integration Ecosystem

Integration Use Cases Status
Microsoft Entra ID IAM, SOC Active
Active Directory (WinRM) IAM, SOC Active
Freshservice IAM Active
UKG Pro HCM IAM Active
Microsoft Defender for Endpoint SOC Active
Microsoft Teams SOC Active
Jira SOC / GRC Active
DNS Dumpster / PowerShell DNS Other Active
SharePoint GRC Active
CrowdStrike Falcon SOC Built, inactive
VirusTotal SOC Built, inactive
AbuseIPDB SOC Built, inactive
URLScan SOC Built, inactive
Okta SOC Built, inactive
Google Workspace SOC Built, inactive
Slack SOC Built, inactive
GitHub SOC Built, inactive
Wiz Cloud Security Built, inactive
AWS CloudTrail SOC Built, inactive
Azure Monitor SOC Built, inactive
Microsoft Defender for Cloud Apps SOC Built, inactive
Delinea Secret Server IAM Built, inactive
Blink API GRC Active
Netbox Other Built, inactive
Microsoft SQL Server Other Built, inactive
SSH IAM Built, inactive
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 18 tasks (12m)

AI Agents

Active Agents
1
of 6 total
Tasks Executed (12m)
18
0 in last 30d
Data Usage (12m)
514,896
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Jimmy POC 18 0 514,896
2 Agent Blink HR_Workspace 0 0 0
3 Agent Blink POC 0 0 0
4 DNS Zone Cleanup (Demo - Mocked) andrew.black@blinkops.com 0 0 0
5 New Agent HR_Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
POC18
HR_Workspace0
andrew.black@blinkops.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Offboarding table 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 9 use cases | 53 executions (12m)

Business KPIs

Metric Count Playbook
Employee offboardings automated end-to-end 12 Create Offboarding Job
Endpoint device status checks (AD + Defender) 10 AD - Get Device Status, Defender - Get Machine Info
Weekly automation documentation reports published 5 Weekly Documentation
Risky user identities investigated in Entra ID 4 MSFT - Get Risky User Details
Compromised user sessions revoked & risk flags cleared 3 MSFT - Dismiss User Risk
Security change requests auto-created in Jira 3 Jira - Create Change Request Ticket
DNS zone audits & stale record cleanups 3 DNS - List Zone Records, DNS - Delete Stale Record
SOC escalation alerts dispatched to Teams 1 Teams - Send SOC Escalation Alert
Store password-reset group memberships maintained 2 Maintain Members of Store Password Reset Groups
In the last 12 months, Blink automated: - 12 employee offboardings triggered and orchestrated end-to-end - 10 endpoint device status checks across Active Directory and Microsoft Defender - 5 weekly security automation documentation reports published to SharePoint - 4 risky user identities investigated in Microsoft Entra ID - 3 compromised user sessions revoked and risk flags cleared - 3 security change requests auto-created in Jira - 3 DNS zone audits and stale record cleanups completed - 2 store password-reset group memberships maintained across store locations - 1 SOC escalation alert dispatched to Microsoft Teams

Use Case Summary

# Use Case Category Playbooks Active Playbooks Total Executions
1 Employee Offboarding Automation IAM 6 4 24
2 Identity Threat Detection & Response SOC 5 4 11
3 Alert Enrichment & IOC Investigation SOC 29 2 10
4 SOAR Case Management Platform SOC 28 0 0
5 EDR Containment & Endpoint Response SOC 3 0 0
6 Network Infrastructure Hygiene Other 7 2 3
7 Security Documentation & Audit Trail GRC 3 1 5
8 Privileged Access Management Integration IAM 3 0 0
9 Store Identity & Access Administration IAM 2 1 2
Total 86 14 55

Use Cases

1. Employee Offboarding Automation

Category: IAM

Subcategories: Employee offboarding, Identity lifecycle automation, Identity sync & directory mgmt

Description: End-to-end automation of employee offboarding, triggered by a Freshservice ITSM ticket and orchestrated across Active Directory, Microsoft Entra ID, and UKG Pro HCM. Blink deactivates accounts, terminates sessions, verifies SSO status, and manages scheduled batch offboarding jobs without manual IT intervention.

Business problem solved: Manual offboarding across disparate HR and identity systems is error-prone, slow, and creates security risk when access is not revoked promptly after an employee's departure.

Integrations: Freshservice, Active Directory (WinRM + PowerShell), Microsoft Entra ID, UKG Pro HCM, Blink Tables

Playbook Executions (12 mo.) Subcategory
Create Offboarding Job 12 Employee offboarding
Run_Scheduled_Employee_Offboard_Jobs 3 Employee offboarding
Subflow - Offboard User AD and Entra Tasks 6 Employee offboarding
UKG - Get Employee SSO Status 3 Identity sync & directory mgmt
Clone Fresh Service Ticket 0 Employee offboarding
Manage MyStaff Groups 0 Access review & group mgmt

2. Identity Threat Detection & Response

Category: SOC

Subcategories: Identity threat response, Alert enrichment / IOC lookup, Case mgmt & SOAR

Description: Detects and responds to identity-based threats in Microsoft Entra ID — investigating risky user flags, pulling sign-in logs, revoking active sessions, dismissing risk after remediation, and escalating confirmed incidents to Teams and Jira. Provides an automated first-response loop for compromised account scenarios.

Business problem solved: Identity-based attacks are the leading entry point for breaches. Without automation, analysts must manually cross-reference Entra risky-user signals, pull sign-in history, revoke sessions, and file change tickets — a process that can take hours per incident.

Integrations: Microsoft Entra ID, Microsoft Teams, Jira

Playbook Executions (12 mo.) Subcategory
MSFT - Get Risky User Details 4 Identity threat response
MSFT - Dismiss User Risk 3 Identity threat response
Jira - Create Change Request Ticket 3 Case mgmt & SOAR
MSFT - List User Sign-Ins 2 Alert enrichment / IOC lookup
Teams - Send SOC Escalation Alert 1 Case mgmt & SOAR

3. Alert Enrichment & IOC Investigation

Category: SOC

Subcategories: Alert enrichment / IOC lookup, EDR containment & response

Description: A comprehensive library of enrichment playbooks that automatically look up indicators of compromise — IPs, hashes, URLs, domains, email addresses, and usernames — across CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, Slack, and GitHub. Also includes device status lookups against Active Directory and Microsoft Defender for Endpoint. These playbooks serve as the enrichment backbone for the SOAR platform.

Business problem solved: Manual IOC investigation requires analysts to context-switch across 8–12 consoles per alert. This enrichment library automates the data-gathering phase so analysts receive pre-populated context rather than starting from scratch.

Integrations: Active Directory, Microsoft Defender for Endpoint, CrowdStrike Falcon, VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, Microsoft Entra ID, Slack, GitHub, Whois, dig/DNS

Playbook Executions (12 mo.) Subcategory
AD - Get Device Status 5 Alert enrichment / IOC lookup
Defender - Get Machine Info 5 Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 Alert enrichment / IOC lookup
Enrich - Username - Github 0 Alert enrichment / IOC lookup
Enrich - Email Address - Slack 0 Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 Alert enrichment / IOC lookup
Enrich - IP - VT 0 Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 0 Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 Alert enrichment / IOC lookup
Enrich - URL - VT 0 Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 Alert enrichment / IOC lookup
Enrich - Hash - VT 0 Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 Alert enrichment / IOC lookup
Get User Information Using Google Workspace 0 Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 Alert enrichment / IOC lookup
Get User Information Using Okta 0 Alert enrichment / IOC lookup
Get User Information Using Github 0 Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack 0 Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 Alert enrichment / IOC lookup
Analyze URL with URLScan 0 Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 Alert enrichment / IOC lookup
Okta Search for User Activity 0 Alert enrichment / IOC lookup
Run Dig Command 0 Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 Alert enrichment / IOC lookup

4. SOAR Case Management Platform

Category: SOC

Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring, Phishing detection & response, EDR containment & response

Description: A full Blink-native SOAR platform encompassing alert ingestion from six sources, observable extraction and deduplication, automated enrichment routing, phishing and malware response subflows, and a library of case management utilities. Provides the operational backbone for tier-1 SOC triage with zero executions in the measurement window — indicating the platform is built and configured but awaiting production alert volume activation.

Business problem solved: Building a custom SOAR without a dedicated platform requires expensive licensing and long implementation cycles. This use case demonstrates a fully self-built SOAR running entirely on Blink, covering the complete alert-to-case lifecycle.

Integrations: Blink Case Management, CrowdStrike Falcon, Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, Wiz, Microsoft Outlook, Email

Playbook Executions (12 mo.) Subcategory
Process Alert 0 Case mgmt & SOAR
Subflow - Response - Main Router 0 Case mgmt & SOAR
Response Subflow - Phishing 0 Phishing detection & response
Response Subflow - Malware 0 EDR containment & response
EXAMPLE Ingest - CrowdStrike 0 SIEM & log pipeline monitoring
EXAMPLE Ingest - CrowdStrike Falcon LogScale -- 0 SIEM & log pipeline monitoring
EXAMPLE Ingest - Microsoft Defender For Cloud Apps 0 SIEM & log pipeline monitoring
EXAMPLE Ingest - Azure 0 SIEM & log pipeline monitoring
EXAMPLE Ingest - AWS CloudTrail 0 SIEM & log pipeline monitoring
EXAMPLE Ingest - Wiz 0 SIEM & log pipeline monitoring
Subflow - Enrich Observables - Main Router 0 Case mgmt & SOAR
Subflow - Update Enrichment Data 0 Case mgmt & SOAR
Subflow - Missing Alert Template Notification 0 Case mgmt & SOAR
Error Handling - Send Error Notification Email 0 Case mgmt & SOAR
Utility - Update Enrichment 0 Case mgmt & SOAR
Utility - Set Or Update Observable Relation 0 Case mgmt & SOAR
Utility - Delete Observable Relation 0 Case mgmt & SOAR
Utility - List Alert Observable Relations 0 Case mgmt & SOAR
Utility - List Observable Alert Relations 0 Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables 0 Case mgmt & SOAR
Utility - Close Stale Cases 0 Case mgmt & SOAR
Table Action - Validate Observables Extraction Template 0 Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables 0 Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts 0 Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources 0 Case mgmt & SOAR
Simulate Crowdstrike Alert 0 Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment 0 Case mgmt & SOAR

5. EDR Containment & Endpoint Response

Category: SOC

Subcategories: EDR containment & response

Description: Playbooks for remote endpoint containment and command execution via CrowdStrike Falcon Real Time Response (RTR). Supports both single-host and bulk-host quarantine/de-quarantine operations and ad-hoc command execution over live sessions.

Business problem solved: Containment of compromised endpoints requires rapid, repeatable action that bypasses manual console access. These playbooks enable one-click or automated quarantine directly from a case without requiring direct CrowdStrike console access.

Integrations: CrowdStrike Falcon (RTR)

Playbook Executions (12 mo.) Subcategory
Manage Endpoint Quarantine Status in Crowdstrike 0 EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 EDR containment & response
CrowdStrike RTR to a Single Host 0 EDR containment & response

6. Network Infrastructure Hygiene

Category: Other

Subcategories: IT/OT & network infra monitoring

Description: Automates DNS zone auditing and stale record remediation, and provisions store-location network infrastructure in Netbox (IPAM/DCIM) — pulling store records from Microsoft SQL Server into Blink Tables and using them to create corresponding sites, locations, and IP subnets in Netbox. Together these playbooks keep DNS and network documentation synchronized with the authoritative store database as locations are added or change.

Business problem solved: Stale DNS records are a persistent hygiene issue that can be exploited for subdomain takeovers or create confusion in incident investigations, and manually creating Netbox sites/locations/subnets for each store is a repetitive, error-prone task. Automating both keeps network infrastructure records accurate without manual upkeep.

Integrations: DNS Dumpster, PowerShell / WinRM, Netbox, Microsoft SQL Server, Blink Tables

Playbook Executions (12 mo.) Subcategory
DNS - List Zone Records 2 IT/OT & network infra monitoring
DNS - Delete Stale Record 1 IT/OT & network infra monitoring
Populate GSE_Stores Table 0 IT/OT & network infra monitoring
Create Sites in Netbox 0 IT/OT & network infra monitoring
Create Locations in Netbox 0 IT/OT & network infra monitoring
Update Location IDs 0 IT/OT & network infra monitoring
Create IP Subnets in Netbox 0 IT/OT & network infra monitoring

7. Security Documentation & Audit Trail

Category: GRC

Subcategories: Security metrics & reporting, DevSecOps compliance

Description: A scheduled weekly automation that inventories all Blink workflows modified in the prior week, extracts their YAML definitions, converts them to human-readable documentation, and publishes the output to SharePoint. Provides a continuous, tamper-evident audit trail of automation logic changes for compliance and governance purposes.

Business problem solved: Security automation logic is often undocumented, creating audit risk and knowledge gaps during staff transitions or regulatory reviews. This use case produces automated, version-tracked documentation on a fixed schedule without analyst involvement.

Integrations: Blink API, SharePoint

Playbook Executions (12 mo.) Subcategory
Weekly Documentation 5 Security metrics & reporting
Create Documentation in sharepoint 0 Security metrics & reporting
Get Playbook Yaml 0 Security metrics & reporting

8. Privileged Access Management Integration

Category: IAM

Subcategories: Privileged account mgmt, Password & credential lifecycle

Description: Integration with Delinea Secret Server (PAM vault) for retrieving and storing privileged credentials. Beyond the initial test connection, this now includes generating and vaulting SFTP service-account passwords for EDI trading-partner access (with matching SSH provisioning and rsyslog configuration), and retrieving vaulted Token2 hardware OTP seed files to provision multi-factor authenticators directly into Microsoft Entra ID.

Business problem solved: Hardcoded credentials in automation are a critical security risk. Integrating Delinea allows automated workflows to retrieve secrets at runtime from a managed vault and push credentials or MFA seeds into downstream systems (SSH/SFTP servers, Entra ID) without manual handling, enforcing least-privilege and full audit logging of credential access.

Integrations: Delinea Secret Server, WinRM, SSH, Microsoft Entra ID

Playbook Executions (12 mo.) Subcategory
Test Delinea 0 Privileged account mgmt
Create EDI SFTP Account 0 Privileged account mgmt
Add Token2 Seeds to Entra 0 Password & credential lifecycle

9. Store Identity & Access Administration

Category: IAM

Subcategories: Identity lifecycle automation, Access review & group mgmt

Description: Automates the identity and access scaffolding required to stand up a new store location — creating a dedicated Microsoft Entra ID administrative unit per store and maintaining group membership for store-level password-reset delegation. Runs alongside the Netbox network provisioning pipeline to fully provision a new store's identity footprint from a single store record.

Business problem solved: As Binny's opens or updates store locations, IT and identity administrators must manually create delegated administrative scopes and manage local password-reset group membership per site — a repetitive, error-prone task when done by hand across dozens of retail locations.

Integrations: Microsoft Entra ID, Blink Tables

Playbook Executions (12 mo.) Subcategory
Set up Administrative Units for Stores 0 Identity lifecycle automation
Maintain Members of Store Password Reset Groups 2 Access review & group mgmt

Key Observations

Strengths

IAM offboarding is the production anchor. The employee offboarding use case has the highest execution volume (24 runs across 4 active playbooks) and the tightest integration footprint — Freshservice → Blink → AD/Entra/UKG. The webhook-triggered Create Offboarding Job running 12 times indicates a real operational dependency on Blink for identity lifecycle management.

Identity threat response is fully operational. The MSFT risky-user workflow cluster (Get Risky User Details, Dismiss User Risk, List Sign-Ins) shows consistent use across 9 executions in the measurement window. The presence of a Jira change-request automation in the same workspace suggests a structured remediation workflow is in place.

Broad enrichment library built, ready to activate. 28 distinct enrichment playbooks span 12 integration sources — CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, Slack, GitHub, Whois, dig. This is a production-ready enrichment layer that accelerates SOAR activation significantly.

Self-documenting automation practice. The weekly documentation workflow publishing to SharePoint is a differentiated governance practice — few organizations auto-document their automation logic for audit. 5 runs indicate this has been consistently running since deployment.

Gaps & Opportunities

SOAR platform built but not ingesting live alerts. 28 case management playbooks — including 6 source ingestion templates (CrowdStrike, Defender for Cloud Apps, Azure, AWS CloudTrail, Wiz), the full deduplication/enrichment/response pipeline — show zero executions. The infrastructure is fully built; the gap is activating the ingest connectors with production alert sources. This represents significant latent value ready to unlock.

EDR containment playbooks are dormant. CrowdStrike RTR capabilities (single host, batch, quarantine) are built but unused. These should be wired into the malware response subflow or made available as case actions to enable automated containment in the existing SOAR pipeline.

PAM integration has moved past proof-of-concept but is not yet running in production. Delinea now backs two real provisioning workflows — EDI SFTP account creation and Token2 MFA seed provisioning into Entra ID — beyond the original test playbook, but all three show zero executions. Operationalizing these would eliminate hardcoded credentials and manual MFA seeding from onboarding workflows, a low-effort, high-security-value maturity step.

Store network and identity provisioning is built but not yet activated. Seven new playbooks — pulling store records from Microsoft SQL Server and using them to provision Netbox sites/locations/subnets, Entra ID administrative units, and password-reset group membership — form a complete new-store provisioning pipeline. Only one playbook (password-reset group membership) has recorded executions so far; the rest are likely awaiting the next store opening or rollout milestone to trigger.

No phishing or cloud security coverage active. The phishing response subflow and all cloud security ingestion (Wiz, Azure, AWS CloudTrail) show zero executions. Given that Binnys has Wiz and CrowdStrike in the environment, activating those ingest triggers is a near-term expansion opportunity.

Integration Ecosystem

Integration Use Cases Status
Microsoft Entra ID IAM, SOC Active
Active Directory (WinRM) IAM, SOC Active
Freshservice IAM Active
UKG Pro HCM IAM Active
Microsoft Defender for Endpoint SOC Active
Microsoft Teams SOC Active
Jira SOC / GRC Active
DNS Dumpster / PowerShell DNS Other Active
SharePoint GRC Active
CrowdStrike Falcon SOC Built, inactive
VirusTotal SOC Built, inactive
AbuseIPDB SOC Built, inactive
URLScan SOC Built, inactive
Okta SOC Built, inactive
Google Workspace SOC Built, inactive
Slack SOC Built, inactive
GitHub SOC Built, inactive
Wiz Cloud Security Built, inactive
AWS CloudTrail SOC Built, inactive
Azure Monitor SOC Built, inactive
Microsoft Defender for Cloud Apps SOC Built, inactive
Delinea Secret Server IAM Built, inactive
Blink API GRC Active
Netbox Other Built, inactive
Microsoft SQL Server Other Built, inactive
SSH IAM Built, inactive
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.