Blink Security Automation — Confidential

bvnt — Customer Success Report

Generated 2026-09-10 | bvnt-value-report.md
2026-09-10Report Date
739Total Playbooks
173Unique Workflows (12m)
2,337,511Actions Automated (12m)
$601,212Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

739
Total playbooks built
all non-deleted workflows
252
Active playbooks
currently enabled
173
Unique workflows executed (12m)
distinct workflows that ran
2,337,511
Actions automated (12m)
completed action steps
12,986.2h
Hours saved (12m)
@ 20s per action
$601,212
Money saved (12m)
@ $100K avg salary
2
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
4
Active AI agents
of 6 total
203
AI agent tasks executed (12m)
60 in last 30d
In the last 12 months, Blink automated: - 11,549 portal and CDP user accounts deprovisioned through dual-approval workflows - 9,881 security inbox emails auto-categorized and routed by source tool - 7,759 security alerts auto-triaged and escalated to Jira & Slack without analyst touch - 3,252 physical access control events processed and ticketed automatically - 2,528 code PII/secrets exposures detected and routed to the security team - 1,925 automated account management lifecycle events processed across identity platforms - 1,387 employee HR changes synced from ADP to Okta in real time - 285 secure eShare client site access requests fulfilled end-to-end

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Security Alert Triage & Escalation
  • 5IR Slack channels auto-created for security incidents
19.0%
20
16 active
Physical Security Monitoring
  • 3,252Physical access control events auto-processed
0.0%
3
2 active
Security Mailbox Automation
  • 12Foreign travel security reviews automated
15.1%
6
6 active
Case Management & SOAR (Internal MDR Platform)2 executions
0.0%
24
24 active
Automated Account Management & HR Systems Sync
  • 1,925IAM lifecycle events processed (AAM engine)
  • 1,387Employee identity changes synced from ADP to Okta
  • 245Manager assignments auto-propagated from HR system
5.3%
12
11 active
Employee Offboarding51 executions
0.1%
11
11 active
GitLab SaaS Access Management
  • 57GitLab/SaaS access changes processed
0.4%
13
13 active
JIT Privileged Access Management (Portal Okta)1,006 executions
2.1%
7
7 active
Customer Portal User Deprovisioning (CDP/Okta)
  • 11,549Portal/CDP user accounts deprovisioned via approved workflow
24.4%
11
11 active
eShare Client Site & Access Management
  • 285eShare secure client access requests fulfilled
3.0%
6
6 active
Threat Intelligence & Code Security
  • 2,528Code PII/secrets exposures detected & alerted
8.2%
8
8 active
B2B Customer Onboarding0 executions
0.0%
3
3 active
IT Operations & Credential Hygiene
  • 241Jira IT asset records synced
0.6%
9
9 active
GCCH Account Provisioning (Public Sector)0 executions
0.0%
1
1 active
Sec-Eng Privileged Access Management (Entra ID)14 executions
0.0%
3
3 active
Agentic SecEng Ticket Triage
  • 40Security engineering Jira tickets triaged by AI agent
0.1%
1
1 active
Total36,953 executions100%
138
132 active

Use Case Growth Over Time

447 unique playbooks  |  16 operational use cases  |  47,145 total executions (12m)  |  2024-09 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Case Management & SOAR (Internal MDR Platform)
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Microsoft Outlook Slack
Employee Offboarding
Okta Jamf Slack Microsoft Entra ID Jira
B2B Customer Onboarding
String Utilities GitLab Web Form Slack
Customer Portal User Deprovisioning (CDP/Okta)
Okta Web Form Slack
Security Alert Triage & Escalation
Slack Jira Microsoft Outlook Email
eShare Client Site & Access Management
Slack Microsoft Graph Web Form Microsoft Entra ID
GitLab SaaS Access Management
GitLab Slack Jira Okta
Security Mailbox Automation
Microsoft Outlook
Automated Account Management & HR Systems Sync
Okta Slack AWS Jira Microsoft Graph
Threat Intelligence & Code Security
Microsoft Entra ID OpenCTI
JIT Privileged Access Management (Portal Okta)
Web Form Okta Slack
IT Operations & Credential Hygiene
Microsoft Graph Slack Jamf Okta Jira
GCCH Account Provisioning (Public Sector)
Jira Slack Microsoft Outlook Okta
Sec-Eng Privileged Access Management (Entra ID)
Microsoft Entra ID
Agentic SecEng Ticket Triage
Agents Jira

04Key Observations

✓  Strengths

Strengths

Deep, multi-tenant identity stack. The IAM automation estate spans Okta (corporate, portal, GDAP, GCCH), Microsoft Entra ID (commercial, GovCloud, onmicrosoft), JAMF, and ADP — all wired into a shared event bus. The AAM engine and ADP webhook sync represent a mature, production-grade identity lifecycle pipeline processing thousands of events per year.

Unified alert pipeline across cyber and physical. All security alert sources — email security, cloud posture, identity, data security, and physical access control — feed through the same JIRA/Slack sub-flow with shared deduplication and threshold logic. This yields consistent ticket formatting and a single pane of glass regardless of source, processing over 11,000 combined alert and dedup events in 12 months.

JIT enforcement at scale. The Portal Okta JIT system with automated hourly revocation represents a genuine least-privilege implementation, not just a policy. 963 automated access removal monitor executions over the year demonstrate ongoing enforcement rather than a one-time setup.

eShare lifecycle ownership. The complete create → request → enforce expiry → inventory cycle for eShare client sites is a well-designed closed-loop automation. 963 hourly cleanup runs and 285 fulfilled access requests show this is operationally active.

PII/secrets detection in code. 2,528 Wiz code scanning alerts routed and actioned in 12 months indicates active DevSecOps integration — this is a signal of a mature security program applying shift-left controls.

Agentic triage now live for Sec-Eng tickets. The new SecEng Triage Agent uses an AI agent to analyze inbound Jira security-engineering tickets and auto-comment triage findings, with 40 executions in its first stretch of use — a concrete first step toward the agentic SOC model, distinct from the still-dormant CrowdStrike-based MDR platform noted below.

###

△  Gaps & Growth Opportunities

Gaps

Case Management & SOAR platform shows zero executions. The internal MDR platform (24 workflows covering CrowdStrike alert processing, observable enrichment, and phishing/malware response) has not run in the past 12 months. This is either a pre-production deployment awaiting activation, or it was stood down. The enrichment library (VirusTotal, AbuseIPDB, URLScan, CrowdStrike) is well-structured and ready to activate.

Employee offboarding is underutilized relative to org size. The main offboarding automation (commercial and global combined) shows only 30 executions. Given the scale of the ADP sync (1,387 hire/change events), a significant deprovisioning gap likely exists. The Salesforce-triggered offboarding (7 runs) only covers one HR system trigger path.

B2B and GCCH onboarding workflows are dormant. Zero executions across all B2B customer onboarding and public sector provisioning workflows. These may be in staging, replaced by other processes, or triggered via paths not captured in the execution data.

ReversingLabs IOC portal has never been used in production. The "Joesneyland" analyst IOC lookup tool (hash, IP, URL via ReversingLabs) has zero executions despite being a fully built interactive web form tool. Analyst awareness or integration into the SOC workflow may be missing.

Conquest Commercial alert sources are inactive. Both Defender for Cloud Apps and Defender for Endpoint polling triggers for Conquest Commercial show zero executions — either the integrations are not connected or the tenant has no alerts flowing.

Integration Ecosystem

Domain Integrations
Security Tools CrowdStrike, Wiz, Sublime Security, Obsidian Security, Varonis, Mimecast, Keeper Security, VirusTotal, AbuseIPDB, URLScan, ReversingLabs, OpenCTI, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Verkada, Palo Alto, Cloudflare
Identity & Directory Okta (5+ connection contexts), Microsoft Entra ID (commercial, GCCH, GDAP, onmicrosoft), JAMF, ADP, Mimecast
Collaboration & Ticketing Jira, Slack, Microsoft Outlook, Confluence
Cloud & Infrastructure Microsoft Graph API, SharePoint, eShare, AWS Lambda
Business Systems Salesforce, TalentLMS, GitLab (cloud + on-prem)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 4 active | 203 tasks (12m)

AI Agents

Active Agents
4
of 6 total
Tasks Executed (12m)
203
60 in last 30d
Data Usage (12m)
27,283,056
1,765,937 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Mr. KQL 5000 Agents Testing 70 0 17,128,779
2 SecEng Triage Engineer SecEng 60 60 1,765,937
3 Threat Hunt Bot Agents Testing 49 0 7,078,730
4 Metric Man Agents Testing 24 0 1,309,610
5 Agent Blink Case Management 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Agents Testing143
SecEng60
Case Management0
C Self-Service & Webforms 0 app runs | 27 form submissions

Self-Service Applications

Apps
9
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 opportunity products 00
2 test 00
3 Onboarding Retro Dashboard 00
4 SecOps Performance 00
5 Portal Okta PAM 00

Webforms

Forms
23
active webforms
Total Submissions
27
all time
Completed
25
fully submitted
Submissions (30d)
25
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Add/Update Permission in Portal Okta 1513
2 Requesting Elevated Access to Portal Okta 1212
3 BlueVoyant Azure B2B Onboarding 00
4 Query IdP Configurations 00
5 Employee Offboarding 00
D Full Use Case Analysis 16 use cases | 47,145 executions (12m)

Business KPIs

Metric Count Playbook
Security inbox emails auto-categorized & routed 9,881 Sec Inbox Move Mail Rule (Okta, Mimecast, Jira, Palo Alto, Cloudflare)
Portal/CDP user accounts deprovisioned via approved workflow 11,549 DESTRUCTIVE - Post-Approval Process
Security alerts auto-triaged & escalated to Jira/Slack 7,759 Sublime Security (BV LLC + BVGS), Entra Alerts (BV LLC + BVGS), Obsidian (Threat/Posture/Integration), Varonis, Wiz (Threats + Issues), Mimecast Outbound, Duplicate JIRA Linking, Health Monitoring
Physical access control events auto-processed 3,252 Verkada Access Control Alerts
Code PII/secrets exposures detected & alerted 2,528 Alert on PII/Secrets in Wiz Code
IAM lifecycle events processed (AAM engine) 1,925 AAM - 2. Processor - Followup
Employee identity changes synced from ADP to Okta 1,387 Webhook Based ADP to Okta Sync - Prod
eShare secure client access requests fulfilled 285 Request eShare client site access
Manager assignments auto-propagated from HR system 245 Automatically Assign Manager From Jira Ticket
Jira IT asset records synced 241 Jira Asset Sync Service
GitLab/SaaS access changes processed 57 Service - process SaaS waitlist entries
Foreign travel security reviews automated 12 Foreign travel internal security review
Security engineering Jira tickets triaged by AI agent 40 SecEng Triage Agent
IR Slack channels auto-created for security incidents 5 IR Process Slack Channel Creation
In the last 12 months, Blink automated: - 11,549 portal and CDP user accounts deprovisioned through dual-approval workflows - 9,881 security inbox emails auto-categorized and routed by source tool - 7,759 security alerts auto-triaged and escalated to Jira & Slack without analyst touch - 3,252 physical access control events processed and ticketed automatically - 2,528 code PII/secrets exposures detected and routed to the security team - 1,925 automated account management lifecycle events processed across identity platforms - 1,387 employee HR changes synced from ADP to Okta in real time - 285 secure eShare client site access requests fulfilled end-to-end

Use Case Summary

# Use Case Category Subcategory Playbooks Combined Executions (12 mo)
1 Security Alert Triage & Escalation SOC Case mgmt & SOAR, SIEM & log pipeline monitoring 21 7,764
2 Physical Security Monitoring Other IT/OT & network infra monitoring 3 3,255
3 Security Mailbox Automation SOC SIEM & log pipeline monitoring, Case mgmt & SOAR 7 9,893
4 Case Management & SOAR (Internal MDR Platform) SOC Agentic SOC, Case mgmt & SOAR, Alert enrichment / IOC lookup, Phishing detection & response, EDR containment & response 24 0
5 Automated Account Management & HR Systems Sync IAM Identity sync & directory mgmt, Full employee lifecycle, Identity lifecycle automation 16 3,883
6 Employee Offboarding IAM Employee offboarding, Full employee lifecycle 18 30
7 GitLab SaaS Access Management IAM Access review & group mgmt, Identity lifecycle automation 13 257
8 JIT Privileged Access Management (Portal Okta) IAM JIT & temporary access, Privileged account mgmt 7 989
9 Customer Portal User Deprovisioning (CDP/Okta) IAM Employee offboarding, Identity lifecycle automation 12 11,552
10 eShare Client Site & Access Management Other SaaS / IT administration, Customer registry & FinOps auto 7 1,397
11 Threat Intelligence & Code Security SOC / GRC Threat intel ingest & curation, DLP triage & exposure resp, DevSecOps compliance 9 2,612
12 B2B Customer Onboarding Other Customer registry & FinOps auto 4 0
13 IT Operations & Credential Hygiene Other / IAM Endpoint hygiene & MDM ops, Password & credential lifecycle, SaaS / IT administration 10 296
14 GCCH Account Provisioning (Public Sector) IAM Employee onboarding, Identity lifecycle automation 2 0
15 Sec-Eng Privileged Access Management (Entra ID) IAM JIT & temporary access, Privileged account mgmt 3 14
16 Agentic SecEng Ticket Triage SOC Agentic SOC, Case mgmt & SOAR 1 40

Use Cases

1. Security Alert Triage & Escalation

Description: Ingests security alerts from eight or more disparate platforms, normalizes payloads, checks for duplicate events and rate-threshold violations, then creates Jira tickets and sends Slack notifications. A shared sub-flow handles Jira ticket creation with custom formatting, deduplication table writes, and Slack notification delivery for every inbound alert source.

Business problem solved: Alert fatigue from multiple disconnected security tools. Without automation, analysts manually triage alerts from email security, cloud posture, identity, and data security platforms, each with its own format and severity scale.

Integrations: Sublime Security, Microsoft Entra ID, Obsidian Security, Varonis, Wiz, Mimecast, Keeper Security, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Jira, Slack

Playbook Executions (12 mo) Type
Sublime Security BV LLC 1,437 Event trigger
Sublime Security BVGS 172 Event trigger
BV LLC Entra Alerts 2,182 Polling trigger
BVGS GCC Entra Alerts 16 Polling trigger
Obsidian Threat Alerts 186 Webhook
Obsidian Posture Alerts 29 Webhook
Obsidian Integration Alerts 54 Webhook
Varonis Alerts 8 Webhook
Wiz BV LLC - Threats 13 Webhook
Wiz BV LLC - Issues 3 Webhook
Mimecast Outbound Personal Alerts 496 Polling trigger
Keeper Security Alerts 0 Webhook
Conquest Commercial Microsoft Cloud App Alert 0 Polling trigger
Conquest Commercial Defender for Endpoint Alert 0 Polling trigger
Mail received in BVGS Security Mailbox 0 Polling trigger
JIRA/Slack Alerting Sub-Flow 4,677 Subflow
Alert Threshold Check 4,671 Subflow
Check If Duplicate Event 4,671 Subflow
Linking Duplicate JIRA Alert Tickets 3,123 Polling trigger
Health Monitoring for Alerting Failures 40 Scheduled
IR Process Slack Channel Creation 5 Webhook

2. Physical Security Monitoring

Description: Routes Verkada physical security events (camera motion triggers, access control badge events, alarms) into the same Jira/Slack alerting pipeline used for cyber alerts, providing a unified security operations view across physical and digital environments.

Business problem solved: Physical security events were siloed from the cyber SOC workflow. Connecting Verkada to the central Jira/Slack pipeline enables unified incident tracking regardless of whether the trigger is a phishing email or an unauthorized badge swipe.

Integrations: Verkada, Jira, Slack

Playbook Executions (12 mo) Type
Verkada Access Control Alerts 3,252 Webhook
Verkada Camera Security Alerts 3 Webhook
Verkada Alarms Alerts 0 Webhook

3. Security Mailbox Automation

Description: Monitors the corporate security inbox for inbound emails from specific security vendor sources and automatically routes them to the corresponding sub-folders using per-vendor trigger criteria. A parallel workflow processes foreign travel laptop requests from Jira, applying country-based security approval logic.

Business problem solved: A high-volume shared security inbox receiving notifications from Okta, Mimecast, Jira, Palo Alto, and Cloudflare requires manual sorting. Automation keeps the inbox clean and enforces consistent categorization at scale.

Integrations: Microsoft Outlook, Okta, Mimecast, Jira, Palo Alto, Cloudflare

Playbook Executions (12 mo) Type
Sec Inbox Move Mail Rule - Okta 1,967 Polling trigger
Sec Inbox Move Mail Rule - Jira 1,981 Polling trigger
Sec Inbox Move Mail Rule - Palo Alto 1,995 Polling trigger
Sec Inbox Move Mail Rule - Cloudflare 1,977 Polling trigger
Sec Inbox Move Mail Rule - Mimecast 1,961 Polling trigger
Mail received in BVGS Security Mailbox 0 Polling trigger
Foreign travel internal security review 12 Polling trigger

4. Case Management & SOAR (Internal MDR Platform)

Description: A full-stack SOC automation platform built on top of Blink's native case management module. Processes incoming CrowdStrike alerts, extracts and deduplicates observables (IPs, URLs, file hashes, usernames, email addresses), enriches them in parallel across VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, and GitHub, then routes cases through specialized response subflows for phishing and malware incident types. Includes recovery workflows for unprocessed alerts and un-enriched observables.

Business problem solved: SOC analysts handling CrowdStrike and email-based alerts spend significant manual effort on observable extraction, enrichment lookups across multiple consoles, and case deduplication. This platform automates the entire triage-to-response pipeline.

Integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, GitHub, Microsoft Outlook, Slack

Playbook Executions (12 mo) Type
Process Alert 0 Polling trigger
Response Subflow - Phishing 0 Subflow
Response Subflow - Malware 0 Subflow
Subflow - Response - Main Router 0 Subflow
Subflow - Enrich Observables - Main Router 0 Subflow
Enrich - Hash - VT 0 Subflow
Enrich - Hash - Crowdstrike 0 Subflow
Enrich - IP - VT 0 Subflow
Enrich - IP - IPDB 0 Subflow
Enrich - IP or Domain - Whois 0 Subflow
Enrich - URL - VT 0 Subflow
Enrich - URL - URLScan 0 Subflow
Enrich - Username or Email - Okta 0 Subflow
Enrich - Username or Email - Microsoft Entra ID 0 Subflow
Enrich - Username or Email - Google Workspace 0 Subflow
Enrich - Email Address - Slack 0 Subflow
Enrich - Username - Github 0 Subflow
Enrich - Agent ID - Crowdstrike 0 Subflow
Manage Endpoint Quarantine Status in Crowdstrike 0 On-demand
Recovery - Handle Unprocessed Alerts 0 On-demand
Recovery - Enrich Non-Enriched Observables 0 On-demand
Utility - Find Similar Cases Based on Observables 0 Utility
Simulate Crowdstrike Alert 0 On-demand
Simulate Multiple Alerts from Different Sources 0 On-demand

5. Automated Account Management & HR Systems Sync

Description: End-to-end identity lifecycle automation driven by ADP HR events. ADP changes (new hires, transfers, terminations) arrive via webhook and fan out to provision or update accounts in Okta, Microsoft Entra ID, and Mimecast. A separate AAM engine monitors lifecycle state and processes Entra-specific account creation and followup events. Supporting workflows handle manager assignment from Jira, Slack-to-Okta timezone synchronization, and Mimecast directory sync.

Business problem solved: Employee lifecycle changes originating in ADP required manual propagation to identity systems, introducing provisioning delays and de-provisioning gaps. The ADP webhook integration eliminates this lag and the AAM engine ensures cross-platform consistency.

Integrations: ADP, Okta (multiple tenants), Microsoft Entra ID, Mimecast, Slack, Jira, AWS Lambda

Playbook Executions (12 mo) Type
Webhook Based ADP to Okta Sync - Prod 1,387 Webhook
AAM - 2. Processor - Followup 1,925 Scheduled
AAM - Lifecycle Controller - 0. Activity Monitor 161 Scheduled
Automatically Assign Manager From Jira Ticket 245 Webhook
AAM - 0. Initiator - BlueVoyant Okta 14 Webhook
AAM - 1. Processor - Entra 14 Polling trigger
Platform Workflow - Entra - Create 12 Polling trigger
Slack to Okta - TimeZone Sync 40 Scheduled
Mimecast Sync 8 Webhook
BV Demo Azure Tenant - Create User / Add or Remove Group / Disable Account 19 Webhook
Support - Generate Event Contract 56 Subflow
Start Lambda ADP to Okta Sync 2 On-demand
Okta employee event intake 0 Webhook
Panopticon - Okta - Manage Employee Records 0 On-demand
Support - Notify on dead letter 0 Polling trigger

6. Employee Offboarding

Description: Multi-step offboarding automation that collects employee profiles from Okta, JAMF, and Microsoft Entra ID (including GDAP and onmicrosoft accounts), presents a Slack DM approval to both the triggering manager and a confirming user, then executes destructive offboarding actions: session revocation, password expiry, group removal, and device lock across all three platforms. A parallel workflow handles Salesforce-driven offboarding events. Implementations exist for both commercial and global entity environments.

Business problem solved: Offboarding required a security team member to manually coordinate across Okta, JAMF, and Entra. Missed steps left accounts active or devices unlocked. Dual-authorization via Slack ensures no offboarding runs without confirmation.

Integrations: Okta, JAMF, Microsoft Entra ID, Slack, Jira

Playbook Executions (12 mo) Type
Offboarding - Data gathering 0 Web form
Offboarding - Destructive actions 0 Webhook
Ask Y/N DM question 23 Subflow
Okta - Offboarding data gathering 0 Subflow
JAMF - Offboarding data gathering 0 Subflow
Entra - Offboarding data gathering 0 Subflow
Okta - Offboard target 0 Subflow
JAMF - Offboard Target 0 Subflow
Entra - Offboard target 0 Subflow
Log to Jira ticket and slack (Commercial) 0 Subflow
Okta Salesforce Offboarding - Slack Notification AND Jira Ticket 7 Webhook
Okta Offboarding Certina And Xactly - Slack Notification AND Jira Ticket 0 Webhook
Okta - Offboarding data gathering (Global) 0 Subflow
JAMF - Offboarding data gathering (Global) 0 Subflow
Entra - Offboarding data gathering (Global) 0 Subflow
Okta - Offboard target (Global) 0 Subflow
JAMF - Offboard Target (Global) 0 Subflow
Log to Jira ticket and slack (Global) 0 Subflow

7. GitLab SaaS Access Management

Description: Manages GitLab repository membership for employees via a Jira-driven intake. When a membership change request is submitted in Jira, the workflow validates the user against Okta, queues the request in a SaaS access waitlist table, and processes it on a weekday schedule. Supports both cloud and on-premise GitLab instances. A Panopticon event model captures all membership state changes for auditability.

Business problem solved: Developer access provisioning to GitLab repositories required manual back-and-forth between IT and security, with no queue management or audit trail. The waitlist model decouples request intake from fulfillment and ensures every change is logged.

Integrations: GitLab (cloud + on-prem), Jira, Okta, Slack

Playbook Executions (12 mo) Type
Gitlab user.membership.update command 44 Webhook
Service - Schedule user membership waitlist 44 Webhook
Service - process SaaS waitlist entries 57 Webhook
Gitlab - Send process waitlist webhooks 38 Scheduled
V1 - Manage user codebase membership 34 On-demand
Prep gitlab add-project inputs 17 Subflow
Okta - request addition of okta group 23 Subflow
Generate Panopticon event 128 Subflow
Gitlab domain is on-prem 67 Utility
V1 - Manage user codebase membership on-prem 0 On-demand
WIP - Gitlab - Event model 0 Subflow
New Blink Self-Service Group mapping 0 On-demand
SpiceDB container maybe 0 Webhook

8. JIT Privileged Access Management (Portal Okta)

Description: A self-service just-in-time privileged access system for Portal Okta. Users request elevated roles via a web form with justification. The system checks current active grants, applies the role via Okta group membership, records the grant in a state table, and uses an hourly monitor to automatically revoke access when windows expire. An access cleanup workflow enforces removal and session revocation.

Business problem solved: Standing privileged access to the customer portal's Okta instance created unnecessary risk. JIT with automatic expiry enforces least-privilege without requiring manual IT involvement for every short-term access need.

Integrations: Okta, Slack

Playbook Executions (12 mo) Type
Request Portal Okta Admin Access 7 Web form
Add/Update PAM access to user 5 Web form
Apply permissions 7 Subflow
Access Removal monitor 963 Scheduled
Permissions cleanup 7 Polling trigger
Add PAM access request app from users 0 Polling trigger
Remove PAM request app from users with no permissions 0 Polling trigger

9. Customer Portal User Deprovisioning (CDP/Okta)

Description: Web form-driven workflow allowing operations staff to request bulk deletion of users from the Customer Delivery Platform (CDP) and/or Portal Okta. Requests are queued with approval state; a polling trigger detects approved records and executes the deletions. SSO troubleshooting and IdP configuration tooling lives in the same workspace.

Business problem solved: Removing inactive or churned customer users from the portal required manual coordination between ops and identity teams, with no audit trail. The approval-gated automation ensures deletions are authorized, logged, and complete.

Integrations: Okta, Slack

Playbook Executions (12 mo) Type
DESTRUCTIVE - Post-Approval Process 11,549 Polling trigger
Get IdP status 3 Scheduled
START - Webform - User deletion request 0 Web form
Okta - Checks 0 Subflow
CDP - Checks 0 Subflow
CDP - Delete 0 Subflow
Okta - Delete 0 Subflow
Slack Approval and notifications 0 Subflow
SSO Troubleshooting - Okta 0 Web form
Query IdP Configurations 0 Web form
Query IdP Configurations - JSON web form 0 Web form
Okta - query user record (portal) 0 Subflow

10. eShare Client Site & Access Management

Description: Automates the full lifecycle of eShare (SharePoint-backed secure file sharing) sites used for client deliverables. Covers provisioning new client or vendor sites with Microsoft Graph group setup and folder structure creation, a self-service access request form with Slack-delivered links, time-limited access grants with an hourly automated cleanup cycle, and a daily scanner that syncs the site inventory to a tracking table. SharePoint site monitoring runs on a daily schedule.

Business problem solved: eShare site creation required multi-step Microsoft Graph and eShare API calls performed manually by IT. Temporary access grants had no enforcement mechanism, leading to stale access accumulating over time.

Integrations: Microsoft Graph API, SharePoint, eShare, Slack

Playbook Executions (12 mo) Type
Check and remove eShare temporary access 963 Scheduled
Request eShare client site access 285 On-demand
New Workflow (SharePoint site monitor) 41 Scheduled
Scan for eShare client sites 40 Scheduled
Create an eShare client site 34 On-demand
Create eShare service folders 31 Subflow
Create an eShare vendor site 3 On-demand

11. Threat Intelligence & Code Security

Description: Covers two threat-facing automation streams: (1) threat intelligence ingestion from OpenCTI — daily queries for email observables, domain/IP list generation, and posting to downstream parsers; (2) DLP alerting for PII and secrets detected in code repositories by Wiz, routing 2,528 findings to the security team over the past year. On-demand OSINT tooling for Entra tenant lookups and ReversingLabs IOC queries (hash, IP, URL) rounds out the use case.

Business problem solved: Threat intel feeds and code security scans produce raw findings that need processing and routing before they are actionable. Manual handling introduces delays and inconsistency.

Integrations: Wiz, OpenCTI, ReversingLabs, Microsoft Entra ID, Jira, Slack

Playbook Executions (12 mo) Type
Alert on PII/Secrets in Wiz Code 2,528 Webhook
OpenCTI Email Observables Query 40 Scheduled
Generate domain and email lists 39 Webhook
Entra Tenant OSINT 5 On-demand
Joesneyland web form (IOC lookup portal) 0 Web form
ReversingLabs query 0 Subflow
Joesneyland - IP report 0 Subflow
Joesneyland - File hash report 0 Subflow
Joesneyland - URL report 0 Subflow

12. B2B Customer Onboarding

Description: Self-service web form for onboarding new managed service customers into the Azure B2B tenant. Captures customer name, Salesforce ID, Azure tenant ID, region, service level, and public sector flag; generates a customer UUID; checks for existing registrations; and posts to a tracking table. A Jira-webhook variant initiates the flow from an existing ticketing process with Slack notification and Panopticon event logging.

Business problem solved: Each new B2B customer required manual Azure admin consent configuration and registration. The web form plus automated registration pipeline removes the IT dependency from an operationally critical onboarding step.

Integrations: Jira, Slack, Microsoft Azure (admin consent), Salesforce

Playbook Executions (12 mo) Type
Onboard New Customer 0 Web form
START - New B2B Customer 0 Webhook
Write to B2B workspace table 0 Webhook
Generate Panopticon event (B2B) 0 Subflow

13. IT Operations & Credential Hygiene

Description: A collection of IT hygiene automations: weekly monitoring of Okta API token expiry across corporate and portal environments with Slack alerting; daily Microsoft 365 license utilization monitoring; recurring Jira asset sync from Python-driven service; and JAMF-based Mac endpoint management including self-service lock/wipe, group assignment, and admin elevation via web form.

Business problem solved: API token expiry, license over/under-provisioning, and endpoint management tasks were handled ad hoc. Scheduled checks and self-service endpoints reduce IT toil and catch hygiene issues before they become incidents.

Integrations: Okta, Microsoft 365, Microsoft Graph, JAMF, Jira, Slack, AWS

Playbook Executions (12 mo) Type
Jira Asset Sync Service 241 Scheduled
Microsoft 365 License Monitoring 40 Scheduled
Corp Okta API tokens 6 Scheduled
Portal Okta API tokens 6 Scheduled
Add Macs To Tel Aviv Static Groups 3 Web form
Lock or Wipe a Mac 0 Web form
Scope Make Me Admin For 5 Minutes To A Mac 0 Web form
Delete a Computer from Jamf 0 Web form
Link Personal Microsoft Learn Account 0 Webhook

14. GCCH Account Provisioning (Public Sector)

Description: Specialized onboarding flow for GovCloud (GCCH / CQ Fed) accounts that validates TalentLMS public sector training completion before creating a new account. Triggered from a Jira automation webhook, it checks ADP for the new hire record and verifies course completion status via the TalentLMS API before proceeding.

Business problem solved: Public sector employees require proof of compliance training before receiving GovCloud access. Without automation, verifying training completion was a manual step prone to being skipped.

Integrations: Okta, Jira, TalentLMS, ADP

Playbook Executions (12 mo) Type
01 - GCCH Account Provisioning CQ Fed - Check ADP 0 Webhook
02 - GCCH Account Provisioning CQ Fed - Create Account With Checking TalentLMS 0 Webhook

15. Sec-Eng Privileged Access Management (Entra ID)

Description: On-demand tooling giving the Security Engineering team self-service, ticket-linked privileged access. A request flow captures role, service, and session length against a Jira ticket ID and logs the grant to a tracking table; a companion tool resets a user's MFA/GDAP assignment in Entra ID; a timer-based sub-flow enforces automatic removal from the Administrative Unit once the requested session length elapses.

Business problem solved: Security engineers needed ad hoc elevated access to specific roles/services and occasional Entra ID MFA/GDAP remediation, previously requiring direct admin intervention with no consistent expiry. Ticket-linked requests with automatic timer-based revocation reduce standing privileged access while giving Sec-Eng self-service speed.

Integrations: Microsoft Entra ID, Jira

Playbook Executions (12 mo) Type
Manual PIM for Sec-Eng requests 1 On-demand
Entra ID - Reset MFA/GDAP Assignment 7 On-demand
SubFlow - Remove from AU timer 6 Subflow

16. Agentic SecEng Ticket Triage

Description: An AI agent ("SecEng Triage Engineer") triggered by inbound Jira security-engineering tickets. The workflow extracts and saves issue details, invokes the agent to analyze the request, posts the agent's findings back to the Jira ticket as a comment, and logs the agent's output to a tracking table for audit and tuning.

Business problem solved: Security Engineering ticket triage previously required a human to read, assess, and respond to every inbound Jira request. An AI triage agent now performs first-pass analysis and commentary automatically, cutting manual triage load while preserving a full audit trail of agent decisions.

Integrations: Jira

Playbook Executions (12 mo) Type
SecEng Triage Agent 40 Webhook

Key Observations

Strengths

Deep, multi-tenant identity stack. The IAM automation estate spans Okta (corporate, portal, GDAP, GCCH), Microsoft Entra ID (commercial, GovCloud, onmicrosoft), JAMF, and ADP — all wired into a shared event bus. The AAM engine and ADP webhook sync represent a mature, production-grade identity lifecycle pipeline processing thousands of events per year.

Unified alert pipeline across cyber and physical. All security alert sources — email security, cloud posture, identity, data security, and physical access control — feed through the same JIRA/Slack sub-flow with shared deduplication and threshold logic. This yields consistent ticket formatting and a single pane of glass regardless of source, processing over 11,000 combined alert and dedup events in 12 months.

JIT enforcement at scale. The Portal Okta JIT system with automated hourly revocation represents a genuine least-privilege implementation, not just a policy. 963 automated access removal monitor executions over the year demonstrate ongoing enforcement rather than a one-time setup.

eShare lifecycle ownership. The complete create → request → enforce expiry → inventory cycle for eShare client sites is a well-designed closed-loop automation. 963 hourly cleanup runs and 285 fulfilled access requests show this is operationally active.

PII/secrets detection in code. 2,528 Wiz code scanning alerts routed and actioned in 12 months indicates active DevSecOps integration — this is a signal of a mature security program applying shift-left controls.

Agentic triage now live for Sec-Eng tickets. The new SecEng Triage Agent uses an AI agent to analyze inbound Jira security-engineering tickets and auto-comment triage findings, with 40 executions in its first stretch of use — a concrete first step toward the agentic SOC model, distinct from the still-dormant CrowdStrike-based MDR platform noted below.

Gaps

Case Management & SOAR platform shows zero executions. The internal MDR platform (24 workflows covering CrowdStrike alert processing, observable enrichment, and phishing/malware response) has not run in the past 12 months. This is either a pre-production deployment awaiting activation, or it was stood down. The enrichment library (VirusTotal, AbuseIPDB, URLScan, CrowdStrike) is well-structured and ready to activate.

Employee offboarding is underutilized relative to org size. The main offboarding automation (commercial and global combined) shows only 30 executions. Given the scale of the ADP sync (1,387 hire/change events), a significant deprovisioning gap likely exists. The Salesforce-triggered offboarding (7 runs) only covers one HR system trigger path.

B2B and GCCH onboarding workflows are dormant. Zero executions across all B2B customer onboarding and public sector provisioning workflows. These may be in staging, replaced by other processes, or triggered via paths not captured in the execution data.

ReversingLabs IOC portal has never been used in production. The "Joesneyland" analyst IOC lookup tool (hash, IP, URL via ReversingLabs) has zero executions despite being a fully built interactive web form tool. Analyst awareness or integration into the SOC workflow may be missing.

Conquest Commercial alert sources are inactive. Both Defender for Cloud Apps and Defender for Endpoint polling triggers for Conquest Commercial show zero executions — either the integrations are not connected or the tenant has no alerts flowing.

Integration Ecosystem

Domain Integrations
Security Tools CrowdStrike, Wiz, Sublime Security, Obsidian Security, Varonis, Mimecast, Keeper Security, VirusTotal, AbuseIPDB, URLScan, ReversingLabs, OpenCTI, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Verkada, Palo Alto, Cloudflare
Identity & Directory Okta (5+ connection contexts), Microsoft Entra ID (commercial, GCCH, GDAP, onmicrosoft), JAMF, ADP, Mimecast
Collaboration & Ticketing Jira, Slack, Microsoft Outlook, Confluence
Cloud & Infrastructure Microsoft Graph API, SharePoint, eShare, AWS Lambda
Business Systems Salesforce, TalentLMS, GitLab (cloud + on-prem)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.