01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Security Alert Triage & Escalation |
| 19.0% | 20 16 active |
| Physical Security Monitoring |
| 0.0% | 3 2 active |
| Security Mailbox Automation |
| 15.1% | 6 6 active |
| Case Management & SOAR (Internal MDR Platform) | 2 executions | 0.0% | 24 24 active |
| Automated Account Management & HR Systems Sync |
| 5.3% | 12 11 active |
| Employee Offboarding | 51 executions | 0.1% | 11 11 active |
| GitLab SaaS Access Management |
| 0.4% | 13 13 active |
| JIT Privileged Access Management (Portal Okta) | 1,006 executions | 2.1% | 7 7 active |
| Customer Portal User Deprovisioning (CDP/Okta) |
| 24.4% | 11 11 active |
| eShare Client Site & Access Management |
| 3.0% | 6 6 active |
| Threat Intelligence & Code Security |
| 8.2% | 8 8 active |
| B2B Customer Onboarding | 0 executions | 0.0% | 3 3 active |
| IT Operations & Credential Hygiene |
| 0.6% | 9 9 active |
| GCCH Account Provisioning (Public Sector) | 0 executions | 0.0% | 1 1 active |
| Sec-Eng Privileged Access Management (Entra ID) | 14 executions | 0.0% | 3 3 active |
| Agentic SecEng Ticket Triage |
| 0.1% | 1 1 active |
| Total | 36,953 executions | 100% | 138 132 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep, multi-tenant identity stack. The IAM automation estate spans Okta (corporate, portal, GDAP, GCCH), Microsoft Entra ID (commercial, GovCloud, onmicrosoft), JAMF, and ADP — all wired into a shared event bus. The AAM engine and ADP webhook sync represent a mature, production-grade identity lifecycle pipeline processing thousands of events per year.
Unified alert pipeline across cyber and physical. All security alert sources — email security, cloud posture, identity, data security, and physical access control — feed through the same JIRA/Slack sub-flow with shared deduplication and threshold logic. This yields consistent ticket formatting and a single pane of glass regardless of source, processing over 11,000 combined alert and dedup events in 12 months.
JIT enforcement at scale. The Portal Okta JIT system with automated hourly revocation represents a genuine least-privilege implementation, not just a policy. 963 automated access removal monitor executions over the year demonstrate ongoing enforcement rather than a one-time setup.
eShare lifecycle ownership. The complete create → request → enforce expiry → inventory cycle for eShare client sites is a well-designed closed-loop automation. 963 hourly cleanup runs and 285 fulfilled access requests show this is operationally active.
PII/secrets detection in code. 2,528 Wiz code scanning alerts routed and actioned in 12 months indicates active DevSecOps integration — this is a signal of a mature security program applying shift-left controls.
Agentic triage now live for Sec-Eng tickets. The new SecEng Triage Agent uses an AI agent to analyze inbound Jira security-engineering tickets and auto-comment triage findings, with 40 executions in its first stretch of use — a concrete first step toward the agentic SOC model, distinct from the still-dormant CrowdStrike-based MDR platform noted below.
###
Gaps
Case Management & SOAR platform shows zero executions. The internal MDR platform (24 workflows covering CrowdStrike alert processing, observable enrichment, and phishing/malware response) has not run in the past 12 months. This is either a pre-production deployment awaiting activation, or it was stood down. The enrichment library (VirusTotal, AbuseIPDB, URLScan, CrowdStrike) is well-structured and ready to activate.
Employee offboarding is underutilized relative to org size. The main offboarding automation (commercial and global combined) shows only 30 executions. Given the scale of the ADP sync (1,387 hire/change events), a significant deprovisioning gap likely exists. The Salesforce-triggered offboarding (7 runs) only covers one HR system trigger path.
B2B and GCCH onboarding workflows are dormant. Zero executions across all B2B customer onboarding and public sector provisioning workflows. These may be in staging, replaced by other processes, or triggered via paths not captured in the execution data.
ReversingLabs IOC portal has never been used in production. The "Joesneyland" analyst IOC lookup tool (hash, IP, URL via ReversingLabs) has zero executions despite being a fully built interactive web form tool. Analyst awareness or integration into the SOC workflow may be missing.
Conquest Commercial alert sources are inactive. Both Defender for Cloud Apps and Defender for Endpoint polling triggers for Conquest Commercial show zero executions — either the integrations are not connected or the tenant has no alerts flowing.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| Security Tools | CrowdStrike, Wiz, Sublime Security, Obsidian Security, Varonis, Mimecast, Keeper Security, VirusTotal, AbuseIPDB, URLScan, ReversingLabs, OpenCTI, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Verkada, Palo Alto, Cloudflare |
| Identity & Directory | Okta (5+ connection contexts), Microsoft Entra ID (commercial, GCCH, GDAP, onmicrosoft), JAMF, ADP, Mimecast |
| Collaboration & Ticketing | Jira, Slack, Microsoft Outlook, Confluence |
| Cloud & Infrastructure | Microsoft Graph API, SharePoint, eShare, AWS Lambda |
| Business Systems | Salesforce, TalentLMS, GitLab (cloud + on-prem) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 4 active | 203 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Mr. KQL 5000 | Agents Testing | 70 | 0 | 17,128,779 |
| 2 | SecEng Triage Engineer | SecEng | 60 | 60 | 1,765,937 |
| 3 | Threat Hunt Bot | Agents Testing | 49 | 0 | 7,078,730 |
| 4 | Metric Man | Agents Testing | 24 | 0 | 1,309,610 |
| 5 | Agent Blink | Case Management | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Agents Testing | 143 |
| SecEng | 60 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 27 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | opportunity products | 0 | 0 |
| 2 | test | 0 | 0 |
| 3 | Onboarding Retro Dashboard | 0 | 0 |
| 4 | SecOps Performance | 0 | 0 |
| 5 | Portal Okta PAM | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Add/Update Permission in Portal Okta | 15 | 13 |
| 2 | Requesting Elevated Access to Portal Okta | 12 | 12 |
| 3 | BlueVoyant Azure B2B Onboarding | 0 | 0 |
| 4 | Query IdP Configurations | 0 | 0 |
| 5 | Employee Offboarding | 0 | 0 |
D Full Use Case Analysis 16 use cases | 47,145 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security inbox emails auto-categorized & routed | 9,881 | Sec Inbox Move Mail Rule (Okta, Mimecast, Jira, Palo Alto, Cloudflare) |
| Portal/CDP user accounts deprovisioned via approved workflow | 11,549 | DESTRUCTIVE - Post-Approval Process |
| Security alerts auto-triaged & escalated to Jira/Slack | 7,759 | Sublime Security (BV LLC + BVGS), Entra Alerts (BV LLC + BVGS), Obsidian (Threat/Posture/Integration), Varonis, Wiz (Threats + Issues), Mimecast Outbound, Duplicate JIRA Linking, Health Monitoring |
| Physical access control events auto-processed | 3,252 | Verkada Access Control Alerts |
| Code PII/secrets exposures detected & alerted | 2,528 | Alert on PII/Secrets in Wiz Code |
| IAM lifecycle events processed (AAM engine) | 1,925 | AAM - 2. Processor - Followup |
| Employee identity changes synced from ADP to Okta | 1,387 | Webhook Based ADP to Okta Sync - Prod |
| eShare secure client access requests fulfilled | 285 | Request eShare client site access |
| Manager assignments auto-propagated from HR system | 245 | Automatically Assign Manager From Jira Ticket |
| Jira IT asset records synced | 241 | Jira Asset Sync Service |
| GitLab/SaaS access changes processed | 57 | Service - process SaaS waitlist entries |
| Foreign travel security reviews automated | 12 | Foreign travel internal security review |
| Security engineering Jira tickets triaged by AI agent | 40 | SecEng Triage Agent |
| IR Slack channels auto-created for security incidents | 5 | IR Process Slack Channel Creation |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks | Combined Executions (12 mo) |
|---|---|---|---|---|---|
| 1 | Security Alert Triage & Escalation | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring | 21 | 7,764 |
| 2 | Physical Security Monitoring | Other | IT/OT & network infra monitoring | 3 | 3,255 |
| 3 | Security Mailbox Automation | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR | 7 | 9,893 |
| 4 | Case Management & SOAR (Internal MDR Platform) | SOC | Agentic SOC, Case mgmt & SOAR, Alert enrichment / IOC lookup, Phishing detection & response, EDR containment & response | 24 | 0 |
| 5 | Automated Account Management & HR Systems Sync | IAM | Identity sync & directory mgmt, Full employee lifecycle, Identity lifecycle automation | 16 | 3,883 |
| 6 | Employee Offboarding | IAM | Employee offboarding, Full employee lifecycle | 18 | 30 |
| 7 | GitLab SaaS Access Management | IAM | Access review & group mgmt, Identity lifecycle automation | 13 | 257 |
| 8 | JIT Privileged Access Management (Portal Okta) | IAM | JIT & temporary access, Privileged account mgmt | 7 | 989 |
| 9 | Customer Portal User Deprovisioning (CDP/Okta) | IAM | Employee offboarding, Identity lifecycle automation | 12 | 11,552 |
| 10 | eShare Client Site & Access Management | Other | SaaS / IT administration, Customer registry & FinOps auto | 7 | 1,397 |
| 11 | Threat Intelligence & Code Security | SOC / GRC | Threat intel ingest & curation, DLP triage & exposure resp, DevSecOps compliance | 9 | 2,612 |
| 12 | B2B Customer Onboarding | Other | Customer registry & FinOps auto | 4 | 0 |
| 13 | IT Operations & Credential Hygiene | Other / IAM | Endpoint hygiene & MDM ops, Password & credential lifecycle, SaaS / IT administration | 10 | 296 |
| 14 | GCCH Account Provisioning (Public Sector) | IAM | Employee onboarding, Identity lifecycle automation | 2 | 0 |
| 15 | Sec-Eng Privileged Access Management (Entra ID) | IAM | JIT & temporary access, Privileged account mgmt | 3 | 14 |
| 16 | Agentic SecEng Ticket Triage | SOC | Agentic SOC, Case mgmt & SOAR | 1 | 40 |
Use Cases
1. Security Alert Triage & Escalation
Description: Ingests security alerts from eight or more disparate platforms, normalizes payloads, checks for duplicate events and rate-threshold violations, then creates Jira tickets and sends Slack notifications. A shared sub-flow handles Jira ticket creation with custom formatting, deduplication table writes, and Slack notification delivery for every inbound alert source.
Business problem solved: Alert fatigue from multiple disconnected security tools. Without automation, analysts manually triage alerts from email security, cloud posture, identity, and data security platforms, each with its own format and severity scale.
Integrations: Sublime Security, Microsoft Entra ID, Obsidian Security, Varonis, Wiz, Mimecast, Keeper Security, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Jira, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Sublime Security BV LLC | 1,437 | Event trigger |
| Sublime Security BVGS | 172 | Event trigger |
| BV LLC Entra Alerts | 2,182 | Polling trigger |
| BVGS GCC Entra Alerts | 16 | Polling trigger |
| Obsidian Threat Alerts | 186 | Webhook |
| Obsidian Posture Alerts | 29 | Webhook |
| Obsidian Integration Alerts | 54 | Webhook |
| Varonis Alerts | 8 | Webhook |
| Wiz BV LLC - Threats | 13 | Webhook |
| Wiz BV LLC - Issues | 3 | Webhook |
| Mimecast Outbound Personal Alerts | 496 | Polling trigger |
| Keeper Security Alerts | 0 | Webhook |
| Conquest Commercial Microsoft Cloud App Alert | 0 | Polling trigger |
| Conquest Commercial Defender for Endpoint Alert | 0 | Polling trigger |
| Mail received in BVGS Security Mailbox | 0 | Polling trigger |
| JIRA/Slack Alerting Sub-Flow | 4,677 | Subflow |
| Alert Threshold Check | 4,671 | Subflow |
| Check If Duplicate Event | 4,671 | Subflow |
| Linking Duplicate JIRA Alert Tickets | 3,123 | Polling trigger |
| Health Monitoring for Alerting Failures | 40 | Scheduled |
| IR Process Slack Channel Creation | 5 | Webhook |
2. Physical Security Monitoring
Description: Routes Verkada physical security events (camera motion triggers, access control badge events, alarms) into the same Jira/Slack alerting pipeline used for cyber alerts, providing a unified security operations view across physical and digital environments.
Business problem solved: Physical security events were siloed from the cyber SOC workflow. Connecting Verkada to the central Jira/Slack pipeline enables unified incident tracking regardless of whether the trigger is a phishing email or an unauthorized badge swipe.
Integrations: Verkada, Jira, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Verkada Access Control Alerts | 3,252 | Webhook |
| Verkada Camera Security Alerts | 3 | Webhook |
| Verkada Alarms Alerts | 0 | Webhook |
3. Security Mailbox Automation
Description: Monitors the corporate security inbox for inbound emails from specific security vendor sources and automatically routes them to the corresponding sub-folders using per-vendor trigger criteria. A parallel workflow processes foreign travel laptop requests from Jira, applying country-based security approval logic.
Business problem solved: A high-volume shared security inbox receiving notifications from Okta, Mimecast, Jira, Palo Alto, and Cloudflare requires manual sorting. Automation keeps the inbox clean and enforces consistent categorization at scale.
Integrations: Microsoft Outlook, Okta, Mimecast, Jira, Palo Alto, Cloudflare
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Sec Inbox Move Mail Rule - Okta | 1,967 | Polling trigger |
| Sec Inbox Move Mail Rule - Jira | 1,981 | Polling trigger |
| Sec Inbox Move Mail Rule - Palo Alto | 1,995 | Polling trigger |
| Sec Inbox Move Mail Rule - Cloudflare | 1,977 | Polling trigger |
| Sec Inbox Move Mail Rule - Mimecast | 1,961 | Polling trigger |
| Mail received in BVGS Security Mailbox | 0 | Polling trigger |
| Foreign travel internal security review | 12 | Polling trigger |
4. Case Management & SOAR (Internal MDR Platform)
Description: A full-stack SOC automation platform built on top of Blink's native case management module. Processes incoming CrowdStrike alerts, extracts and deduplicates observables (IPs, URLs, file hashes, usernames, email addresses), enriches them in parallel across VirusTotal, AbuseIPDB, URLScan, Okta, Entra ID, Google Workspace, and GitHub, then routes cases through specialized response subflows for phishing and malware incident types. Includes recovery workflows for unprocessed alerts and un-enriched observables.
Business problem solved: SOC analysts handling CrowdStrike and email-based alerts spend significant manual effort on observable extraction, enrichment lookups across multiple consoles, and case deduplication. This platform automates the entire triage-to-response pipeline.
Integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, GitHub, Microsoft Outlook, Slack
5. Automated Account Management & HR Systems Sync
Description: End-to-end identity lifecycle automation driven by ADP HR events. ADP changes (new hires, transfers, terminations) arrive via webhook and fan out to provision or update accounts in Okta, Microsoft Entra ID, and Mimecast. A separate AAM engine monitors lifecycle state and processes Entra-specific account creation and followup events. Supporting workflows handle manager assignment from Jira, Slack-to-Okta timezone synchronization, and Mimecast directory sync.
Business problem solved: Employee lifecycle changes originating in ADP required manual propagation to identity systems, introducing provisioning delays and de-provisioning gaps. The ADP webhook integration eliminates this lag and the AAM engine ensures cross-platform consistency.
Integrations: ADP, Okta (multiple tenants), Microsoft Entra ID, Mimecast, Slack, Jira, AWS Lambda
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Webhook Based ADP to Okta Sync - Prod | 1,387 | Webhook |
| AAM - 2. Processor - Followup | 1,925 | Scheduled |
| AAM - Lifecycle Controller - 0. Activity Monitor | 161 | Scheduled |
| Automatically Assign Manager From Jira Ticket | 245 | Webhook |
| AAM - 0. Initiator - BlueVoyant Okta | 14 | Webhook |
| AAM - 1. Processor - Entra | 14 | Polling trigger |
| Platform Workflow - Entra - Create | 12 | Polling trigger |
| Slack to Okta - TimeZone Sync | 40 | Scheduled |
| Mimecast Sync | 8 | Webhook |
| BV Demo Azure Tenant - Create User / Add or Remove Group / Disable Account | 19 | Webhook |
| Support - Generate Event Contract | 56 | Subflow |
| Start Lambda ADP to Okta Sync | 2 | On-demand |
| Okta employee event intake | 0 | Webhook |
| Panopticon - Okta - Manage Employee Records | 0 | On-demand |
| Support - Notify on dead letter | 0 | Polling trigger |
6. Employee Offboarding
Description: Multi-step offboarding automation that collects employee profiles from Okta, JAMF, and Microsoft Entra ID (including GDAP and onmicrosoft accounts), presents a Slack DM approval to both the triggering manager and a confirming user, then executes destructive offboarding actions: session revocation, password expiry, group removal, and device lock across all three platforms. A parallel workflow handles Salesforce-driven offboarding events. Implementations exist for both commercial and global entity environments.
Business problem solved: Offboarding required a security team member to manually coordinate across Okta, JAMF, and Entra. Missed steps left accounts active or devices unlocked. Dual-authorization via Slack ensures no offboarding runs without confirmation.
Integrations: Okta, JAMF, Microsoft Entra ID, Slack, Jira
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Offboarding - Data gathering | 0 | Web form |
| Offboarding - Destructive actions | 0 | Webhook |
| Ask Y/N DM question | 23 | Subflow |
| Okta - Offboarding data gathering | 0 | Subflow |
| JAMF - Offboarding data gathering | 0 | Subflow |
| Entra - Offboarding data gathering | 0 | Subflow |
| Okta - Offboard target | 0 | Subflow |
| JAMF - Offboard Target | 0 | Subflow |
| Entra - Offboard target | 0 | Subflow |
| Log to Jira ticket and slack (Commercial) | 0 | Subflow |
| Okta Salesforce Offboarding - Slack Notification AND Jira Ticket | 7 | Webhook |
| Okta Offboarding Certina And Xactly - Slack Notification AND Jira Ticket | 0 | Webhook |
| Okta - Offboarding data gathering (Global) | 0 | Subflow |
| JAMF - Offboarding data gathering (Global) | 0 | Subflow |
| Entra - Offboarding data gathering (Global) | 0 | Subflow |
| Okta - Offboard target (Global) | 0 | Subflow |
| JAMF - Offboard Target (Global) | 0 | Subflow |
| Log to Jira ticket and slack (Global) | 0 | Subflow |
7. GitLab SaaS Access Management
Description: Manages GitLab repository membership for employees via a Jira-driven intake. When a membership change request is submitted in Jira, the workflow validates the user against Okta, queues the request in a SaaS access waitlist table, and processes it on a weekday schedule. Supports both cloud and on-premise GitLab instances. A Panopticon event model captures all membership state changes for auditability.
Business problem solved: Developer access provisioning to GitLab repositories required manual back-and-forth between IT and security, with no queue management or audit trail. The waitlist model decouples request intake from fulfillment and ensures every change is logged.
Integrations: GitLab (cloud + on-prem), Jira, Okta, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Gitlab user.membership.update command | 44 | Webhook |
| Service - Schedule user membership waitlist | 44 | Webhook |
| Service - process SaaS waitlist entries | 57 | Webhook |
| Gitlab - Send process waitlist webhooks | 38 | Scheduled |
| V1 - Manage user codebase membership | 34 | On-demand |
| Prep gitlab add-project inputs | 17 | Subflow |
| Okta - request addition of okta group | 23 | Subflow |
| Generate Panopticon event | 128 | Subflow |
| Gitlab domain is on-prem | 67 | Utility |
| V1 - Manage user codebase membership on-prem | 0 | On-demand |
| WIP - Gitlab - Event model | 0 | Subflow |
| New Blink Self-Service Group mapping | 0 | On-demand |
| SpiceDB container maybe | 0 | Webhook |
8. JIT Privileged Access Management (Portal Okta)
Description: A self-service just-in-time privileged access system for Portal Okta. Users request elevated roles via a web form with justification. The system checks current active grants, applies the role via Okta group membership, records the grant in a state table, and uses an hourly monitor to automatically revoke access when windows expire. An access cleanup workflow enforces removal and session revocation.
Business problem solved: Standing privileged access to the customer portal's Okta instance created unnecessary risk. JIT with automatic expiry enforces least-privilege without requiring manual IT involvement for every short-term access need.
Integrations: Okta, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Request Portal Okta Admin Access | 7 | Web form |
| Add/Update PAM access to user | 5 | Web form |
| Apply permissions | 7 | Subflow |
| Access Removal monitor | 963 | Scheduled |
| Permissions cleanup | 7 | Polling trigger |
| Add PAM access request app from users | 0 | Polling trigger |
| Remove PAM request app from users with no permissions | 0 | Polling trigger |
9. Customer Portal User Deprovisioning (CDP/Okta)
Description: Web form-driven workflow allowing operations staff to request bulk deletion of users from the Customer Delivery Platform (CDP) and/or Portal Okta. Requests are queued with approval state; a polling trigger detects approved records and executes the deletions. SSO troubleshooting and IdP configuration tooling lives in the same workspace.
Business problem solved: Removing inactive or churned customer users from the portal required manual coordination between ops and identity teams, with no audit trail. The approval-gated automation ensures deletions are authorized, logged, and complete.
Integrations: Okta, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| DESTRUCTIVE - Post-Approval Process | 11,549 | Polling trigger |
| Get IdP status | 3 | Scheduled |
| START - Webform - User deletion request | 0 | Web form |
| Okta - Checks | 0 | Subflow |
| CDP - Checks | 0 | Subflow |
| CDP - Delete | 0 | Subflow |
| Okta - Delete | 0 | Subflow |
| Slack Approval and notifications | 0 | Subflow |
| SSO Troubleshooting - Okta | 0 | Web form |
| Query IdP Configurations | 0 | Web form |
| Query IdP Configurations - JSON web form | 0 | Web form |
| Okta - query user record (portal) | 0 | Subflow |
10. eShare Client Site & Access Management
Description: Automates the full lifecycle of eShare (SharePoint-backed secure file sharing) sites used for client deliverables. Covers provisioning new client or vendor sites with Microsoft Graph group setup and folder structure creation, a self-service access request form with Slack-delivered links, time-limited access grants with an hourly automated cleanup cycle, and a daily scanner that syncs the site inventory to a tracking table. SharePoint site monitoring runs on a daily schedule.
Business problem solved: eShare site creation required multi-step Microsoft Graph and eShare API calls performed manually by IT. Temporary access grants had no enforcement mechanism, leading to stale access accumulating over time.
Integrations: Microsoft Graph API, SharePoint, eShare, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Check and remove eShare temporary access | 963 | Scheduled |
| Request eShare client site access | 285 | On-demand |
| New Workflow (SharePoint site monitor) | 41 | Scheduled |
| Scan for eShare client sites | 40 | Scheduled |
| Create an eShare client site | 34 | On-demand |
| Create eShare service folders | 31 | Subflow |
| Create an eShare vendor site | 3 | On-demand |
11. Threat Intelligence & Code Security
Description: Covers two threat-facing automation streams: (1) threat intelligence ingestion from OpenCTI — daily queries for email observables, domain/IP list generation, and posting to downstream parsers; (2) DLP alerting for PII and secrets detected in code repositories by Wiz, routing 2,528 findings to the security team over the past year. On-demand OSINT tooling for Entra tenant lookups and ReversingLabs IOC queries (hash, IP, URL) rounds out the use case.
Business problem solved: Threat intel feeds and code security scans produce raw findings that need processing and routing before they are actionable. Manual handling introduces delays and inconsistency.
Integrations: Wiz, OpenCTI, ReversingLabs, Microsoft Entra ID, Jira, Slack
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Alert on PII/Secrets in Wiz Code | 2,528 | Webhook |
| OpenCTI Email Observables Query | 40 | Scheduled |
| Generate domain and email lists | 39 | Webhook |
| Entra Tenant OSINT | 5 | On-demand |
| Joesneyland web form (IOC lookup portal) | 0 | Web form |
| ReversingLabs query | 0 | Subflow |
| Joesneyland - IP report | 0 | Subflow |
| Joesneyland - File hash report | 0 | Subflow |
| Joesneyland - URL report | 0 | Subflow |
12. B2B Customer Onboarding
Description: Self-service web form for onboarding new managed service customers into the Azure B2B tenant. Captures customer name, Salesforce ID, Azure tenant ID, region, service level, and public sector flag; generates a customer UUID; checks for existing registrations; and posts to a tracking table. A Jira-webhook variant initiates the flow from an existing ticketing process with Slack notification and Panopticon event logging.
Business problem solved: Each new B2B customer required manual Azure admin consent configuration and registration. The web form plus automated registration pipeline removes the IT dependency from an operationally critical onboarding step.
Integrations: Jira, Slack, Microsoft Azure (admin consent), Salesforce
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Onboard New Customer | 0 | Web form |
| START - New B2B Customer | 0 | Webhook |
| Write to B2B workspace table | 0 | Webhook |
| Generate Panopticon event (B2B) | 0 | Subflow |
13. IT Operations & Credential Hygiene
Description: A collection of IT hygiene automations: weekly monitoring of Okta API token expiry across corporate and portal environments with Slack alerting; daily Microsoft 365 license utilization monitoring; recurring Jira asset sync from Python-driven service; and JAMF-based Mac endpoint management including self-service lock/wipe, group assignment, and admin elevation via web form.
Business problem solved: API token expiry, license over/under-provisioning, and endpoint management tasks were handled ad hoc. Scheduled checks and self-service endpoints reduce IT toil and catch hygiene issues before they become incidents.
Integrations: Okta, Microsoft 365, Microsoft Graph, JAMF, Jira, Slack, AWS
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Jira Asset Sync Service | 241 | Scheduled |
| Microsoft 365 License Monitoring | 40 | Scheduled |
| Corp Okta API tokens | 6 | Scheduled |
| Portal Okta API tokens | 6 | Scheduled |
| Add Macs To Tel Aviv Static Groups | 3 | Web form |
| Lock or Wipe a Mac | 0 | Web form |
| Scope Make Me Admin For 5 Minutes To A Mac | 0 | Web form |
| Delete a Computer from Jamf | 0 | Web form |
| Link Personal Microsoft Learn Account | 0 | Webhook |
14. GCCH Account Provisioning (Public Sector)
Description: Specialized onboarding flow for GovCloud (GCCH / CQ Fed) accounts that validates TalentLMS public sector training completion before creating a new account. Triggered from a Jira automation webhook, it checks ADP for the new hire record and verifies course completion status via the TalentLMS API before proceeding.
Business problem solved: Public sector employees require proof of compliance training before receiving GovCloud access. Without automation, verifying training completion was a manual step prone to being skipped.
Integrations: Okta, Jira, TalentLMS, ADP
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| 01 - GCCH Account Provisioning CQ Fed - Check ADP | 0 | Webhook |
| 02 - GCCH Account Provisioning CQ Fed - Create Account With Checking TalentLMS | 0 | Webhook |
15. Sec-Eng Privileged Access Management (Entra ID)
Description: On-demand tooling giving the Security Engineering team self-service, ticket-linked privileged access. A request flow captures role, service, and session length against a Jira ticket ID and logs the grant to a tracking table; a companion tool resets a user's MFA/GDAP assignment in Entra ID; a timer-based sub-flow enforces automatic removal from the Administrative Unit once the requested session length elapses.
Business problem solved: Security engineers needed ad hoc elevated access to specific roles/services and occasional Entra ID MFA/GDAP remediation, previously requiring direct admin intervention with no consistent expiry. Ticket-linked requests with automatic timer-based revocation reduce standing privileged access while giving Sec-Eng self-service speed.
Integrations: Microsoft Entra ID, Jira
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Manual PIM for Sec-Eng requests | 1 | On-demand |
| Entra ID - Reset MFA/GDAP Assignment | 7 | On-demand |
| SubFlow - Remove from AU timer | 6 | Subflow |
16. Agentic SecEng Ticket Triage
Description: An AI agent ("SecEng Triage Engineer") triggered by inbound Jira security-engineering tickets. The workflow extracts and saves issue details, invokes the agent to analyze the request, posts the agent's findings back to the Jira ticket as a comment, and logs the agent's output to a tracking table for audit and tuning.
Business problem solved: Security Engineering ticket triage previously required a human to read, assess, and respond to every inbound Jira request. An AI triage agent now performs first-pass analysis and commentary automatically, cutting manual triage load while preserving a full audit trail of agent decisions.
Integrations: Jira
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| SecEng Triage Agent | 40 | Webhook |
Key Observations
Strengths
Deep, multi-tenant identity stack. The IAM automation estate spans Okta (corporate, portal, GDAP, GCCH), Microsoft Entra ID (commercial, GovCloud, onmicrosoft), JAMF, and ADP — all wired into a shared event bus. The AAM engine and ADP webhook sync represent a mature, production-grade identity lifecycle pipeline processing thousands of events per year.
Unified alert pipeline across cyber and physical. All security alert sources — email security, cloud posture, identity, data security, and physical access control — feed through the same JIRA/Slack sub-flow with shared deduplication and threshold logic. This yields consistent ticket formatting and a single pane of glass regardless of source, processing over 11,000 combined alert and dedup events in 12 months.
JIT enforcement at scale. The Portal Okta JIT system with automated hourly revocation represents a genuine least-privilege implementation, not just a policy. 963 automated access removal monitor executions over the year demonstrate ongoing enforcement rather than a one-time setup.
eShare lifecycle ownership. The complete create → request → enforce expiry → inventory cycle for eShare client sites is a well-designed closed-loop automation. 963 hourly cleanup runs and 285 fulfilled access requests show this is operationally active.
PII/secrets detection in code. 2,528 Wiz code scanning alerts routed and actioned in 12 months indicates active DevSecOps integration — this is a signal of a mature security program applying shift-left controls.
Agentic triage now live for Sec-Eng tickets. The new SecEng Triage Agent uses an AI agent to analyze inbound Jira security-engineering tickets and auto-comment triage findings, with 40 executions in its first stretch of use — a concrete first step toward the agentic SOC model, distinct from the still-dormant CrowdStrike-based MDR platform noted below.
Gaps
Case Management & SOAR platform shows zero executions. The internal MDR platform (24 workflows covering CrowdStrike alert processing, observable enrichment, and phishing/malware response) has not run in the past 12 months. This is either a pre-production deployment awaiting activation, or it was stood down. The enrichment library (VirusTotal, AbuseIPDB, URLScan, CrowdStrike) is well-structured and ready to activate.
Employee offboarding is underutilized relative to org size. The main offboarding automation (commercial and global combined) shows only 30 executions. Given the scale of the ADP sync (1,387 hire/change events), a significant deprovisioning gap likely exists. The Salesforce-triggered offboarding (7 runs) only covers one HR system trigger path.
B2B and GCCH onboarding workflows are dormant. Zero executions across all B2B customer onboarding and public sector provisioning workflows. These may be in staging, replaced by other processes, or triggered via paths not captured in the execution data.
ReversingLabs IOC portal has never been used in production. The "Joesneyland" analyst IOC lookup tool (hash, IP, URL via ReversingLabs) has zero executions despite being a fully built interactive web form tool. Analyst awareness or integration into the SOC workflow may be missing.
Conquest Commercial alert sources are inactive. Both Defender for Cloud Apps and Defender for Endpoint polling triggers for Conquest Commercial show zero executions — either the integrations are not connected or the tenant has no alerts flowing.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| Security Tools | CrowdStrike, Wiz, Sublime Security, Obsidian Security, Varonis, Mimecast, Keeper Security, VirusTotal, AbuseIPDB, URLScan, ReversingLabs, OpenCTI, Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Verkada, Palo Alto, Cloudflare |
| Identity & Directory | Okta (5+ connection contexts), Microsoft Entra ID (commercial, GCCH, GDAP, onmicrosoft), JAMF, ADP, Mimecast |
| Collaboration & Ticketing | Jira, Slack, Microsoft Outlook, Confluence |
| Cloud & Infrastructure | Microsoft Graph API, SharePoint, eShare, AWS Lambda |
| Business Systems | Salesforce, TalentLMS, GitLab (cloud + on-prem) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.