Blink Security Automation — Confidential

blumira-development — Customer Success Report

Generated 2026-09-10 | blumira-development-value-report.md
2026-09-10Report Date
270Total Playbooks
74Unique Workflows (12m)
19,733,719Actions Automated (12m)
$5,075,545Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

270
Total playbooks built
all non-deleted workflows
185
Active playbooks
currently enabled
74
Unique workflows executed (12m)
distinct workflows that ran
19,733,719
Actions automated (12m)
completed action steps
109,631.8h
Hours saved (12m)
@ 20s per action
$5,075,545
Money saved (12m)
@ $100K avg salary
27
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 57,820 security log ingestion routing cycles executed without analyst involvement - 12,015 security log collection runs across Microsoft 365 and Okta - 31 customer deployment and onboarding operations automated - 8 M365 tenant credentials validated programmatically

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SIEM & Log Ingestion Pipeline
  • 57,820Security log ingestion routing cycles completed
  • 11,068Microsoft 365 audit log batches collected
  • 947Okta identity log batches collected
98.4%
5
2 active
EDR Containment & Endpoint Response0 executions
0.0%
6
6 active
Identity Containment & Session Revocation0 executions
0.0%
8
8 active
Alert Enrichment & IOC Lookup0 executions
0.0%
1
1 active
Password & Credential Lifecycle
  • 8M365 tenant credentials validated
0.1%
2
2 active
Customer Deployment & Onboarding Automation
  • 23Ad-hoc customer workspace deployments automated
  • 8Customer environments provisioned end-to-end
1.5%
6
6 active
Total1,954 executions100%
28
25 active

Use Case Growth Over Time

83 unique playbooks  |  6 operational use cases  |  1,954 total executions (12m)  |  2024-09 to 2026-04
Toggle:
Toggle:

03Integration Ecosystem

Identity Containment & Session Revocation
Microsoft Entra ID String Utilities LimaCharlie
Alert Enrichment & IOC Lookup
VirusTotal Recorded Future
Password & Credential Lifecycle
Microsoft Entra ID
EDR Containment & Endpoint Response
LimaCharlie
SIEM & Log Ingestion Pipeline
Microsoft Office 365 Management Activity GCP Okta

04Key Observations

✓  Strengths

Strengths

1. High-volume, fully automated log pipeline. The SIEM log ingestion pipeline runs continuously without analyst intervention, having executed over 70,000 times in the past 12 months. The minute-level polling cadence and per-vendor collection architecture demonstrate a mature, production-grade log ingestion system that sustains Blumira's core SIEM value proposition for its customers.

2. Comprehensive EDR containment toolkit deployed at scale. Six LimaCharlie-based containment actions — covering process kill, process tree termination, file deletion, and both local and AD user disable — are deployed uniformly across 13+ customer workspaces. This gives the SOC immediate automated containment reach across the entire customer base without per-customer configuration.

3. Defense-in-depth identity response architecture. The identity containment library covers multiple layers: cloud identity session revocation (Entra ID), endpoint-level user disable (LimaCharlie AD/local), and credential pre-flight validation — providing automated response across the full identity stack when a user is compromised.

4. Automated platform operations. Blumira uses Blink to automate its own platform operations — onboarding new customers, deploying playbook updates to all workspaces, and maintaining the connection registry. This reduces the operational burden of managing a multi-tenant Blink environment at scale and is a strong proof point of internal adoption.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. EDR and identity response playbooks are staged but inactive. Despite a well-designed containment library, none of the response playbooks have been invoked in the past 12 months. These appear configured and ready but not yet wired into automated alert-driven triggers. Connecting these to Blumira's detection alerts would immediately activate automated response value without building new workflows.

2. No alert-driven SOAR orchestration layer. The environment lacks a top-level case management or alert triage workflow — a workflow that fires on a new Blumira detection, enriches it, and routes to the appropriate response playbook. Adding this orchestration layer would close the detect-to-respond loop and unlock the full value of the containment library already built.

3. Version proliferation in identity response. Four variants of the disable-and-revoke pattern (v1, v2, v3, copy) coexist alongside the atomized sub-actions (entra_disable_user, entra_revoke_session). Consolidating to a single canonical version with explicit deprecation of older variants would reduce maintenance overhead and analyst confusion.

4. No vulnerability management or GRC workflows. The environment covers SOC response and IAM containment but has no workflows addressing vulnerability scanning ingestion, compliance reporting, or risk automation. These are natural expansion areas given the existing identity and EDR integrations.

5. Test and development artifacts remain in customer workspaces. Nine test and development playbooks (Getting Started - Hello World, Mason_E2E_testing, Test Prowler, etc.) are active across multiple workspaces. Isolating these in a dedicated development workspace would keep the production catalog clean and avoid confusion in the customer-facing environment.

Integration Ecosystem

Integration Use Case Category
Microsoft O365 Management Activity API SIEM log ingestion SOC
Okta SIEM log ingestion SOC
LimaCharlie EDR EDR containment, identity disable SOC
Microsoft Entra ID / Azure AD Identity containment, password lifecycle SOC / IAM
Microsoft Graph API Identity containment, credential validation SOC / IAM
VirusTotal IOC / IP enrichment SOC
Recorded Future IOC / IP enrichment SOC
Blink API Internal deployment & onboarding ops Other
Blink Tables Customer registry, log pipeline state Other
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 6 use cases | 1,954 executions (12m)

Business KPIs

Metric Count Playbook
Security log ingestion routing cycles completed 57,820 Parent - Log Ingestion Router
Microsoft 365 audit log batches collected 11,068 microsoft-o365-management-activity-get-logs
Okta identity log batches collected 947 okta-get-logs
Ad-hoc customer workspace deployments automated 23 Deploy - Ad Hoc
Customer environments provisioned end-to-end 8 customer_blink_onboarding
M365 tenant credentials validated 8 validate_credentials
In the last 12 months, Blink automated: - 57,820 security log ingestion routing cycles executed without analyst involvement - 12,015 security log collection runs across Microsoft 365 and Okta - 31 customer deployment and onboarding operations automated - 8 M365 tenant credentials validated programmatically

Use Case Summary

Use Case Category Subcategory Unique Playbooks Total Executions
SIEM & Log Ingestion Pipeline SOC SIEM & log pipeline monitoring 5 71,766
EDR Containment & Endpoint Response SOC EDR containment & response 6 0
Identity Containment & Session Revocation SOC Identity threat response 8 0
Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 1 0
Password & Credential Lifecycle IAM Password & credential lifecycle 2 8
Customer Deployment & Onboarding Automation Other DevOps & release automation 6 31

Use Cases

1. SIEM & Log Ingestion Pipeline

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: A fully automated, continuous log ingestion pipeline that collects and routes security events from Microsoft 365 and Okta into Blumira's SIEM platform. A scheduled router workflow executes every minute, reads the active log-source connection registry, and dispatches per-vendor collection playbooks to pull the latest audit events.

Business problem solved: Ensures uninterrupted security telemetry from cloud identity and productivity platforms without manual intervention — sustaining SIEM coverage, alert fidelity, and detection freshness at scale.

Integrations: Blink API (connection registry), Microsoft O365 Management Activity API, Okta, Blink internal tables

Playbook Executions (12 mo) Automation Type
Parent - Log Ingestion Router 57,820 Scheduled (every minute)
microsoft-o365-management-activity-get-logs 11,068 On-demand (called by router)
okta-get-logs 947 On-demand (called by router)
SCHEDULED Update Cust Workspaces Global Variable 965 Scheduled (hourly)
Subflow - Update Customer Workspaces Global Variable 966 Subflow

2. EDR Containment & Endpoint Response

Category: SOC | Subcategory: EDR containment & response

Description: A library of LimaCharlie EDR containment actions — kill malicious processes or entire process trees, delete suspected malware files, and disable compromised user accounts at the endpoint level (both local accounts and Active Directory accounts). These playbooks are deployed uniformly across 10+ customer workspaces, ready for one-click or automated invocation from Blumira's detection platform.

Business problem solved: When Blumira detects an active threat on a customer endpoint, analysts can execute surgical containment actions through Blink without switching tools or logging into the EDR console directly — reducing mean time to contain (MTTC).

Integrations: LimaCharlie EDR (sensor management, reliable task execution), Active Directory (via LimaCharlie)

Playbook Executions (12 mo) Automation Type
limacharlie_kill_process 0 On-demand
limacharlie_kill_process_tree 0 On-demand
limacharlie_delete_file 0 On-demand
limacharlie_disable_local_user 0 On-demand
limacharlie_disable_local_user_v5 0 On-demand
limacharlie_disable_ad_user 0 On-demand

*These playbooks are deployed across 13+ customer workspaces. All instances show 0 executions — they are configured and staged for response but have not been invoked in production in the last 12 months.*

3. Identity Containment & Session Revocation

Category: SOC | Subcategory: Identity threat response

Description: A suite of identity containment playbooks that disable compromised accounts, revoke active sessions, and terminate access in Microsoft Entra ID (formerly Azure AD). Multiple versions reflect iterative development of the core disable-and-revoke pattern; newer versions incorporate LimaCharlie endpoint-side disabling alongside cloud identity actions.

Business problem solved: When a user account is compromised or a suspicious authenticated session is detected, analysts can immediately disable the account and invalidate all active tokens — preventing lateral movement, persistent access, and further damage within minutes of detection.

Integrations: Microsoft Entra ID / Azure AD, Microsoft Graph API, LimaCharlie EDR (for endpoint-side disable)

Playbook Executions (12 mo) Automation Type
disable_user_and_revoke_session 0 On-demand
disable_user_and_revoke_session_v2 0 On-demand
disable_user_and_revoke_session_v3 0 On-demand
1-DisableUserandRevokeSession-v1 0 On-demand
DisableUserAndRevokeSession-v2 0 On-demand
entra_disable_user 0 On-demand
entra_revoke_session 0 On-demand
disable_user_and_revoke_session copy 0 On-demand

*The atomic sub-actions (entra_disable_user, entra_revoke_session) are deployed across 15+ customer workspaces as composable building blocks for the combined disable-and-revoke workflows.*

4. Alert Enrichment & IOC Lookup

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: Automated IP address reputation enrichment that queries VirusTotal and Recorded Future in parallel, then branches on the verdict to flag whether the IP is malicious. Designed as a callable enrichment step within broader alert triage workflows.

Business problem solved: Eliminates manual context switching and lookup time during alert triage by delivering automated, multi-source threat intelligence verdicts directly within the response flow.

Integrations: VirusTotal, Recorded Future

Playbook Executions (12 mo) Automation Type
VT-RF CheckIP 0 On-demand

5. Password & Credential Lifecycle

Category: IAM | Subcategory: Password & credential lifecycle

Description: Automated M365 tenant credential validation and forced password reset. validate_credentials verifies that a tenant's client ID and connection configuration are valid before executing downstream containment actions. entra_reset_password forces an immediate password change on a targeted Entra ID user account.

Business problem solved: Ensures automated identity response actions execute against validated, live tenant credentials — preventing silent failures in containment workflows due to stale or misconfigured connection settings.

Integrations: Microsoft Entra ID, Microsoft Graph API

Playbook Executions (12 mo) Automation Type
validate_credentials 8 On-demand
entra_reset_password 0 On-demand

*validate_credentials is deployed across 17 customer workspaces as a pre-flight check called by identity response workflows.*

6. Customer Deployment & Onboarding Automation

Category: Other | Subcategory: DevOps & release automation, Customer registry & FinOps auto

Description: Internal automation managing the full lifecycle of deploying Blink playbooks to customer workspaces and provisioning new customer environments. Covers staged deployment (staging environment), targeted ad-hoc deployments to specific customer workspaces, bulk deployment to all customers, and end-to-end customer onboarding that creates and validates new tenant setups.

Business problem solved: Eliminates manual, error-prone deployment of security automation playbooks across a large and growing customer base — enabling Blumira's team to ship and update response capabilities to all customers at scale, without per-customer manual steps.

Integrations: Blink API, Blink Tables (customer workspace registry), HTTP (internal APIs)

Playbook Executions (12 mo) Automation Type
customer_blink_onboarding 8 On-demand
Deploy - Ad Hoc 23 On-demand
Deploy - Staging 0 On-demand
Deploy - Overwrite Existing Versions 0 On-demand
Deploy - All Customers 0 On-demand
Fail Forward - Workflow Deployment Ad Hoc 0 On-demand

Key Observations

Strengths

1. High-volume, fully automated log pipeline. The SIEM log ingestion pipeline runs continuously without analyst intervention, having executed over 70,000 times in the past 12 months. The minute-level polling cadence and per-vendor collection architecture demonstrate a mature, production-grade log ingestion system that sustains Blumira's core SIEM value proposition for its customers.

2. Comprehensive EDR containment toolkit deployed at scale. Six LimaCharlie-based containment actions — covering process kill, process tree termination, file deletion, and both local and AD user disable — are deployed uniformly across 13+ customer workspaces. This gives the SOC immediate automated containment reach across the entire customer base without per-customer configuration.

3. Defense-in-depth identity response architecture. The identity containment library covers multiple layers: cloud identity session revocation (Entra ID), endpoint-level user disable (LimaCharlie AD/local), and credential pre-flight validation — providing automated response across the full identity stack when a user is compromised.

4. Automated platform operations. Blumira uses Blink to automate its own platform operations — onboarding new customers, deploying playbook updates to all workspaces, and maintaining the connection registry. This reduces the operational burden of managing a multi-tenant Blink environment at scale and is a strong proof point of internal adoption.

Gaps & Opportunities

1. EDR and identity response playbooks are staged but inactive. Despite a well-designed containment library, none of the response playbooks have been invoked in the past 12 months. These appear configured and ready but not yet wired into automated alert-driven triggers. Connecting these to Blumira's detection alerts would immediately activate automated response value without building new workflows.

2. No alert-driven SOAR orchestration layer. The environment lacks a top-level case management or alert triage workflow — a workflow that fires on a new Blumira detection, enriches it, and routes to the appropriate response playbook. Adding this orchestration layer would close the detect-to-respond loop and unlock the full value of the containment library already built.

3. Version proliferation in identity response. Four variants of the disable-and-revoke pattern (v1, v2, v3, copy) coexist alongside the atomized sub-actions (entra_disable_user, entra_revoke_session). Consolidating to a single canonical version with explicit deprecation of older variants would reduce maintenance overhead and analyst confusion.

4. No vulnerability management or GRC workflows. The environment covers SOC response and IAM containment but has no workflows addressing vulnerability scanning ingestion, compliance reporting, or risk automation. These are natural expansion areas given the existing identity and EDR integrations.

5. Test and development artifacts remain in customer workspaces. Nine test and development playbooks (Getting Started - Hello World, Mason_E2E_testing, Test Prowler, etc.) are active across multiple workspaces. Isolating these in a dedicated development workspace would keep the production catalog clean and avoid confusion in the customer-facing environment.

Integration Ecosystem

Integration Use Case Category
Microsoft O365 Management Activity API SIEM log ingestion SOC
Okta SIEM log ingestion SOC
LimaCharlie EDR EDR containment, identity disable SOC
Microsoft Entra ID / Azure AD Identity containment, password lifecycle SOC / IAM
Microsoft Graph API Identity containment, credential validation SOC / IAM
VirusTotal IOC / IP enrichment SOC
Recorded Future IOC / IP enrichment SOC
Blink API Internal deployment & onboarding ops Other
Blink Tables Customer registry, log pipeline state Other
E New Integrations (detail) 3 added in last 30d

New Integrations Added - Last 30 Days

3 new connections
TenantIntegrationConnection NameAdded
blumira-development active-directory active_directory_a31fbabf_248f_47bb_a7ea_ce38712b3104 2026-08-21
blumira-development active-directory active_directory_8055b737_5acf_4236_a55a_7c16a95f7461 2026-08-21
blumira-development active-directory active_directory_32cda33c_b961_405d_b4ef_8de974932851 2026-08-20