Blink Security Automation — Confidential

blumira-production — Customer Success Report

Generated 2026-09-10 | blumira-production-value-report.md
2026-09-10Report Date
5125Total Playbooks
396Unique Workflows (12m)
64,986Actions Automated (12m)
$16,715Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

5125
Total playbooks built
all non-deleted workflows
5113
Active playbooks
currently enabled
396
Unique workflows executed (12m)
distinct workflows that ran
64,986
Actions automated (12m)
completed action steps
361.0h
Hours saved (12m)
@ 20s per action
$16,715
Money saved (12m)
@ $100K avg salary
252
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 76 customer environments activated and provisioned on the MDR platform - 14 malicious files removed from customer endpoints via LimaCharlie EDR - 7 compromised user accounts disabled and active sessions revoked - 3 active threat process trees terminated and contained on customer endpoints - 1 malicious process terminated on a customer endpoint - 3 Entra ID sessions force-revoked for at-risk users

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
MSSP Platform Operations & Customer Onboarding
  • 76Customer environments activated on the MDR platform
82.1%
5
5 active
Playbook Deployment & Release Automation427 executions
17.3%
6
6 active
EDR Endpoint Containment
  • 14Malicious files removed from customer endpoints
  • 3Active threat process trees terminated on endpoints
  • 1Malicious processes terminated on customer endpoints
0.1%
3
3 active
Identity Threat Response
  • 7Compromised accounts disabled and sessions terminated
  • 3Entra ID sessions force-revoked for at-risk users
0.4%
6
6 active
Total2,462 executions100%
20
20 active

Use Case Growth Over Time

22 unique playbooks  |  4 operational use cases  |  2,462 total executions (12m)  |  2024-12 to 2026-04
Toggle:
Toggle:

03Integration Ecosystem

Identity Threat Response
Microsoft Entra ID LimaCharlie
MSSP Platform Operations & Customer Onboarding
Microsoft Entra ID Slack
EDR Endpoint Containment
LimaCharlie

04Key Observations

✓  Strengths

Strengths

Production-scale multi-tenant MSSP architecture. The deployment model is architected for scale: a single master workspace manages provisioning and rollout to 558 customer workspaces, each with a consistent, standardized set of response playbooks. The automated onboarding pipeline (76 customers provisioned in 12 months) and hourly workspace sync demonstrate a mature, automated operations layer.

Dual-vector identity containment coverage. The identity response suite covers both cloud (Entra ID) and on-premises (Active Directory via LimaCharlie sensor) attack surfaces in a single coordinated playbook (disable_user_and_revoke_session_v4). This eliminates the risk of revoking cloud sessions while leaving on-prem credentials intact — a critical

△  Gaps & Growth Opportunities

gap in many MDR response programs.

EDR containment at machine speed. File deletion and process termination actions are wired directly to LimaCharlie's reliable task API, enabling sub-minute endpoint response across the entire customer base. These playbooks are deployed and armed in 558 customer environments.

Robust release engineering pipeline. The deployment automation (staging ingestion, multi-customer rollout, version overwrite, failure recovery) mirrors enterprise DevOps practices. This infrastructure enables Blumira to continuously improve and ship response playbooks across their entire customer base without manual per-workspace work.

Gaps & Opportunities

Response playbook activation rate is low relative to scale. 558 customer workspaces have response playbooks deployed, yet only a handful of EDR and identity containment actions have fired. Playbooks for entra_disable_user, limacharlie_disable_ad_user, and limacharlie_disable_local_user have zero executions. If these are expected to fire on detections, the integration wiring from Blumira's SIEM/detection layer into Blink should be reviewed.

No alert enrichment or IOC lookup automation. There are no workflows for threat intelligence enrichment, indicator lookups, or automated alert triage. Adding enrichment playbooks (VirusTotal, Shodan, threat intel feeds) before containment actions would improve decision quality and reduce false-positive containment.

No case management or ticketing integration. Containment actions fire silently — there is no SOAR-style case creation, ticket update (e.g., Jira, ServiceNow), or analyst notification wired to response outcomes. Adding post-action notifications and case updates would improve SOC visibility and audit trail.

Cloud security and vulnerability management are absent. No playbooks exist for CSPM triage, cloud misconfiguration remediation, or vulnerability scan ingestion. As Blumira expands its MDR offering, these are natural adjacencies.

Integration Ecosystem

Integration Usage
LimaCharlie EDR Endpoint containment — file deletion, process termination, AD user disable, local user disable
Microsoft Entra ID / Azure AD Cloud identity containment — user disable, session revocation
Active Directory (on-prem) On-prem identity containment via LimaCharlie domain controller sensor
Blink Platform API Cross-workspace orchestration — staging-to-production promotion, multi-customer deployment
Slack Ops alerting — onboarding failure notifications
HTTP / REST Internal data tables — customer registry, deployment logs, workspace inventory
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 4 use cases | 2,462 executions (12m)

Business KPIs

Metric Count Playbook
Customer environments activated on the MDR platform 76 customer_blink_onboarding
Malicious files removed from customer endpoints 14 limacharlie_delete_file
Compromised accounts disabled and sessions terminated 7 disable_user_and_revoke_session_v4
Active threat process trees terminated on endpoints 3 limacharlie_kill_process_tree
Malicious processes terminated on customer endpoints 1 limacharlie_kill_process
Entra ID sessions force-revoked for at-risk users 3 entra_revoke_session
In the last 12 months, Blink automated: - 76 customer environments activated and provisioned on the MDR platform - 14 malicious files removed from customer endpoints via LimaCharlie EDR - 7 compromised user accounts disabled and active sessions revoked - 3 active threat process trees terminated and contained on customer endpoints - 1 malicious process terminated on a customer endpoint - 3 Entra ID sessions force-revoked for at-risk users

Use Case Summary

# Use Case Category Total Playbooks Active (Executions > 0)
1 MSSP Platform Operations & Customer Onboarding Other 5 4
2 Playbook Deployment & Release Automation Other 6 0
3 EDR Endpoint Containment SOC 3 3
4 Identity Threat Response SOC 6 2
Total 20 9

Use Cases

1. MSSP Platform Operations & Customer Onboarding

Description: Automates the full lifecycle of onboarding new customer environments onto the Blumira MDR platform. Each run provisions a new customer workspace in Blink, configures integrations, and validates credentials — turning a multi-step manual process into a single automated flow.

Business problem solved: Blumira delivers MDR services to hundreds of customers. Manual provisioning of each customer's Blink response environment is operationally expensive and error-prone. Automation ensures consistent, repeatable onboarding with built-in error alerting and real-time workspace inventory.

Taxonomy: Other → Customer registry & FinOps auto, SaaS / IT administration

Playbook Executions (12 mo) Notes
customer_blink_onboarding 76 Top-level onboarding orchestrator; creates customer workspace, configures integrations
validate_credentials 168 (182 instances) Validates customer integration credentials; deployed per customer workspace
SCHEDULED Update Cust Workspaces Global Variable 962 Hourly scheduler that refreshes the live customer workspace inventory
Subflow - Update Customer Workspaces Global Variable 961 Subflow: fetches workspace records and updates the global variable
Customer Onboarding Failure Notification 0 Triggers on onboarding errors; sends Slack alert to ops team

Key integrations: Blink platform API (cross-workspace), HTTP/REST (internal data tables), Slack

2. Playbook Deployment & Release Automation

Description: A CI/CD pipeline for managing the lifecycle of response playbooks across all 558+ customer workspaces. Covers ingestion of new playbooks from a staging environment, multi-tenant deployment (ad hoc or bulk), version management, and failure recovery.

Business problem solved: As Blumira develops and improves response playbooks, distributing updates to hundreds of customer workspaces manually is unsustainable. This pipeline automates promotion from staging to production, deployment to selected or all customers, and safe version overwriting — with error recovery to prevent partial deployments from leaving workspaces in an inconsistent state.

Taxonomy: Other → DevOps & release automation

Playbook Executions (12 mo) Notes
Ingest Staging Push Request 0 Webhook-triggered; promotes a workflow from staging to production and submits for approval
Deploy - All Customers 0 Deploys a workflow version to every customer workspace
Deploy - Ad Hoc 0 Deploys a workflow to a targeted subset of customer workspaces
Deploy - Overwrite Existing Versions 0 Force-overwrites an already-deployed version across affected customer workspaces
Fail Forward - Workflow Deployment Ad Hoc 0 Retries and recovers failed deployments for individual customer workspaces
Mason_E2E_testing 0 End-to-end platform testing automation (9 test instances deployed)

Key integrations: Blink platform API (staging and production cross-connect), HTTP/REST (deployment log tables)

3. EDR Endpoint Containment

Description: Automated endpoint response actions executed via LimaCharlie EDR on behalf of customer environments when threats are detected. Actions include terminating malicious processes and removing hostile files — all orchestrated without analyst intervention.

Business problem solved: When Blumira's detection engine identifies active malware or a compromised process on a customer endpoint, immediate containment is critical. These playbooks perform surgical EDR actions (file deletion, process termination) automatically and at machine speed, reducing dwell time and limiting blast radius before a human analyst reviews the incident.

Taxonomy: SOC → EDR containment & response

Playbook Executions (12 mo) Deployed Instances Notes
limacharlie_delete_file 14 566 Deletes a specified file from an endpoint via LimaCharlie reliable task
limacharlie_kill_process_tree 3 566 Terminates a full process tree on an endpoint (parent + child processes)
limacharlie_kill_process 1 566 Terminates a single process on an endpoint via LimaCharlie reliable task

Key integrations: LimaCharlie EDR (sensor-level actions via reliable task API)

4. Identity Threat Response

Description: Automated identity containment actions covering both cloud identity (Microsoft Entra ID / Azure AD) and on-premises Active Directory via LimaCharlie's endpoint-resident sensor. Actions include disabling accounts, killing active sessions, and revoking cloud authentication tokens — all deployable across 558 customer workspaces.

Business problem solved: Identity-based attacks — account takeover, lateral movement via compromised credentials — require immediate containment. These playbooks automatically disable the compromised account and revoke all active sessions (cloud and on-prem) the moment a threat is confirmed, drastically cutting the window of attacker access without waiting for analyst intervention.

Taxonomy: SOC → Identity threat response

Playbook Executions (12 mo) Deployed Instances Notes
disable_user_and_revoke_session_v4 7 566 Full containment: disables AD account via LimaCharlie sensor + revokes Entra session
entra_revoke_session 3 567 Revokes all active Microsoft Entra ID / Azure AD sessions for a user
entra_disable_user 0 567 Disables a user account in Entra ID; available, not yet activated
limacharlie_disable_ad_user 0 566 Disables an on-premises Active Directory user via LimaCharlie domain controller runner
limacharlie_disable_local_user 0 567 Disables a local system account on an endpoint via LimaCharlie sensor
disable_user_and_revoke_session 0 1 Prior version (v3); superseded by v4

Key integrations: Microsoft Entra ID / Azure AD (Graph API), LimaCharlie EDR (domain controller & endpoint sensor), Active Directory (on-prem via LimaCharlie reliable task)

Key Observations

Strengths

Production-scale multi-tenant MSSP architecture. The deployment model is architected for scale: a single master workspace manages provisioning and rollout to 558 customer workspaces, each with a consistent, standardized set of response playbooks. The automated onboarding pipeline (76 customers provisioned in 12 months) and hourly workspace sync demonstrate a mature, automated operations layer.

Dual-vector identity containment coverage. The identity response suite covers both cloud (Entra ID) and on-premises (Active Directory via LimaCharlie sensor) attack surfaces in a single coordinated playbook (disable_user_and_revoke_session_v4). This eliminates the risk of revoking cloud sessions while leaving on-prem credentials intact — a critical gap in many MDR response programs.

EDR containment at machine speed. File deletion and process termination actions are wired directly to LimaCharlie's reliable task API, enabling sub-minute endpoint response across the entire customer base. These playbooks are deployed and armed in 558 customer environments.

Robust release engineering pipeline. The deployment automation (staging ingestion, multi-customer rollout, version overwrite, failure recovery) mirrors enterprise DevOps practices. This infrastructure enables Blumira to continuously improve and ship response playbooks across their entire customer base without manual per-workspace work.

Gaps & Opportunities

Response playbook activation rate is low relative to scale. 558 customer workspaces have response playbooks deployed, yet only a handful of EDR and identity containment actions have fired. Playbooks for entra_disable_user, limacharlie_disable_ad_user, and limacharlie_disable_local_user have zero executions. If these are expected to fire on detections, the integration wiring from Blumira's SIEM/detection layer into Blink should be reviewed.

No alert enrichment or IOC lookup automation. There are no workflows for threat intelligence enrichment, indicator lookups, or automated alert triage. Adding enrichment playbooks (VirusTotal, Shodan, threat intel feeds) before containment actions would improve decision quality and reduce false-positive containment.

No case management or ticketing integration. Containment actions fire silently — there is no SOAR-style case creation, ticket update (e.g., Jira, ServiceNow), or analyst notification wired to response outcomes. Adding post-action notifications and case updates would improve SOC visibility and audit trail.

Cloud security and vulnerability management are absent. No playbooks exist for CSPM triage, cloud misconfiguration remediation, or vulnerability scan ingestion. As Blumira expands its MDR offering, these are natural adjacencies.

Integration Ecosystem

Integration Usage
LimaCharlie EDR Endpoint containment — file deletion, process termination, AD user disable, local user disable
Microsoft Entra ID / Azure AD Cloud identity containment — user disable, session revocation
Active Directory (on-prem) On-prem identity containment via LimaCharlie domain controller sensor
Blink Platform API Cross-workspace orchestration — staging-to-production promotion, multi-customer deployment
Slack Ops alerting — onboarding failure notifications
HTTP / REST Internal data tables — customer registry, deployment logs, workspace inventory
E New Integrations (detail) 17 added in last 30d

New Integrations Added - Last 30 Days

17 new connections
TenantIntegrationConnection NameAdded
blumira-production active-directory active_directory_05b86b85_6024_4128_a694_a7dc2d43b83c 2026-09-09
blumira-production active-directory active_directory_369258dc_75c2_4aa7_a4a4_f9ffb5af3efe 2026-09-08
blumira-production active-directory active_directory_953373d4_008d_436b_8ba4_e354ae8fece0 2026-09-01
blumira-production active-directory active_directory_9e542b25_4c34_48ce_8f18_17bf24a83a11 2026-08-28
blumira-production active-directory active_directory_ea66909a_7761_4b89_8cbb_c782eede5480 2026-08-27
blumira-production active-directory active_directory_ae2b14c4_b191_4577_8176_a458317a7600 2026-08-26
blumira-production active-directory active_directory_0e4e29d2_d435_4146_bf06_27cd9bce8ce6 2026-08-23
blumira-production active-directory active_directory_d4b44f74_b1b0_472d_a869_ba82fef61452 2026-08-23
blumira-production active-directory active_directory_fff02da6_7661_434d_9f83_9660f330ff2e 2026-08-23
blumira-production active-directory active_directory_ccc873ac_db1a_4c02_9914_3cc3d51581f8 2026-08-23
blumira-production active-directory active_directory_2ee4a2cb_e670_4946_a85d_e841b4ae9094 2026-08-20
blumira-production active-directory active_directory_07854c6f_50d4_4565_8284_5a16544797aa 2026-08-17
blumira-production active-directory active_directory_47825bf4_8a5b_47ed_83c2_9026ad2d951e 2026-08-17
blumira-production active-directory active_directory_660ee8fb_960c_4f72_a027_a69631618e98 2026-08-17
blumira-production active-directory active_directory_09a45435_5266_49ff_b6a8_dc6b764f1459 2026-08-17
blumira-production active-directory active_directory_1f70bbe5_3561_41b3_819c_153331170b8c 2026-08-13
blumira-production active-directory active_directory_a811a0c5_e599_4624_9d49_710667103d8b 2026-08-13