01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| IT Helpdesk Ticket Enrichment |
| 5.8% | 3 0 active |
| Phishing Simulation & Awareness Training |
| 16.6% | 10 2 active |
| Password Expiration Lifecycle | 811 executions | 23.4% | 4 0 active |
| Identity Lifecycle & Access Review |
| 7.4% | 3 3 active |
| Security Alert Triage & Case Management |
| 5.6% | 4 0 active |
| Threat Intel Auto-Triage |
| 2.9% | 2 2 active |
| Threat Hunting & User Investigation |
| 3.2% | 2 1 active |
| Workforce Physical Access Verification |
| 1.2% | 1 0 active |
| Vendor Risk Monitoring |
| 5.5% | 1 1 active |
| IT Self-Service & Operations |
| 1.4% | 5 3 active |
| Cloud Security Posture | 0 executions | 0.0% | 1 0 active |
| Network Infrastructure Monitoring | 37 executions | 1.1% | 1 1 active |
| Total | 2,561 executions | 100% | 37 13 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Mature self-service awareness program. Phishing-sim + LMS + three internal gamified-awareness apps all feed a single per-employee scorecard surfaced through Slack — this is well beyond what most security programs do for awareness analytics.
- Region-aware lifecycle workflows. The Pass-Expiration use case is split into Americas / EMEA / APAC variants so alerts land in working hours — a small detail that drives big reductions in help-desk volume.
- AI-assisted intel parsing. Cyber-intel auto-triage uses Azure OpenAI to extract structured indicators from unstructured alert bodies — turning what is usually 5+ minutes of analyst work into a sub-second extract.
- First-class IT-ticket enrichment. The Freshservice ticket-enrichment workflow pulls device data from both Kandji (Mac) and Intune (Windows) plus Cato Networks SDP context, and posts a structured note back to the ticket. This is one of the highest-volume workflows in the environment.
- Strong identity surface coverage. Microsoft Entra ID, HiBob, Slack, Kandji, and Intune are all wired into the same automation fabric — making one-Slack-command user investigations possible across all of them.
Gaps / Opportunities
- Cloud Security Posture is under-utilized. The single AWS IAM root-MFA check is published but never executed on a schedule. There's runway here to add scheduled CSPM-style sweeps (S3 public buckets, security-group exposure, IAM key age).
- Vulnerability Management is absent. No workflows tie scanner output (Tenable / Wiz / Qualys-style) to ticket creation or owner notification. A vuln-to-ticket pipeline would be a natural next addition.
- EDR containment & response is observational only. The USB-mount hunt detects but does not isolate / block. A "compromised host → isolate via Defender / Kandji lock" workflow would close that loop.
- Several "test" / draft workflows in production. Names like "Elastic Test", "TEST- Self service Portal", "Device Enrichment - Cursor Edition" are running with meaningful execution counts — they should be promoted to production names (no
TEST/Cursor Editionsuffixes) and the obsolete duplicates retired. - Many regional / backup duplicates. There are 6+
Pass Exp Alertvariants (backup-with-region, backup-no-region, copy, copy-copy, 16/02). Consolidating to the live four (master + Americas/EMEA/APAC) would reduce drift risk.
Integration ecosystem
The active automations span ~25 distinct integrations: Microsoft Entra ID, Microsoft Graph, Microsoft Defender for Endpoint, Microsoft Intune, Microsoft Outlook, Kandji, Slack, Jira, Freshservice, HiBob, Cato Networks, Genea, Elastic, AbuseIPDB, Azure OpenAI, Skilljar, ZIP, Apple Business Manager, AWS, Mist (Juniper), plus the Blink-native primitives (Tables, Web Form, Case Management, Python, HTTP, Global Variables). The Microsoft stack + Slack form the backbone of most workflows.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 118 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | IT-Device-Enrichment | alex.dolea@catonetworks.com | 118 | 0 | 6,222,122 |
| 2 | Agent Blink | Information Security | 0 | 0 | 0 |
| 3 | Agent Blink | Security Operations & Systems | 0 | 0 | 0 |
| 4 | Agent Blink | shahar.laksman@catonetworks.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| alex.dolea@catonetworks.com | 118 |
| Information Security | 0 |
| Security Operations & Systems | 0 |
| shahar.laksman@catonetworks.com | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 12 use cases | 3,459 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| After-hours office access events verified with the badge holder | 667 | Genea |
| IT support tickets auto-enriched with device, user & network context | 276 | Freshservice Ticket - Device Info |
| Security awareness training completion checks processed | 271 | Tutorials scoring – day 1 / day 2 / day 3 / day 4 |
| Security alerts (Elastic) auto-enriched and converted into cases | 192 | Elastic Test |
| Daily inactive-user sweeps against the corporate directory | 152 | Inactive users- CatoAll group |
| One-Slack-command user investigations completed | 124 | One-Query User Investigator |
| Region-aware password expiration alert sweeps delivered | 424 | Pass Exp Alert (109) / Americas (107) / EMEA (101) / APAC (107) |
| Vendor contact integrity checks (cross-domain email risk) | 93 | ZIP Vendor Contact checking |
| Quarterly phishing-simulation result syncs | 69 | Phishing Simulation - Scores |
| Cyber-intel domain takedown alerts auto-triaged with LLM extraction | 44 | Cyber Intel Alerts- Domain take Down |
| Cyber-intel credential exposure alerts auto-triaged with LLM extraction | 24 | Cyber Intel Alerts- Credentials |
| Weekly endpoint USB-mount threat hunts | 62 | Detect DOK connection |
| Internal security-awareness scoring events (Base 44 games) | 17 | ObjectHunt (7) / PhraseHunt (7) / Connections Daily (3) |
| Phishing campaign summaries served on-demand from Slack | 11 | Phishing Campaign Summary |
| Slack-driven IT lookups for terminated-user laptop calculations | 10 | Slack /command trigger |
| Laptop self-service price calculations completed (web form) | 8 | Webform - Laptop Price Calculator |
| Office parking automation requests served via Slack | 5 | Slack Trigger Parking Automation |
| HR-source new-hire roll-ups generated (monthly) | 2 | Hibob New Hired Collection |
Use Case Summary
| # | Use Case | Category | Playbooks |
|---|---|---|---|
| 1 | IT Helpdesk Ticket Enrichment | Other | 6 |
| 2 | Phishing Simulation & Awareness Training | SOC | 10 |
| 3 | Password Expiration Lifecycle | IAM | 4 |
| 4 | Identity Lifecycle & Access Review | IAM | 3 |
| 5 | Security Alert Triage & Case Management | SOC | 4 |
| 6 | Threat Intel Auto-Triage | SOC | 2 |
| 7 | Threat Hunting & User Investigation | SOC | 3 |
| 8 | Workforce Physical Access Verification | SOC | 1 |
| 9 | Vendor Risk Monitoring | GRC | 1 |
| 10 | IT Self-Service & Operations | Other | 5 |
| 11 | Cloud Security Posture | Cloud Security | 1 |
| 12 | Network Infrastructure Monitoring | Other | 1 |
Use Cases
1. IT Helpdesk Ticket Enrichment
Description. When a Freshservice ticket is opened, Blink automatically classifies the request, identifies the requester's primary device across Kandji (Mac) and Intune (Windows), looks up Cato Networks SDP/Socket connection data, and posts a structured enrichment note back onto the ticket so the IT analyst has the full context without manual data-gathering.
Business problem. IT analysts spend the first minutes of every ticket pivoting between Freshservice, the MDM (Kandji/Intune), the directory, and the SD-WAN. Blink collapses that into a single enrichment note — cutting mean-time-to-first-response and reducing the back-and-forth with the requester.
Integrations. Freshservice · Kandji · Microsoft Intune · Microsoft Entra ID · Cato Networks · HiBob · Agents (LLM classifier) · Slack
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Freshservice Ticket - Device Info | 276 | Freshservice webhook |
| Device Enrichment - Main | 121 | Webhook |
| Device Enrichment - Cursor Edition | 51 | Webhook |
| List Users' Kandji Device | 86 | Subflow (on-demand) |
| List Users' Intune Devices | 0 | Subflow (on-demand) |
| Find Employee Manager | 0 | Subflow (on-demand) |
2. Phishing Simulation & Awareness Training
Description. A full security-awareness scoring program: Microsoft Defender phishing-simulation results are pulled quarterly, Skilljar tutorial completions are checked every 4 hours across all 4 onboarding days, and three internal gamified-awareness apps (Base 44 — ObjectHunt, PhraseHunt, Connections) score employees in real time. A self-service Slack portal surfaces an employee's combined awareness scorecard.
Business problem. Security awareness programs typically suffer from siloed scoring across the phishing-sim platform, the LMS, and any custom training. Blink consolidates all of it into a single per-employee score, surfaced on-demand via Slack — and keeps a historical record for trend analysis.
Integrations. Microsoft Graph (Defender / Attack Simulator) · Skilljar (HTTP) · Slack · Tables · HiBob · Web Form
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Tutorials scoring- day 1 | 70 | Scheduled (every 4h) |
| Tutorials scoring- day 2 | 67 | Scheduled (every 4h) |
| Tutorials scoring- day 3 | 67 | Scheduled (every 4h) |
| Tutorials scoring- day 4 | 67 | Scheduled (every 4h) |
| Phishing Simulation - Scores | 69 | Scheduled (quarterly) |
| Phishing Simulation - Update Table - Subflow | 2 | Subflow |
| Phishing Simulation - Init Table from CSV | 1 | On-demand |
| Phishing Campaign Summary | 11 | Slack webhook |
| Base 44- ObjectHunt Scoring | 7 | Webhook |
| Base 44- PhraseHunt Scoring | 7 | Webhook |
| Base 44- Connections Daily Scoring | 3 | Webhook |
| TEST- Self service Portal | 6 | Webhook |
| Upload BOB excel to table | 4 | Web form |
3. Password Expiration Lifecycle
Description. Four daily scheduled workflows (global + three regional variants — Americas, EMEA, APAC) query Microsoft Entra ID for accounts whose password is approaching expiration, then send personalized reminders via Outlook and Slack in the recipient's working hours.
Business problem. Mass-emailing 6 a.m. "your password expires soon" reminders results in service disruptions when employees miss them. Splitting the run by region ensures the alert lands during the employee's workday and dramatically cuts help-desk volume around password resets.
Integrations. Microsoft Entra ID · Microsoft Outlook · Slack · Tables · Python
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Pass Exp Alert | 109 | Scheduled (daily) |
| Pass Exp Alert 2 - Americas | 107 | Scheduled (daily) |
| Pass Exp Alert 2 - EMEA | 101 | Scheduled (daily) |
| Pass Exp Alert 2 - APAC | 107 | Scheduled (daily) |
4. Identity Lifecycle & Access Review
Description. Joiner-mover-leaver oversight: a daily sweep flags accounts inactive for 35+ days that are still members of the all-employees group, a monthly HR sync pulls last month's new hires from HiBob, and a directory helper resolves an employee's manager on demand.
Business problem. Stale accounts in critical groups expand the attack surface and break the principle of least privilege. Blink keeps inactive-user identification continuous instead of quarterly, and keeps HR & directory views aligned.
Integrations. Microsoft Entra ID · HiBob · Slack · Tables · Python
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Inactive users- CatoAll group | 152 | Scheduled (daily) |
| Hibob New Hired Collection | 2 | Scheduled (monthly) |
| Find Employee Manager | 0 | Subflow |
5. Security Alert Triage & Case Management
Description. Inbound security alerts (currently from an Elastic detection pipeline) trigger a Blink flow that enriches source IPs with AbuseIPDB, opens a Blink-native case with severity & vendor metadata, and notifies the case owner by email. Jira-driven incident workflows spin up dedicated Slack incident-response channels for higher-severity cases.
Business problem. Most SIEM detections never reach an analyst with enough context to act on them. Blink standardizes the first-pass triage — IP reputation, structured case creation, ownership routing — so alerts arrive already enriched and assigned.
Integrations. Elastic (webhook) · AbuseIPDB · Blink Case Management · Slack · Jira · Email
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Elastic Test | 192 | Webhook |
| Incident Management- Slack Channel | 1 | Jira polling |
| Cato Networks - CMA Analysis | 0 | On-demand |
| Risky Users - Scores | 0 | Scheduled |
6. Threat Intel Auto-Triage
Description. External cyber-intel feeds push two categories of alert into Blink: domain-takedown candidates and credential-exposure events. An Azure-hosted LLM extracts the structured indicators (domains, emails) from the free-text alert body, the workflow opens a Jira ticket for action, and Slack notifies the responder.
Business problem. Cyber-intel vendors deliver alerts as unstructured text that an analyst has to parse and tabulate before any takedown or password-reset action can be taken. The LLM extraction step removes that manual parsing entirely, dropping triage time per alert from minutes to seconds.
Integrations. Azure OpenAI · Jira · Slack · Python · HTTP
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Cyber Intel Alerts- Domain take Down | 44 | Webhook |
| Cyber Intel Alerts- Credentials | 24 | Webhook |
7. Threat Hunting & User Investigation
Description. A weekly Microsoft Defender hunt queries DeviceEvents and DeviceFileEvents looking for USB drives that mounted in the past 7 days and then wrote files within minutes of the mount — a classic data-exfiltration / unsanctioned-storage signal. Separately, a Slack slash command lets any analyst paste a @user and immediately get a consolidated profile across Slack, Entra ID, Intune & Kandji.
Business problem. Manual user investigations require swiveling between 4–5 admin consoles. Blink turns it into a one-line Slack command. And periodic EDR hunts ensure storage-device risk doesn't accumulate silently between alert-driven workflows.
Integrations. Microsoft Defender for Endpoint · Microsoft Graph · Microsoft Entra ID · Intune · Kandji · Slack · Python
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Detect DOK connection | 62 | Scheduled (weekly) |
| One-Query User Investigator | 124 | Slack slash command |
8. Workforce Physical Access Verification
Description. Genea (physical access control system) emits an event whenever a covered employee badges into the office. Blink writes the event to a tracking table and, for after-hours entries, sends the badge holder a Slack confirmation prompt — "was this you?" — converting denials into a security review.
Business problem. Badge-cloning and tailgating attacks usually go unnoticed because no one reviews after-hours physical-access events. A direct ask-the-user workflow turns every entry into a self-attesting control with zero analyst overhead.
Integrations. Genea (webhook) · Slack · Tables
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Genea | 667 | Webhook |
9. Vendor Risk Monitoring
Description. A daily sweep of the procurement platform's vendor records (ZIP) finds vendors whose listed contacts use email addresses across multiple unrelated domains — a structural integrity signal that frequently indicates an impersonation or compromised-vendor risk.
Business problem. Vendor-master records degrade over time as contacts change, get added by ad-hoc users, or get spoofed. Continuous validation of contact-domain consistency surfaces TPRM red flags well before they show up in an invoice-fraud incident.
Integrations. ZIP · Python · HTTP
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| ZIP Vendor Contact checking | 93 | Scheduled (daily) |
10. IT Self-Service & Operations
Description. Employee-facing self-service automations: a web form / Slack chatbot that calculates a laptop's residual price using live FX rates, an Apple Business Manager pull for serial-lookup, and a Slack-driven parking-spot reservation system. Exchange rates are cached weekly to keep the calculator resilient when the FX API is unavailable.
Business problem. Routine IT/HR requests (laptop pricing, parking) sit in a help-desk queue for hours when they could be answered in seconds. Self-service workflows cut ticket volume and improve employee experience.
Integrations. Web Form · Slack · HTTP (Exchange-rate API) · Apple Business Manager · HiBob · Tables · Global Variables
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Webform - Laptop Price Calculator | 8 | Web form |
| Slack /command trigger | 10 | Slack slash command |
| Slack - Laptop Price Calculator | 0 | Subflow |
| Slack Trigger Parking Automation | 5 | Slack slash command |
| Exchange rate | 9 | Scheduled (weekly) |
11. Cloud Security Posture
Description. A point-in-time AWS audit playbook that lists IAM accounts that do not have MFA configured on the root user — published but not yet on a regular schedule.
Business problem. Root-without-MFA is one of the highest-impact misconfigurations on AWS. Automating the check converts it from a periodic-audit finding into a continuous control.
Integrations. AWS
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Get AWS IAM Accounts Without Root Mfa | 0 | On-demand |
12. Network Infrastructure Monitoring
Description. Listens for site-level alerts from the Juniper Mist wireless platform and posts a structured summary into Slack so the network team can triage from chat.
Business problem. Mist's native alerts are noisy and email-based. Routing them through Blink lets the team filter, format, and consolidate them in Slack — the same channel they use for everything else.
Integrations. Mist (Juniper) · Slack
| Playbook | Executions (12mo) | Trigger |
|---|---|---|
| Mist - Site Alerts to Slack | 0 | Webhook |
Key Observations
Strengths
- Mature self-service awareness program. Phishing-sim + LMS + three internal gamified-awareness apps all feed a single per-employee scorecard surfaced through Slack — this is well beyond what most security programs do for awareness analytics.
- Region-aware lifecycle workflows. The Pass-Expiration use case is split into Americas / EMEA / APAC variants so alerts land in working hours — a small detail that drives big reductions in help-desk volume.
- AI-assisted intel parsing. Cyber-intel auto-triage uses Azure OpenAI to extract structured indicators from unstructured alert bodies — turning what is usually 5+ minutes of analyst work into a sub-second extract.
- First-class IT-ticket enrichment. The Freshservice ticket-enrichment workflow pulls device data from both Kandji (Mac) and Intune (Windows) plus Cato Networks SDP context, and posts a structured note back to the ticket. This is one of the highest-volume workflows in the environment.
- Strong identity surface coverage. Microsoft Entra ID, HiBob, Slack, Kandji, and Intune are all wired into the same automation fabric — making one-Slack-command user investigations possible across all of them.
Gaps / Opportunities
- Cloud Security Posture is under-utilized. The single AWS IAM root-MFA check is published but never executed on a schedule. There's runway here to add scheduled CSPM-style sweeps (S3 public buckets, security-group exposure, IAM key age).
- Vulnerability Management is absent. No workflows tie scanner output (Tenable / Wiz / Qualys-style) to ticket creation or owner notification. A vuln-to-ticket pipeline would be a natural next addition.
- EDR containment & response is observational only. The USB-mount hunt detects but does not isolate / block. A "compromised host → isolate via Defender / Kandji lock" workflow would close that loop.
- Several "test" / draft workflows in production. Names like "Elastic Test", "TEST- Self service Portal", "Device Enrichment - Cursor Edition" are running with meaningful execution counts — they should be promoted to production names (no
TEST/Cursor Editionsuffixes) and the obsolete duplicates retired. - Many regional / backup duplicates. There are 6+
Pass Exp Alertvariants (backup-with-region, backup-no-region, copy, copy-copy, 16/02). Consolidating to the live four (master + Americas/EMEA/APAC) would reduce drift risk.
Integration ecosystem
The active automations span ~25 distinct integrations: Microsoft Entra ID, Microsoft Graph, Microsoft Defender for Endpoint, Microsoft Intune, Microsoft Outlook, Kandji, Slack, Jira, Freshservice, HiBob, Cato Networks, Genea, Elastic, AbuseIPDB, Azure OpenAI, Skilljar, ZIP, Apple Business Manager, AWS, Mist (Juniper), plus the Blink-native primitives (Tables, Web Form, Case Management, Python, HTTP, Global Variables). The Microsoft stack + Slack form the backbone of most workflows.
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.