01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| IP Blocklist & Access Control | 0 executions | 0.0% | 2 2 active |
| WAF Configuration Management | 0 executions | 0.0% | 1 1 active |
| CDN Cache Lifecycle Management |
| 93.0% | 2 2 active |
| Identity Anomaly Detection | 0 executions | 0.0% | 1 1 active |
| Alert & Case Management |
| 7.0% | 4 4 active |
| IP Alert Enrichment | 0 executions | 0.0% | 1 1 active |
| Total | 43 executions | 100% | 11 11 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Operational automation is live and running. Scheduled Cache Purge has accumulated 40 executions over 12 months, demonstrating that at least one automation is embedded into routine platform operations and running without manual triggers.
- Full SOC triage chain is designed. The alert → case → Jira pipeline (use case 5) covers the complete path from Cloudflare webhook event to ticketed incident, which is a strong structural foundation for SOC workflow automation.
- Security operations coverage is broad. The playbook set spans IP containment, WAF management, identity anomaly detection, and alert enrichment — covering the most critical Cloudflare security response scenarios.
###
Gaps
- Most playbooks have zero executions. Nine of eleven playbooks show 0 runs in the last 12 months. The automation library exists but is not being actively invoked — indicating either low adoption, lack of awareness, or that the playbooks serve as on-demand tools that haven't been needed.
- IP blocklist and WAF playbooks are unused. These are high-value containment actions during an incident, but their zero-execution counts suggest they haven't been integrated into any incident response runbook or SOC playbook routing.
- Check for Impossible Traveller has no runs. This is the only detection-oriented playbook in the set. Its absence from execution data means there is no automated identity anomaly monitoring running against Cloudflare accounts today.
- No enrichment sources are wired to external threat intel. The IP Enrichment playbook uses internal Python only — no connections to VirusTotal, Shodan, or similar IOC sources are visible in the YAML.
Integration Ecosystem
| Integration | Playbooks Using It | Notes |
|---|---|---|
| Cloudflare | 9 | Core platform — used across all use cases |
| Slack | 1 | Notification on IP block; unblock approval flow references it |
| Jira | 1 | Ticket creation only; no bidirectional sync |
| Blink Case Management | 2 | Alert-to-case and case linking |
| Internal (Python) | 1 | IP extraction in enrichment flow |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Shared Workspace | 4 | 0 | 0 | N/A |
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | Shared Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Shared Workspace | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 6 use cases | 43 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Scheduled cache maintenance cycles completed automatically | 40 | Scheduled Cache Purge |
| Cloudflare events ingested and converted to security alerts | 1 | Create Alert from Webhook Event |
Use Case Summary
| Use Case | Category | Playbook Count | Active Playbooks |
|---|---|---|---|
| IP Blocklist & Access Control | Cloud Security | 2 | 0 |
| WAF Configuration Management | Cloud Security | 1 | 0 |
| CDN Cache Lifecycle Management | Other | 2 | 1 |
| Identity Anomaly Detection | SOC | 1 | 0 |
| Alert & Case Management | SOC | 4 | 1 |
| IP Alert Enrichment | SOC | 1 | 0 |
Use Cases
1. IP Blocklist & Access Control
Description: Automates the enforcement and review of IP-based access controls within Cloudflare. Operators can block a specific IP for a defined window and later verify or reverse that block through a Slack-driven approval flow — removing the need to log into the Cloudflare console for routine containment actions.
Business problem: Manually managing Cloudflare Access Group blocklists is slow and error-prone during an active incident. These playbooks give SOC operators a fast, auditable path to block and unblock IPs without direct console access.
Category: Cloud Security
Subcategories: Cloud access & SaaS policy mgmt
Integrations: Cloudflare, Slack
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| Block IP address for 20 minutes | 0 | On-demand | Open |
| Check if IP address is on Cloudflare Blocklist and unblock via Slack | 0 | On-demand | Open |
2. WAF Configuration Management
Description: Provides a parameterized, on-demand interface for modifying Cloudflare WAF rules — allowing security or platform teams to adjust rule actions, match types, and match values without direct API knowledge or console access.
Business problem: Ad-hoc WAF changes during incidents introduce risk when performed manually via the Cloudflare UI. This playbook creates a controlled, repeatable interface for WAF updates that can be invoked by non-platform engineers.
Category: Cloud Security
Subcategories: Config audit & remediation
Integrations: Cloudflare
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| Make Change to WAF | 0 | On-demand | Open |
3. CDN Cache Lifecycle Management
Description: Manages Cloudflare CDN cache purges at both the individual zone level (on-demand) and across all zones on a nightly schedule. The scheduled variant iterates every active zone automatically, eliminating the need for manual purge runs.
Business problem: Stale CDN cache can serve outdated content to end users and requires periodic clearing. Manual purge processes are forgotten or inconsistently applied; these playbooks ensure reliable, zero-touch cache hygiene.
Category: Other
Subcategories: DevOps & release automation
Integrations: Cloudflare
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| Scheduled Cache Purge | 40 | Scheduled (nightly) | Open |
| Cache purge single zone | 0 | On-demand | Open |
4. Identity Anomaly Detection
Description: Detects impossible-travel patterns by enumerating Cloudflare account users and checking each for simultaneous or geographically implausible active sessions. Runs as an event-triggered flow to surface potential account compromise.
Business problem: Stolen Cloudflare credentials used from unexpected locations are difficult to detect without automated session-analysis tooling. This playbook brings impossible-travel detection directly to the Cloudflare identity layer.
Category: SOC
Subcategories: Identity threat response
Integrations: Cloudflare
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| Check for Impossible Traveller | 0 | Event | Open |
5. Alert & Case Management
Description: Captures Cloudflare platform events via webhook, converts them to structured security alerts, and provides playbooks for opening case management cases, linking alerts to cases, and escalating to Jira — forming a complete SOC triage-to-ticket workflow.
Business problem: Cloudflare events arriving as raw webhook payloads have no automatic path into a SOC workflow. This use case bridges Cloudflare's alerting output to Blink's case management and Jira, giving analysts a structured incident record with minimal manual effort.
Category: SOC
Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring
Integrations: Cloudflare (webhook), Blink Case Management, Jira
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| Create Alert from Webhook Event | 1 | Webhook (event) | Open |
| Create Case Management Case | 0 | On-demand | Open |
| Add to Case | 0 | On-demand | Open |
| Create Jira Ticket | 0 | On-demand | Open |
6. IP Alert Enrichment
Description: Accepts raw event data containing one or more IP addresses, extracts them with a Python-based parser, and iterates through each to perform enrichment lookups — returning a consolidated enrichment summary as output.
Business problem: Analysts investigating Cloudflare alerts often need context on observed IP addresses from multiple sources. This playbook automates IP extraction and enrichment, reducing the manual lookup cycle during triage.
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Integrations: Internal (Python)
| Playbook | Executions (12mo) | Trigger | Link |
|---|---|---|---|
| IP Enrichment | 0 | On-demand | Open |
Key Observations
Strengths
- Operational automation is live and running. Scheduled Cache Purge has accumulated 40 executions over 12 months, demonstrating that at least one automation is embedded into routine platform operations and running without manual triggers.
- Full SOC triage chain is designed. The alert → case → Jira pipeline (use case 5) covers the complete path from Cloudflare webhook event to ticketed incident, which is a strong structural foundation for SOC workflow automation.
- Security operations coverage is broad. The playbook set spans IP containment, WAF management, identity anomaly detection, and alert enrichment — covering the most critical Cloudflare security response scenarios.
Gaps
- Most playbooks have zero executions. Nine of eleven playbooks show 0 runs in the last 12 months. The automation library exists but is not being actively invoked — indicating either low adoption, lack of awareness, or that the playbooks serve as on-demand tools that haven't been needed.
- IP blocklist and WAF playbooks are unused. These are high-value containment actions during an incident, but their zero-execution counts suggest they haven't been integrated into any incident response runbook or SOC playbook routing.
- Check for Impossible Traveller has no runs. This is the only detection-oriented playbook in the set. Its absence from execution data means there is no automated identity anomaly monitoring running against Cloudflare accounts today.
- No enrichment sources are wired to external threat intel. The IP Enrichment playbook uses internal Python only — no connections to VirusTotal, Shodan, or similar IOC sources are visible in the YAML.
Integration Ecosystem
| Integration | Playbooks Using It | Notes |
|---|---|---|
| Cloudflare | 9 | Core platform — used across all use cases |
| Slack | 1 | Notification on IP block; unblock approval flow references it |
| Jira | 1 | Ticket creation only; no bidirectional sync |
| Blink Case Management | 2 | Alert-to-case and case linking |
| Internal (Python) | 1 | IP extraction in enrichment flow |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.