Blink Security Automation — Confidential

CloudFlare Cloud — Customer Success Report

Generated 2026-09-10 | cloudflare-cloud-value-report.md
2026-09-10Report Date
25Total Playbooks
2Unique Workflows (12m)
1,040Actions Automated (12m)
$267Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

25
Total playbooks built
all non-deleted workflows
11
Active playbooks
currently enabled
2
Unique workflows executed (12m)
distinct workflows that ran
1,040
Actions automated (12m)
completed action steps
5.8h
Hours saved (12m)
@ 20s per action
$267
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
4
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 40 CDN cache maintenance cycles executed without manual intervention - 1 Cloudflare platform event converted to a trackable security alert automatically

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
IP Blocklist & Access Control0 executions
0.0%
2
2 active
WAF Configuration Management0 executions
0.0%
1
1 active
CDN Cache Lifecycle Management
  • 40Scheduled cache maintenance cycles completed automatically
93.0%
2
2 active
Identity Anomaly Detection0 executions
0.0%
1
1 active
Alert & Case Management
  • 1Cloudflare events ingested and converted to security alerts
7.0%
4
4 active
IP Alert Enrichment0 executions
0.0%
1
1 active
Total43 executions100%
11
11 active

Use Case Growth Over Time

16 unique playbooks  |  6 operational use cases  |  43 total executions (12m)  |  2024-02 to 2024-06
Toggle:
Toggle:

03Integration Ecosystem

IP Blocklist & Access Control
Cloudflare Slack
CDN Cache Lifecycle Management
Cloudflare
Identity Anomaly Detection
Cloudflare Okta Slack
WAF Configuration Management
Cloudflare
Alert & Case Management
Jira
IP Alert Enrichment
Whois AbuseIPDB VirusTotal

04Key Observations

✓  Strengths

Strengths

  • Operational automation is live and running. Scheduled Cache Purge has accumulated 40 executions over 12 months, demonstrating that at least one automation is embedded into routine platform operations and running without manual triggers.
  • Full SOC triage chain is designed. The alert → case → Jira pipeline (use case 5) covers the complete path from Cloudflare webhook event to ticketed incident, which is a strong structural foundation for SOC workflow automation.
  • Security operations coverage is broad. The playbook set spans IP containment, WAF management, identity anomaly detection, and alert enrichment — covering the most critical Cloudflare security response scenarios.

###

△  Gaps & Growth Opportunities

Gaps

  • Most playbooks have zero executions. Nine of eleven playbooks show 0 runs in the last 12 months. The automation library exists but is not being actively invoked — indicating either low adoption, lack of awareness, or that the playbooks serve as on-demand tools that haven't been needed.
  • IP blocklist and WAF playbooks are unused. These are high-value containment actions during an incident, but their zero-execution counts suggest they haven't been integrated into any incident response runbook or SOC playbook routing.
  • Check for Impossible Traveller has no runs. This is the only detection-oriented playbook in the set. Its absence from execution data means there is no automated identity anomaly monitoring running against Cloudflare accounts today.
  • No enrichment sources are wired to external threat intel. The IP Enrichment playbook uses internal Python only — no connections to VirusTotal, Shodan, or similar IOC sources are visible in the YAML.

Integration Ecosystem

Integration Playbooks Using It Notes
Cloudflare 9 Core platform — used across all use cases
Slack 1 Notification on IP block; unblock approval flow references it
Jira 1 Ticket creation only; no bidirectional sync
Blink Case Management 2 Alert-to-case and case linking
Internal (Python) 1 IP extraction in enrichment flow
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
4
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Shared Workspace 4 0 0 N/A
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink Shared Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Shared Workspace0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 6 use cases | 43 executions (12m)

Business KPIs

Metric Count Playbook
Scheduled cache maintenance cycles completed automatically 40 Scheduled Cache Purge
Cloudflare events ingested and converted to security alerts 1 Create Alert from Webhook Event
In the last 12 months, Blink automated: - 40 CDN cache maintenance cycles executed without manual intervention - 1 Cloudflare platform event converted to a trackable security alert automatically

Use Case Summary

Use Case Category Playbook Count Active Playbooks
IP Blocklist & Access Control Cloud Security 2 0
WAF Configuration Management Cloud Security 1 0
CDN Cache Lifecycle Management Other 2 1
Identity Anomaly Detection SOC 1 0
Alert & Case Management SOC 4 1
IP Alert Enrichment SOC 1 0

Use Cases

1. IP Blocklist & Access Control

Description: Automates the enforcement and review of IP-based access controls within Cloudflare. Operators can block a specific IP for a defined window and later verify or reverse that block through a Slack-driven approval flow — removing the need to log into the Cloudflare console for routine containment actions.

Business problem: Manually managing Cloudflare Access Group blocklists is slow and error-prone during an active incident. These playbooks give SOC operators a fast, auditable path to block and unblock IPs without direct console access.

Category: Cloud Security

Subcategories: Cloud access & SaaS policy mgmt

Integrations: Cloudflare, Slack

Playbook Executions (12mo) Trigger Link
Block IP address for 20 minutes 0 On-demand Open
Check if IP address is on Cloudflare Blocklist and unblock via Slack 0 On-demand Open

2. WAF Configuration Management

Description: Provides a parameterized, on-demand interface for modifying Cloudflare WAF rules — allowing security or platform teams to adjust rule actions, match types, and match values without direct API knowledge or console access.

Business problem: Ad-hoc WAF changes during incidents introduce risk when performed manually via the Cloudflare UI. This playbook creates a controlled, repeatable interface for WAF updates that can be invoked by non-platform engineers.

Category: Cloud Security

Subcategories: Config audit & remediation

Integrations: Cloudflare

Playbook Executions (12mo) Trigger Link
Make Change to WAF 0 On-demand Open

3. CDN Cache Lifecycle Management

Description: Manages Cloudflare CDN cache purges at both the individual zone level (on-demand) and across all zones on a nightly schedule. The scheduled variant iterates every active zone automatically, eliminating the need for manual purge runs.

Business problem: Stale CDN cache can serve outdated content to end users and requires periodic clearing. Manual purge processes are forgotten or inconsistently applied; these playbooks ensure reliable, zero-touch cache hygiene.

Category: Other

Subcategories: DevOps & release automation

Integrations: Cloudflare

Playbook Executions (12mo) Trigger Link
Scheduled Cache Purge 40 Scheduled (nightly) Open
Cache purge single zone 0 On-demand Open

4. Identity Anomaly Detection

Description: Detects impossible-travel patterns by enumerating Cloudflare account users and checking each for simultaneous or geographically implausible active sessions. Runs as an event-triggered flow to surface potential account compromise.

Business problem: Stolen Cloudflare credentials used from unexpected locations are difficult to detect without automated session-analysis tooling. This playbook brings impossible-travel detection directly to the Cloudflare identity layer.

Category: SOC

Subcategories: Identity threat response

Integrations: Cloudflare

Playbook Executions (12mo) Trigger Link
Check for Impossible Traveller 0 Event Open

5. Alert & Case Management

Description: Captures Cloudflare platform events via webhook, converts them to structured security alerts, and provides playbooks for opening case management cases, linking alerts to cases, and escalating to Jira — forming a complete SOC triage-to-ticket workflow.

Business problem: Cloudflare events arriving as raw webhook payloads have no automatic path into a SOC workflow. This use case bridges Cloudflare's alerting output to Blink's case management and Jira, giving analysts a structured incident record with minimal manual effort.

Category: SOC

Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring

Integrations: Cloudflare (webhook), Blink Case Management, Jira

Playbook Executions (12mo) Trigger Link
Create Alert from Webhook Event 1 Webhook (event) Open
Create Case Management Case 0 On-demand Open
Add to Case 0 On-demand Open
Create Jira Ticket 0 On-demand Open

6. IP Alert Enrichment

Description: Accepts raw event data containing one or more IP addresses, extracts them with a Python-based parser, and iterates through each to perform enrichment lookups — returning a consolidated enrichment summary as output.

Business problem: Analysts investigating Cloudflare alerts often need context on observed IP addresses from multiple sources. This playbook automates IP extraction and enrichment, reducing the manual lookup cycle during triage.

Category: SOC

Subcategories: Alert enrichment / IOC lookup

Integrations: Internal (Python)

Playbook Executions (12mo) Trigger Link
IP Enrichment 0 On-demand Open

Key Observations

Strengths

  • Operational automation is live and running. Scheduled Cache Purge has accumulated 40 executions over 12 months, demonstrating that at least one automation is embedded into routine platform operations and running without manual triggers.
  • Full SOC triage chain is designed. The alert → case → Jira pipeline (use case 5) covers the complete path from Cloudflare webhook event to ticketed incident, which is a strong structural foundation for SOC workflow automation.
  • Security operations coverage is broad. The playbook set spans IP containment, WAF management, identity anomaly detection, and alert enrichment — covering the most critical Cloudflare security response scenarios.

Gaps

  • Most playbooks have zero executions. Nine of eleven playbooks show 0 runs in the last 12 months. The automation library exists but is not being actively invoked — indicating either low adoption, lack of awareness, or that the playbooks serve as on-demand tools that haven't been needed.
  • IP blocklist and WAF playbooks are unused. These are high-value containment actions during an incident, but their zero-execution counts suggest they haven't been integrated into any incident response runbook or SOC playbook routing.
  • Check for Impossible Traveller has no runs. This is the only detection-oriented playbook in the set. Its absence from execution data means there is no automated identity anomaly monitoring running against Cloudflare accounts today.
  • No enrichment sources are wired to external threat intel. The IP Enrichment playbook uses internal Python only — no connections to VirusTotal, Shodan, or similar IOC sources are visible in the YAML.

Integration Ecosystem

Integration Playbooks Using It Notes
Cloudflare 9 Core platform — used across all use cases
Slack 1 Notification on IP block; unblock approval flow references it
Jira 1 Ticket creation only; no bidirectional sync
Blink Case Management 2 Alert-to-case and case linking
Internal (Python) 1 IP extraction in enrichment flow
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.