Blink Security Automation — Confidential

Sandbox SRC — Customer Success Report

Generated 2026-09-10 | sandbox-src-value-report.md
2026-09-10Report Date
3Total Playbooks
1Unique Workflows (12m)
25Actions Automated (12m)
$6Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

3
Total playbooks built
all non-deleted workflows
1
Active playbooks
currently enabled
1
Unique workflows executed (12m)
distinct workflows that ran
25
Actions automated (12m)
completed action steps
0.1h
Hours saved (12m)
@ 20s per action
$6
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 5 security alerts auto-triaged and closed for known corporate IP ranges

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Alert IP Triage & Auto-Close
  • 5Security alerts auto-triaged and closed for known corporate IP ranges
100.0%
1
1 active
Total5 executions100%
1
1 active

Use Case Growth Over Time

2 unique playbooks  |  1 operational use cases  |  5 total executions (12m)  |  2026-07 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

No integration data found — ensure the CSV contains an actions column.

04Key Observations

✓  Strengths

Strengths: The deployed playbook automates a real first-pass triage decision (auto-close on fully-known IP ranges), directly reducing analyst noise for Coralogix-sourced alerts.

△  Gaps & Growth Opportunities

Gaps: Sandbox SRC currently has a single automated use case with low execution volume (5 runs/12 months), indicating an early-stage deployment. There is no coverage yet for other SOC subcategories (case management, EDR containment, phishing response, identity threat response) or other pillars (Cloud Security, Vulnerability Mgmt, GRC, IAM).

  • Integration ecosystem: The workflow pairs Coralogix as the alerting/observability source with Blink's native Tables feature for maintaining the corporate IP/CIDR reference data — a lightweight, self-contained integration footprint with room to expand to additional security tools.
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 1 use cases | 5 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-triaged and closed for known corporate IP ranges 5 Alert IP Triage - Known Ranges Auto-Close
In the last 12 months, Blink automated: - 5 security alerts auto-triaged and closed for known corporate IP ranges

Use Case Summary

Use Case Category Playbooks
Alert IP Triage & Auto-Close SOC 1

Use Cases

1. Alert IP Triage & Auto-Close

Category: SOC

Subcategories: Agentic SOC, Alert enrichment / IOC lookup

Description:

Automatically extracts IP addresses from incoming Coralogix alerts, checks them against a maintained table of known corporate IP/CIDR ranges, and auto-closes the alert when every IP resolves to trusted internal infrastructure.

Business problem solved:

Cuts manual triage effort by filtering out and closing alerts that only reference recognized, trusted internal IP ranges — freeing analyst attention for alerts involving unrecognized or external IPs.

Integrations: Coralogix · Blink Tables

Playbooks

Playbook Executions Role
Alert IP Triage - Known Ranges Auto-Close 5 Extracts alert IPs, checks them against corporate CIDR ranges, and auto-closes the alert if all IPs are known internal infrastructure.

Key Observations

  • Strengths: The deployed playbook automates a real first-pass triage decision (auto-close on fully-known IP ranges), directly reducing analyst noise for Coralogix-sourced alerts.
  • Gaps: Sandbox SRC currently has a single automated use case with low execution volume (5 runs/12 months), indicating an early-stage deployment. There is no coverage yet for other SOC subcategories (case management, EDR containment, phishing response, identity threat response) or other pillars (Cloud Security, Vulnerability Mgmt, GRC, IAM).
  • Integration ecosystem: The workflow pairs Coralogix as the alerting/observability source with Blink's native Tables feature for maintaining the corporate IP/CIDR reference data — a lightweight, self-contained integration footprint with room to expand to additional security tools.
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Sandbox SRC coralogix-incident-management my_coralogix_incident_management_connection 2026-08-23