Blink Security Automation — Confidential

Forvis — Customer Success Report

Generated 2026-09-10 | forvis-value-report.md
2026-09-10Report Date
165Total Playbooks
43Unique Workflows (12m)
2,320,736Actions Automated (12m)
$596,897Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

165
Total playbooks built
all non-deleted workflows
58
Active playbooks
currently enabled
43
Unique workflows executed (12m)
distinct workflows that ran
2,320,736
Actions automated (12m)
completed action steps
12,893.0h
Hours saved (12m)
@ 20s per action
$596,897
Money saved (12m)
@ $100K avg salary
2
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 35,072 expired DLP access exceptions automatically revoked — no analyst queuing required - 11,521 risky user monitoring scans completed, each routing confirmed threats to analyst review - 423 phishing incident records created or updated in tracking tables, maintaining full case history - 372 phishing alerts processed through an automated triage driver running every 15 minutes - 371 DLP access exception requests processed end-to-end from ITSM ticket to enforcement - 272 user passwords provisioned or reset without manual IT intervention - 219 device isolation actions executed in response to confirmed security threats - 124 endpoint alerts ingested, enriched, and routed through structured triage - 85 phishing-related threat IDs linked to incident records for cross-case correlation - 80 security alert response workflows orchestrated with built-in analyst approval gates - 51 risky user cases investigated and remediated with full audit trail - 28 stale device cleanup cycles executed, disabling or removing inactive AD computer objects - 11 Power Platform environments scanned for security posture issues via Wiz integration - 30 server onboarding and offboarding events processed through automated vulnerability workflows

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
EDR Alert Triage, Enrichment & Containment
  • 219Devices isolated in response to confirmed security threats
  • 124Endpoint alerts ingested and triaged
  • 80Security alert response workflows orchestrated with analyst gate
0.9%
11
11 active
Identity Threat Monitoring & Response
  • 11,521Risky user monitoring scans completed
  • 51Risky users investigated and remediated
24.5%
2
2 active
DLP Exception Lifecycle Management
  • 35,072Expired DLP access exceptions automatically revoked
  • 371DLP access exception requests processed end-to-end
63.3%
7
7 active
Stale Device Lifecycle Automation
  • 28Stale device cleanup cycles run against Active Directory
1.8%
4
4 active
Password & Credential Management
  • 272User passwords provisioned or reset without manual intervention
0.7%
7
7 active
Server Vulnerability & Asset Lifecycle
  • 16Server onboarding vulnerability scans triggered via ITSM ticket
  • 14Server offboardings processed with automated asset removal
0.0%
5
5 active
Agentic SOC Toolset0 executions
0.0%
11
11 active
Phishing Alert Triage & Response
  • 423Phishing incident records created or updated in tracking tables
  • 372Phishing alerts processed by automated triage driver
  • 85Phishing-related threat IDs linked to incident records
8.6%
4
4 active
Power Platform Security Posture Monitoring
  • 11Power Platform environments scanned for security posture issues
0.0%
1
1 active
Total47,052 executions100%
52
52 active

Use Case Growth Over Time

125 unique playbooks  |  9 operational use cases  |  47,077 total executions (12m)  |  2023-12 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Stale Device Lifecycle Automation
SSH Splunk Email Microsoft Teams Web Form
Identity Threat Monitoring & Response
Microsoft Entra ID VirusTotal Web Form Email
EDR Alert Triage, Enrichment & Containment
CrowdStrike Microsoft Defender For Endpoints String Utilities Microsoft Teams Web Form Email Microsoft Entra ID Microsoft Intune VirusTotal
Password & Credential Management
Microsoft Entra ID Email Delinea Microsoft Defender For Endpoints Microsoft Teams Microsoft SQL Server Splunk
Server Vulnerability & Asset Lifecycle
Tenable Email
DLP Exception Lifecycle Management
Delinea LDAP Email
Agentic SOC Toolset
Microsoft Entra ID Microsoft Defender For Endpoints CrowdStrike Splunk Azure
Phishing Alert Triage & Response
Rapid7 Threat Command VirusTotal Email Web Form
Power Platform Security Posture Monitoring
Email

04Key Observations

✓  Strengths

Strengths

High-volume DLP enforcement at scale. The DLP exception lifecycle is the most operationally active use case, with 35,072 automated exception removals and 371 additions over 12 months. This represents a mature, production-grade compliance automation covering the full add-track-expire-revoke lifecycle with no manual queuing required.

Analyst-gated SOC workflow architecture. Alert response is structured around an explicit human approval gate (web form + email), meaning automation handles enrichment, context aggregation, and orchestration while analysts retain decision authority. This is a defensible, audit-friendly design appropriate for a regulated financial services environment.

Dual-EDR coverage with unified pipeline. Both CrowdStrike and Microsoft Defender for Endpoints are integrated into a single alert triage pipeline, with IOC extraction and enrichment abstracted as reusable subflows. Cross-platform alert correlation happens automatically before any analyst interaction.

IAM automation breadth. Password lifecycle, stale device cleanup, user restoration, and privileged credential management are all automated across Entra ID, Active Directory, Delinea, and UserCube — covering the most common IAM failure modes in an enterprise environment.

Agentic SOC foundation in place. A structured Ability library covering CrowdStrike, Defender, Entra ID, Splunk, and Power Platform is deployed in a dedicated workspace. Initial execution counts (13 executions across 6 abilities) indicate early-stage adoption with a platform ready to scale into autonomous investigation workflows.

New phishing triage pipeline established. A 15-minute scheduled driver now logs phishing submissions to tracking tables, links related threat IDs for cross-case correlation, and dispatches analyst notifications — 1,252 combined executions across the driver and its subflows indicate immediate high-volume adoption.

###

△  Gaps & Growth Opportunities

Gaps

CrowdStrike alert pipeline inactive. Ingest - Crowdstrike Alert has 0 executions despite the full workflow being built with webhook trigger and alert enrichment steps. CrowdStrike-originated alerts are not flowing through Blink, leaving Microsoft Defender as the sole active EDR ingest source. This is a coverage gap given CrowdStrike is also deployed for containment.

Vulnerability management pipeline not operationalized. The Tenable integration handles server onboarding and offboarding (30 executions combined) but Server Vulnerability Submissions, Run Tenable Scan, and Rescan all have 0 executions. Vulnerability scanning, prioritization, and remediation tracking are not yet automated beyond asset registration.

Containment response actions unused. Subflow - AV Scan Host, Subflow - Auto Investigate, and Subflow - Isolate Host with Crowdstrike all have 0 executions. These response capabilities are built and integrated with CrowdStrike and Defender but are not being triggered through the alert response facilitation workflow.

DLP USB exception flow not activated. DLP USB Exception Workflow exists with a webhook trigger but has 0 executions. USB-based DLP exception requests are likely still being handled through a manual process outside of Blink.

Agentic SOC at early adoption. The Ability library has 11 workflows built but only 5 have been invoked (13 total executions). The agentic investigation pattern has not yet been scaled into continuous autonomous workflows.

Power Platform posture monitoring at early adoption. Wiz Integration for Power Platform is Forvis's first Cloud Security automation, running daily but with only 11 executions to date — early-stage compared to the mature DLP and identity pipelines.

Integration Ecosystem

Forvis's automation estate spans 16 distinct integrations:

Integration Use Cases
Microsoft Entra ID / Active Directory Identity threat response, EDR enrichment, Password management, Stale device cleanup, Agentic SOC
CrowdStrike EDR alert ingest (built, inactive), Device isolation, Alert enrichment, Agentic SOC
Microsoft Defender for Endpoints EDR alert ingest (active), Alert enrichment, Agentic SOC
Microsoft Intune Device enrichment in EDR pipeline
Splunk Stale device validation, EDR enrichment, Agentic SOC
Delinea DLP bypass removal, Onboarding password cleanup
SendGrid Alert notifications, Analyst approvals, End-user notifications, Phishing notifications
Tenable Server vulnerability scanning, Asset lifecycle management
EasyVista Server onboarding/offboarding triggers, DLP exception requests
UserCube Password provisioning trigger via IGA webhook
SSH / WinRM AD computer object management, DLP group enforcement
Blink Web Forms Alert approvals, Vulnerability submissions, Risky user approvals, Phishing response forms
Blink Tables Case tracking, Exception expiry tracking, EDR record management, Phishing data tracking
Wiz Power Platform security posture monitoring
Microsoft Power Platform Power Platform security posture monitoring
Microsoft SQL Server Offboarding compliance reconciliation (Missed Offboards)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Security Alert Investigation & Enrichment Analyst Agents POC 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Agents POC0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Risky Users 00

Webforms

Forms
3
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 header 00
2 Testing Webform 00
3 Server Vulnerability Submission 00
D Full Use Case Analysis 9 use cases | 47,077 executions (12m)

Business KPIs

Metric Count Playbook
Expired DLP access exceptions automatically revoked 35,072 DLP Exclusion Remove Expired
Risky user monitoring scans completed 11,521 Parent - Find Risky Users
Phishing incident records created or updated in tracking tables 423 Subflow - Add or Update New Phishing Data to Tables
Phishing alerts processed by automated triage driver 372 Phishing Driver
DLP access exception requests processed end-to-end 371 DLP Exclusion Addition
User passwords provisioned or reset without manual intervention 272 Set User Password
Devices isolated in response to confirmed security threats 219 Isolate Device
Endpoint alerts ingested and triaged 124 Ingest - MD Alert
Phishing-related threat IDs linked to incident records 85 Subflow - Add or Update Phishing_related_threat_ids table
Security alert response workflows orchestrated with analyst gate 80 Parent - Alert Response Facilitation
Risky users investigated and remediated 51 Subflow - Risky User Approval and Remediation
Stale device cleanup cycles run against Active Directory 28 Parent - Disable_Delete Stale Devices
Server onboarding vulnerability scans triggered via ITSM ticket 16 Ingest EasyVista Ticket Data
Server offboardings processed with automated asset removal 14 Server Offboarding - Ingest EasyVista Ticket
Power Platform environments scanned for security posture issues 11 Wiz Integration for Power Platform
In the last 12 months, Blink automated: - 35,072 expired DLP access exceptions automatically revoked — no analyst queuing required - 11,521 risky user monitoring scans completed, each routing confirmed threats to analyst review - 423 phishing incident records created or updated in tracking tables, maintaining full case history - 372 phishing alerts processed through an automated triage driver running every 15 minutes - 371 DLP access exception requests processed end-to-end from ITSM ticket to enforcement - 272 user passwords provisioned or reset without manual IT intervention - 219 device isolation actions executed in response to confirmed security threats - 124 endpoint alerts ingested, enriched, and routed through structured triage - 85 phishing-related threat IDs linked to incident records for cross-case correlation - 80 security alert response workflows orchestrated with built-in analyst approval gates - 51 risky user cases investigated and remediated with full audit trail - 28 stale device cleanup cycles executed, disabling or removing inactive AD computer objects - 11 Power Platform environments scanned for security posture issues via Wiz integration - 30 server onboarding and offboarding events processed through automated vulnerability workflows

Use Case Summary

Use Case Category Subcategories Playbooks Total Executions (12 mo.)
EDR Alert Triage, Enrichment & Containment SOC EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR 11 716
Identity Threat Monitoring & Response SOC Identity threat response 2 11,572
DLP Exception Lifecycle Management GRC DLP triage & exposure resp 7 35,527
Stale Device Lifecycle Automation IAM Access review & group mgmt, Identity sync & directory mgmt 4 315
Password & Credential Management IAM Password & credential lifecycle, Privileged account mgmt, Identity lifecycle automation 7 315
Server Vulnerability & Asset Lifecycle Vulnerability Mgmt Vuln scan lifecycle automation, Vuln scanning ingest & report 5 30
Agentic SOC Toolset SOC Agentic SOC, Alert enrichment / IOC lookup 11 13
Phishing Alert Triage & Response SOC Phishing detection & response 4 1,252
Power Platform Security Posture Monitoring Cloud Security CSPM ingest & triage 1 11

Use Cases

1. EDR Alert Triage, Enrichment & Containment

Category: SOC — EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR

Description: A full-stack EDR alert pipeline spanning CrowdStrike and Microsoft Defender for Endpoints. Each alert is ingested, enriched with device, user, and IOC context from Intune, Entra ID, CrowdStrike, and Splunk, then routed through an analyst-gated approval form before automated response actions (dismiss, isolate, AV scan, or auto-investigate) are executed. Device isolation requests from Azure runbooks flow through the same containment engine.

Business Problem: SOC analysts were manually triaging alerts across two EDR platforms, correlating device and user context without tooling, and executing response actions without a structured approval workflow — leading to inconsistent triage quality and undocumented response decisions.

Integrations: CrowdStrike, Microsoft Defender for Endpoints, Microsoft Intune, Microsoft Entra ID, Splunk, SendGrid, Blink Tables

Playbook Type Executions (12 mo.) Category Subcategory
Ingest - Crowdstrike Alert Event (webhook) 0 SOC Alert enrichment / IOC lookup, Case mgmt & SOAR
Ingest - MD Alert Event (polling) 124 SOC Alert enrichment / IOC lookup, Case mgmt & SOAR
Parent - Alert Response Facilitation On-demand 80 SOC Case mgmt & SOAR, EDR containment & response
Subflow - IOC Extraction On-demand 134 SOC Alert enrichment / IOC lookup
Subflow - Enrich Device User and IOC On-demand 90 SOC Alert enrichment / IOC lookup
Subflow - Dismiss EDR Alert On-demand 13 SOC EDR containment & response
Subflow - AV Scan Host On-demand 0 SOC EDR containment & response
Subflow - Auto Investigate On-demand 0 SOC EDR containment & response
Isolate Device Event (webhook) 219 SOC EDR containment & response
Subflow - Isolate Host with Crowdstrike On-demand 0 SOC EDR containment & response
EDR Tracking Table Cleanup Scheduled 56 SOC Case mgmt & SOAR

2. Identity Threat Monitoring & Response

Category: SOC — Identity threat response

Description: Entra ID is polled every 5 minutes for risky user detections. When a risky user is identified, an analyst approval workflow is triggered — delivering enriched sign-in context and IP geolocation data via a web form and email notification. Upon analyst confirmation, automated remediation actions are executed with a full audit record written back to the case table.

Business Problem: Risky user detections in Microsoft Entra ID required manual analyst review with no structured triage or remediation workflow, creating response delays and inconsistent handling across analysts.

Integrations: Microsoft Entra ID, SendGrid, Blink Web Forms, Blink Tables

Playbook Type Executions (12 mo.) Category Subcategory
Parent - Find Risky Users Scheduled 11,521 SOC Identity threat response
Subflow - Risky User Approval and Remediation On-demand 51 SOC Identity threat response

3. DLP Exception Lifecycle Management

Category: GRC — DLP triage & exposure resp

Description: The full lifecycle of DLP exclusions is automated — from ingesting exception requests via EasyVista webhooks, validating destination TLS certificates, provisioning users or hosts into exclusion groups, tracking expiry dates in a Blink table, to automatically revoking exceptions when they expire. A scheduled daily cleanup enforces timely removal of untracked and expired exclusions, and a USB exception workflow handles device-based bypass requests.

Business Problem: DLP exception management was manual and error-prone. There was no automated mechanism to track expiry, enforce timely revocation, or audit active exclusions — creating both compliance exposure and operational overhead for the security team.

Integrations: EasyVista (webhook), Delinea, Blink Tables, PowerShell, SendGrid

Playbook Type Executions (12 mo.) Category Subcategory
DLP Exclusion Addition Event (webhook) 371 GRC DLP triage & exposure resp
DLP Exclusion Remove Expired On-demand 35,072 GRC DLP triage & exposure resp
DLP Exclusion Removal Schedule Scheduled 40 GRC DLP triage & exposure resp
Subflow - DLP Bypass Host Removal Scheduled 40 GRC DLP triage & exposure resp
Adhoc - DLP Exclusion Addition On-demand 4 GRC DLP triage & exposure resp
DLP USB Exception Workflow Event (webhook) 0 GRC DLP triage & exposure resp
DLP Exclusion Remove Untracked On-demand 0 GRC DLP triage & exposure resp

4. Stale Device Lifecycle Automation

Category: IAM — Access review & group mgmt, Identity sync & directory mgmt

Description: Active Directory is queried via SSH and WinRM to identify computer objects that have not authenticated within defined thresholds. Results are cross-referenced against Splunk authentication logs and a curated exclusion list to eliminate false positives. Devices inactive for 90+ days are automatically disabled; devices inactive for 120+ days are deleted. Each cycle generates an HTML summary report delivered via email.

Business Problem: Stale and unmanaged device objects in Active Directory expanded the attack surface and complicated compliance audits. Manual cleanup was infrequent and inconsistent, leaving disabled or forgotten endpoints active in the directory.

Integrations: SSH (Active Directory), WinRM, Splunk, SendGrid

Playbook Type Executions (12 mo.) Category Subcategory
Parent - Disable_Delete Stale Devices Scheduled 28 IAM Access review & group mgmt
Subflow - Generate Stale Candidate List On-demand 28 IAM Identity sync & directory mgmt
Subflow - Disable Workstation in AD On-demand 143 IAM Identity sync & directory mgmt
Subflow - Delete Workstation in AD On-demand 116 IAM Identity sync & directory mgmt

5. Password & Credential Management

Category: IAM — Password & credential lifecycle, Privileged account mgmt, Identity lifecycle automation

Description: User password lifecycle is managed across multiple pathways: automated provisioning triggered by the UserCube IGA platform via webhook, on-demand force-reset with end-user notification via Entra ID, and scheduled cleanup of temporary onboarding passwords in Delinea. A separate restoration workflow handles re-enabling terminated employees through a manager-approval email gate.

Business Problem: Password provisioning during onboarding, forced resets for compromised accounts, and cleanup of privileged temporary credentials all required manual IT intervention across Entra ID, Active Directory, and Delinea — creating delays and credential hygiene gaps.

Integrations: Microsoft Entra ID, Delinea, UserCube (webhook), SendGrid, SSH/WinRM, Blink Tables, Microsoft SQL Server, Splunk

Playbook Type Executions (12 mo.) Category Subcategory
Set User Password Event (webhook) 272 IAM Password & credential lifecycle
Cleanup Delinea Onboarding Passwords Scheduled 40 IAM Privileged account mgmt
On-Demand Set User Password On-demand 1 IAM Password & credential lifecycle
Restore Termed User On-demand 1 IAM Identity lifecycle automation
Missed Offboards Scheduled 1 IAM Identity lifecycle automation
Subflow - Change PW On-demand 0 IAM Password & credential lifecycle
Set User Password (DEV) Event (webhook) 0 IAM Password & credential lifecycle

6. Server Vulnerability & Asset Lifecycle

Category: Vulnerability Mgmt — Vuln scan lifecycle automation, Vuln scanning ingest & report

Description: Tenable vulnerability scanning is integrated with EasyVista IT service management. Server onboarding tickets automatically trigger a targeted Tenable scan; server offboarding tickets remove the asset from Tenable inventory. A web form portal enables system owners to submit targeted plugin-based vulnerability searches without requiring Tenable access.

Business Problem: New servers were not consistently scanned upon deployment, and decommissioned servers remained in Tenable scan targets, producing noisy and inaccurate reports. Asset lifecycle was managed manually across ITSM and vulnerability management platforms with no automation bridge.

Integrations: Tenable, EasyVista (webhook), Blink Web Forms, Blink Tables

Playbook Type Executions (12 mo.) Category Subcategory
Ingest EasyVista Ticket Data Event (webhook) 16 Vulnerability Mgmt Vuln scan lifecycle automation
Server Offboarding - Ingest EasyVista Ticket Event (webhook) 14 Vulnerability Mgmt Vuln scan lifecycle automation
Server Vulnerability Submissions Event (web form) 0 Vulnerability Mgmt Vuln scanning ingest & report
Run Tenable Scan On-demand 0 Vulnerability Mgmt Vuln scan lifecycle automation
Rescan On-demand 0 Vulnerability Mgmt Vuln scan lifecycle automation

7. Agentic SOC Toolset

Category: SOC — Agentic SOC, Alert enrichment / IOC lookup

Description: A library of modular "Ability" workflows designed for use by AI-driven SOC agents. Each ability is a discrete, input-driven action — querying Entra ID user context, executing Defender KQL advanced hunting queries, retrieving CrowdStrike host and alert details, searching Splunk, resolving Power Platform environments, or listing recent device activity. These serve as callable tools for autonomous investigation pipelines.

Business Problem: AI-assisted SOC investigation requires standardized, reusable action interfaces across security tools. Without structured abilities, agents cannot reliably retrieve and act on data from disparate platforms, limiting the effectiveness of autonomous triage.

Integrations: Microsoft Entra ID, Microsoft Defender for Endpoints, CrowdStrike, Splunk, Microsoft Power Platform

Playbook Type Executions (12 mo.) Category Subcategory
Ability - Get Entra User Context On-demand 2 SOC Agentic SOC
Ability - Run Defender Advanced Hunting On-demand 2 SOC Agentic SOC
Ability - Get Defender Alert by ID On-demand 2 SOC Agentic SOC
Ability - Defender KQL Query Guide On-demand 2 SOC Agentic SOC
Ability - Defender Recent Logons for User (preset) On-demand 1 SOC Agentic SOC
Ability - Get CrowdStrike Host Context On-demand 1 SOC Agentic SOC
Ability - Get CrowdStrike Alert Details On-demand 0 SOC Agentic SOC
Ability - Search Splunk On-demand 0 SOC Agentic SOC, SIEM & log pipeline monitoring
Ability - Resolve Power Platform Environment On-demand 0 SOC Agentic SOC
Ability - Get User License Entitlement On-demand 0 SOC Agentic SOC
Ability - Defender List Recent Devices (preset) On-demand 0 SOC Agentic SOC

8. Phishing Alert Triage & Response

Category: SOC — Phishing detection & response

Description: A scheduled driver polls for new phishing submissions every 15 minutes and orchestrates the full triage lifecycle — logging incoming reports to tracking tables, extracting and linking related threat IDs for cross-case correlation, and dispatching analyst notifications or web forms for review and response.

Business Problem: Phishing reports were not centrally logged or correlated with related threat indicators, and there was no structured, low-latency mechanism to notify analysts or end users as new phishing submissions arrived.

Integrations: Blink Tables, Blink Web Forms, SendGrid

Playbook Type Executions (12 mo.) Category Subcategory
Phishing Driver Scheduled 372 SOC Phishing detection & response
Subflow - Add or Update New Phishing Data to Tables On-demand 423 SOC Phishing detection & response
Subflow - Add or Update Phishing_related_threat_ids table On-demand 85 SOC Phishing detection & response
Subflow - Send Emails and Webforms On-demand 372 SOC Phishing detection & response

9. Power Platform Security Posture Monitoring

Category: Cloud Security — CSPM ingest & triage

Description: A daily scheduled job integrates with Wiz to assess the security posture of Microsoft Power Platform environments, extending cloud security posture management coverage to low-code/no-code application infrastructure.

Business Problem: Power Platform environments (apps, flows, connectors) lacked visibility into security posture and misconfiguration risk — an increasingly common blind spot as low-code platforms proliferate outside traditional IT governance.

Integrations: Wiz, Microsoft Power Platform

Playbook Type Executions (12 mo.) Category Subcategory
Wiz Integration for Power Platform Scheduled 11 Cloud Security CSPM ingest & triage

Key Observations

Strengths

High-volume DLP enforcement at scale. The DLP exception lifecycle is the most operationally active use case, with 35,072 automated exception removals and 371 additions over 12 months. This represents a mature, production-grade compliance automation covering the full add-track-expire-revoke lifecycle with no manual queuing required.

Analyst-gated SOC workflow architecture. Alert response is structured around an explicit human approval gate (web form + email), meaning automation handles enrichment, context aggregation, and orchestration while analysts retain decision authority. This is a defensible, audit-friendly design appropriate for a regulated financial services environment.

Dual-EDR coverage with unified pipeline. Both CrowdStrike and Microsoft Defender for Endpoints are integrated into a single alert triage pipeline, with IOC extraction and enrichment abstracted as reusable subflows. Cross-platform alert correlation happens automatically before any analyst interaction.

IAM automation breadth. Password lifecycle, stale device cleanup, user restoration, and privileged credential management are all automated across Entra ID, Active Directory, Delinea, and UserCube — covering the most common IAM failure modes in an enterprise environment.

Agentic SOC foundation in place. A structured Ability library covering CrowdStrike, Defender, Entra ID, Splunk, and Power Platform is deployed in a dedicated workspace. Initial execution counts (13 executions across 6 abilities) indicate early-stage adoption with a platform ready to scale into autonomous investigation workflows.

New phishing triage pipeline established. A 15-minute scheduled driver now logs phishing submissions to tracking tables, links related threat IDs for cross-case correlation, and dispatches analyst notifications — 1,252 combined executions across the driver and its subflows indicate immediate high-volume adoption.

Gaps

CrowdStrike alert pipeline inactive. Ingest - Crowdstrike Alert has 0 executions despite the full workflow being built with webhook trigger and alert enrichment steps. CrowdStrike-originated alerts are not flowing through Blink, leaving Microsoft Defender as the sole active EDR ingest source. This is a coverage gap given CrowdStrike is also deployed for containment.

Vulnerability management pipeline not operationalized. The Tenable integration handles server onboarding and offboarding (30 executions combined) but Server Vulnerability Submissions, Run Tenable Scan, and Rescan all have 0 executions. Vulnerability scanning, prioritization, and remediation tracking are not yet automated beyond asset registration.

Containment response actions unused. Subflow - AV Scan Host, Subflow - Auto Investigate, and Subflow - Isolate Host with Crowdstrike all have 0 executions. These response capabilities are built and integrated with CrowdStrike and Defender but are not being triggered through the alert response facilitation workflow.

DLP USB exception flow not activated. DLP USB Exception Workflow exists with a webhook trigger but has 0 executions. USB-based DLP exception requests are likely still being handled through a manual process outside of Blink.

Agentic SOC at early adoption. The Ability library has 11 workflows built but only 5 have been invoked (13 total executions). The agentic investigation pattern has not yet been scaled into continuous autonomous workflows.

Power Platform posture monitoring at early adoption. Wiz Integration for Power Platform is Forvis's first Cloud Security automation, running daily but with only 11 executions to date — early-stage compared to the mature DLP and identity pipelines.

Integration Ecosystem

Forvis's automation estate spans 16 distinct integrations:

Integration Use Cases
Microsoft Entra ID / Active Directory Identity threat response, EDR enrichment, Password management, Stale device cleanup, Agentic SOC
CrowdStrike EDR alert ingest (built, inactive), Device isolation, Alert enrichment, Agentic SOC
Microsoft Defender for Endpoints EDR alert ingest (active), Alert enrichment, Agentic SOC
Microsoft Intune Device enrichment in EDR pipeline
Splunk Stale device validation, EDR enrichment, Agentic SOC
Delinea DLP bypass removal, Onboarding password cleanup
SendGrid Alert notifications, Analyst approvals, End-user notifications, Phishing notifications
Tenable Server vulnerability scanning, Asset lifecycle management
EasyVista Server onboarding/offboarding triggers, DLP exception requests
UserCube Password provisioning trigger via IGA webhook
SSH / WinRM AD computer object management, DLP group enforcement
Blink Web Forms Alert approvals, Vulnerability submissions, Risky user approvals, Phishing response forms
Blink Tables Case tracking, Exception expiry tracking, EDR record management, Phishing data tracking
Wiz Power Platform security posture monitoring
Microsoft Power Platform Power Platform security posture monitoring
Microsoft SQL Server Offboarding compliance reconciliation (Missed Offboards)
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Forvis mssql my_microsoft_sql_server_connection 2026-08-31