01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Employee & Contractor Lifecycle |
| 0.5% | 4 4 active |
| Security Operations & Alert Management |
| 35.2% | 21 21 active |
| Vulnerability Lifecycle Management |
| 0.6% | 5 5 active |
| AI-Driven HR Process Automation |
| 0.2% | 2 2 active |
| Contract Lifecycle Automation |
| 1.0% | 6 6 active |
| Executive & Business Reporting |
| 1.0% | 7 7 active |
| Software Deployment & IT Self-Service |
| 0.9% | 5 5 active |
| Finance Operations Automation |
| 0.5% | 4 4 active |
| Vendor Risk & Software Assurance Automation |
| 0.9% | 5 5 active |
| Total | 2,294 executions | 100% | 59 59 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature, multi-system IAM lifecycle. Both employee and contractor onboarding and offboarding run fully automated, touching AD, Entra ID, Okta, Duo, Atlassian, Exchange Online, Intune, and Freshservice in a single orchestrated flow. With 15 onboardings and 9 offboardings in 12 months, this is a high-trust, production-grade operation.
Well-architected SOC stack. The SOC automation follows a clean modular design: four ingest connectors → Process Alert orchestrator → Enrich Observables router → 13 typed enrichers → Response Main Router → dedicated response subflows. The 60 enrichment routing calls and 32 processed alerts confirm the pipeline is live and running.
Broad and growing AI agent adoption. Agentic workflows now span executive briefing (Thursday Special), job description drafting (Job Intake), CEO summary generation (Alex Report), security activity analysis (User Device Activity Search), a four-agent spend validation chain (SQL Query Agent → Price Analysis Agent → Legal Assistant → Report Assembler Bot in Finance Spend Validation Master Workflow, 26 executions), and Claude-driven document analysis for SOC2 CUEC extraction (30 executions) and software assurance ticket review (SAP Engine). This is one of the more diverse AI automation footprints in production.
Contract automation at scale. 26 contracts automatically routed from Salesforce to IronClad is a high-value, measurable outcome — replacing a manual handoff between sales and legal that is both time-sensitive and error-prone.
Vulnerability management is fully scheduled. The twice-weekly Vuln Management Engine runs a complete cycle — sync from CrowdStrike, reconcile the master table, and generate per-department HTML reports — without any analyst involvement.
Vendor risk automation now includes AI-driven document analysis. SOC2 CUEC Analysis ran 30 times in its first period — using Claude to extract complementary user entity controls directly from vendor SOC2 reports — while Update Vendor Information from Risk Rank and Fortress Platform to OpenGRC Vendor Sync keep the vendor registry and risk scores current automatically.
###
Gaps & Opportunities
SOC enrichment modules are built but dormant. The Enrich Observables router fired 60 times, but all 13 individual enrichment subflows show 0 executions. This suggests the router may be making conditional calls that rarely satisfy enricher trigger conditions, or the routing logic needs tuning to activate the enrichment library. Resolving this would convert the existing investment into measurable IOC coverage.
PDQ software deployment is partially live. Freshservice: Install Software using PDQ (6 executions) and Deploy software using PDQ Connect (4 executions) are now running in production, but the original four PDQ subflows (ticket intake → device lookup → package deploy → completion polling) still show 0 executions. Consolidating onto the active workflows and retiring the unused duplicates would reduce maintenance overhead.
Finance Database Analyzer and BETA invoice validation remain unused. The Finance Spend Validation Master Workflow is now live and processing vendor spend approvals end-to-end (26 executions), but the four-agent Finance Database Analyzer and the BETA: Finance Validation workflow against Bill.com/QuickBooks have never run. Extending the same AI-agent pattern that powers spend validation would help activate these quickly.
Phishing and malware response flows not yet triggered. Both response subflows have 0 executions. With 32 alerts processed through Process Alert and 30 routing calls through the Response Main Router, the response layer exists — but either no alerts have matched phishing/malware classification or the routing conditions need review.
Document Contract Review disconnected. The Salesforce-triggered Document Contract Review workflow has 0 executions while the parallel Contract to IronClad flow (same trigger type) ran 26 times. These likely need to share the same Salesforce trigger event or the connection may not be configured.
User Device Activity Search unused. This CrowdStrike + Defender + AI investigative workflow has 0 executions. As a security-critical capability for device forensics, enabling this for incident response would extend the SOC automation coverage significantly.
Integration Ecosystem
The automation stack spans 20+ distinct integrations across seven domains:
| Domain | Integrations |
|---|---|
| Identity & Access | Active Directory (WinRM), Microsoft Entra ID, Okta, Duo, AWS WorkSpaces |
| Microsoft 365 | Microsoft Graph, Exchange Online, Microsoft Outlook, SharePoint, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Intune, Microsoft Teams |
| IT Service Management | Freshservice |
| Security | CrowdStrike, Splunk, VirusTotal, AbuseIPDB, URLScan |
| Business Systems | Salesforce, Atlassian (Jira + User Management), Harvest, Bill.com |
| GRC / Vendor Risk | Fortress Platform API, OpenGRC |
| Endpoint Management | PDQ Connect |
A Case Management 1,098 cases (12m) | MTTR 8h 46m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 1,098 | 1,098 | 1,091 | 8h 46m |
B AI Agents 16 active | 1,838 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Omni Alert | Case Management | 1,089 | 588 | 44,345,462 |
| 2 | Executive Wrangler Bot | Executives | 197 | 23 | 8,271,559 |
| 3 | Recruiter Battle Bot | Corporate Automations | 180 | 8 | 12,782,059 |
| 4 | SQL Query Agent | Executives | 71 | 26 | 2,229,588 |
| 5 | FLSA Regulator Bot | Corporate Automations | 53 | 3 | 15,940,220 |
| Workspace | Tasks (12m) |
|---|---|
| Case Management | 1,089 |
| Executives | 446 |
| Corporate Automations | 291 |
| Fortress Platform | 12 |
C Self-Service & Webforms 0 app runs | 45 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Vulnerability Tracking | 0 | 0 |
| 2 | Thursday Special Dashboard | 0 | 0 |
| 3 | test | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Vendor Information Review | 23 | 21 |
| 2 | Vendor Information Review | 22 | 17 |
D Full Use Case Analysis 9 use cases | 5,630 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Executive status reports submitted via AI | 44 | Thursday Special |
| Security alerts processed end-to-end | 32 | Process Alert |
| Contracts automatically routed to IronClad | 26 | Contract to IronClad |
| Job descriptions drafted & distributed by AI | 20 | Job Intake from FreshService (HR) |
| HR job description folders created in SharePoint | 18 | Create JD Folders & Move Templates (HR) |
| Splunk alerts ingested into case management | 16 | Ingest - Splunk Alerts |
| Employees onboarded end-to-end | 13 | Onboarding-Employee Automation |
| Vulnerability database syncs executed | 12 | Vulnerability Table Updater |
| Defender XDR alerts ingested | 11 | EXAMPLE Ingest - Microsoft Defender XDR |
| Bi-weekly vulnerability management cycles completed | 11 | Vuln Management Engine |
| Per-department vulnerability reports generated | 13 | Open Vulnerability Report Generator, RL TEST - 03 Open Vulnerability Report |
| Employees fully offboarded across all systems | 8 | Off-Boarding Automation |
| SOC2 reports analyzed by AI for CUEC coverage | 30 | SOC2 CUEC Analysis |
| Vendor spend validations processed end-to-end | 26 | Finance Spend Validation Master Workflow |
| Contract expiration reminders sent (30/60/90-day) | 16 | Notify Users of Expiring Contracts (30/60/90 days) |
| Software installations executed via PDQ | 10 | Freshservice: Install Software using PDQ, Deploy software using PDQ Connect |
| Freshservice ticket-monitoring cycles completed | 2 | Freshservice: Periodic Ticket Monitor |
| Unassigned Freshservice tickets flagged via Teams | 1 | Freshservice: Unassigned Ticket Monitor |
| Freshservice ticket reminders sent to agents | 1 | Freshservice: User Ticket Reminder |
| Vendor risk rank records updated | 16 | Update Vendor Information from Risk Rank, Copy Update Vendor Information from Risk Rank |
| Software assurance tickets analyzed via AI | 1 | SAP Engine |
| Weekly executive summary reports sent | 6 | Thursday Special - Sunday Report |
| Software assurance checks performed | 6 | Software Assurance |
| Offboarding security notifications sent to FSO team | 5 | FSO Off-Board Notification |
| CrowdStrike detections ingested | 4 | Ingest - CrowdStrike Detections |
| Security document deliveries (FSO team) | 3 | FSO Docs Delivery, CC FSO Pros (Security) |
| Contractors onboarded | 2 | Onboarding-Contractor |
| Contractors fully offboarded | 1 | Off-Boarding: Contractors |
| CEO summary reports generated | 1 | Alex Report |
| Monthly time reports generated | 1 | Harvest Time Report |
| Executive notifications sent | 1 | Notify Execs |
| Software installations via self-service portal | 1 | Install Software from Portal |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks | Executions |
|---|---|---|---|---|---|
| 1 | Employee & Contractor Lifecycle | IAM | Employee onboarding, Employee offboarding, Identity lifecycle automation | 9 | 56 |
| 2 | Security Operations & Alert Management | SOC | Case mgmt & SOAR, Alert enrichment / IOC lookup, EDR containment & response, Phishing detection & response, SIEM & log pipeline monitoring | 25 | 153 |
| 3 | Vulnerability Lifecycle Management | Vulnerability Mgmt | Vuln scanning ingest & report, Vuln lifecycle prioritize & ticket, Vuln scan lifecycle automation | 7 | 37 |
| 4 | AI-Driven HR Process Automation | GRC | AI / HR compliance automation | 2 | 38 |
| 5 | Contract Lifecycle Automation | GRC | Vendor risk & TPRM, Compliance questionnaire | 6 | 45 |
| 6 | Executive & Business Reporting | GRC | Security metrics & reporting | 8 | 59 |
| 7 | Software Deployment & IT Self-Service | Other | Endpoint hygiene & MDM ops, IT helpdesk & ticket routing, SaaS / IT administration | 18 | 21 |
| 8 | Finance Operations Automation | Other | Financial & fraud operations | 4 | 26 |
| 9 | Vendor Risk & Software Assurance Automation | GRC | Vendor risk & TPRM, Compliance questionnaire | 5 | 47 |
Use Cases
1. Employee & Contractor Lifecycle
Description: Fully automated onboarding and offboarding for both employees and contractors, orchestrating identity provisioning and deprovisioning across Active Directory, Microsoft 365, Okta, Duo, and Atlassian. Each lifecycle event is triggered by a Freshservice ticket approval and closes with an automated summary note — no manual steps required.
Business problem solved: Manual onboarding and offboarding are error-prone, slow, and leave orphaned accounts that create security and compliance risk. Automation ensures consistent, auditable execution across every required system within minutes of a ticket approval.
Integrations: Microsoft Intune, Active Directory (WinRM), Microsoft Entra ID, Microsoft Graph, Exchange Online, Okta, Duo, Atlassian User Management, Jira, AWS WorkSpaces, Freshservice
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Onboarding-Employee Automation | Employee onboarding | Event (webhook) | 13 |
| Onboarding-Contractor | Employee onboarding | Event (webhook) | 2 |
| Off-Boarding Automation | Employee offboarding | Event (webhook) | 8 |
| Off-Boarding: Contractors | Employee offboarding | On demand | 1 |
| Device Isolation & Asset Return Ticket Creation *(subflow)* | Employee offboarding | On demand | 9 |
| Atlassian Deactivation *(subflow)* | Employee offboarding | On demand | 9 |
| Okta Account Deactivation *(subflow)* | Employee offboarding | On demand | 9 |
| FSO Off-Board Notification *(subflow)* | Identity lifecycle automation | On demand | 5 |
| Remove User's AWS Workspace Ticket *(subflow)* | Employee offboarding | On demand | 0 |
2. Security Operations & Alert Management
Description: A full SOC automation stack spanning alert ingest, observable enrichment, and incident response. Alerts from CrowdStrike, Splunk, and Microsoft Defender XDR are ingested into Blink's case management system, observables are automatically extracted and routed through 13+ enrichment modules (covering IP, hash, URL, domain, username, and device types), and confirmed threats are dispatched to dedicated phishing and malware response flows.
Business problem solved: Security analysts are overwhelmed by alert volume and manual triage. This automation handles ingestion, deduplication, enrichment, and response routing end-to-end — reducing analyst workload and mean time to respond.
Integrations: CrowdStrike, Splunk, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Blink Case Management, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, Microsoft Outlook, Bash/Whois
Alert Ingest & Processing
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Process Alert | Case mgmt & SOAR | Event (polling) | 32 |
| Ingest - Splunk Alerts | SIEM & log pipeline monitoring | Event (webhook) | 16 |
| EXAMPLE Ingest - Microsoft Defender XDR | SIEM & log pipeline monitoring | Event (polling) | 11 |
| Ingest - CrowdStrike Detections | SIEM & log pipeline monitoring | Event (webhook) | 4 |
| User Device Activity Search (Security) | Agentic SOC | On demand | 0 |
Response Flows
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Subflow - Response - Main Router *(subflow)* | Case mgmt & SOAR | On demand | 30 |
| Response Subflow - Phishing | Phishing detection & response | On demand | 0 |
| Response Subflow - Malware | EDR containment & response | On demand | 0 |
Observable Enrichment
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router *(subflow)* | Alert enrichment / IOC lookup | On demand | 60 |
| Subflow - Update Enrichment Data *(subflow)* | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Hash - VT | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Hash - Crowdstrike | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - IP - VT | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - IP - IPDB | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - IP or Domain - Whois | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich IP or Domain Using Whois | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - URL - VT | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - URL - URLScan | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Username or Email - Okta | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Username or Email - Microsoft Entra ID | Alert enrichment / IOC lookup | On demand | 0 |
| Get User Information Using Microsoft Entra ID | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Username or Email - Google Workspace | Alert enrichment / IOC lookup | On demand | 0 |
| Get User Information Using Google Workspace | Alert enrichment / IOC lookup | On demand | 0 |
| Enrich - Agent ID - Crowdstrike | Alert enrichment / IOC lookup | On demand | 0 |
| Error Handling - Send Error Notification Email *(utility)* | Case mgmt & SOAR | On demand | 0 |
3. Vulnerability Lifecycle Management
Description: A scheduled, end-to-end vulnerability management pipeline that syncs open vulnerabilities from CrowdStrike into a master Blink table, reconciles inserts/updates/deletes, and generates per-department HTML reports distributed to stakeholders via email. Runs automatically twice a week; the table can also be synced on demand.
Business problem solved: Vulnerability data scattered across tools creates blind spots and manual reporting bottlenecks. This pipeline maintains a single source of truth and ensures each department receives a targeted view of their open risk exposure — without analyst involvement.
Integrations: CrowdStrike, Blink Tables, Bash/Python
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Vuln Management Engine | Vuln scan lifecycle automation | Scheduled (Mon/Thu 9:30 AM ET) | 11 |
| Vulnerability Table Updater *(subflow)* | Vuln lifecycle prioritize & ticket | On demand | 12 |
| Open Vulnerability Report Generator *(subflow)* | Vuln scanning ingest & report | On demand | 11 |
| Vulnerability Table Updater (Unified Sync + Reconcile) | Vuln lifecycle prioritize & ticket | On demand | 1 |
| Master Vulnerability Table Backfill | Vuln scanning ingest & report | On demand | 0 |
| RL TEST - 03 Open Vulnerability Report | Vuln scanning ingest & report | On demand | 2 |
| RL TEST - 04 Vuln Engine | Vuln scan lifecycle automation | On demand | 0 |
4. AI-Driven HR Process Automation
Description: Automates two HR workflows triggered from Freshservice tickets: an AI-powered job intake flow where an agentic bot drafts a formatted job description document from ticket inputs and emails it to HR, and a SharePoint automation that creates folder structures and moves templates whenever a new job description is initiated.
Business problem solved: HR teams spend significant time drafting job descriptions and organizing file structures manually. These workflows deliver a polished job description document within minutes of ticket submission and keep SharePoint organized automatically.
Integrations: Freshservice, Blink AI Agents, SharePoint, Microsoft Outlook, Python/DOCX
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Job Intake from FreshService (HR) | AI / HR compliance automation | Event (webhook) | 20 |
| Create JD Folders & Move Templates (HR) | AI / HR compliance automation | Event (webhook) | 18 |
5. Contract Lifecycle Automation
Description: Automatically moves contracts from Salesforce to IronClad when triggered by a Salesforce webhook event — downloading the attached file, parsing contract metadata, and routing the document through the defined legal workflow. A parallel flow handles AI-assisted document contract review, and a third flow manages secure delivery of FSO-related documents to the security team.
Business problem solved: Manual contract routing between sales and legal causes delays and handoff errors. Automation ensures contracts reach IronClad immediately upon Salesforce event, with full metadata intact.
Integrations: Salesforce, IronClad (via email), Microsoft Outlook, Microsoft Entra ID (for FSO group verification)
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Contract to IronClad | Vendor risk & TPRM | Event (Salesforce webhook) | 26 |
| FSO Docs Delivery, CC FSO Pros (Security) | Compliance questionnaire | Event (webhook) | 3 |
| Document Contract Review | Vendor risk & TPRM | Event (Salesforce webhook) | 0 |
| Notify Users of Expiring Contracts 30 days | Vendor risk & TPRM | Scheduled (Tue 8:30 AM ET) | 6 |
| Notify Users of Expiring Contracts 60 days | Vendor risk & TPRM | Scheduled (Tue 8:30 AM ET) | 5 |
| Notify Users of Expiring Contracts 90 days | Vendor risk & TPRM | Scheduled (Tue 8:30 AM ET) | 5 |
6. Executive & Business Reporting
Description: A suite of AI-powered and scheduled reporting workflows. The centerpiece is "Thursday Special" — team leads submit weekly status updates (blockers, priorities, meetings, time off) which an AI agent synthesizes into an executive briefing, stored in a Blink table and emailed every Sunday morning. Complementary flows deliver CEO summaries from Salesforce data, monthly time tracking reports from Harvest, and weekly executive email notifications.
Business problem solved: Executive reporting requires significant time gathering and synthesizing information across teams. These automations replace manual aggregation with AI-generated insight delivered on a consistent cadence.
Integrations: Blink AI Agents, Blink Tables, Salesforce, Harvest, Microsoft Outlook, Fortress Platform API
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Thursday Special | Security metrics & reporting | On demand | 44 |
| Thursday Special - Sunday Report | Security metrics & reporting | Scheduled (Mon 8:59 AM ET) | 6 |
| Nuke Thursday Special Table *(infrastructure)* | Security metrics & reporting | Scheduled (Wed 12:01 PM ET) | 6 |
| Alex Report | Security metrics & reporting | Scheduled (Mon 9:01 AM ET) | 1 |
| Notify Execs | Security metrics & reporting | Scheduled (Thu 3:45 PM ET) | 1 |
| Harvest Time Report | Security metrics & reporting | Scheduled (1st of month 9:15 AM ET) | 1 |
| Sales Inactivity Report | Security metrics & reporting | On demand | 0 |
| Risk Rank Reminders | Security metrics & reporting | Scheduled | 0 |
7. Software Deployment & IT Self-Service
Description: Automated software deployment via PDQ Connect, fulfilling Freshservice-ticketed software installation requests end-to-end: lookup the device, find the package, deploy, and poll for completion. Includes a self-service portal workflow for employee-initiated installs and a software assurance check workflow. Supporting utilities handle Freshservice custom object queries and email delivery.
Business problem solved: Software installation requests create IT helpdesk backlog and delay employee productivity. Automation fulfills requests directly from the ticket without IT intervention.
Integrations: PDQ Connect, Freshservice, Microsoft Graph (email), Bitbucket (SSH)
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Software Assurance | Endpoint hygiene & MDM ops | On demand / webhook | 6 |
| Install Software from Portal | IT helpdesk & ticket routing | On demand | 1 |
| Freshservice: Install Software using PDQ | IT helpdesk & ticket routing | On demand | 6 |
| Deploy software using PDQ Connect | Endpoint hygiene & MDM ops | On demand | 4 |
| Freshservice Ticket: Install Software using PDQ | IT helpdesk & ticket routing | On demand | 0 |
| Deploy PDQ Package to Device *(subflow)* | Endpoint hygiene & MDM ops | On demand | 0 |
| Deploy PDQ Package to Device *(subflow, dev workspace)* | Endpoint hygiene & MDM ops | On demand | 0 |
| PDQ Software Install Dev *(dev)* | IT helpdesk & ticket routing | On demand | 0 |
| Find Freshservice Service Item Custom Object Record *(utility)* | IT helpdesk & ticket routing | On demand | 0 |
| Launch Freshservice Workflow *(utility)* | IT helpdesk & ticket routing | Event (webhook) | 0 |
| Query FreshService Object Records *(utility)* | IT helpdesk & ticket routing | On demand | 0 |
| Send Graph Email *(utility)* | IT helpdesk & ticket routing | On demand | 0 |
| Python Software Install *(utility)* | Endpoint hygiene & MDM ops | On demand | 0 |
| FS Get Service Items *(utility)* | IT helpdesk & ticket routing | On demand | 0 |
| Freshservice: Periodic Ticket Monitor | IT helpdesk & ticket routing | Scheduled (Mon-Fri 8:00 AM ET) | 2 |
| Freshservice: Unassigned Ticket Monitor | IT helpdesk & ticket routing | On demand | 1 |
| Freshservice: User Ticket Reminder | IT helpdesk & ticket routing | On demand | 1 |
| Azure: Find Application *(utility)* | SaaS / IT administration | On demand | 0 |
8. Finance Operations Automation
Description: AI-powered finance analysis workflows. The Finance Spend Validation Master Workflow is fully active — triggered by a Salesforce webhook, it chains four specialized AI agents (SQL Query Agent, Price Analysis Agent, Legal Assistant, Report Assembler Bot) to validate vendor spend against budget, contract terms, and pricing before emailing an approval report. Two additional workflows remain in development: the Finance Database Analyzer, which uses four AI agents for spend anomaly detection, coding validation, month-end close assistance, and account variance narration; and a Beta workflow for invoice validation against Bill.com and QuickBooks.
Business problem solved: Finance operations require significant manual analysis time across multiple systems. The Finance Spend Validation Master Workflow now automates vendor spend validation end-to-end — from Salesforce trigger through AI-driven cost and contract analysis to email-based approval — while the remaining AI agents are being brought into production for anomaly detection and invoice validation.
Integrations: Blink AI Agents, Salesforce, Blink Tables, Bill.com, QuickBooks, PowerShell, Microsoft Outlook
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| Finance Spend Validation Master Workflow | Financial & fraud operations | Event (Salesforce webhook) | 26 |
| Update Budget Table | Financial & fraud operations | On demand | 0 |
| Finance Database Analizer | Financial & fraud operations | On demand | 0 |
| BETA: Finance Validation | Financial & fraud operations | On demand | 0 |
9. Vendor Risk & Software Assurance Automation
Description: Automates vendor risk management using the Fortress Platform API — pulling the master vendor registry and risk-rank scores, analyzing SOC2 reports with AI to identify complementary user entity controls (CUECs), running AI-driven software assurance ticket analysis triggered from Freshservice, and syncing active vendor records into OpenGRC on a monthly schedule.
Business problem solved: Vendor security reviews — pulling risk data, reading SOC2 reports, and keeping GRC systems in sync — are manual and time-intensive for the security team. These automations pull vendor data programmatically and use AI to analyze compliance documents in minutes instead of hours, while keeping OpenGRC continuously synced with the vendor registry.
Integrations: Fortress Platform API, Freshservice, Claude AI (Bash), Blink Tables, OpenGRC (HTTP)
| Playbook | Subcategory | Trigger | Executions |
|---|---|---|---|
| SOC2 CUEC Analysis | Compliance questionnaire | On demand | 30 |
| Update Vendor Information from Risk Rank | Vendor risk & TPRM | Event (web form) | 3 |
| SAP Engine | Vendor risk & TPRM | Event (webhook) | 1 |
| Fortress Platform to OpenGRC Vendor Sync | Vendor risk & TPRM | Scheduled (1st of month 8:30 AM ET) | 0 |
| Copy Update Vendor Information from Risk Rank | Vendor risk & TPRM | Event (web form) | 13 |
Key Observations
Strengths
Mature, multi-system IAM lifecycle. Both employee and contractor onboarding and offboarding run fully automated, touching AD, Entra ID, Okta, Duo, Atlassian, Exchange Online, Intune, and Freshservice in a single orchestrated flow. With 15 onboardings and 9 offboardings in 12 months, this is a high-trust, production-grade operation.
Well-architected SOC stack. The SOC automation follows a clean modular design: four ingest connectors → Process Alert orchestrator → Enrich Observables router → 13 typed enrichers → Response Main Router → dedicated response subflows. The 60 enrichment routing calls and 32 processed alerts confirm the pipeline is live and running.
Broad and growing AI agent adoption. Agentic workflows now span executive briefing (Thursday Special), job description drafting (Job Intake), CEO summary generation (Alex Report), security activity analysis (User Device Activity Search), a four-agent spend validation chain (SQL Query Agent → Price Analysis Agent → Legal Assistant → Report Assembler Bot in Finance Spend Validation Master Workflow, 26 executions), and Claude-driven document analysis for SOC2 CUEC extraction (30 executions) and software assurance ticket review (SAP Engine). This is one of the more diverse AI automation footprints in production.
Contract automation at scale. 26 contracts automatically routed from Salesforce to IronClad is a high-value, measurable outcome — replacing a manual handoff between sales and legal that is both time-sensitive and error-prone.
Vulnerability management is fully scheduled. The twice-weekly Vuln Management Engine runs a complete cycle — sync from CrowdStrike, reconcile the master table, and generate per-department HTML reports — without any analyst involvement.
Vendor risk automation now includes AI-driven document analysis. SOC2 CUEC Analysis ran 30 times in its first period — using Claude to extract complementary user entity controls directly from vendor SOC2 reports — while Update Vendor Information from Risk Rank and Fortress Platform to OpenGRC Vendor Sync keep the vendor registry and risk scores current automatically.
Gaps & Opportunities
SOC enrichment modules are built but dormant. The Enrich Observables router fired 60 times, but all 13 individual enrichment subflows show 0 executions. This suggests the router may be making conditional calls that rarely satisfy enricher trigger conditions, or the routing logic needs tuning to activate the enrichment library. Resolving this would convert the existing investment into measurable IOC coverage.
PDQ software deployment is partially live. Freshservice: Install Software using PDQ (6 executions) and Deploy software using PDQ Connect (4 executions) are now running in production, but the original four PDQ subflows (ticket intake → device lookup → package deploy → completion polling) still show 0 executions. Consolidating onto the active workflows and retiring the unused duplicates would reduce maintenance overhead.
Finance Database Analyzer and BETA invoice validation remain unused. The Finance Spend Validation Master Workflow is now live and processing vendor spend approvals end-to-end (26 executions), but the four-agent Finance Database Analyzer and the BETA: Finance Validation workflow against Bill.com/QuickBooks have never run. Extending the same AI-agent pattern that powers spend validation would help activate these quickly.
Phishing and malware response flows not yet triggered. Both response subflows have 0 executions. With 32 alerts processed through Process Alert and 30 routing calls through the Response Main Router, the response layer exists — but either no alerts have matched phishing/malware classification or the routing conditions need review.
Document Contract Review disconnected. The Salesforce-triggered Document Contract Review workflow has 0 executions while the parallel Contract to IronClad flow (same trigger type) ran 26 times. These likely need to share the same Salesforce trigger event or the connection may not be configured.
User Device Activity Search unused. This CrowdStrike + Defender + AI investigative workflow has 0 executions. As a security-critical capability for device forensics, enabling this for incident response would extend the SOC automation coverage significantly.
Integration Ecosystem
The automation stack spans 20+ distinct integrations across seven domains:
| Domain | Integrations |
|---|---|
| Identity & Access | Active Directory (WinRM), Microsoft Entra ID, Okta, Duo, AWS WorkSpaces |
| Microsoft 365 | Microsoft Graph, Exchange Online, Microsoft Outlook, SharePoint, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Intune, Microsoft Teams |
| IT Service Management | Freshservice |
| Security | CrowdStrike, Splunk, VirusTotal, AbuseIPDB, URLScan |
| Business Systems | Salesforce, Atlassian (Jira + User Management), Harvest, Bill.com |
| GRC / Vendor Risk | Fortress Platform API, OpenGRC |
| Endpoint Management | PDQ Connect |
E New Integrations (detail) 6 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Fortress | freshservice | freshservice | 2026-09-10 |
| Fortress | microsoft-teams | my_microsoft_teams_connection | 2026-09-08 |
| Fortress | microsoft-graph | azure_application_permissions | 2026-09-03 |
| Fortress | 2lo_auth | paycor_test | 2026-08-27 |
| Fortress | winrm | connection_to_fiscorpagent01 | 2026-08-25 |
| Fortress | winrm | connection_to_fiscorpagent03 | 2026-08-25 |