Blink Security Automation — Confidential

Fortress — Customer Success Report

Generated 2026-09-10 | fortress-value-report.md
2026-09-10Report Date
192Total Playbooks
75Unique Workflows (12m)
146,548Actions Automated (12m)
$37,692Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

192
Total playbooks built
all non-deleted workflows
89
Active playbooks
currently enabled
75
Unique workflows executed (12m)
distinct workflows that ran
146,548
Actions automated (12m)
completed action steps
814.2h
Hours saved (12m)
@ 20s per action
$37,692
Money saved (12m)
@ $100K avg salary
7
New active workflows (last 30d)
recently created & enabled
1,098
Total cases managed
1,098 opened in last 12m
8h 46m
MTTR — mean time to resolve
closed cases, last 12m
16
Active AI agents
of 17 total
1,838
AI agent tasks executed (12m)
726 in last 30d
In the last 12 months, Blink automated: - 44 executive status reports submitted and analyzed by AI — delivering weekly leadership insight from across the organization - 63 security alerts ingested and processed end-to-end across CrowdStrike, Splunk, and Microsoft Defender XDR - 26 contracts automatically routed from Salesforce to IronClad without manual handoff - 20 AI-drafted job descriptions generated and distributed from Freshservice ticket intake - 15 employees and contractors fully onboarded across AD, M365, Okta, Duo, and Freshservice - 11 bi-weekly vulnerability management cycles completed — from CrowdStrike sync to per-department report delivery - 9 employees and contractors fully offboarded across every connected identity system - 30 SOC2 reports analyzed by AI for complementary user entity controls (CUECs) - 26 vendor spend validations processed end-to-end — from Salesforce trigger through AI-driven price analysis and legal contract review to email approval - 16 contract expiration reminders sent to stakeholders (30/60/90-day notices)

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Employee & Contractor Lifecycle
  • 13Employees onboarded end-to-end
  • 8Employees fully offboarded across all systems
  • 2Contractors onboarded
0.5%
4
4 active
Security Operations & Alert Management
  • 32Security alerts processed end-to-end
  • 16Splunk alerts ingested into case management
  • 11Defender XDR alerts ingested
35.2%
21
21 active
Vulnerability Lifecycle Management
  • 13Per-department vulnerability reports generated
  • 11Bi-weekly vulnerability management cycles completed
0.6%
5
5 active
AI-Driven HR Process Automation
  • 20Job descriptions drafted & distributed by AI
  • 18HR job description folders created in SharePoint
0.2%
2
2 active
Contract Lifecycle Automation
  • 26Contracts automatically routed to IronClad
1.0%
6
6 active
Executive & Business Reporting
  • 44Executive status reports submitted via AI
  • 6Weekly executive summary reports sent
  • 1CEO summary reports generated
1.0%
7
7 active
Software Deployment & IT Self-Service
  • 10Software installations executed via PDQ
  • 6Software assurance checks performed
  • 2Freshservice ticket-monitoring cycles completed
0.9%
5
5 active
Finance Operations Automation
  • 26Vendor spend validations processed end-to-end
0.5%
4
4 active
Vendor Risk & Software Assurance Automation
  • 30SOC2 reports analyzed by AI for CUEC coverage
  • 16Vendor risk rank records updated
  • 1Software assurance tickets analyzed via AI
0.9%
5
5 active
Total2,294 executions100%
59
59 active

Use Case Growth Over Time

158 unique playbooks  |  9 operational use cases  |  5,630 total executions (12m)  |  1970-01 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Employee & Contractor Lifecycle
Freshservice Microsoft Entra ID Microsoft Graph Active Directory On-Prem Exchange Online Duo Microsoft Teams Email
AI-Driven HR Process Automation
Agents Microsoft Outlook Email SharePoint
Contract Lifecycle Automation
Microsoft Entra ID Microsoft Outlook Salesforce
Security Operations & Alert Management
CrowdStrike Microsoft Defender For Cloud Apps Agents Microsoft Outlook Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan Microsoft Teams
Finance Operations Automation
Salesforce Microsoft Outlook Agents
Executive & Business Reporting
Microsoft Outlook Agents Salesforce
Vulnerability Lifecycle Management
CrowdStrike Microsoft Outlook
Vendor Risk & Software Assurance Automation
Web Form Freshservice
Software Deployment & IT Self-Service
Freshservice Microsoft Teams

04Key Observations

✓  Strengths

Strengths

Mature, multi-system IAM lifecycle. Both employee and contractor onboarding and offboarding run fully automated, touching AD, Entra ID, Okta, Duo, Atlassian, Exchange Online, Intune, and Freshservice in a single orchestrated flow. With 15 onboardings and 9 offboardings in 12 months, this is a high-trust, production-grade operation.

Well-architected SOC stack. The SOC automation follows a clean modular design: four ingest connectors → Process Alert orchestrator → Enrich Observables router → 13 typed enrichers → Response Main Router → dedicated response subflows. The 60 enrichment routing calls and 32 processed alerts confirm the pipeline is live and running.

Broad and growing AI agent adoption. Agentic workflows now span executive briefing (Thursday Special), job description drafting (Job Intake), CEO summary generation (Alex Report), security activity analysis (User Device Activity Search), a four-agent spend validation chain (SQL Query Agent → Price Analysis Agent → Legal Assistant → Report Assembler Bot in Finance Spend Validation Master Workflow, 26 executions), and Claude-driven document analysis for SOC2 CUEC extraction (30 executions) and software assurance ticket review (SAP Engine). This is one of the more diverse AI automation footprints in production.

Contract automation at scale. 26 contracts automatically routed from Salesforce to IronClad is a high-value, measurable outcome — replacing a manual handoff between sales and legal that is both time-sensitive and error-prone.

Vulnerability management is fully scheduled. The twice-weekly Vuln Management Engine runs a complete cycle — sync from CrowdStrike, reconcile the master table, and generate per-department HTML reports — without any analyst involvement.

Vendor risk automation now includes AI-driven document analysis. SOC2 CUEC Analysis ran 30 times in its first period — using Claude to extract complementary user entity controls directly from vendor SOC2 reports — while Update Vendor Information from Risk Rank and Fortress Platform to OpenGRC Vendor Sync keep the vendor registry and risk scores current automatically.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

SOC enrichment modules are built but dormant. The Enrich Observables router fired 60 times, but all 13 individual enrichment subflows show 0 executions. This suggests the router may be making conditional calls that rarely satisfy enricher trigger conditions, or the routing logic needs tuning to activate the enrichment library. Resolving this would convert the existing investment into measurable IOC coverage.

PDQ software deployment is partially live. Freshservice: Install Software using PDQ (6 executions) and Deploy software using PDQ Connect (4 executions) are now running in production, but the original four PDQ subflows (ticket intake → device lookup → package deploy → completion polling) still show 0 executions. Consolidating onto the active workflows and retiring the unused duplicates would reduce maintenance overhead.

Finance Database Analyzer and BETA invoice validation remain unused. The Finance Spend Validation Master Workflow is now live and processing vendor spend approvals end-to-end (26 executions), but the four-agent Finance Database Analyzer and the BETA: Finance Validation workflow against Bill.com/QuickBooks have never run. Extending the same AI-agent pattern that powers spend validation would help activate these quickly.

Phishing and malware response flows not yet triggered. Both response subflows have 0 executions. With 32 alerts processed through Process Alert and 30 routing calls through the Response Main Router, the response layer exists — but either no alerts have matched phishing/malware classification or the routing conditions need review.

Document Contract Review disconnected. The Salesforce-triggered Document Contract Review workflow has 0 executions while the parallel Contract to IronClad flow (same trigger type) ran 26 times. These likely need to share the same Salesforce trigger event or the connection may not be configured.

User Device Activity Search unused. This CrowdStrike + Defender + AI investigative workflow has 0 executions. As a security-critical capability for device forensics, enabling this for incident response would extend the SOC automation coverage significantly.

Integration Ecosystem

The automation stack spans 20+ distinct integrations across seven domains:

Domain Integrations
Identity & Access Active Directory (WinRM), Microsoft Entra ID, Okta, Duo, AWS WorkSpaces
Microsoft 365 Microsoft Graph, Exchange Online, Microsoft Outlook, SharePoint, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Intune, Microsoft Teams
IT Service Management Freshservice
Security CrowdStrike, Splunk, VirusTotal, AbuseIPDB, URLScan
Business Systems Salesforce, Atlassian (Jira + User Management), Harvest, Bill.com
GRC / Vendor Risk Fortress Platform API, OpenGRC
Endpoint Management PDQ Connect
Appendices
A Case Management 1,098 cases (12m) | MTTR 8h 46m

Case Management

Total Cases (all-time)
1,098
1,098 opened in last 12m
Cases Opened (30d)
403
402 closed in last 30d
Cases Closed (12m)
1,091
of 1,098 opened
MTTR
8h 46m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 1,098 1,098 1,091 8h 46m
B AI Agents 16 active | 1,838 tasks (12m)

AI Agents

Active Agents
16
of 17 total
Tasks Executed (12m)
1,838
726 in last 30d
Data Usage (12m)
107,765,523
28,346,967 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Omni Alert Case Management 1,089 588 44,345,462
2 Executive Wrangler Bot Executives 197 23 8,271,559
3 Recruiter Battle Bot Corporate Automations 180 8 12,782,059
4 SQL Query Agent Executives 71 26 2,229,588
5 FLSA Regulator Bot Corporate Automations 53 3 15,940,220
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Case Management1,089
Executives446
Corporate Automations291
Fortress Platform12
C Self-Service & Webforms 0 app runs | 45 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Vulnerability Tracking 00
2 Thursday Special Dashboard 00
3 test 00

Webforms

Forms
2
active webforms
Total Submissions
45
all time
Completed
38
fully submitted
Submissions (30d)
45
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Vendor Information Review 2321
2 Vendor Information Review 2217
D Full Use Case Analysis 9 use cases | 5,630 executions (12m)

Business KPIs

Metric Count Playbook
Executive status reports submitted via AI 44 Thursday Special
Security alerts processed end-to-end 32 Process Alert
Contracts automatically routed to IronClad 26 Contract to IronClad
Job descriptions drafted & distributed by AI 20 Job Intake from FreshService (HR)
HR job description folders created in SharePoint 18 Create JD Folders & Move Templates (HR)
Splunk alerts ingested into case management 16 Ingest - Splunk Alerts
Employees onboarded end-to-end 13 Onboarding-Employee Automation
Vulnerability database syncs executed 12 Vulnerability Table Updater
Defender XDR alerts ingested 11 EXAMPLE Ingest - Microsoft Defender XDR
Bi-weekly vulnerability management cycles completed 11 Vuln Management Engine
Per-department vulnerability reports generated 13 Open Vulnerability Report Generator, RL TEST - 03 Open Vulnerability Report
Employees fully offboarded across all systems 8 Off-Boarding Automation
SOC2 reports analyzed by AI for CUEC coverage 30 SOC2 CUEC Analysis
Vendor spend validations processed end-to-end 26 Finance Spend Validation Master Workflow
Contract expiration reminders sent (30/60/90-day) 16 Notify Users of Expiring Contracts (30/60/90 days)
Software installations executed via PDQ 10 Freshservice: Install Software using PDQ, Deploy software using PDQ Connect
Freshservice ticket-monitoring cycles completed 2 Freshservice: Periodic Ticket Monitor
Unassigned Freshservice tickets flagged via Teams 1 Freshservice: Unassigned Ticket Monitor
Freshservice ticket reminders sent to agents 1 Freshservice: User Ticket Reminder
Vendor risk rank records updated 16 Update Vendor Information from Risk Rank, Copy Update Vendor Information from Risk Rank
Software assurance tickets analyzed via AI 1 SAP Engine
Weekly executive summary reports sent 6 Thursday Special - Sunday Report
Software assurance checks performed 6 Software Assurance
Offboarding security notifications sent to FSO team 5 FSO Off-Board Notification
CrowdStrike detections ingested 4 Ingest - CrowdStrike Detections
Security document deliveries (FSO team) 3 FSO Docs Delivery, CC FSO Pros (Security)
Contractors onboarded 2 Onboarding-Contractor
Contractors fully offboarded 1 Off-Boarding: Contractors
CEO summary reports generated 1 Alex Report
Monthly time reports generated 1 Harvest Time Report
Executive notifications sent 1 Notify Execs
Software installations via self-service portal 1 Install Software from Portal
In the last 12 months, Blink automated: - 44 executive status reports submitted and analyzed by AI — delivering weekly leadership insight from across the organization - 63 security alerts ingested and processed end-to-end across CrowdStrike, Splunk, and Microsoft Defender XDR - 26 contracts automatically routed from Salesforce to IronClad without manual handoff - 20 AI-drafted job descriptions generated and distributed from Freshservice ticket intake - 15 employees and contractors fully onboarded across AD, M365, Okta, Duo, and Freshservice - 11 bi-weekly vulnerability management cycles completed — from CrowdStrike sync to per-department report delivery - 9 employees and contractors fully offboarded across every connected identity system - 30 SOC2 reports analyzed by AI for complementary user entity controls (CUECs) - 26 vendor spend validations processed end-to-end — from Salesforce trigger through AI-driven price analysis and legal contract review to email approval - 16 contract expiration reminders sent to stakeholders (30/60/90-day notices)

Use Case Summary

# Use Case Category Subcategories Playbooks Executions
1 Employee & Contractor Lifecycle IAM Employee onboarding, Employee offboarding, Identity lifecycle automation 9 56
2 Security Operations & Alert Management SOC Case mgmt & SOAR, Alert enrichment / IOC lookup, EDR containment & response, Phishing detection & response, SIEM & log pipeline monitoring 25 153
3 Vulnerability Lifecycle Management Vulnerability Mgmt Vuln scanning ingest & report, Vuln lifecycle prioritize & ticket, Vuln scan lifecycle automation 7 37
4 AI-Driven HR Process Automation GRC AI / HR compliance automation 2 38
5 Contract Lifecycle Automation GRC Vendor risk & TPRM, Compliance questionnaire 6 45
6 Executive & Business Reporting GRC Security metrics & reporting 8 59
7 Software Deployment & IT Self-Service Other Endpoint hygiene & MDM ops, IT helpdesk & ticket routing, SaaS / IT administration 18 21
8 Finance Operations Automation Other Financial & fraud operations 4 26
9 Vendor Risk & Software Assurance Automation GRC Vendor risk & TPRM, Compliance questionnaire 5 47

Use Cases

1. Employee & Contractor Lifecycle

Description: Fully automated onboarding and offboarding for both employees and contractors, orchestrating identity provisioning and deprovisioning across Active Directory, Microsoft 365, Okta, Duo, and Atlassian. Each lifecycle event is triggered by a Freshservice ticket approval and closes with an automated summary note — no manual steps required.

Business problem solved: Manual onboarding and offboarding are error-prone, slow, and leave orphaned accounts that create security and compliance risk. Automation ensures consistent, auditable execution across every required system within minutes of a ticket approval.

Integrations: Microsoft Intune, Active Directory (WinRM), Microsoft Entra ID, Microsoft Graph, Exchange Online, Okta, Duo, Atlassian User Management, Jira, AWS WorkSpaces, Freshservice

Playbook Subcategory Trigger Executions
Onboarding-Employee Automation Employee onboarding Event (webhook) 13
Onboarding-Contractor Employee onboarding Event (webhook) 2
Off-Boarding Automation Employee offboarding Event (webhook) 8
Off-Boarding: Contractors Employee offboarding On demand 1
Device Isolation & Asset Return Ticket Creation *(subflow)* Employee offboarding On demand 9
Atlassian Deactivation *(subflow)* Employee offboarding On demand 9
Okta Account Deactivation *(subflow)* Employee offboarding On demand 9
FSO Off-Board Notification *(subflow)* Identity lifecycle automation On demand 5
Remove User's AWS Workspace Ticket *(subflow)* Employee offboarding On demand 0

2. Security Operations & Alert Management

Description: A full SOC automation stack spanning alert ingest, observable enrichment, and incident response. Alerts from CrowdStrike, Splunk, and Microsoft Defender XDR are ingested into Blink's case management system, observables are automatically extracted and routed through 13+ enrichment modules (covering IP, hash, URL, domain, username, and device types), and confirmed threats are dispatched to dedicated phishing and malware response flows.

Business problem solved: Security analysts are overwhelmed by alert volume and manual triage. This automation handles ingestion, deduplication, enrichment, and response routing end-to-end — reducing analyst workload and mean time to respond.

Integrations: CrowdStrike, Splunk, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Blink Case Management, VirusTotal, AbuseIPDB, URLScan, Okta, Microsoft Entra ID, Google Workspace, Microsoft Outlook, Bash/Whois

Alert Ingest & Processing

Playbook Subcategory Trigger Executions
Process Alert Case mgmt & SOAR Event (polling) 32
Ingest - Splunk Alerts SIEM & log pipeline monitoring Event (webhook) 16
EXAMPLE Ingest - Microsoft Defender XDR SIEM & log pipeline monitoring Event (polling) 11
Ingest - CrowdStrike Detections SIEM & log pipeline monitoring Event (webhook) 4
User Device Activity Search (Security) Agentic SOC On demand 0

Response Flows

Playbook Subcategory Trigger Executions
Subflow - Response - Main Router *(subflow)* Case mgmt & SOAR On demand 30
Response Subflow - Phishing Phishing detection & response On demand 0
Response Subflow - Malware EDR containment & response On demand 0

Observable Enrichment

Playbook Subcategory Trigger Executions
Subflow - Enrich Observables - Main Router *(subflow)* Alert enrichment / IOC lookup On demand 60
Subflow - Update Enrichment Data *(subflow)* Alert enrichment / IOC lookup On demand 0
Enrich - Hash - VT Alert enrichment / IOC lookup On demand 0
Enrich - Hash - Crowdstrike Alert enrichment / IOC lookup On demand 0
Enrich - IP - VT Alert enrichment / IOC lookup On demand 0
Enrich - IP - IPDB Alert enrichment / IOC lookup On demand 0
Enrich - IP or Domain - Whois Alert enrichment / IOC lookup On demand 0
Enrich IP or Domain Using Whois Alert enrichment / IOC lookup On demand 0
Enrich - URL - VT Alert enrichment / IOC lookup On demand 0
Enrich - URL - URLScan Alert enrichment / IOC lookup On demand 0
Enrich - Username or Email - Okta Alert enrichment / IOC lookup On demand 0
Enrich - Username or Email - Microsoft Entra ID Alert enrichment / IOC lookup On demand 0
Get User Information Using Microsoft Entra ID Alert enrichment / IOC lookup On demand 0
Enrich - Username or Email - Google Workspace Alert enrichment / IOC lookup On demand 0
Get User Information Using Google Workspace Alert enrichment / IOC lookup On demand 0
Enrich - Agent ID - Crowdstrike Alert enrichment / IOC lookup On demand 0
Error Handling - Send Error Notification Email *(utility)* Case mgmt & SOAR On demand 0

3. Vulnerability Lifecycle Management

Description: A scheduled, end-to-end vulnerability management pipeline that syncs open vulnerabilities from CrowdStrike into a master Blink table, reconciles inserts/updates/deletes, and generates per-department HTML reports distributed to stakeholders via email. Runs automatically twice a week; the table can also be synced on demand.

Business problem solved: Vulnerability data scattered across tools creates blind spots and manual reporting bottlenecks. This pipeline maintains a single source of truth and ensures each department receives a targeted view of their open risk exposure — without analyst involvement.

Integrations: CrowdStrike, Blink Tables, Bash/Python

Playbook Subcategory Trigger Executions
Vuln Management Engine Vuln scan lifecycle automation Scheduled (Mon/Thu 9:30 AM ET) 11
Vulnerability Table Updater *(subflow)* Vuln lifecycle prioritize & ticket On demand 12
Open Vulnerability Report Generator *(subflow)* Vuln scanning ingest & report On demand 11
Vulnerability Table Updater (Unified Sync + Reconcile) Vuln lifecycle prioritize & ticket On demand 1
Master Vulnerability Table Backfill Vuln scanning ingest & report On demand 0
RL TEST - 03 Open Vulnerability Report Vuln scanning ingest & report On demand 2
RL TEST - 04 Vuln Engine Vuln scan lifecycle automation On demand 0

4. AI-Driven HR Process Automation

Description: Automates two HR workflows triggered from Freshservice tickets: an AI-powered job intake flow where an agentic bot drafts a formatted job description document from ticket inputs and emails it to HR, and a SharePoint automation that creates folder structures and moves templates whenever a new job description is initiated.

Business problem solved: HR teams spend significant time drafting job descriptions and organizing file structures manually. These workflows deliver a polished job description document within minutes of ticket submission and keep SharePoint organized automatically.

Integrations: Freshservice, Blink AI Agents, SharePoint, Microsoft Outlook, Python/DOCX

Playbook Subcategory Trigger Executions
Job Intake from FreshService (HR) AI / HR compliance automation Event (webhook) 20
Create JD Folders & Move Templates (HR) AI / HR compliance automation Event (webhook) 18

5. Contract Lifecycle Automation

Description: Automatically moves contracts from Salesforce to IronClad when triggered by a Salesforce webhook event — downloading the attached file, parsing contract metadata, and routing the document through the defined legal workflow. A parallel flow handles AI-assisted document contract review, and a third flow manages secure delivery of FSO-related documents to the security team.

Business problem solved: Manual contract routing between sales and legal causes delays and handoff errors. Automation ensures contracts reach IronClad immediately upon Salesforce event, with full metadata intact.

Integrations: Salesforce, IronClad (via email), Microsoft Outlook, Microsoft Entra ID (for FSO group verification)

Playbook Subcategory Trigger Executions
Contract to IronClad Vendor risk & TPRM Event (Salesforce webhook) 26
FSO Docs Delivery, CC FSO Pros (Security) Compliance questionnaire Event (webhook) 3
Document Contract Review Vendor risk & TPRM Event (Salesforce webhook) 0
Notify Users of Expiring Contracts 30 days Vendor risk & TPRM Scheduled (Tue 8:30 AM ET) 6
Notify Users of Expiring Contracts 60 days Vendor risk & TPRM Scheduled (Tue 8:30 AM ET) 5
Notify Users of Expiring Contracts 90 days Vendor risk & TPRM Scheduled (Tue 8:30 AM ET) 5

6. Executive & Business Reporting

Description: A suite of AI-powered and scheduled reporting workflows. The centerpiece is "Thursday Special" — team leads submit weekly status updates (blockers, priorities, meetings, time off) which an AI agent synthesizes into an executive briefing, stored in a Blink table and emailed every Sunday morning. Complementary flows deliver CEO summaries from Salesforce data, monthly time tracking reports from Harvest, and weekly executive email notifications.

Business problem solved: Executive reporting requires significant time gathering and synthesizing information across teams. These automations replace manual aggregation with AI-generated insight delivered on a consistent cadence.

Integrations: Blink AI Agents, Blink Tables, Salesforce, Harvest, Microsoft Outlook, Fortress Platform API

Playbook Subcategory Trigger Executions
Thursday Special Security metrics & reporting On demand 44
Thursday Special - Sunday Report Security metrics & reporting Scheduled (Mon 8:59 AM ET) 6
Nuke Thursday Special Table *(infrastructure)* Security metrics & reporting Scheduled (Wed 12:01 PM ET) 6
Alex Report Security metrics & reporting Scheduled (Mon 9:01 AM ET) 1
Notify Execs Security metrics & reporting Scheduled (Thu 3:45 PM ET) 1
Harvest Time Report Security metrics & reporting Scheduled (1st of month 9:15 AM ET) 1
Sales Inactivity Report Security metrics & reporting On demand 0
Risk Rank Reminders Security metrics & reporting Scheduled 0

7. Software Deployment & IT Self-Service

Description: Automated software deployment via PDQ Connect, fulfilling Freshservice-ticketed software installation requests end-to-end: lookup the device, find the package, deploy, and poll for completion. Includes a self-service portal workflow for employee-initiated installs and a software assurance check workflow. Supporting utilities handle Freshservice custom object queries and email delivery.

Business problem solved: Software installation requests create IT helpdesk backlog and delay employee productivity. Automation fulfills requests directly from the ticket without IT intervention.

Integrations: PDQ Connect, Freshservice, Microsoft Graph (email), Bitbucket (SSH)

Playbook Subcategory Trigger Executions
Software Assurance Endpoint hygiene & MDM ops On demand / webhook 6
Install Software from Portal IT helpdesk & ticket routing On demand 1
Freshservice: Install Software using PDQ IT helpdesk & ticket routing On demand 6
Deploy software using PDQ Connect Endpoint hygiene & MDM ops On demand 4
Freshservice Ticket: Install Software using PDQ IT helpdesk & ticket routing On demand 0
Deploy PDQ Package to Device *(subflow)* Endpoint hygiene & MDM ops On demand 0
Deploy PDQ Package to Device *(subflow, dev workspace)* Endpoint hygiene & MDM ops On demand 0
PDQ Software Install Dev *(dev)* IT helpdesk & ticket routing On demand 0
Find Freshservice Service Item Custom Object Record *(utility)* IT helpdesk & ticket routing On demand 0
Launch Freshservice Workflow *(utility)* IT helpdesk & ticket routing Event (webhook) 0
Query FreshService Object Records *(utility)* IT helpdesk & ticket routing On demand 0
Send Graph Email *(utility)* IT helpdesk & ticket routing On demand 0
Python Software Install *(utility)* Endpoint hygiene & MDM ops On demand 0
FS Get Service Items *(utility)* IT helpdesk & ticket routing On demand 0
Freshservice: Periodic Ticket Monitor IT helpdesk & ticket routing Scheduled (Mon-Fri 8:00 AM ET) 2
Freshservice: Unassigned Ticket Monitor IT helpdesk & ticket routing On demand 1
Freshservice: User Ticket Reminder IT helpdesk & ticket routing On demand 1
Azure: Find Application *(utility)* SaaS / IT administration On demand 0

8. Finance Operations Automation

Description: AI-powered finance analysis workflows. The Finance Spend Validation Master Workflow is fully active — triggered by a Salesforce webhook, it chains four specialized AI agents (SQL Query Agent, Price Analysis Agent, Legal Assistant, Report Assembler Bot) to validate vendor spend against budget, contract terms, and pricing before emailing an approval report. Two additional workflows remain in development: the Finance Database Analyzer, which uses four AI agents for spend anomaly detection, coding validation, month-end close assistance, and account variance narration; and a Beta workflow for invoice validation against Bill.com and QuickBooks.

Business problem solved: Finance operations require significant manual analysis time across multiple systems. The Finance Spend Validation Master Workflow now automates vendor spend validation end-to-end — from Salesforce trigger through AI-driven cost and contract analysis to email-based approval — while the remaining AI agents are being brought into production for anomaly detection and invoice validation.

Integrations: Blink AI Agents, Salesforce, Blink Tables, Bill.com, QuickBooks, PowerShell, Microsoft Outlook

Playbook Subcategory Trigger Executions
Finance Spend Validation Master Workflow Financial & fraud operations Event (Salesforce webhook) 26
Update Budget Table Financial & fraud operations On demand 0
Finance Database Analizer Financial & fraud operations On demand 0
BETA: Finance Validation Financial & fraud operations On demand 0

9. Vendor Risk & Software Assurance Automation

Description: Automates vendor risk management using the Fortress Platform API — pulling the master vendor registry and risk-rank scores, analyzing SOC2 reports with AI to identify complementary user entity controls (CUECs), running AI-driven software assurance ticket analysis triggered from Freshservice, and syncing active vendor records into OpenGRC on a monthly schedule.

Business problem solved: Vendor security reviews — pulling risk data, reading SOC2 reports, and keeping GRC systems in sync — are manual and time-intensive for the security team. These automations pull vendor data programmatically and use AI to analyze compliance documents in minutes instead of hours, while keeping OpenGRC continuously synced with the vendor registry.

Integrations: Fortress Platform API, Freshservice, Claude AI (Bash), Blink Tables, OpenGRC (HTTP)

Playbook Subcategory Trigger Executions
SOC2 CUEC Analysis Compliance questionnaire On demand 30
Update Vendor Information from Risk Rank Vendor risk & TPRM Event (web form) 3
SAP Engine Vendor risk & TPRM Event (webhook) 1
Fortress Platform to OpenGRC Vendor Sync Vendor risk & TPRM Scheduled (1st of month 8:30 AM ET) 0
Copy Update Vendor Information from Risk Rank Vendor risk & TPRM Event (web form) 13

Key Observations

Strengths

Mature, multi-system IAM lifecycle. Both employee and contractor onboarding and offboarding run fully automated, touching AD, Entra ID, Okta, Duo, Atlassian, Exchange Online, Intune, and Freshservice in a single orchestrated flow. With 15 onboardings and 9 offboardings in 12 months, this is a high-trust, production-grade operation.

Well-architected SOC stack. The SOC automation follows a clean modular design: four ingest connectors → Process Alert orchestrator → Enrich Observables router → 13 typed enrichers → Response Main Router → dedicated response subflows. The 60 enrichment routing calls and 32 processed alerts confirm the pipeline is live and running.

Broad and growing AI agent adoption. Agentic workflows now span executive briefing (Thursday Special), job description drafting (Job Intake), CEO summary generation (Alex Report), security activity analysis (User Device Activity Search), a four-agent spend validation chain (SQL Query Agent → Price Analysis Agent → Legal Assistant → Report Assembler Bot in Finance Spend Validation Master Workflow, 26 executions), and Claude-driven document analysis for SOC2 CUEC extraction (30 executions) and software assurance ticket review (SAP Engine). This is one of the more diverse AI automation footprints in production.

Contract automation at scale. 26 contracts automatically routed from Salesforce to IronClad is a high-value, measurable outcome — replacing a manual handoff between sales and legal that is both time-sensitive and error-prone.

Vulnerability management is fully scheduled. The twice-weekly Vuln Management Engine runs a complete cycle — sync from CrowdStrike, reconcile the master table, and generate per-department HTML reports — without any analyst involvement.

Vendor risk automation now includes AI-driven document analysis. SOC2 CUEC Analysis ran 30 times in its first period — using Claude to extract complementary user entity controls directly from vendor SOC2 reports — while Update Vendor Information from Risk Rank and Fortress Platform to OpenGRC Vendor Sync keep the vendor registry and risk scores current automatically.

Gaps & Opportunities

SOC enrichment modules are built but dormant. The Enrich Observables router fired 60 times, but all 13 individual enrichment subflows show 0 executions. This suggests the router may be making conditional calls that rarely satisfy enricher trigger conditions, or the routing logic needs tuning to activate the enrichment library. Resolving this would convert the existing investment into measurable IOC coverage.

PDQ software deployment is partially live. Freshservice: Install Software using PDQ (6 executions) and Deploy software using PDQ Connect (4 executions) are now running in production, but the original four PDQ subflows (ticket intake → device lookup → package deploy → completion polling) still show 0 executions. Consolidating onto the active workflows and retiring the unused duplicates would reduce maintenance overhead.

Finance Database Analyzer and BETA invoice validation remain unused. The Finance Spend Validation Master Workflow is now live and processing vendor spend approvals end-to-end (26 executions), but the four-agent Finance Database Analyzer and the BETA: Finance Validation workflow against Bill.com/QuickBooks have never run. Extending the same AI-agent pattern that powers spend validation would help activate these quickly.

Phishing and malware response flows not yet triggered. Both response subflows have 0 executions. With 32 alerts processed through Process Alert and 30 routing calls through the Response Main Router, the response layer exists — but either no alerts have matched phishing/malware classification or the routing conditions need review.

Document Contract Review disconnected. The Salesforce-triggered Document Contract Review workflow has 0 executions while the parallel Contract to IronClad flow (same trigger type) ran 26 times. These likely need to share the same Salesforce trigger event or the connection may not be configured.

User Device Activity Search unused. This CrowdStrike + Defender + AI investigative workflow has 0 executions. As a security-critical capability for device forensics, enabling this for incident response would extend the SOC automation coverage significantly.

Integration Ecosystem

The automation stack spans 20+ distinct integrations across seven domains:

Domain Integrations
Identity & Access Active Directory (WinRM), Microsoft Entra ID, Okta, Duo, AWS WorkSpaces
Microsoft 365 Microsoft Graph, Exchange Online, Microsoft Outlook, SharePoint, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Intune, Microsoft Teams
IT Service Management Freshservice
Security CrowdStrike, Splunk, VirusTotal, AbuseIPDB, URLScan
Business Systems Salesforce, Atlassian (Jira + User Management), Harvest, Bill.com
GRC / Vendor Risk Fortress Platform API, OpenGRC
Endpoint Management PDQ Connect
E New Integrations (detail) 6 added in last 30d

New Integrations Added - Last 30 Days

6 new connections
TenantIntegrationConnection NameAdded
Fortress freshservice freshservice 2026-09-10
Fortress microsoft-teams my_microsoft_teams_connection 2026-09-08
Fortress microsoft-graph azure_application_permissions 2026-09-03
Fortress 2lo_auth paycor_test 2026-08-27
Fortress winrm connection_to_fiscorpagent01 2026-08-25
Fortress winrm connection_to_fiscorpagent03 2026-08-25