Blink Security Automation — Confidential

humansecurity — Customer Success Report

Generated 2026-08-30 | humansecurity-value-report.md
2026-08-30Report Date
848Total Playbooks
245Unique Workflows (12m)
2,069,609Actions Automated (12m)
$532,307Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

848
Total playbooks built
all non-deleted workflows
323
Active playbooks
currently enabled
245
Unique workflows executed (12m)
distinct workflows that ran
2,069,609
Actions automated (12m)
completed action steps
11,497.8h
Hours saved (12m)
@ 20s per action
$532,307
Money saved (12m)
@ $100K avg salary
6
New active workflows (last 30d)
recently created & enabled
4,291
Total cases managed
3,145 opened in last 12m
6d 3h
MTTR — mean time to resolve
closed cases, last 12m
32
Active AI agents
of 59 total
25,570
AI agent tasks executed (12m)
8,456 in last 30d
In the last 12 months, Blink automated: - 66,224 vulnerability events automatically ingested and processed from Aikido - 4,837 AI-powered security checks on departing or recently separated employees - 3,443 Salesforce leads automatically persona-matched via AI using LinkedIn title analysis - 2,789 Salesforce leads automatically ICP-qualified with AI-enriched scoring - 1,283 developer pull requests automatically security-reviewed against Jira - 1,068 Google Cloud Pub-Sub security events monitored and triaged - 372 combined executions across a 17-playbook AI + Playwright product documentation validation suite - 301 employee offboarding operations fully orchestrated across Akamai, Fastly, and downstream systems - 343 Sumo Logic SIEM alerts auto-processed into case management and escalated to Jira - 437 customer support tickets automatically routed, categorized, and acknowledged with AI

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOC Alert Processing & Case Management
  • 343SIEM alerts ingested from Sumo Logic into case management
  • 343Security cases auto-escalated to Jira
0.5%
31
30 active
SIEM Log Health & Product Dashboard Monitoring
  • 1,068Google Pub-Sub cloud security events monitored
  • 388Product security dashboard anomaly checks run
1.1%
22
21 active
Agentic Threat Hunting
  • 40AI-powered threat hunts run via Glean-integrated agent
0.2%
14
14 active
GCP Cloud Security Monitoring
  • 1,709GCP privilege escalation events audited
19.1%
10
10 active
Employee Separation Monitoring
  • 4,837AI-powered post-separation employee security monitoring checks
  • 1,927Separation monitoring batches executed (multi-system sweep per run)
  • 301Employee offboarding workflows completed
70.5%
13
13 active
Vulnerability Management — Aikido
  • 66,224Vulnerability events auto-ingested & processed from Aikido
0.0%
2
1 active
DevSecOps Code Security Review
  • 1,283Developer PRs automatically security-reviewed
1.2%
4
4 active
Vendor Risk Management & Contract Monitoring
  • 140Vendor contract approval deadlines monitored
0.1%
9
9 active
Access Review (UAR)15 executions
0.0%
7
7 active
PCI Compliance & Regulatory Evidence
  • 255PCI compliance evidence items auto-submitted to A-Scend
0.0%
19
19 active
DLP & Data Security
  • 63DLP issues ingested from Cyera and queued
0.0%
4
4 active
Customer Support Automation
  • 437Customer support tickets auto-routed & triaged
0.0%
10
7 active
CRM & Lead Intelligence
  • 3,443Salesforce leads automatically persona-matched via AI (LinkedIn title → role mapping)
  • 2,789Salesforce leads automatically ICP-qualified via AI
  • 86New Salesforce accounts auto-created with AI-generated company profile
5.0%
4
4 active
Security Metrics & Reporting
  • 40Daily AI-generated security summaries delivered
0.2%
7
7 active
IT Asset & Endpoint Management (JAMF)
  • 49IT asset inventory records synced from Jamf to Snipe-IT
0.1%
7
7 active
Documentation Validation & QA Automation
  • 144Product documentation pages automatically fetched & validated against the live product
0.3%
17
17 active
Workspace & SaaS Administration
  • 13Inactive Slack channels reviewed for workspace hygiene cleanup
0.0%
7
7 active
Security Awareness Training Compliance (Wizer)
  • 11Security awareness training compliance checks run
0.0%
3
3 active
Total125,954 executions100%
190
184 active

Use Case Growth Over Time

681 unique playbooks  |  18 operational use cases  |  127,962 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Vulnerability Management — Aikido
GCP Google Sheets
SOC Alert Processing & Case Management
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Check Point Harmony IPWHOIS Jira Extraction Utilities Slack Sumo Logic Microsoft Outlook Wiz Agents Email Glean Node.js
SIEM Log Health & Product Dashboard Monitoring
String Utilities Slack Sumo Logic Agents
Access Review (UAR)
GitHub Slack Jira BambooHR Okta Glean Node.js
Security Metrics & Reporting
Sumo Logic Slack Jira Gemini Wiz Google Sheets BambooHR Glean
Customer Support Automation
Jira Slack Confluence Node.js Postgres Google Sheets Gemini
Vendor Risk Management & Contract Monitoring
Jira Glean Node.js SecurityScorecard BambooHR
DevSecOps Code Security Review
Jira Gemini GitHub Email Google Drive Glean Node.js Slack
PCI Compliance & Regulatory Evidence
Google Sheets Jira Agents Slack Confluence Google Drive Glean Snowflake
Agentic Threat Hunting
Gmail Agents Slack Jira CrowdStrike Glean Node.js
Security Awareness Training Compliance (Wizer)
BambooHR Slack
GCP Cloud Security Monitoring
GCP Google Sheets
DLP & Data Security
Google Sheets Cyera Google Admin Console Jira Slack
CRM & Lead Intelligence
Salesforce Glean Google Docs OpenAI
Employee Separation Monitoring
Akamai Client List Jira Fastly Sumo Logic Agents Slack Jamf CrowdStrike Okta BambooHR
IT Asset & Endpoint Management (JAMF)
Jamf Control D
Workspace & SaaS Administration
Confluence Slack Jira Dashboards Web Form
Documentation Validation & QA Automation
Agents Dashboards

04Key Observations

✓  Strengths

Strengths

Deep agentic AI investment. The organization has deployed Blink AI agents across nearly every security domain — CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, Jira, and a dedicated L1 SOC email bot. The "Bot Activate" pattern makes agentic hunting accessible on-demand. The HUMAN Dashboard Agent running every hour across 13 anomaly dimensions is a particularly sophisticated production deployment.

Unique separation monitoring architecture. The employee separation use case is one of the most comprehensive seen in this segment. Running every 30 minutes with parallel Sumo Logic searches across five data planes (file access, outbound email, GitHub, Google Workspace, CrowdStrike USB) per departing employee demonstrates mature insider threat operations. The protected list guard prevents accidental deprovisioning at scale.

Own-product security as a use case. Unusually, Blink is being used to monitor HUMAN Security's own product dashboards (bot detection metrics, block rates, CAPTCHA outcomes). This "drink your own champagne" pattern, running 388 times in the last year, underscores the trust placed in the platform.

High-volume vulnerability management at scale. 66,224 Aikido events processed in 12 months — roughly 180/day — without analyst involvement. Paired with monthly trend reporting to Google Sheets, this represents a fully automated vulnerability intake pipeline.

PCI compliance automation depth. The MRC framework — spanning Snowflake evidence collection, Confluence quarterly page generation, Jira ticket cloning, and A-Scend integration — is a production-grade compliance automation stack, not a prototype.

AI-driven product documentation QA at scale. A 17-playbook suite translates HUMAN Security's own product documentation into Playwright test cases, executes them against the live product, and grounds results in the live DOM — 372 combined executions in its first period. This is an unusually mature application of Blink to internal product-quality assurance, extending the platform beyond traditional security use cases.

Persona Matching is now the highest-volume single playbook in the tenant. At 3,443 executions, the Salesforce Persona Matching workflow (AI-driven LinkedIn title → persona classification) runs more often than any other automation, reinforcing Blink's expanding role in real-time CRM enrichment alongside the existing Lead ICP Designation pipeline.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Crowdstrike and Wiz ingestion paths have zero executions. The CM - Wiz Ingestion and CM - Crowdstrike ingestion workflows were built but have not run, suggesting the SIEM-based Sumo Logic path is the sole alert source in production. Enabling native CrowdStrike and Wiz webhook ingest would accelerate alert MTTR and reduce Sumo Logic dependency.

Phishing response has low execution volume relative to infrastructure. The Subflow - Phishing (40) and Subflow - Phishing Gmail (0) flows exist but run infrequently. The Check Point Harmony integration is connected but underutilized — the email remediation path (Restore Email - Harmony TEST) appears to still be in testing.

Access review playbooks built but not yet running. Aikido UAR Reject, Github UAR, and supporting Okta/UAR Table utilities all show zero executions. Only the UAR - AI Review Loop has been activated (18 runs). Completing the UAR pipeline would close a key IAM governance gap.

DLP triage stops at ingestion. Cyera issues are ingested (63 events) and added to a table, but there is no downstream triage, Jira ticket creation, or owner notification automation visible in the active playbooks. The Cyera backlog importer also has zero executions, suggesting the Cyera→Jira pipeline is incomplete.

GCP monitoring playbooks are built but idle. Eight "Invoke GCP …" wrappers (owner grants, dangerous roles, log sink tampering, org policy changes, etc.) all show zero executions. Only Invoke GCP Service Account Key Creation has been activated. Connecting the remaining GCP monitors to scheduled or event-triggered execution would complete the cloud control-plane coverage.

IT self-service and admin health-check tooling is built but not yet in active rotation. Jamf Lookup by Serial, Find computer by email, Confluence Search, and Jira Connection Functionality Test all show zero executions, suggesting several JAMF lookup paths and connection-health probes are staged but not yet driving day-to-day IT workflows.

Integration Ecosystem

Category Integrations
SIEM / Logging Sumo Logic, GCP Log Explorer, BigQuery
EDR / Identity CrowdStrike, Okta, JAMF
Cloud Security Wiz, Aikido, Cyera, GCP
Ticketing Jira (5+ connections), Confluence
Collaboration Slack (multiple connections), Gmail
CDN / Edge Akamai, Fastly
Compliance A-Scend, SecurityScorecard, Snowflake
AI / Knowledge Gemini, Glean (multiple connections), OpenAI
CRM / Sales Salesforce, Gong
HRIS BambooHR
Dev GitHub, Sumo Logic (PR events)
Productivity Google Sheets, Google Drive, Google Docs
Endpoint / Asset Mgmt JAMF, Snipe-IT, Control D
QA / Testing Playwright
Security Awareness Wizer
Appendices
A Case Management 3,145 cases (12m) | MTTR 6d 3h

Case Management

Total Cases (all-time)
4,291
3,145 opened in last 12m
Cases Opened (30d)
99
1 closed in last 30d
Cases Closed (12m)
2,749
of 3,145 opened
MTTR
6d 3h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 4,199 3,092 2,749 6d 3h
AI SOC TESTING 53 53 0 N/A
CM V9 Migration Temp 39 0 0 N/A
B AI Agents 32 active | 25,570 tasks (12m)

AI Agents

Active Agents
32
of 59 total
Tasks Executed (12m)
25,570
8,456 in last 30d
Data Usage (12m)
2,360,459,446
662,875,212 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Separation Monitor daniel.reich@humansecurity.com 21,130 8,355 1,744,820,709
2 Level 1 SOC Bot david.grable@humansecurity.com 2,302 0 187,689,953
3 HUMAN Dashboard Corporate Security 512 0 180,756,420
4 DSAR Agent david.grable@humansecurity.com 257 0 17,133,260
5 Doc-to-Playwright Test Case Translator Prod Ops - Tech Docs Dev 199 41 67,443,647
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
daniel.reich@humansecurity.com21,389
david.grable@humansecurity.com3,071
Corporate Security516
AI SOC TESTING316
Prod Ops - Tech Docs Dev199
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
17
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Jira Overview 00
2 Case Dash 00
3 Wizer 00
4 Okta Users Dashboard 00
5 ChatGPT Use 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 IT to Cyber Intern Request Form 00
2 Holiday event parameters 00
3 Engage the Cyber Security Incident Response Team 00
4 Sub Domain Takeover Ticket Generator 00
D Full Use Case Analysis 18 use cases | 127,962 executions (12m)

Business KPIs

Metric Count Playbook
Vulnerability events auto-ingested & processed from Aikido 66,224 Aikido Webhook
AI-powered post-separation employee security monitoring checks 4,837 Invoke Security Agent Monitor Employee
Salesforce leads automatically persona-matched via AI (LinkedIn title → role mapping) 3,443 Persona Matching
Salesforce leads automatically ICP-qualified via AI 2,789 PROD Lead ICP Designation
Developer PRs automatically security-reviewed 1,283 Trigger Github PR Review Action Workflow
Google Pub-Sub cloud security events monitored 1,068 Gemini Monitoring
Separation monitoring batches executed (multi-system sweep per run) 1,927 Run Scheduled Separation Searches
GCP privilege escalation events audited 1,709 Invoke GCP Service Account Key Creation
Product documentation pages automatically fetched & validated against the live product 144 HUMAN-DocVal-Ability-FetchDocPage
Product security dashboard anomaly checks run 388 Invoke HUMAN Dashboard Agent
Customer support tickets auto-routed & triaged 437 000 - Entrypoint
New Salesforce accounts auto-created with AI-generated company profile 86 Create Account SFDC Workflow v2
SIEM alerts ingested from Sumo Logic into case management 343 Sumo Logic Insight Ingestion
Security cases auto-escalated to Jira 343 Copy Cases to JIRA
Employee offboarding workflows completed 301 Offboarding from Jira (OH)
PCI compliance evidence items auto-submitted to A-Scend 255 Jira Transition to Push to A-scend
Vendor contract approval deadlines monitored 140 Tropic Request Monitor
IT asset inventory records synced from Jamf to Snipe-IT 49 Jamf to Snipe
DLP issues ingested from Cyera and queued 63 Cyera Issues Handling
AI-powered threat hunts run via Glean-integrated agent 40 Invoke AI Hunter Glean Edition
Daily AI-generated security summaries delivered 40 Daily Executive Summary
Inactive Slack channels reviewed for workspace hygiene cleanup 13 Slack - Quarterly Inactive Channel Cleanup
Security awareness training compliance checks run 11 Wizer Flow
In the last 12 months, Blink automated: - 66,224 vulnerability events automatically ingested and processed from Aikido - 4,837 AI-powered security checks on departing or recently separated employees - 3,443 Salesforce leads automatically persona-matched via AI using LinkedIn title analysis - 2,789 Salesforce leads automatically ICP-qualified with AI-enriched scoring - 1,283 developer pull requests automatically security-reviewed against Jira - 1,068 Google Cloud Pub-Sub security events monitored and triaged - 372 combined executions across a 17-playbook AI + Playwright product documentation validation suite - 301 employee offboarding operations fully orchestrated across Akamai, Fastly, and downstream systems - 343 Sumo Logic SIEM alerts auto-processed into case management and escalated to Jira - 437 customer support tickets automatically routed, categorized, and acknowledged with AI

Use Case Summary

# Use Case Category Active Playbooks Total Playbooks
1 SOC Alert Processing & Case Management SOC 8 30
2 SIEM Log Health & Product Dashboard Monitoring SOC 21 22
3 Agentic Threat Hunting SOC 4 14
4 GCP Cloud Security Monitoring Cloud Security 2 11
5 Employee Separation Monitoring IAM 13 13
6 Vulnerability Management — Aikido Vulnerability Mgmt 2 2
7 DevSecOps Code Security Review GRC 2 4
8 Vendor Risk Management & Contract Monitoring GRC 7 10
9 Access Review (UAR) IAM 1 7
10 PCI Compliance & Regulatory Evidence GRC 5 19
11 DLP & Data Security GRC 1 4
12 Customer Support Automation Other 5 11
13 CRM & Lead Intelligence Other 4 5
14 Security Metrics & Reporting GRC 6 7
15 IT Asset & Endpoint Management (JAMF) Other 5 7
16 Documentation Validation & QA Automation Other 7 17
17 Workspace & SaaS Administration Other 5 7
18 Security Awareness Training Compliance (Wizer) SOC 1 3

Use Cases

1. SOC Alert Processing & Case Management

Description: End-to-end SIEM alert ingestion, observable extraction, deduplication, case creation, enrichment, and response orchestration. Alerts from Sumo Logic are ingested, normalized into Blink's case management system, deduplicated, enriched via VirusTotal, IPDB, URLScan, and Okta, then responded to via Jira tickets and Slack notifications.

Business Problem: Manual SOC triage is slow and inconsistent. This pipeline automates the full alert-to-case lifecycle — from ingest through to analyst notification — reducing MTTR and ensuring every alert is tracked, enriched, and escalated.

Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup, Phishing detection & response

Key Integrations: Sumo Logic, Jira, Slack, VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Check Point Harmony, Wiz, IPWhois

Playbook Executions Link
Sumo Logic Insight Ingestion 343 top-level
Process Alert V9 345 top-level
Copy Cases to JIRA 343 top-level
Subflow 4 - Response 201 subflow
Subflow - WIZ 111 top-level
SIEM Alert Processing 50 top-level
Subflow - Phishing 40 subflow
Case Closeout 1 top-level
Subflow 1 - Extract Observables 0 subflow
Subflow 2.1 - Get Deduplication Rule 0 subflow
Subflow 2.2 - Check for Case Deduplicates 0 subflow
Subflow 2.3 - Link Alert to Existing Case 0 subflow
Subflow 2 - Create Case 0 subflow
Subflow 3 - Enrich Observable 0 subflow
Enrich - Agent ID - CrowdStrike 0 subflow
Enrich - URL - URLScan 0 subflow
Enrich - Hash - VT 0 subflow
Enrich - IP - IPDB 0 subflow
Enrich - Username or Email - Okta 0 subflow
Enrich - IP - VT 0 subflow
Enrich - URL - VT 0 subflow
Subflow - Update Enrichment Data 0 subflow
Alert Post Processing 0 infrastructure
CM - Wiz Ingestion 0 top-level
CM - Crowdstrike Ingestion 0 top-level
Subflow - Phishing Gmail 0 subflow
Recovery - Handle Unprocessed Alerts 0 infrastructure
Utility - Daily Missing Template Report 40 utility
Clean up cases by query 0 on-demand
SubDomain Takeover Ticket Filer 0 event-driven

2. SIEM Log Health & Product Dashboard Monitoring

Description: A two-track monitoring framework. Track 1 (Log Health) runs daily AI-powered checks across six log sources — Aikido, Auth0, AWS, Datadog, BigQuery email records, and the HUMAN internal dashboard — alerting on ingestion gaps. Track 2 (HUMAN Dashboard) runs hourly, with an AI agent analyzing thirteen distinct anomaly categories across HUMAN Security's own product traffic (block rates, bot governance, spoofing, CAPTCHA outcomes, media abuse, etc.) and pushing findings to Slack.

Business Problem: Silent log pipeline failures mean delayed breach detection; product anomalies left unmonitored can indicate real-time attacks on customers. This use case eliminates both blind spots through continuous automated vigilance.

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Agentic SOC

Key Integrations: Sumo Logic, Slack, Google Gemini, Glean

Playbook Executions Link
Invoke HUMAN Dashboard Agent 388 top-level
Get Sumo Aggregated Results 4,707 subflow
Get HUMAN Dashboard Block Rate Anomalies 389 subflow
Get HUMAN Dashboard Spoof + Missing Sensor Data cluster 389 subflow
Get HUMAN Dashboard Denylisted / hosting-provider abuse 389 subflow
Get HUMAN Dashboard AI crawler / qualified bot governance 389 subflow
Get HUMAN Dashboard Volumetric rule / anomaly escalation 389 subflow
Get HUMAN Dashboard CAPTCHA / challenge outcome monitoring 389 subflow
Get HUMAN Dashboard /_vercel/image and media abuse 389 subflow
Get HUMAN Dashboard Backup / admin / config file probing 389 subflow
Get HUMAN Dashboard Production route and origin-status anomalies 389 subflow
Get HUMAN Dashboard Allowed 404 recon spike by domain 389 subflow
Get HUMAN Dashboard Origin errors after allowed traffic by domain 389 subflow
Get HUMAN Dashboard Partial-content media abuse by domain 389 subflow
Gemini Monitoring 1,068 top-level
Invoke Log Health Monitoring 37 top-level
LogHealth - Aikido 38 subflow
loghealth - auth0 38 subflow
loghealth - aws 38 subflow
loghealth - datadog 38 subflow
loghealth - bigquery email records 38 subflow
loghealth - Human dashboard 38 subflow
Daily Executive Summary 40 top-level

3. Agentic Threat Hunting

Description: A suite of AI agent-driven threat hunt playbooks covering CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, and Jira. The hub-and-spoke model deploys specialized "Bot Activate" wrappers that accept freeform queries and invoke domain-expert agents. A scheduled "AI Hunter" runs daily, specifically hunting computers making connections to AI-tool domains — an emerging shadow-IT / DLP risk. Results are posted to Slack.

Business Problem: Manual threat hunting is infrequent and scope-limited. This use case operationalizes continuous agentic hunting across all key security data sources, enabling the SOC to detect novel behaviors without writing new queries.

Category: SOC | Subcategories: Agentic SOC, Threat hunting & detection

Key Integrations: CrowdStrike (Next-Gen SIEM), Wiz, Okta, Sumo Logic, JAMF, Jira, Slack, Gemini

Playbook Executions Link
Invoke AI Hunter 35 scheduled
Invoke AI Hunter Glean Edition 40 scheduled
CrowdStrike Computers Talking to AI Domains 35 subflow
Crowdstrike hosts in RFM 28 scheduled
Threat Hunt Intake 0 on-demand
security email 0 event-driven
CrowdStrike Bot Activate 0 on-demand
Wiz Bot Activate 0 on-demand
Okta Bot Activate 0 on-demand
Sumo Search Bot 0 on-demand
JAMF Bot Activate 0 on-demand
Jira Bot 0 on-demand
L1 Security Analyst - Vulnerability 0 on-demand
Invoke Crowdstrike Health Monitoring 0 on-demand

4. GCP Cloud Security Monitoring

Description: Real-time GCP audit log surveillance across nine distinct threat categories — service account key creation, owner role grants, dangerous role assignments, public access grants, log sink tampering, org policy changes, API enable/disable events, and custom role modifications. Each "Invoke GCP …" playbook wraps a shared GCP Log Explorer search utility and is ready to be triggered on-demand or integrated into automated triage.

Business Problem: GCP privilege escalation and configuration drift are leading indicators of supply chain attacks and insider threats. This use case provides programmatic visibility into GCP's control plane with near-zero query-authoring overhead.

Category: Cloud Security | Subcategories: CSPM ingest & triage, Config audit & remediation

Key Integrations: GCP (Log Explorer, BigQuery), Wiz

Playbook Executions Link
GCP Log Explorer Search 1,708 shared utility
Invoke GCP Service Account Key Creation 1,709 top-level
Invoke GCP Owner Granted 0 on-demand
Invoke GCP Service accounts granted dangerous roles 0 on-demand
Invoke GCP Public access granted 0 on-demand
Invoke GCP Log Sink Tampering 0 on-demand
Invoke GCP Org Policy Changes 0 on-demand
Invoke GCP API Enable/Disable 0 on-demand
Invoke GCP Custom Role Events 0 on-demand
Wiz Get License Usage Data 40 scheduled
GCP Projects Monitoring 0 on-demand

5. Employee Separation Monitoring

Description: A comprehensive post-separation surveillance framework. When an offboarding ticket is created in the OH Jira project, Blink orchestrates deprovisioning across Akamai and Fastly CDN accounts. Separately, a scheduled AI agent runs every 30 minutes to pull all active offboarding tickets and execute parallel Sumo Logic searches per departing employee — scanning file access, outbound email, GitHub activity, Google Workspace device activity, and CrowdStrike USB events. A protected list prevents accidental deprovisioning of shared accounts.

Business Problem: Insider threats and data exfiltration risk peak during the employee separation window. Manual monitoring is infeasible at scale. This use case provides continuous, multi-vector surveillance and automated deprovisioning across CDN edge systems.

Category: IAM | Subcategories: Employee offboarding, Identity threat response, Identity lifecycle automation

Key Integrations: Jira, Akamai, Fastly, Sumo Logic, CrowdStrike, JAMF, Google Workspace, Slack, BambooHR

Playbook Executions Link
Invoke Security Agent Monitor Employee 4,837 top-level
File Access 4,783 subflow
Outbound Email 4,771 subflow
Google Workspace Devices 4,771 subflow
Separation - Github Search 4,765 subflow
Separation - CrowdStrike USB Monitoring 4,762 subflow
Gather IP Addresses 4,145 subflow
Run Scheduled Separation Searches 1,927 scheduled
Separation - enumerate offboard tickets 1,925 subflow
Offboarding from Jira (OH) 301 event-driven
OH JIRA Board Monitor v2 29 scheduled
Protected List Guard 36 subflow
Akamai Offboard User 12 subflow
Fastly Offboard User 12 subflow

6. Vulnerability Management — Aikido

Description: Aikido Security vulnerability events are ingested via webhook at high volume (66,000+ events/year) and processed in real-time. A monthly scheduled report computes high/critical vulnerability trends and publishes a summary to a Google Sheet, enabling trend analysis by the security team.

Business Problem: Keeping up with a high-velocity vulnerability feed without missing critical findings. Automated ingest + trend reporting transforms raw scanner data into actionable intelligence without manual queue management.

Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Vuln scan lifecycle automation

Key Integrations: Aikido, Google Sheets, GCP

Playbook Executions Link
Aikido Webhook 66,224 event-driven
Aikido High/Critical Trend Report 22 scheduled

7. DevSecOps Code Security Review

Description: Every GitHub pull request that generates a Sumo Logic event triggers an automated security review workflow. The playbook parses the PR diff, creates a Jira ticket, appends an AI-generated security analysis as a comment, and evaluates whether the code change introduces security risks. This closes the loop between developer velocity and security review without requiring analyst involvement on every PR.

Business Problem: Security teams cannot manually review every code change at development speed. This use case scales security code review to match engineering throughput.

Category: GRC | Subcategories: DevSecOps compliance, Threat hunting & detection

Key Integrations: GitHub, Jira, Sumo Logic, Node.js (AI parsing)

Playbook Executions Link
Trigger Github PR Review Action Workflow 1,283 event-driven
repo_changes 0 on-demand
JIRA Autostart 0 on-demand
Entity OSINT 0 event-driven

8. Vendor Risk Management & Contract Monitoring

Description: Two complementary VRM tracks. First, a SecurityScorecard-integrated pipeline manages vendor portfolios by division, runs vendor risk reports, and attaches them to Jira VRM tickets — with an AI review loop for AI-generated vendor assessments. Second, Tropic contract approvals are monitored on a six-hour schedule to surface pending approvals before deadlines.

Business Problem: Vendor risk reviews are time-consuming and often inconsistent. This use case automates portfolio management, report generation, and AI-assisted review, while ensuring procurement contracts don't stall.

Category: GRC | Subcategories: Vendor risk & TPRM, Security metrics & reporting

Key Integrations: SecurityScorecard, Jira, BambooHR, Glean, Tropic, Slack

Playbook Executions Link
Tropic Request Monitor 140 scheduled
VRM - AI Review Loop 11 event-driven
SSR VRM Extract Domain from submitted form 10 subflow
Bamboo Get Employee Department 10 subflow
Add vendor to portfolio 9 subflow
SecurityScorecard Get Reports 5 subflow
Attach Reports to Jira Issue 0 subflow
Manage Portfolios 0 on-demand
Create Portfolios 0 on-demand

9. Access Review (UAR)

Description: A Glean AI-assisted access review pipeline for Aikido and GitHub. The UAR - AI Review Loop workflow triggers on Sumo Logic events, pulls the relevant Jira UAR ticket, queries current application users (Okta), and runs an AI-driven review — generating recommendations and posting them back to Jira. PTO awareness (BambooHR) is built in to avoid sending reviews to employees on leave.

Business Problem: Annual and periodic access reviews are labor-intensive. This use case automates the evidence collection, AI-assisted analysis, and review workflow, reducing reviewer burden while improving consistency.

Category: IAM | Subcategories: Access review & group mgmt, RBAC review & access mgmt

Key Integrations: Jira, Okta, GitHub, Glean, Slack, BambooHR

Playbook Executions Link
UAR - AI Review Loop 18 event-driven
Aikido UAR Reject 0 on-demand
Github UAR 0 on-demand
Okta User Pull 0 subflow
UAR Table Pull 0 subflow
Okta Table Application Pull 0 subflow
PTO Check 0 subflow

10. PCI Compliance & Regulatory Evidence

Description: A multi-system compliance evidence pipeline centered on A-Scend (the PCI evidence management platform). Jira tickets transition automatically into A-Scend evidence submissions via webhook. Snowflake SQL evidence collection, Confluence quarterly page building, and Jira activity ticket cloning are orchestrated through the MRC Quarterly Orchestrator — producing a fully automated compliance evidence package each quarter. A PCI Bot answers ad-hoc compliance questions via a Glean-backed AI agent.

Business Problem: PCI evidence collection is manual, error-prone, and consumes significant compliance team time each quarter. This use case automates evidence ingestion, quarterly Confluence page generation, and Jira ticket management, compressing multi-day work to minutes.

Category: GRC | Subcategories: PCI & regulatory monitoring, Compliance questionnaire, Security metrics & reporting

Key Integrations: Jira, Snowflake, Confluence, Google Sheets, Glean, A-Scend

Playbook Executions Link
Jira Transition to Push to A-scend 255 event-driven
MRC Probe - Jira JQL Custom Search 18 on-demand
MRC Probe - Get Jira Ticket via mrc_jira 18 on-demand
MRC Probe - Confluence Page Storage Body 8 on-demand
MRC Probe Confluence Search 4 on-demand
MRC Snowflake Evidence 2 subflow
MRC Quarterly Orchestrator 0 on-demand
MRC Build Quarterly Confluence Page 0 subflow
MRC Clone Activity Jira Ticket 0 subflow
MRC Google Doc Date Scrape 0 subflow
PBC ticket generator 0 on-demand
Get PCI Table Data 0 subflow
Get ASCEND DATA 0 subflow
PCI Bot Questions 0 on-demand
Table Balance 0 on-demand
Get All A-Scend Requests 0 on-demand
Populate tables: A-scend data by reference ID 0 subflow
Push Ascend Evidence 0 subflow
Responsive Trust Center Authorization 0 on-demand

11. DLP & Data Security

Description: Cyera DLP issues are ingested via webhook in real-time and recorded to a Blink table for downstream triage. A backlog seeder imports historical Cyera issues into Jira. A DSAR registration workflow appends new data subject access requests to a Google Sheet for compliance tracking. Glean log access events are monitored and alerted on Slack.

Business Problem: Data exposure findings from Cyera need immediate logging and tracking. Manual DSAR intake creates compliance risk. This use case automates ingestion at both ends of the data governance lifecycle.

Category: GRC | Subcategories: DLP triage & exposure resp, DSAR & privacy automation

Key Integrations: Cyera, Jira, Google Sheets, Slack, Glean

Playbook Executions Link
Cyera Issues Handling 63 event-driven
DSAR Table 0 on-demand
Cyera backlog 0 on-demand
Glean Log Monitor 0 event-driven

12. Customer Support Automation

Description: A fully automated customer support routing and AI-response system built on top of Jira Service Desk. The 000 - Entrypoint workflow catches every new Jira ticket update via webhook, validates routing criteria, uses Gemini AI to classify the request type, and dispatches to specialized sub-workflows. 001 - Initial Acknowledgement sends an AI-personalized acknowledgement. The 003 - 02 - Missed attack sub-workflow collects structured details about missed bot/attack events via an AI-driven Jira conversation loop. Glean is used to automatically record RFP submissions.

Business Problem: High support ticket volume with repetitive initial triage and acknowledgement tasks. This use case automates the full intake-to-routing pipeline and AI-assisted information gathering, reducing time-to-first-response and freeing analyst capacity for complex cases.

Category: Other | Subcategories: IT helpdesk & ticket routing, Agentic SOC

Key Integrations: Jira, Gemini, Google Sheets, Postgres, Glean, Sumo Logic, Slack

Playbook Executions Link
000 - Entrypoint 437 event-driven
003 - 02 - Missed attack 286 on-demand
001 - Initial Acknowledgement 92 on-demand
Spike In tickets 40 scheduled
Glean RFP Recorder 9 event-driven
jsm-snitch-escalation-agent-details 1 event-driven
On Snitch Enrichment Flow 0 event-driven
JSM - List Pending TAM 0 on-demand
Find related Jira tickets 0 on-demand
Send Slack message on new DRP ticket creation 0 event-driven
COPS Report Building 0 on-demand

13. CRM & Lead Intelligence

Description: Salesforce lead records are automatically ICP-qualified via AI on ingest. A Glean AI model retrieves NAICS codes, annual revenue, and industry segments for each new lead and writes the enriched ICP designation back to Salesforce. A daily Account Planning job processes open opportunities to ensure coverage.

Business Problem: Sales team capacity is wasted on manual lead qualification. This use case applies AI scoring immediately on lead creation, enabling instant prioritization of high-fit accounts.

Category: Other | Subcategories: SaaS / IT administration, Customer registry & FinOps auto

Key Integrations: Salesforce, Glean, Google Sheets, OpenAI

Playbook Executions Link
Persona Matching 3,443 event-driven
PROD Lead ICP Designation 2,789 event-driven
Create Account SFDC Workflow v2 86 event-driven
Account Planning 26 scheduled
Fill BPQ Workflow 0 on-demand

14. Security Metrics & Reporting

Description: A set of scheduled reporting workflows that monitor Jira board health, track active and labeled tickets, flag SCR (Security Change Review) backlog items, and deliver daily AI-generated executive security summaries combining Sumo Logic data with Glean intelligence. Cloud license consumption (Wiz) is tracked daily to a Google Sheet.

Business Problem: Security leaders need regular visibility into ticket hygiene, operational metrics, and posture trends without manual report assembly. This use case automates the full metrics pipeline from data collection to Slack delivery.

Category: GRC | Subcategories: Security metrics & reporting

Key Integrations: Jira, Slack, Sumo Logic, Glean, Wiz, Google Sheets, BambooHR

Playbook Executions Link
Daily Executive Summary 40 scheduled
JIRA Active Tickets 40 scheduled
JIRA Labels 40 scheduled
Check for new SCR Tickets 40 scheduled
OH JIRA Board Monitor v2 29 scheduled
Wiz Get License Usage Data 40 scheduled
Post Monthly Security Team Report 0 on-demand

15. IT Asset & Endpoint Management (JAMF)

Description: JAMF MDM inventory is queried, transformed, and routed across several IT operations workflows — syncing computer inventory into Snipe-IT nightly, resolving Slack IT-channel requests to JAMF computer records by email or serial number, comparing JAMF inventory against Control D device lists to flag unmanaged devices, and generating on-demand check-in compliance reports for a specific smart group. A Slack slash-command router gates access to this tooling based on IT team group membership.

Business Problem: IT and helpdesk staff need fast, self-service access to endpoint inventory data without direct JAMF console access, and asset records must stay synchronized across JAMF and the Snipe-IT system of record. This suite automates lookups, syncing, and reconciliation that would otherwise require manual console work.

Category: Other | Subcategories: Endpoint hygiene & MDM ops, IT helpdesk & ticket routing

Key Integrations: JAMF, Snipe-IT, Slack, Control D

Playbook Executions Link
Jamf to Snipe 49 scheduled
Jamf Slack Router 20 event-driven
Jamf Lookup by Email 9 on-demand
ControlDvsJamfcheck 6 scheduled
Jamf Checkin Report 4 on-demand
Find computer by email 0 on-demand
Jamf Lookup by Serial 0 on-demand

16. Documentation Validation & QA Automation

Description: A comprehensive AI + Playwright pipeline that translates HUMAN Security product documentation into executable test cases, grounds them against the live product DOM, executes them end-to-end, and reports pass/fail status. Supporting diagnostic playbooks isolate specific UI behaviors — settings-category clicks, sidebar navigation, invite-user modals, bot-block pages, browser reconnect handling, and login flows — while a caching layer avoids re-deriving confirmed navigation chains on repeat runs.

Business Problem: Product documentation drifts out of sync with the live UI as features ship, and manually re-validating every documented workflow is impractical at HUMAN's release cadence. This use case continuously proves (or disproves) that documented steps still work against the live product, catching documentation debt before customers hit it.

Category: Other | Subcategories: DevOps & release automation

Key Integrations: Playwright (browser automation), Blink AI agents, Blink Tables (confirmed-chain cache)

Playbook Executions Link
HUMAN-DocVal-Ability-FetchDocPage 144 subflow
HUMAN-DocVal-Execute-Test-Case 72 subflow
HUMAN-DocVal-Translate-Doc-To-Test-Case 65 on-demand
HUMAN-DocVal-Ability-GroundInLiveDOM 61 subflow
HUMAN-DocVal-Diag-SidebarEnumerate 24 on-demand
Playwright Blink Docs Smoke Test 3 on-demand
HUMAN-DocVal-Diagnostic-SettingsClick 3 on-demand
HUMAN-DocVal-MVP-Add-Application 0 on-demand
HUMAN-DocVal-NetDiag 0 on-demand
HUMAN-DocVal-LocalBrowserDiag 0 on-demand
HUMAN-DocVal-BotBlockDiag 0 on-demand
HUMAN-DocVal-CaptureBlockScreenshot 0 on-demand
HUMAN-DocVal-LoginScreenshot 0 on-demand
HUMAN-DocVal-Diag-InviteModal 0 on-demand
HUMAN-DocVal-TestCase-InviteUser 0 on-demand
HUMAN-DocVal-Diag-ReactLoop 0 on-demand
HUMAN-DocVal-Diag-BrowserReconnect 0 on-demand

17. Workspace & SaaS Administration

Description: Cross-cutting administrative automation for the tools the IT and program teams rely on day to day — a quarterly Slack workspace hygiene sweep that pages through admin APIs to identify and archive inactive channels (with guest and external-share detection safeguards and a Jira review subtask for anything excluded), a general Confluence content search utility, Jira connection health tests, and a lightweight Kanban-based project tracker (with an intake web form) for triaging BlinkOps Builder bugs, requests, and tasks across the MRC Audit, Slack Cleanup, Slack-Jamf, and Tech Docs initiatives.

Business Problem: Running dozens of automations across Slack, Jira, and Confluence requires ongoing administrative upkeep — stale channels accumulate, connections need periodic validation, and a growing automation backlog needs a lightweight tracking system. This use case keeps the underlying SaaS workspace and its own delivery backlog healthy.

Category: Other | Subcategories: SaaS / IT administration, IT helpdesk & ticket routing

Key Integrations: Slack (admin APIs), Jira, Confluence

Playbook Executions Link
Slack - Quarterly Inactive Channel Cleanup 13 on-demand
BlinkOps Builder PM Tracker - Refresh Kanban 9 scheduled
Probe - Guest Reason Fix Retest (read-only) 7 on-demand
Probe - Verify IT-679 and Cleanup IT-676-678 2 on-demand
BlinkOps Builder PM Tracker - Submit Request 1 event-driven
Confluence Search 0 on-demand
Jira Connection Functionality Test 0 on-demand

18. Security Awareness Training Compliance (Wizer)

Description: A twice-weekly scheduled workflow cross-references BambooHR's who's-off list against the employee directory and pulls the Wizer security-awareness training master report to identify training gaps. A separate escalation flow queries PCI and Code training records and processes overdue completions. A shared "Is Employee OOO" check prevents nudges from being sent to employees who are out of office.

Business Problem: Security-awareness and PCI training compliance requires continuously cross-referencing HR status against training completion records — manual reconciliation is easy to let slip. This use case automates detection of training gaps while respecting employee PTO.

Category: SOC | Subcategories: Phishing sim & awareness

Key Integrations: Wizer, BambooHR

Playbook Executions Link
Wizer Flow 11 scheduled
WizerEscalation 0 on-demand
Is Employee OOO 0 subflow

Key Observations

Strengths

Deep agentic AI investment. The organization has deployed Blink AI agents across nearly every security domain — CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, Jira, and a dedicated L1 SOC email bot. The "Bot Activate" pattern makes agentic hunting accessible on-demand. The HUMAN Dashboard Agent running every hour across 13 anomaly dimensions is a particularly sophisticated production deployment.

Unique separation monitoring architecture. The employee separation use case is one of the most comprehensive seen in this segment. Running every 30 minutes with parallel Sumo Logic searches across five data planes (file access, outbound email, GitHub, Google Workspace, CrowdStrike USB) per departing employee demonstrates mature insider threat operations. The protected list guard prevents accidental deprovisioning at scale.

Own-product security as a use case. Unusually, Blink is being used to monitor HUMAN Security's own product dashboards (bot detection metrics, block rates, CAPTCHA outcomes). This "drink your own champagne" pattern, running 388 times in the last year, underscores the trust placed in the platform.

High-volume vulnerability management at scale. 66,224 Aikido events processed in 12 months — roughly 180/day — without analyst involvement. Paired with monthly trend reporting to Google Sheets, this represents a fully automated vulnerability intake pipeline.

PCI compliance automation depth. The MRC framework — spanning Snowflake evidence collection, Confluence quarterly page generation, Jira ticket cloning, and A-Scend integration — is a production-grade compliance automation stack, not a prototype.

AI-driven product documentation QA at scale. A 17-playbook suite translates HUMAN Security's own product documentation into Playwright test cases, executes them against the live product, and grounds results in the live DOM — 372 combined executions in its first period. This is an unusually mature application of Blink to internal product-quality assurance, extending the platform beyond traditional security use cases.

Persona Matching is now the highest-volume single playbook in the tenant. At 3,443 executions, the Salesforce Persona Matching workflow (AI-driven LinkedIn title → persona classification) runs more often than any other automation, reinforcing Blink's expanding role in real-time CRM enrichment alongside the existing Lead ICP Designation pipeline.

Gaps & Opportunities

Crowdstrike and Wiz ingestion paths have zero executions. The CM - Wiz Ingestion and CM - Crowdstrike ingestion workflows were built but have not run, suggesting the SIEM-based Sumo Logic path is the sole alert source in production. Enabling native CrowdStrike and Wiz webhook ingest would accelerate alert MTTR and reduce Sumo Logic dependency.

Phishing response has low execution volume relative to infrastructure. The Subflow - Phishing (40) and Subflow - Phishing Gmail (0) flows exist but run infrequently. The Check Point Harmony integration is connected but underutilized — the email remediation path (Restore Email - Harmony TEST) appears to still be in testing.

Access review playbooks built but not yet running. Aikido UAR Reject, Github UAR, and supporting Okta/UAR Table utilities all show zero executions. Only the UAR - AI Review Loop has been activated (18 runs). Completing the UAR pipeline would close a key IAM governance gap.

DLP triage stops at ingestion. Cyera issues are ingested (63 events) and added to a table, but there is no downstream triage, Jira ticket creation, or owner notification automation visible in the active playbooks. The Cyera backlog importer also has zero executions, suggesting the Cyera→Jira pipeline is incomplete.

GCP monitoring playbooks are built but idle. Eight "Invoke GCP …" wrappers (owner grants, dangerous roles, log sink tampering, org policy changes, etc.) all show zero executions. Only Invoke GCP Service Account Key Creation has been activated. Connecting the remaining GCP monitors to scheduled or event-triggered execution would complete the cloud control-plane coverage.

IT self-service and admin health-check tooling is built but not yet in active rotation. Jamf Lookup by Serial, Find computer by email, Confluence Search, and Jira Connection Functionality Test all show zero executions, suggesting several JAMF lookup paths and connection-health probes are staged but not yet driving day-to-day IT workflows.

Integration Ecosystem

Category Integrations
SIEM / Logging Sumo Logic, GCP Log Explorer, BigQuery
EDR / Identity CrowdStrike, Okta, JAMF
Cloud Security Wiz, Aikido, Cyera, GCP
Ticketing Jira (5+ connections), Confluence
Collaboration Slack (multiple connections), Gmail
CDN / Edge Akamai, Fastly
Compliance A-Scend, SecurityScorecard, Snowflake
AI / Knowledge Gemini, Glean (multiple connections), OpenAI
CRM / Sales Salesforce, Gong
HRIS BambooHR
Dev GitHub, Sumo Logic (PR events)
Productivity Google Sheets, Google Drive, Google Docs
Endpoint / Asset Mgmt JAMF, Snipe-IT, Control D
QA / Testing Playwright
Security Awareness Wizer
E New Integrations (detail) 4 added in last 30d

New Integrations Added - Last 30 Days

4 new connections
TenantIntegrationConnection NameAdded
humansecurity jira sierra_3 2026-08-19
humansecurity jira sierra_testing_2 2026-08-14
humansecurity jira sierra_jira_testing 2026-08-13
humansecurity slack archive_bot_testing_only_sierra_grid_sandbox 2026-08-07