01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SOC Alert Processing & Case Management |
| 0.5% | 31 30 active |
| SIEM Log Health & Product Dashboard Monitoring |
| 1.1% | 22 21 active |
| Agentic Threat Hunting |
| 0.2% | 14 14 active |
| GCP Cloud Security Monitoring |
| 19.1% | 10 10 active |
| Employee Separation Monitoring |
| 70.5% | 13 13 active |
| Vulnerability Management — Aikido |
| 0.0% | 2 1 active |
| DevSecOps Code Security Review |
| 1.2% | 4 4 active |
| Vendor Risk Management & Contract Monitoring |
| 0.1% | 9 9 active |
| Access Review (UAR) | 15 executions | 0.0% | 7 7 active |
| PCI Compliance & Regulatory Evidence |
| 0.0% | 19 19 active |
| DLP & Data Security |
| 0.0% | 4 4 active |
| Customer Support Automation |
| 0.0% | 10 7 active |
| CRM & Lead Intelligence |
| 5.0% | 4 4 active |
| Security Metrics & Reporting |
| 0.2% | 7 7 active |
| IT Asset & Endpoint Management (JAMF) |
| 0.1% | 7 7 active |
| Documentation Validation & QA Automation |
| 0.3% | 17 17 active |
| Workspace & SaaS Administration |
| 0.0% | 7 7 active |
| Security Awareness Training Compliance (Wizer) |
| 0.0% | 3 3 active |
| Total | 125,954 executions | 100% | 190 184 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep agentic AI investment. The organization has deployed Blink AI agents across nearly every security domain — CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, Jira, and a dedicated L1 SOC email bot. The "Bot Activate" pattern makes agentic hunting accessible on-demand. The HUMAN Dashboard Agent running every hour across 13 anomaly dimensions is a particularly sophisticated production deployment.
Unique separation monitoring architecture. The employee separation use case is one of the most comprehensive seen in this segment. Running every 30 minutes with parallel Sumo Logic searches across five data planes (file access, outbound email, GitHub, Google Workspace, CrowdStrike USB) per departing employee demonstrates mature insider threat operations. The protected list guard prevents accidental deprovisioning at scale.
Own-product security as a use case. Unusually, Blink is being used to monitor HUMAN Security's own product dashboards (bot detection metrics, block rates, CAPTCHA outcomes). This "drink your own champagne" pattern, running 388 times in the last year, underscores the trust placed in the platform.
High-volume vulnerability management at scale. 66,224 Aikido events processed in 12 months — roughly 180/day — without analyst involvement. Paired with monthly trend reporting to Google Sheets, this represents a fully automated vulnerability intake pipeline.
PCI compliance automation depth. The MRC framework — spanning Snowflake evidence collection, Confluence quarterly page generation, Jira ticket cloning, and A-Scend integration — is a production-grade compliance automation stack, not a prototype.
AI-driven product documentation QA at scale. A 17-playbook suite translates HUMAN Security's own product documentation into Playwright test cases, executes them against the live product, and grounds results in the live DOM — 372 combined executions in its first period. This is an unusually mature application of Blink to internal product-quality assurance, extending the platform beyond traditional security use cases.
Persona Matching is now the highest-volume single playbook in the tenant. At 3,443 executions, the Salesforce Persona Matching workflow (AI-driven LinkedIn title → persona classification) runs more often than any other automation, reinforcing Blink's expanding role in real-time CRM enrichment alongside the existing Lead ICP Designation pipeline.
###
Gaps & Opportunities
Crowdstrike and Wiz ingestion paths have zero executions. The CM - Wiz Ingestion and CM - Crowdstrike ingestion workflows were built but have not run, suggesting the SIEM-based Sumo Logic path is the sole alert source in production. Enabling native CrowdStrike and Wiz webhook ingest would accelerate alert MTTR and reduce Sumo Logic dependency.
Phishing response has low execution volume relative to infrastructure. The Subflow - Phishing (40) and Subflow - Phishing Gmail (0) flows exist but run infrequently. The Check Point Harmony integration is connected but underutilized — the email remediation path (Restore Email - Harmony TEST) appears to still be in testing.
Access review playbooks built but not yet running. Aikido UAR Reject, Github UAR, and supporting Okta/UAR Table utilities all show zero executions. Only the UAR - AI Review Loop has been activated (18 runs). Completing the UAR pipeline would close a key IAM governance gap.
DLP triage stops at ingestion. Cyera issues are ingested (63 events) and added to a table, but there is no downstream triage, Jira ticket creation, or owner notification automation visible in the active playbooks. The Cyera backlog importer also has zero executions, suggesting the Cyera→Jira pipeline is incomplete.
GCP monitoring playbooks are built but idle. Eight "Invoke GCP …" wrappers (owner grants, dangerous roles, log sink tampering, org policy changes, etc.) all show zero executions. Only Invoke GCP Service Account Key Creation has been activated. Connecting the remaining GCP monitors to scheduled or event-triggered execution would complete the cloud control-plane coverage.
IT self-service and admin health-check tooling is built but not yet in active rotation. Jamf Lookup by Serial, Find computer by email, Confluence Search, and Jira Connection Functionality Test all show zero executions, suggesting several JAMF lookup paths and connection-health probes are staged but not yet driving day-to-day IT workflows.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Logging | Sumo Logic, GCP Log Explorer, BigQuery |
| EDR / Identity | CrowdStrike, Okta, JAMF |
| Cloud Security | Wiz, Aikido, Cyera, GCP |
| Ticketing | Jira (5+ connections), Confluence |
| Collaboration | Slack (multiple connections), Gmail |
| CDN / Edge | Akamai, Fastly |
| Compliance | A-Scend, SecurityScorecard, Snowflake |
| AI / Knowledge | Gemini, Glean (multiple connections), OpenAI |
| CRM / Sales | Salesforce, Gong |
| HRIS | BambooHR |
| Dev | GitHub, Sumo Logic (PR events) |
| Productivity | Google Sheets, Google Drive, Google Docs |
| Endpoint / Asset Mgmt | JAMF, Snipe-IT, Control D |
| QA / Testing | Playwright |
| Security Awareness | Wizer |
A Case Management 3,145 cases (12m) | MTTR 6d 3h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 4,199 | 3,092 | 2,749 | 6d 3h |
| AI SOC TESTING | 53 | 53 | 0 | N/A |
| CM V9 Migration Temp | 39 | 0 | 0 | N/A |
B AI Agents 32 active | 25,570 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Separation Monitor | daniel.reich@humansecurity.com | 21,130 | 8,355 | 1,744,820,709 |
| 2 | Level 1 SOC Bot | david.grable@humansecurity.com | 2,302 | 0 | 187,689,953 |
| 3 | HUMAN Dashboard | Corporate Security | 512 | 0 | 180,756,420 |
| 4 | DSAR Agent | david.grable@humansecurity.com | 257 | 0 | 17,133,260 |
| 5 | Doc-to-Playwright Test Case Translator | Prod Ops - Tech Docs Dev | 199 | 41 | 67,443,647 |
| Workspace | Tasks (12m) |
|---|---|
| daniel.reich@humansecurity.com | 21,389 |
| david.grable@humansecurity.com | 3,071 |
| Corporate Security | 516 |
| AI SOC TESTING | 316 |
| Prod Ops - Tech Docs Dev | 199 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Jira Overview | 0 | 0 |
| 2 | Case Dash | 0 | 0 |
| 3 | Wizer | 0 | 0 |
| 4 | Okta Users Dashboard | 0 | 0 |
| 5 | ChatGPT Use | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | IT to Cyber Intern Request Form | 0 | 0 |
| 2 | Holiday event parameters | 0 | 0 |
| 3 | Engage the Cyber Security Incident Response Team | 0 | 0 |
| 4 | Sub Domain Takeover Ticket Generator | 0 | 0 |
D Full Use Case Analysis 18 use cases | 127,962 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Vulnerability events auto-ingested & processed from Aikido | 66,224 | Aikido Webhook |
| AI-powered post-separation employee security monitoring checks | 4,837 | Invoke Security Agent Monitor Employee |
| Salesforce leads automatically persona-matched via AI (LinkedIn title → role mapping) | 3,443 | Persona Matching |
| Salesforce leads automatically ICP-qualified via AI | 2,789 | PROD Lead ICP Designation |
| Developer PRs automatically security-reviewed | 1,283 | Trigger Github PR Review Action Workflow |
| Google Pub-Sub cloud security events monitored | 1,068 | Gemini Monitoring |
| Separation monitoring batches executed (multi-system sweep per run) | 1,927 | Run Scheduled Separation Searches |
| GCP privilege escalation events audited | 1,709 | Invoke GCP Service Account Key Creation |
| Product documentation pages automatically fetched & validated against the live product | 144 | HUMAN-DocVal-Ability-FetchDocPage |
| Product security dashboard anomaly checks run | 388 | Invoke HUMAN Dashboard Agent |
| Customer support tickets auto-routed & triaged | 437 | 000 - Entrypoint |
| New Salesforce accounts auto-created with AI-generated company profile | 86 | Create Account SFDC Workflow v2 |
| SIEM alerts ingested from Sumo Logic into case management | 343 | Sumo Logic Insight Ingestion |
| Security cases auto-escalated to Jira | 343 | Copy Cases to JIRA |
| Employee offboarding workflows completed | 301 | Offboarding from Jira (OH) |
| PCI compliance evidence items auto-submitted to A-Scend | 255 | Jira Transition to Push to A-scend |
| Vendor contract approval deadlines monitored | 140 | Tropic Request Monitor |
| IT asset inventory records synced from Jamf to Snipe-IT | 49 | Jamf to Snipe |
| DLP issues ingested from Cyera and queued | 63 | Cyera Issues Handling |
| AI-powered threat hunts run via Glean-integrated agent | 40 | Invoke AI Hunter Glean Edition |
| Daily AI-generated security summaries delivered | 40 | Daily Executive Summary |
| Inactive Slack channels reviewed for workspace hygiene cleanup | 13 | Slack - Quarterly Inactive Channel Cleanup |
| Security awareness training compliance checks run | 11 | Wizer Flow |
Use Case Summary
| # | Use Case | Category | Active Playbooks | Total Playbooks |
|---|---|---|---|---|
| 1 | SOC Alert Processing & Case Management | SOC | 8 | 30 |
| 2 | SIEM Log Health & Product Dashboard Monitoring | SOC | 21 | 22 |
| 3 | Agentic Threat Hunting | SOC | 4 | 14 |
| 4 | GCP Cloud Security Monitoring | Cloud Security | 2 | 11 |
| 5 | Employee Separation Monitoring | IAM | 13 | 13 |
| 6 | Vulnerability Management — Aikido | Vulnerability Mgmt | 2 | 2 |
| 7 | DevSecOps Code Security Review | GRC | 2 | 4 |
| 8 | Vendor Risk Management & Contract Monitoring | GRC | 7 | 10 |
| 9 | Access Review (UAR) | IAM | 1 | 7 |
| 10 | PCI Compliance & Regulatory Evidence | GRC | 5 | 19 |
| 11 | DLP & Data Security | GRC | 1 | 4 |
| 12 | Customer Support Automation | Other | 5 | 11 |
| 13 | CRM & Lead Intelligence | Other | 4 | 5 |
| 14 | Security Metrics & Reporting | GRC | 6 | 7 |
| 15 | IT Asset & Endpoint Management (JAMF) | Other | 5 | 7 |
| 16 | Documentation Validation & QA Automation | Other | 7 | 17 |
| 17 | Workspace & SaaS Administration | Other | 5 | 7 |
| 18 | Security Awareness Training Compliance (Wizer) | SOC | 1 | 3 |
Use Cases
1. SOC Alert Processing & Case Management
Description: End-to-end SIEM alert ingestion, observable extraction, deduplication, case creation, enrichment, and response orchestration. Alerts from Sumo Logic are ingested, normalized into Blink's case management system, deduplicated, enriched via VirusTotal, IPDB, URLScan, and Okta, then responded to via Jira tickets and Slack notifications.
Business Problem: Manual SOC triage is slow and inconsistent. This pipeline automates the full alert-to-case lifecycle — from ingest through to analyst notification — reducing MTTR and ensuring every alert is tracked, enriched, and escalated.
Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup, Phishing detection & response
Key Integrations: Sumo Logic, Jira, Slack, VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Check Point Harmony, Wiz, IPWhois
2. SIEM Log Health & Product Dashboard Monitoring
Description: A two-track monitoring framework. Track 1 (Log Health) runs daily AI-powered checks across six log sources — Aikido, Auth0, AWS, Datadog, BigQuery email records, and the HUMAN internal dashboard — alerting on ingestion gaps. Track 2 (HUMAN Dashboard) runs hourly, with an AI agent analyzing thirteen distinct anomaly categories across HUMAN Security's own product traffic (block rates, bot governance, spoofing, CAPTCHA outcomes, media abuse, etc.) and pushing findings to Slack.
Business Problem: Silent log pipeline failures mean delayed breach detection; product anomalies left unmonitored can indicate real-time attacks on customers. This use case eliminates both blind spots through continuous automated vigilance.
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Agentic SOC
Key Integrations: Sumo Logic, Slack, Google Gemini, Glean
3. Agentic Threat Hunting
Description: A suite of AI agent-driven threat hunt playbooks covering CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, and Jira. The hub-and-spoke model deploys specialized "Bot Activate" wrappers that accept freeform queries and invoke domain-expert agents. A scheduled "AI Hunter" runs daily, specifically hunting computers making connections to AI-tool domains — an emerging shadow-IT / DLP risk. Results are posted to Slack.
Business Problem: Manual threat hunting is infrequent and scope-limited. This use case operationalizes continuous agentic hunting across all key security data sources, enabling the SOC to detect novel behaviors without writing new queries.
Category: SOC | Subcategories: Agentic SOC, Threat hunting & detection
Key Integrations: CrowdStrike (Next-Gen SIEM), Wiz, Okta, Sumo Logic, JAMF, Jira, Slack, Gemini
| Playbook | Executions | Link |
|---|---|---|
| Invoke AI Hunter | 35 | scheduled |
| Invoke AI Hunter Glean Edition | 40 | scheduled |
| CrowdStrike Computers Talking to AI Domains | 35 | subflow |
| Crowdstrike hosts in RFM | 28 | scheduled |
| Threat Hunt Intake | 0 | on-demand |
| security email | 0 | event-driven |
| CrowdStrike Bot Activate | 0 | on-demand |
| Wiz Bot Activate | 0 | on-demand |
| Okta Bot Activate | 0 | on-demand |
| Sumo Search Bot | 0 | on-demand |
| JAMF Bot Activate | 0 | on-demand |
| Jira Bot | 0 | on-demand |
| L1 Security Analyst - Vulnerability | 0 | on-demand |
| Invoke Crowdstrike Health Monitoring | 0 | on-demand |
4. GCP Cloud Security Monitoring
Description: Real-time GCP audit log surveillance across nine distinct threat categories — service account key creation, owner role grants, dangerous role assignments, public access grants, log sink tampering, org policy changes, API enable/disable events, and custom role modifications. Each "Invoke GCP …" playbook wraps a shared GCP Log Explorer search utility and is ready to be triggered on-demand or integrated into automated triage.
Business Problem: GCP privilege escalation and configuration drift are leading indicators of supply chain attacks and insider threats. This use case provides programmatic visibility into GCP's control plane with near-zero query-authoring overhead.
Category: Cloud Security | Subcategories: CSPM ingest & triage, Config audit & remediation
Key Integrations: GCP (Log Explorer, BigQuery), Wiz
| Playbook | Executions | Link |
|---|---|---|
| GCP Log Explorer Search | 1,708 | shared utility |
| Invoke GCP Service Account Key Creation | 1,709 | top-level |
| Invoke GCP Owner Granted | 0 | on-demand |
| Invoke GCP Service accounts granted dangerous roles | 0 | on-demand |
| Invoke GCP Public access granted | 0 | on-demand |
| Invoke GCP Log Sink Tampering | 0 | on-demand |
| Invoke GCP Org Policy Changes | 0 | on-demand |
| Invoke GCP API Enable/Disable | 0 | on-demand |
| Invoke GCP Custom Role Events | 0 | on-demand |
| Wiz Get License Usage Data | 40 | scheduled |
| GCP Projects Monitoring | 0 | on-demand |
5. Employee Separation Monitoring
Description: A comprehensive post-separation surveillance framework. When an offboarding ticket is created in the OH Jira project, Blink orchestrates deprovisioning across Akamai and Fastly CDN accounts. Separately, a scheduled AI agent runs every 30 minutes to pull all active offboarding tickets and execute parallel Sumo Logic searches per departing employee — scanning file access, outbound email, GitHub activity, Google Workspace device activity, and CrowdStrike USB events. A protected list prevents accidental deprovisioning of shared accounts.
Business Problem: Insider threats and data exfiltration risk peak during the employee separation window. Manual monitoring is infeasible at scale. This use case provides continuous, multi-vector surveillance and automated deprovisioning across CDN edge systems.
Category: IAM | Subcategories: Employee offboarding, Identity threat response, Identity lifecycle automation
Key Integrations: Jira, Akamai, Fastly, Sumo Logic, CrowdStrike, JAMF, Google Workspace, Slack, BambooHR
| Playbook | Executions | Link |
|---|---|---|
| Invoke Security Agent Monitor Employee | 4,837 | top-level |
| File Access | 4,783 | subflow |
| Outbound Email | 4,771 | subflow |
| Google Workspace Devices | 4,771 | subflow |
| Separation - Github Search | 4,765 | subflow |
| Separation - CrowdStrike USB Monitoring | 4,762 | subflow |
| Gather IP Addresses | 4,145 | subflow |
| Run Scheduled Separation Searches | 1,927 | scheduled |
| Separation - enumerate offboard tickets | 1,925 | subflow |
| Offboarding from Jira (OH) | 301 | event-driven |
| OH JIRA Board Monitor v2 | 29 | scheduled |
| Protected List Guard | 36 | subflow |
| Akamai Offboard User | 12 | subflow |
| Fastly Offboard User | 12 | subflow |
6. Vulnerability Management — Aikido
Description: Aikido Security vulnerability events are ingested via webhook at high volume (66,000+ events/year) and processed in real-time. A monthly scheduled report computes high/critical vulnerability trends and publishes a summary to a Google Sheet, enabling trend analysis by the security team.
Business Problem: Keeping up with a high-velocity vulnerability feed without missing critical findings. Automated ingest + trend reporting transforms raw scanner data into actionable intelligence without manual queue management.
Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Vuln scan lifecycle automation
Key Integrations: Aikido, Google Sheets, GCP
| Playbook | Executions | Link |
|---|---|---|
| Aikido Webhook | 66,224 | event-driven |
| Aikido High/Critical Trend Report | 22 | scheduled |
7. DevSecOps Code Security Review
Description: Every GitHub pull request that generates a Sumo Logic event triggers an automated security review workflow. The playbook parses the PR diff, creates a Jira ticket, appends an AI-generated security analysis as a comment, and evaluates whether the code change introduces security risks. This closes the loop between developer velocity and security review without requiring analyst involvement on every PR.
Business Problem: Security teams cannot manually review every code change at development speed. This use case scales security code review to match engineering throughput.
Category: GRC | Subcategories: DevSecOps compliance, Threat hunting & detection
Key Integrations: GitHub, Jira, Sumo Logic, Node.js (AI parsing)
| Playbook | Executions | Link |
|---|---|---|
| Trigger Github PR Review Action Workflow | 1,283 | event-driven |
| repo_changes | 0 | on-demand |
| JIRA Autostart | 0 | on-demand |
| Entity OSINT | 0 | event-driven |
8. Vendor Risk Management & Contract Monitoring
Description: Two complementary VRM tracks. First, a SecurityScorecard-integrated pipeline manages vendor portfolios by division, runs vendor risk reports, and attaches them to Jira VRM tickets — with an AI review loop for AI-generated vendor assessments. Second, Tropic contract approvals are monitored on a six-hour schedule to surface pending approvals before deadlines.
Business Problem: Vendor risk reviews are time-consuming and often inconsistent. This use case automates portfolio management, report generation, and AI-assisted review, while ensuring procurement contracts don't stall.
Category: GRC | Subcategories: Vendor risk & TPRM, Security metrics & reporting
Key Integrations: SecurityScorecard, Jira, BambooHR, Glean, Tropic, Slack
| Playbook | Executions | Link |
|---|---|---|
| Tropic Request Monitor | 140 | scheduled |
| VRM - AI Review Loop | 11 | event-driven |
| SSR VRM Extract Domain from submitted form | 10 | subflow |
| Bamboo Get Employee Department | 10 | subflow |
| Add vendor to portfolio | 9 | subflow |
| SecurityScorecard Get Reports | 5 | subflow |
| Attach Reports to Jira Issue | 0 | subflow |
| Manage Portfolios | 0 | on-demand |
| Create Portfolios | 0 | on-demand |
9. Access Review (UAR)
Description: A Glean AI-assisted access review pipeline for Aikido and GitHub. The UAR - AI Review Loop workflow triggers on Sumo Logic events, pulls the relevant Jira UAR ticket, queries current application users (Okta), and runs an AI-driven review — generating recommendations and posting them back to Jira. PTO awareness (BambooHR) is built in to avoid sending reviews to employees on leave.
Business Problem: Annual and periodic access reviews are labor-intensive. This use case automates the evidence collection, AI-assisted analysis, and review workflow, reducing reviewer burden while improving consistency.
Category: IAM | Subcategories: Access review & group mgmt, RBAC review & access mgmt
Key Integrations: Jira, Okta, GitHub, Glean, Slack, BambooHR
| Playbook | Executions | Link |
|---|---|---|
| UAR - AI Review Loop | 18 | event-driven |
| Aikido UAR Reject | 0 | on-demand |
| Github UAR | 0 | on-demand |
| Okta User Pull | 0 | subflow |
| UAR Table Pull | 0 | subflow |
| Okta Table Application Pull | 0 | subflow |
| PTO Check | 0 | subflow |
10. PCI Compliance & Regulatory Evidence
Description: A multi-system compliance evidence pipeline centered on A-Scend (the PCI evidence management platform). Jira tickets transition automatically into A-Scend evidence submissions via webhook. Snowflake SQL evidence collection, Confluence quarterly page building, and Jira activity ticket cloning are orchestrated through the MRC Quarterly Orchestrator — producing a fully automated compliance evidence package each quarter. A PCI Bot answers ad-hoc compliance questions via a Glean-backed AI agent.
Business Problem: PCI evidence collection is manual, error-prone, and consumes significant compliance team time each quarter. This use case automates evidence ingestion, quarterly Confluence page generation, and Jira ticket management, compressing multi-day work to minutes.
Category: GRC | Subcategories: PCI & regulatory monitoring, Compliance questionnaire, Security metrics & reporting
Key Integrations: Jira, Snowflake, Confluence, Google Sheets, Glean, A-Scend
| Playbook | Executions | Link |
|---|---|---|
| Jira Transition to Push to A-scend | 255 | event-driven |
| MRC Probe - Jira JQL Custom Search | 18 | on-demand |
| MRC Probe - Get Jira Ticket via mrc_jira | 18 | on-demand |
| MRC Probe - Confluence Page Storage Body | 8 | on-demand |
| MRC Probe Confluence Search | 4 | on-demand |
| MRC Snowflake Evidence | 2 | subflow |
| MRC Quarterly Orchestrator | 0 | on-demand |
| MRC Build Quarterly Confluence Page | 0 | subflow |
| MRC Clone Activity Jira Ticket | 0 | subflow |
| MRC Google Doc Date Scrape | 0 | subflow |
| PBC ticket generator | 0 | on-demand |
| Get PCI Table Data | 0 | subflow |
| Get ASCEND DATA | 0 | subflow |
| PCI Bot Questions | 0 | on-demand |
| Table Balance | 0 | on-demand |
| Get All A-Scend Requests | 0 | on-demand |
| Populate tables: A-scend data by reference ID | 0 | subflow |
| Push Ascend Evidence | 0 | subflow |
| Responsive Trust Center Authorization | 0 | on-demand |
11. DLP & Data Security
Description: Cyera DLP issues are ingested via webhook in real-time and recorded to a Blink table for downstream triage. A backlog seeder imports historical Cyera issues into Jira. A DSAR registration workflow appends new data subject access requests to a Google Sheet for compliance tracking. Glean log access events are monitored and alerted on Slack.
Business Problem: Data exposure findings from Cyera need immediate logging and tracking. Manual DSAR intake creates compliance risk. This use case automates ingestion at both ends of the data governance lifecycle.
Category: GRC | Subcategories: DLP triage & exposure resp, DSAR & privacy automation
Key Integrations: Cyera, Jira, Google Sheets, Slack, Glean
| Playbook | Executions | Link |
|---|---|---|
| Cyera Issues Handling | 63 | event-driven |
| DSAR Table | 0 | on-demand |
| Cyera backlog | 0 | on-demand |
| Glean Log Monitor | 0 | event-driven |
12. Customer Support Automation
Description: A fully automated customer support routing and AI-response system built on top of Jira Service Desk. The 000 - Entrypoint workflow catches every new Jira ticket update via webhook, validates routing criteria, uses Gemini AI to classify the request type, and dispatches to specialized sub-workflows. 001 - Initial Acknowledgement sends an AI-personalized acknowledgement. The 003 - 02 - Missed attack sub-workflow collects structured details about missed bot/attack events via an AI-driven Jira conversation loop. Glean is used to automatically record RFP submissions.
Business Problem: High support ticket volume with repetitive initial triage and acknowledgement tasks. This use case automates the full intake-to-routing pipeline and AI-assisted information gathering, reducing time-to-first-response and freeing analyst capacity for complex cases.
Category: Other | Subcategories: IT helpdesk & ticket routing, Agentic SOC
Key Integrations: Jira, Gemini, Google Sheets, Postgres, Glean, Sumo Logic, Slack
| Playbook | Executions | Link |
|---|---|---|
| 000 - Entrypoint | 437 | event-driven |
| 003 - 02 - Missed attack | 286 | on-demand |
| 001 - Initial Acknowledgement | 92 | on-demand |
| Spike In tickets | 40 | scheduled |
| Glean RFP Recorder | 9 | event-driven |
| jsm-snitch-escalation-agent-details | 1 | event-driven |
| On Snitch Enrichment Flow | 0 | event-driven |
| JSM - List Pending TAM | 0 | on-demand |
| Find related Jira tickets | 0 | on-demand |
| Send Slack message on new DRP ticket creation | 0 | event-driven |
| COPS Report Building | 0 | on-demand |
13. CRM & Lead Intelligence
Description: Salesforce lead records are automatically ICP-qualified via AI on ingest. A Glean AI model retrieves NAICS codes, annual revenue, and industry segments for each new lead and writes the enriched ICP designation back to Salesforce. A daily Account Planning job processes open opportunities to ensure coverage.
Business Problem: Sales team capacity is wasted on manual lead qualification. This use case applies AI scoring immediately on lead creation, enabling instant prioritization of high-fit accounts.
Category: Other | Subcategories: SaaS / IT administration, Customer registry & FinOps auto
Key Integrations: Salesforce, Glean, Google Sheets, OpenAI
| Playbook | Executions | Link |
|---|---|---|
| Persona Matching | 3,443 | event-driven |
| PROD Lead ICP Designation | 2,789 | event-driven |
| Create Account SFDC Workflow v2 | 86 | event-driven |
| Account Planning | 26 | scheduled |
| Fill BPQ Workflow | 0 | on-demand |
14. Security Metrics & Reporting
Description: A set of scheduled reporting workflows that monitor Jira board health, track active and labeled tickets, flag SCR (Security Change Review) backlog items, and deliver daily AI-generated executive security summaries combining Sumo Logic data with Glean intelligence. Cloud license consumption (Wiz) is tracked daily to a Google Sheet.
Business Problem: Security leaders need regular visibility into ticket hygiene, operational metrics, and posture trends without manual report assembly. This use case automates the full metrics pipeline from data collection to Slack delivery.
Category: GRC | Subcategories: Security metrics & reporting
Key Integrations: Jira, Slack, Sumo Logic, Glean, Wiz, Google Sheets, BambooHR
| Playbook | Executions | Link |
|---|---|---|
| Daily Executive Summary | 40 | scheduled |
| JIRA Active Tickets | 40 | scheduled |
| JIRA Labels | 40 | scheduled |
| Check for new SCR Tickets | 40 | scheduled |
| OH JIRA Board Monitor v2 | 29 | scheduled |
| Wiz Get License Usage Data | 40 | scheduled |
| Post Monthly Security Team Report | 0 | on-demand |
15. IT Asset & Endpoint Management (JAMF)
Description: JAMF MDM inventory is queried, transformed, and routed across several IT operations workflows — syncing computer inventory into Snipe-IT nightly, resolving Slack IT-channel requests to JAMF computer records by email or serial number, comparing JAMF inventory against Control D device lists to flag unmanaged devices, and generating on-demand check-in compliance reports for a specific smart group. A Slack slash-command router gates access to this tooling based on IT team group membership.
Business Problem: IT and helpdesk staff need fast, self-service access to endpoint inventory data without direct JAMF console access, and asset records must stay synchronized across JAMF and the Snipe-IT system of record. This suite automates lookups, syncing, and reconciliation that would otherwise require manual console work.
Category: Other | Subcategories: Endpoint hygiene & MDM ops, IT helpdesk & ticket routing
Key Integrations: JAMF, Snipe-IT, Slack, Control D
| Playbook | Executions | Link |
|---|---|---|
| Jamf to Snipe | 49 | scheduled |
| Jamf Slack Router | 20 | event-driven |
| Jamf Lookup by Email | 9 | on-demand |
| ControlDvsJamfcheck | 6 | scheduled |
| Jamf Checkin Report | 4 | on-demand |
| Find computer by email | 0 | on-demand |
| Jamf Lookup by Serial | 0 | on-demand |
16. Documentation Validation & QA Automation
Description: A comprehensive AI + Playwright pipeline that translates HUMAN Security product documentation into executable test cases, grounds them against the live product DOM, executes them end-to-end, and reports pass/fail status. Supporting diagnostic playbooks isolate specific UI behaviors — settings-category clicks, sidebar navigation, invite-user modals, bot-block pages, browser reconnect handling, and login flows — while a caching layer avoids re-deriving confirmed navigation chains on repeat runs.
Business Problem: Product documentation drifts out of sync with the live UI as features ship, and manually re-validating every documented workflow is impractical at HUMAN's release cadence. This use case continuously proves (or disproves) that documented steps still work against the live product, catching documentation debt before customers hit it.
Category: Other | Subcategories: DevOps & release automation
Key Integrations: Playwright (browser automation), Blink AI agents, Blink Tables (confirmed-chain cache)
| Playbook | Executions | Link |
|---|---|---|
| HUMAN-DocVal-Ability-FetchDocPage | 144 | subflow |
| HUMAN-DocVal-Execute-Test-Case | 72 | subflow |
| HUMAN-DocVal-Translate-Doc-To-Test-Case | 65 | on-demand |
| HUMAN-DocVal-Ability-GroundInLiveDOM | 61 | subflow |
| HUMAN-DocVal-Diag-SidebarEnumerate | 24 | on-demand |
| Playwright Blink Docs Smoke Test | 3 | on-demand |
| HUMAN-DocVal-Diagnostic-SettingsClick | 3 | on-demand |
| HUMAN-DocVal-MVP-Add-Application | 0 | on-demand |
| HUMAN-DocVal-NetDiag | 0 | on-demand |
| HUMAN-DocVal-LocalBrowserDiag | 0 | on-demand |
| HUMAN-DocVal-BotBlockDiag | 0 | on-demand |
| HUMAN-DocVal-CaptureBlockScreenshot | 0 | on-demand |
| HUMAN-DocVal-LoginScreenshot | 0 | on-demand |
| HUMAN-DocVal-Diag-InviteModal | 0 | on-demand |
| HUMAN-DocVal-TestCase-InviteUser | 0 | on-demand |
| HUMAN-DocVal-Diag-ReactLoop | 0 | on-demand |
| HUMAN-DocVal-Diag-BrowserReconnect | 0 | on-demand |
17. Workspace & SaaS Administration
Description: Cross-cutting administrative automation for the tools the IT and program teams rely on day to day — a quarterly Slack workspace hygiene sweep that pages through admin APIs to identify and archive inactive channels (with guest and external-share detection safeguards and a Jira review subtask for anything excluded), a general Confluence content search utility, Jira connection health tests, and a lightweight Kanban-based project tracker (with an intake web form) for triaging BlinkOps Builder bugs, requests, and tasks across the MRC Audit, Slack Cleanup, Slack-Jamf, and Tech Docs initiatives.
Business Problem: Running dozens of automations across Slack, Jira, and Confluence requires ongoing administrative upkeep — stale channels accumulate, connections need periodic validation, and a growing automation backlog needs a lightweight tracking system. This use case keeps the underlying SaaS workspace and its own delivery backlog healthy.
Category: Other | Subcategories: SaaS / IT administration, IT helpdesk & ticket routing
Key Integrations: Slack (admin APIs), Jira, Confluence
| Playbook | Executions | Link |
|---|---|---|
| Slack - Quarterly Inactive Channel Cleanup | 13 | on-demand |
| BlinkOps Builder PM Tracker - Refresh Kanban | 9 | scheduled |
| Probe - Guest Reason Fix Retest (read-only) | 7 | on-demand |
| Probe - Verify IT-679 and Cleanup IT-676-678 | 2 | on-demand |
| BlinkOps Builder PM Tracker - Submit Request | 1 | event-driven |
| Confluence Search | 0 | on-demand |
| Jira Connection Functionality Test | 0 | on-demand |
18. Security Awareness Training Compliance (Wizer)
Description: A twice-weekly scheduled workflow cross-references BambooHR's who's-off list against the employee directory and pulls the Wizer security-awareness training master report to identify training gaps. A separate escalation flow queries PCI and Code training records and processes overdue completions. A shared "Is Employee OOO" check prevents nudges from being sent to employees who are out of office.
Business Problem: Security-awareness and PCI training compliance requires continuously cross-referencing HR status against training completion records — manual reconciliation is easy to let slip. This use case automates detection of training gaps while respecting employee PTO.
Category: SOC | Subcategories: Phishing sim & awareness
Key Integrations: Wizer, BambooHR
| Playbook | Executions | Link |
|---|---|---|
| Wizer Flow | 11 | scheduled |
| WizerEscalation | 0 | on-demand |
| Is Employee OOO | 0 | subflow |
Key Observations
Strengths
Deep agentic AI investment. The organization has deployed Blink AI agents across nearly every security domain — CrowdStrike, Wiz, Okta, Sumo Logic, JAMF, Jira, and a dedicated L1 SOC email bot. The "Bot Activate" pattern makes agentic hunting accessible on-demand. The HUMAN Dashboard Agent running every hour across 13 anomaly dimensions is a particularly sophisticated production deployment.
Unique separation monitoring architecture. The employee separation use case is one of the most comprehensive seen in this segment. Running every 30 minutes with parallel Sumo Logic searches across five data planes (file access, outbound email, GitHub, Google Workspace, CrowdStrike USB) per departing employee demonstrates mature insider threat operations. The protected list guard prevents accidental deprovisioning at scale.
Own-product security as a use case. Unusually, Blink is being used to monitor HUMAN Security's own product dashboards (bot detection metrics, block rates, CAPTCHA outcomes). This "drink your own champagne" pattern, running 388 times in the last year, underscores the trust placed in the platform.
High-volume vulnerability management at scale. 66,224 Aikido events processed in 12 months — roughly 180/day — without analyst involvement. Paired with monthly trend reporting to Google Sheets, this represents a fully automated vulnerability intake pipeline.
PCI compliance automation depth. The MRC framework — spanning Snowflake evidence collection, Confluence quarterly page generation, Jira ticket cloning, and A-Scend integration — is a production-grade compliance automation stack, not a prototype.
AI-driven product documentation QA at scale. A 17-playbook suite translates HUMAN Security's own product documentation into Playwright test cases, executes them against the live product, and grounds results in the live DOM — 372 combined executions in its first period. This is an unusually mature application of Blink to internal product-quality assurance, extending the platform beyond traditional security use cases.
Persona Matching is now the highest-volume single playbook in the tenant. At 3,443 executions, the Salesforce Persona Matching workflow (AI-driven LinkedIn title → persona classification) runs more often than any other automation, reinforcing Blink's expanding role in real-time CRM enrichment alongside the existing Lead ICP Designation pipeline.
Gaps & Opportunities
Crowdstrike and Wiz ingestion paths have zero executions. The CM - Wiz Ingestion and CM - Crowdstrike ingestion workflows were built but have not run, suggesting the SIEM-based Sumo Logic path is the sole alert source in production. Enabling native CrowdStrike and Wiz webhook ingest would accelerate alert MTTR and reduce Sumo Logic dependency.
Phishing response has low execution volume relative to infrastructure. The Subflow - Phishing (40) and Subflow - Phishing Gmail (0) flows exist but run infrequently. The Check Point Harmony integration is connected but underutilized — the email remediation path (Restore Email - Harmony TEST) appears to still be in testing.
Access review playbooks built but not yet running. Aikido UAR Reject, Github UAR, and supporting Okta/UAR Table utilities all show zero executions. Only the UAR - AI Review Loop has been activated (18 runs). Completing the UAR pipeline would close a key IAM governance gap.
DLP triage stops at ingestion. Cyera issues are ingested (63 events) and added to a table, but there is no downstream triage, Jira ticket creation, or owner notification automation visible in the active playbooks. The Cyera backlog importer also has zero executions, suggesting the Cyera→Jira pipeline is incomplete.
GCP monitoring playbooks are built but idle. Eight "Invoke GCP …" wrappers (owner grants, dangerous roles, log sink tampering, org policy changes, etc.) all show zero executions. Only Invoke GCP Service Account Key Creation has been activated. Connecting the remaining GCP monitors to scheduled or event-triggered execution would complete the cloud control-plane coverage.
IT self-service and admin health-check tooling is built but not yet in active rotation. Jamf Lookup by Serial, Find computer by email, Confluence Search, and Jira Connection Functionality Test all show zero executions, suggesting several JAMF lookup paths and connection-health probes are staged but not yet driving day-to-day IT workflows.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Logging | Sumo Logic, GCP Log Explorer, BigQuery |
| EDR / Identity | CrowdStrike, Okta, JAMF |
| Cloud Security | Wiz, Aikido, Cyera, GCP |
| Ticketing | Jira (5+ connections), Confluence |
| Collaboration | Slack (multiple connections), Gmail |
| CDN / Edge | Akamai, Fastly |
| Compliance | A-Scend, SecurityScorecard, Snowflake |
| AI / Knowledge | Gemini, Glean (multiple connections), OpenAI |
| CRM / Sales | Salesforce, Gong |
| HRIS | BambooHR |
| Dev | GitHub, Sumo Logic (PR events) |
| Productivity | Google Sheets, Google Drive, Google Docs |
| Endpoint / Asset Mgmt | JAMF, Snipe-IT, Control D |
| QA / Testing | Playwright |
| Security Awareness | Wizer |
E New Integrations (detail) 4 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| humansecurity | jira | sierra_3 | 2026-08-19 |
| humansecurity | jira | sierra_testing_2 | 2026-08-14 |
| humansecurity | jira | sierra_jira_testing | 2026-08-13 |
| humansecurity | slack | archive_bot_testing_only_sierra_grid_sandbox | 2026-08-07 |