Blink Security Automation — Confidential

Arco: Experts in Safety — Customer Success Report

Generated 2026-08-30 | arco:-experts-in-safety-value-report.md
2026-08-30Report Date
55Total Playbooks
11Unique Workflows (12m)
21,728Actions Automated (12m)
$5,588Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

55
Total playbooks built
all non-deleted workflows
14
Active playbooks
currently enabled
11
Unique workflows executed (12m)
distinct workflows that ran
21,728
Actions automated (12m)
completed action steps
120.7h
Hours saved (12m)
@ 20s per action
$5,588
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1 MFA gap report generated across the full Okta user base - 1 endpoint asset inventory refreshed from Check Point Harmony

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1: Endpoint Security & Threat Event Visibility1 executions
2.5%
6
6 active
Use Case 2: Identity Security & MFA Compliance1 executions
2.5%
2
1 active
Use Case 3: Compliance & eDiscovery0 executions
0.0%
1
1 active
Use Case 4: Web Application Asset Inventory0 executions
0.0%
1
1 active
Use Case 5: IT Service Management0 executions
0.0%
2
2 active
Use Case 6: Communication & Productivity Utilities0 executions
0.0%
2
2 active
Total2 executions100%
14
13 active

Use Case Growth Over Time

46 unique playbooks  |  6 operational use cases  |  40 total executions (12m)  |  2025-11 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Use Case 2: Identity Security & MFA Compliance
Okta Microsoft Teams Check Point Harmony Imperva Freshservice Jira
Use Case 3: Compliance & eDiscovery
Exchange Online Email
Use Case 1: Endpoint Security & Threat Event Visibility
Check Point Harmony Check Point Infinity Events Email
Use Case 4: Web Application Asset Inventory
Imperva Email
Use Case 6: Communication & Productivity Utilities
Microsoft Teams Microsoft Outlook Monday
Use Case 5: IT Service Management
Freshservice Email

04Key Observations

✓  Strengths

Strengths

  • Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
  • Identity hygiene coverage: The MFA
△  Gaps & Growth Opportunities

gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.

  • Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.

Gaps & Opportunities

  • Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
  • No triggered/scheduled automations visible: All playbooks are on_demand with no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive.
  • ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
  • IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
  • Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.

Integration Ecosystem

Integration Playbooks Using It Notes
Check Point Harmony 5 Core detection platform; multiple query and reporting playbooks built
Check Point Infinity Events 1 Log pipeline integration; playbook built but not yet active
Okta 2 MFA auditing active; failed-auth detection in draft
Freshservice 2 ITSM ticketing built but not yet connected to upstream triggers
Microsoft Exchange Online 1 eDiscovery/compliance search capability available
Imperva 1 WAF asset inventory built; not yet running
Microsoft Teams / Outlook 2 Notification testing and inbox management
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 New Agent davidr@blinkops.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
davidr@blinkops.com0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 6 use cases | 40 executions (12m)

Business KPIs

Metric Count Playbook
MFA gap reports generated across Okta user base 1 Report on MFA Gaps in Okta
Endpoint asset inventories refreshed via Check Point Harmony 1 Update Harmony Endpoint Assets Table
In the last 12 months, Blink automated: - 1 MFA gap report generated across the full Okta user base - 1 endpoint asset inventory refreshed from Check Point Harmony

Use Case Summary

Use Case Category Total Playbooks Active (executions > 0)
Endpoint Security & Threat Event Visibility SOC / Other 6 1
Identity Security & MFA Compliance IAM / SOC 2 1
Compliance & eDiscovery GRC 1 0
Web Application Asset Inventory Cloud Security 1 0
IT Service Management Other 2 0
Communication & Productivity Utilities Other 2 0
Total 14 2

Use Cases

Use Case 1: Endpoint Security & Threat Event Visibility

Description: Monitors, queries, and inventories endpoint security data from Check Point Harmony and Check Point Infinity Events. Enables security teams to surface critical events, pull custom data queries, and maintain an up-to-date asset register — all distributed via email for stakeholder visibility.

Business problem solved: Security teams using Check Point struggle to surface actionable endpoint event data and keep asset records current without manual console work. These playbooks automate event querying, asset inventory updates, and reporting distribution.

Integrations: Check Point Harmony, Check Point Infinity Events, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Update Harmony Endpoint Assets Table 1 Other Endpoint hygiene & MDM ops
List Critical Events 0 SOC Alert enrichment / IOC lookup
Query Event with Check Point Harmony and Send Results via Email 0 SOC Alert enrichment / IOC lookup
Check Point Harmony Custom Action and Send Results via Email 0 SOC Alert enrichment / IOC lookup
Create a Check Point Harmony Dashboard 0 SOC SIEM & log pipeline monitoring
List Event Logs Results with Check Point Infinity Events and Send Results via Email 0 SOC SIEM & log pipeline monitoring

Use Case 2: Identity Security & MFA Compliance

Description: Audits the Okta identity environment for MFA gaps across the user population and monitors Okta logs for failed authentication patterns. Surfaces identity hygiene gaps before they become exploitable weaknesses.

Business problem solved: Manually reviewing MFA enrollment status and authentication anomalies across a large Okta directory is time-consuming and error-prone. These playbooks automate MFA gap detection and failed-login log analysis to give the security team continuous visibility without console-level access to Okta reports.

Integrations: Okta

Playbook Executions (12 mo) Category Subcategory
Report on MFA Gaps in Okta 1 IAM RBAC review & access mgmt
New Workflow 0 SOC Identity threat response

Use Case 3: Compliance & eDiscovery

Description: Automates the creation of compliance content searches in Microsoft Exchange Online and delivers results to designated stakeholders via email.

Business problem solved: eDiscovery and compliance search requests typically require specialized admin access to Exchange Online and manual report compilation. This playbook operationalizes the request-to-result workflow end-to-end.

Integrations: Microsoft Exchange Online, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Create Compliance Search with Exchange Online and Send Results via Email 0 GRC Compliance questionnaire, DLP triage & exposure resp

Use Case 4: Web Application Asset Inventory

Description: Retrieves the full list of sites protected by Imperva and distributes the inventory via email for asset tracking and coverage reviews.

Business problem solved: Keeping an accurate inventory of web assets under WAF/CDN protection requires manual pulls from Imperva. This playbook automates site enumeration and routes results to the appropriate team.

Integrations: Imperva, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Get Sites with Imperva and Send Results via Email 0 Cloud Security Cloud asset coverage & inventory

Use Case 5: IT Service Management

Description: Automates ticket creation in Freshservice and provides asset-level reporting from the Freshservice CMDB. Bridges security operations with the IT service desk.

Business problem solved: Security-driven service requests — such as device remediation or access changes — require manual ticket creation and cross-system data pulls. These playbooks connect security workflows to the ITSM layer.

Integrations: Freshservice, HTTP

Playbook Executions (12 mo) Category Subcategory
Create Ticket with Freshservice and Send Results via Email 0 Other IT helpdesk & ticket routing
FS Assets 0 Other IT helpdesk & ticket routing

Use Case 6: Communication & Productivity Utilities

Description: Miscellaneous operational playbooks for testing notification channels and managing email-based data workflows. Includes a Microsoft Teams notification test and an Outlook-based unsubscribe email sorter.

Business problem solved: Validating alerting pipelines and triaging inbox data are recurring operational tasks. These playbooks were built to test integrations or handle one-off data-wrangling needs.

Integrations: Microsoft Teams, Microsoft Outlook

Playbook Executions (12 mo) Category Subcategory
Teams Test 0 Other SaaS / IT administration
Go into Monday and Sort Some Data 0 Other SaaS / IT administration

Key Observations

Strengths

  • Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
  • Identity hygiene coverage: The MFA gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.
  • Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.

Gaps & Opportunities

  • Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
  • No triggered/scheduled automations visible: All playbooks are on_demand with no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive.
  • ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
  • IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
  • Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.

Integration Ecosystem

Integration Playbooks Using It Notes
Check Point Harmony 5 Core detection platform; multiple query and reporting playbooks built
Check Point Infinity Events 1 Log pipeline integration; playbook built but not yet active
Okta 2 MFA auditing active; failed-auth detection in draft
Freshservice 2 ITSM ticketing built but not yet connected to upstream triggers
Microsoft Exchange Online 1 eDiscovery/compliance search capability available
Imperva 1 WAF asset inventory built; not yet running
Microsoft Teams / Outlook 2 Notification testing and inbox management

1. Business KPIs — Last 12 Months

Metric Count Playbook
MFA gap reports generated across Okta user base 1 Report on MFA Gaps in Okta
Endpoint asset inventories refreshed via Check Point Harmony 1 Update Harmony Endpoint Assets Table
In the last 12 months, Blink automated: - 1 MFA gap report generated across the full Okta user base - 1 endpoint asset inventory refreshed from Check Point Harmony

2. Use Case Summary

Use Case Category Total Playbooks Active (executions > 0)
Endpoint Security & Threat Event Visibility SOC / Other 6 1
Identity Security & MFA Compliance IAM / SOC 2 1
Compliance & eDiscovery GRC 1 0
Web Application Asset Inventory Cloud Security 1 0
IT Service Management Other 2 0
Communication & Productivity Utilities Other 2 0
Total 14 2

3. Use Cases

Use Case 1: Endpoint Security & Threat Event Visibility

Description: Monitors, queries, and inventories endpoint security data from Check Point Harmony and Check Point Infinity Events. Enables security teams to surface critical events, pull custom data queries, and maintain an up-to-date asset register — all distributed via email for stakeholder visibility.

Business problem solved: Security teams using Check Point struggle to surface actionable endpoint event data and keep asset records current without manual console work. These playbooks automate event querying, asset inventory updates, and reporting distribution.

Integrations: Check Point Harmony, Check Point Infinity Events, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Update Harmony Endpoint Assets Table 1 Other Endpoint hygiene & MDM ops
List Critical Events 0 SOC Alert enrichment / IOC lookup
Query Event with Check Point Harmony and Send Results via Email 0 SOC Alert enrichment / IOC lookup
Check Point Harmony Custom Action and Send Results via Email 0 SOC Alert enrichment / IOC lookup
Create a Check Point Harmony Dashboard 0 SOC SIEM & log pipeline monitoring
List Event Logs Results with Check Point Infinity Events and Send Results via Email 0 SOC SIEM & log pipeline monitoring

Use Case 2: Identity Security & MFA Compliance

Description: Audits the Okta identity environment for MFA gaps across the user population and monitors Okta logs for failed authentication patterns. Surfaces identity hygiene gaps before they become exploitable weaknesses.

Business problem solved: Manually reviewing MFA enrollment status and authentication anomalies across a large Okta directory is time-consuming and error-prone. These playbooks automate MFA gap detection and failed-login log analysis to give the security team continuous visibility without console-level access to Okta reports.

Integrations: Okta

Playbook Executions (12 mo) Category Subcategory
Report on MFA Gaps in Okta 1 IAM RBAC review & access mgmt
New Workflow 0 SOC Identity threat response

Use Case 3: Compliance & eDiscovery

Description: Automates the creation of compliance content searches in Microsoft Exchange Online and delivers results to designated stakeholders via email.

Business problem solved: eDiscovery and compliance search requests typically require specialized admin access to Exchange Online and manual report compilation. This playbook operationalizes the request-to-result workflow end-to-end.

Integrations: Microsoft Exchange Online, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Create Compliance Search with Exchange Online and Send Results via Email 0 GRC Compliance questionnaire, DLP triage & exposure resp

Use Case 4: Web Application Asset Inventory

Description: Retrieves the full list of sites protected by Imperva and distributes the inventory via email for asset tracking and coverage reviews.

Business problem solved: Keeping an accurate inventory of web assets under WAF/CDN protection requires manual pulls from Imperva. This playbook automates site enumeration and routes results to the appropriate team.

Integrations: Imperva, Email (Blink core)

Playbook Executions (12 mo) Category Subcategory
Get Sites with Imperva and Send Results via Email 0 Cloud Security Cloud asset coverage & inventory

Use Case 5: IT Service Management

Description: Automates ticket creation in Freshservice and provides asset-level reporting from the Freshservice CMDB. Bridges security operations with the IT service desk.

Business problem solved: Security-driven service requests — such as device remediation or access changes — require manual ticket creation and cross-system data pulls. These playbooks connect security workflows to the ITSM layer.

Integrations: Freshservice, HTTP

Playbook Executions (12 mo) Category Subcategory
Create Ticket with Freshservice and Send Results via Email 0 Other IT helpdesk & ticket routing
FS Assets 0 Other IT helpdesk & ticket routing

Use Case 6: Communication & Productivity Utilities

Description: Miscellaneous operational playbooks for testing notification channels and managing email-based data workflows. Includes a Microsoft Teams notification test and an Outlook-based unsubscribe email sorter.

Business problem solved: Validating alerting pipelines and triaging inbox data are recurring operational tasks. These playbooks were built to test integrations or handle one-off data-wrangling needs.

Integrations: Microsoft Teams, Microsoft Outlook

Playbook Executions (12 mo) Category Subcategory
Teams Test 0 Other SaaS / IT administration
Go into Monday and Sort Some Data 0 Other SaaS / IT administration

4. Key Observations

Strengths

  • Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
  • Identity hygiene coverage: The MFA gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.
  • Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.

Gaps & Opportunities

  • Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
  • No triggered/scheduled automations visible: All playbooks are on_demand with no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive.
  • ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
  • IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
  • Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.

Integration Ecosystem

Integration Playbooks Using It Notes
Check Point Harmony 5 Core detection platform; multiple query and reporting playbooks built
Check Point Infinity Events 1 Log pipeline integration; playbook built but not yet active
Okta 2 MFA auditing active; failed-auth detection in draft
Freshservice 2 ITSM ticketing built but not yet connected to upstream triggers
Microsoft Exchange Online 1 eDiscovery/compliance search capability available
Imperva 1 WAF asset inventory built; not yet running
Microsoft Teams / Outlook 2 Notification testing and inbox management
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Arco: Experts in Safety okta lewis_okta 2026-08-11