01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1: Endpoint Security & Threat Event Visibility | 1 executions | 2.5% | 6 6 active |
| Use Case 2: Identity Security & MFA Compliance | 1 executions | 2.5% | 2 1 active |
| Use Case 3: Compliance & eDiscovery | 0 executions | 0.0% | 1 1 active |
| Use Case 4: Web Application Asset Inventory | 0 executions | 0.0% | 1 1 active |
| Use Case 5: IT Service Management | 0 executions | 0.0% | 2 2 active |
| Use Case 6: Communication & Productivity Utilities | 0 executions | 0.0% | 2 2 active |
| Total | 2 executions | 100% | 14 13 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
- Identity hygiene coverage: The MFA
gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.
- Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.
Gaps & Opportunities
- Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
- No triggered/scheduled automations visible: All playbooks are
on_demandwith no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive. - ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
- IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
- Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.
Integration Ecosystem
| Integration | Playbooks Using It | Notes |
|---|---|---|
| Check Point Harmony | 5 | Core detection platform; multiple query and reporting playbooks built |
| Check Point Infinity Events | 1 | Log pipeline integration; playbook built but not yet active |
| Okta | 2 | MFA auditing active; failed-auth detection in draft |
| Freshservice | 2 | ITSM ticketing built but not yet connected to upstream triggers |
| Microsoft Exchange Online | 1 | eDiscovery/compliance search capability available |
| Imperva | 1 | WAF asset inventory built; not yet running |
| Microsoft Teams / Outlook | 2 | Notification testing and inbox management |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | New Agent | davidr@blinkops.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| davidr@blinkops.com | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 6 use cases | 40 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| MFA gap reports generated across Okta user base | 1 | Report on MFA Gaps in Okta |
| Endpoint asset inventories refreshed via Check Point Harmony | 1 | Update Harmony Endpoint Assets Table |
Use Case Summary
| Use Case | Category | Total Playbooks | Active (executions > 0) |
|---|---|---|---|
| Endpoint Security & Threat Event Visibility | SOC / Other | 6 | 1 |
| Identity Security & MFA Compliance | IAM / SOC | 2 | 1 |
| Compliance & eDiscovery | GRC | 1 | 0 |
| Web Application Asset Inventory | Cloud Security | 1 | 0 |
| IT Service Management | Other | 2 | 0 |
| Communication & Productivity Utilities | Other | 2 | 0 |
| Total | 14 | 2 |
Use Cases
Use Case 1: Endpoint Security & Threat Event Visibility
Description: Monitors, queries, and inventories endpoint security data from Check Point Harmony and Check Point Infinity Events. Enables security teams to surface critical events, pull custom data queries, and maintain an up-to-date asset register — all distributed via email for stakeholder visibility.
Business problem solved: Security teams using Check Point struggle to surface actionable endpoint event data and keep asset records current without manual console work. These playbooks automate event querying, asset inventory updates, and reporting distribution.
Integrations: Check Point Harmony, Check Point Infinity Events, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Update Harmony Endpoint Assets Table | 1 | Other | Endpoint hygiene & MDM ops |
| List Critical Events | 0 | SOC | Alert enrichment / IOC lookup |
| Query Event with Check Point Harmony and Send Results via Email | 0 | SOC | Alert enrichment / IOC lookup |
| Check Point Harmony Custom Action and Send Results via Email | 0 | SOC | Alert enrichment / IOC lookup |
| Create a Check Point Harmony Dashboard | 0 | SOC | SIEM & log pipeline monitoring |
| List Event Logs Results with Check Point Infinity Events and Send Results via Email | 0 | SOC | SIEM & log pipeline monitoring |
Use Case 2: Identity Security & MFA Compliance
Description: Audits the Okta identity environment for MFA gaps across the user population and monitors Okta logs for failed authentication patterns. Surfaces identity hygiene gaps before they become exploitable weaknesses.
Business problem solved: Manually reviewing MFA enrollment status and authentication anomalies across a large Okta directory is time-consuming and error-prone. These playbooks automate MFA gap detection and failed-login log analysis to give the security team continuous visibility without console-level access to Okta reports.
Integrations: Okta
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Report on MFA Gaps in Okta | 1 | IAM | RBAC review & access mgmt |
| New Workflow | 0 | SOC | Identity threat response |
Use Case 3: Compliance & eDiscovery
Description: Automates the creation of compliance content searches in Microsoft Exchange Online and delivers results to designated stakeholders via email.
Business problem solved: eDiscovery and compliance search requests typically require specialized admin access to Exchange Online and manual report compilation. This playbook operationalizes the request-to-result workflow end-to-end.
Integrations: Microsoft Exchange Online, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Create Compliance Search with Exchange Online and Send Results via Email | 0 | GRC | Compliance questionnaire, DLP triage & exposure resp |
Use Case 4: Web Application Asset Inventory
Description: Retrieves the full list of sites protected by Imperva and distributes the inventory via email for asset tracking and coverage reviews.
Business problem solved: Keeping an accurate inventory of web assets under WAF/CDN protection requires manual pulls from Imperva. This playbook automates site enumeration and routes results to the appropriate team.
Integrations: Imperva, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Get Sites with Imperva and Send Results via Email | 0 | Cloud Security | Cloud asset coverage & inventory |
Use Case 5: IT Service Management
Description: Automates ticket creation in Freshservice and provides asset-level reporting from the Freshservice CMDB. Bridges security operations with the IT service desk.
Business problem solved: Security-driven service requests — such as device remediation or access changes — require manual ticket creation and cross-system data pulls. These playbooks connect security workflows to the ITSM layer.
Integrations: Freshservice, HTTP
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Create Ticket with Freshservice and Send Results via Email | 0 | Other | IT helpdesk & ticket routing |
| FS Assets | 0 | Other | IT helpdesk & ticket routing |
Use Case 6: Communication & Productivity Utilities
Description: Miscellaneous operational playbooks for testing notification channels and managing email-based data workflows. Includes a Microsoft Teams notification test and an Outlook-based unsubscribe email sorter.
Business problem solved: Validating alerting pipelines and triaging inbox data are recurring operational tasks. These playbooks were built to test integrations or handle one-off data-wrangling needs.
Integrations: Microsoft Teams, Microsoft Outlook
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Teams Test | 0 | Other | SaaS / IT administration |
| Go into Monday and Sort Some Data | 0 | Other | SaaS / IT administration |
Key Observations
Strengths
- Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
- Identity hygiene coverage: The MFA gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.
- Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.
Gaps & Opportunities
- Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
- No triggered/scheduled automations visible: All playbooks are
on_demandwith no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive. - ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
- IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
- Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.
Integration Ecosystem
| Integration | Playbooks Using It | Notes |
|---|---|---|
| Check Point Harmony | 5 | Core detection platform; multiple query and reporting playbooks built |
| Check Point Infinity Events | 1 | Log pipeline integration; playbook built but not yet active |
| Okta | 2 | MFA auditing active; failed-auth detection in draft |
| Freshservice | 2 | ITSM ticketing built but not yet connected to upstream triggers |
| Microsoft Exchange Online | 1 | eDiscovery/compliance search capability available |
| Imperva | 1 | WAF asset inventory built; not yet running |
| Microsoft Teams / Outlook | 2 | Notification testing and inbox management |
1. Business KPIs — Last 12 Months
| Metric | Count | Playbook |
|---|---|---|
| MFA gap reports generated across Okta user base | 1 | Report on MFA Gaps in Okta |
| Endpoint asset inventories refreshed via Check Point Harmony | 1 | Update Harmony Endpoint Assets Table |
2. Use Case Summary
| Use Case | Category | Total Playbooks | Active (executions > 0) |
|---|---|---|---|
| Endpoint Security & Threat Event Visibility | SOC / Other | 6 | 1 |
| Identity Security & MFA Compliance | IAM / SOC | 2 | 1 |
| Compliance & eDiscovery | GRC | 1 | 0 |
| Web Application Asset Inventory | Cloud Security | 1 | 0 |
| IT Service Management | Other | 2 | 0 |
| Communication & Productivity Utilities | Other | 2 | 0 |
| Total | 14 | 2 |
3. Use Cases
Use Case 1: Endpoint Security & Threat Event Visibility
Description: Monitors, queries, and inventories endpoint security data from Check Point Harmony and Check Point Infinity Events. Enables security teams to surface critical events, pull custom data queries, and maintain an up-to-date asset register — all distributed via email for stakeholder visibility.
Business problem solved: Security teams using Check Point struggle to surface actionable endpoint event data and keep asset records current without manual console work. These playbooks automate event querying, asset inventory updates, and reporting distribution.
Integrations: Check Point Harmony, Check Point Infinity Events, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Update Harmony Endpoint Assets Table | 1 | Other | Endpoint hygiene & MDM ops |
| List Critical Events | 0 | SOC | Alert enrichment / IOC lookup |
| Query Event with Check Point Harmony and Send Results via Email | 0 | SOC | Alert enrichment / IOC lookup |
| Check Point Harmony Custom Action and Send Results via Email | 0 | SOC | Alert enrichment / IOC lookup |
| Create a Check Point Harmony Dashboard | 0 | SOC | SIEM & log pipeline monitoring |
| List Event Logs Results with Check Point Infinity Events and Send Results via Email | 0 | SOC | SIEM & log pipeline monitoring |
Use Case 2: Identity Security & MFA Compliance
Description: Audits the Okta identity environment for MFA gaps across the user population and monitors Okta logs for failed authentication patterns. Surfaces identity hygiene gaps before they become exploitable weaknesses.
Business problem solved: Manually reviewing MFA enrollment status and authentication anomalies across a large Okta directory is time-consuming and error-prone. These playbooks automate MFA gap detection and failed-login log analysis to give the security team continuous visibility without console-level access to Okta reports.
Integrations: Okta
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Report on MFA Gaps in Okta | 1 | IAM | RBAC review & access mgmt |
| New Workflow | 0 | SOC | Identity threat response |
Use Case 3: Compliance & eDiscovery
Description: Automates the creation of compliance content searches in Microsoft Exchange Online and delivers results to designated stakeholders via email.
Business problem solved: eDiscovery and compliance search requests typically require specialized admin access to Exchange Online and manual report compilation. This playbook operationalizes the request-to-result workflow end-to-end.
Integrations: Microsoft Exchange Online, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Create Compliance Search with Exchange Online and Send Results via Email | 0 | GRC | Compliance questionnaire, DLP triage & exposure resp |
Use Case 4: Web Application Asset Inventory
Description: Retrieves the full list of sites protected by Imperva and distributes the inventory via email for asset tracking and coverage reviews.
Business problem solved: Keeping an accurate inventory of web assets under WAF/CDN protection requires manual pulls from Imperva. This playbook automates site enumeration and routes results to the appropriate team.
Integrations: Imperva, Email (Blink core)
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Get Sites with Imperva and Send Results via Email | 0 | Cloud Security | Cloud asset coverage & inventory |
Use Case 5: IT Service Management
Description: Automates ticket creation in Freshservice and provides asset-level reporting from the Freshservice CMDB. Bridges security operations with the IT service desk.
Business problem solved: Security-driven service requests — such as device remediation or access changes — require manual ticket creation and cross-system data pulls. These playbooks connect security workflows to the ITSM layer.
Integrations: Freshservice, HTTP
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Create Ticket with Freshservice and Send Results via Email | 0 | Other | IT helpdesk & ticket routing |
| FS Assets | 0 | Other | IT helpdesk & ticket routing |
Use Case 6: Communication & Productivity Utilities
Description: Miscellaneous operational playbooks for testing notification channels and managing email-based data workflows. Includes a Microsoft Teams notification test and an Outlook-based unsubscribe email sorter.
Business problem solved: Validating alerting pipelines and triaging inbox data are recurring operational tasks. These playbooks were built to test integrations or handle one-off data-wrangling needs.
Integrations: Microsoft Teams, Microsoft Outlook
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Teams Test | 0 | Other | SaaS / IT administration |
| Go into Monday and Sort Some Data | 0 | Other | SaaS / IT administration |
4. Key Observations
Strengths
- Check Point Harmony depth: The largest cluster of playbooks (6 out of 14) is built around Check Point Harmony and Infinity Events, reflecting a primary security platform investment. The asset table update playbook is already active, providing a foundation for broader event-driven automation.
- Identity hygiene coverage: The MFA gap report in Okta is actively running, indicating that the team is using Blink for ongoing IAM compliance visibility — a high-value, recurring use case.
- Broad integration footprint: The tenant has connected 7 distinct platforms (Okta, Check Point Harmony, Check Point Infinity Events, Imperva, Freshservice, Microsoft Exchange Online, Microsoft Teams/Outlook), showing infrastructure readiness for deeper automation across multiple domains.
Gaps & Opportunities
- Low activation rate: Only 2 of 14 playbooks (14%) have run in the last 12 months. The majority of the library has been built but not operationalized. Converting even 5–6 of the dormant playbooks to scheduled or trigger-based runs would meaningfully expand automated coverage.
- No triggered/scheduled automations visible: All playbooks are
on_demandwith no event-driven or scheduled triggers apparent in the YAML. Introducing cron or webhook-based triggers — especially for event querying (Check Point) and MFA auditing (Okta) — would shift the program from reactive to proactive. - ITSM integration underutilized: The Freshservice playbooks have zero executions. Connecting security event workflows (e.g., a critical Check Point event → auto-create Freshservice ticket) would close the loop between detection and response tracking.
- IAM threat detection in draft: The Okta failed-authentication monitoring playbook ("New Workflow") has never run and lacks a production-grade name, suggesting it was prototyped but not productionized. Formalizing this as a scheduled or event-triggered detection workflow would add meaningful identity threat visibility.
- Imperva asset coverage unvalidated: The Imperva site inventory playbook has not run, leaving web asset visibility to manual processes. A scheduled weekly pull would give the team a low-effort, always-current asset register.
Integration Ecosystem
| Integration | Playbooks Using It | Notes |
|---|---|---|
| Check Point Harmony | 5 | Core detection platform; multiple query and reporting playbooks built |
| Check Point Infinity Events | 1 | Log pipeline integration; playbook built but not yet active |
| Okta | 2 | MFA auditing active; failed-auth detection in draft |
| Freshservice | 2 | ITSM ticketing built but not yet connected to upstream triggers |
| Microsoft Exchange Online | 1 | eDiscovery/compliance search capability available |
| Imperva | 1 | WAF asset inventory built; not yet running |
| Microsoft Teams / Outlook | 2 | Notification testing and inbox management |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Arco: Experts in Safety | okta | lewis_okta | 2026-08-11 |