01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| IT Helpdesk Automation |
| 3.8% | 15 13 active |
| SOC — Alert Ingestion & Case Management |
| 40.1% | 19 16 active |
| Agentic SOC Investigation | 0 executions | 0.0% | 37 36 active |
| SOC — Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 47 46 active |
| SOC — Phishing Detection & Response | 0 executions | 0.0% | 5 4 active |
| SOC — EDR Containment & Response | 0 executions | 0.0% | 5 4 active |
| Vulnerability Management |
| 0.0% | 11 11 active |
| Shadow IT & Endpoint Coverage |
| 0.0% | 12 12 active |
| Endpoint Device Management & Inventory | 0 executions | 0.0% | 5 5 active |
| IAM — Offboarding & Licensing |
| 0.1% | 13 13 active |
| DLP — Google Drive Exposure Monitoring |
| 0.2% | 2 2 active |
| Financial & Business Operations | 0 executions | 0.0% | 4 4 active |
| Total | 18,217 executions | 100% | 175 166 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
IT Helpdesk automation is the highest-value active use case. The Jira ticket routing stack (Ticket Distributor v2 + WIP v3, 1,209 combined runs) is fully operationalized and eliminates manual triage from the entire helpdesk intake flow. Continuous SLA monitoring (jira find breaches, 168 runs) and calendar-driven queue management (56 automated queue actions) show deep process integration, not just point automation.
SOC infrastructure is comprehensively built and continuously active. Five separate alert sources (Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center ×2, Abnormal Security) are ingesting into a unified case management system on a continuous polling cadence. The enrichment library (47 playbooks) covers every observable type across 10+ intelligence and identity sources. The full agentic investigation stack — Phishing Agent, EDR Agent, Core Investigator — is deployed and ready to run on live cases.
Shadow IT coverage is actively sweeping. The Main - Shadow-IT workflow runs daily, reconciling CrowdStrike, NinjaOne, Jamf, and Rapid7 across ~39 sweeps and automatically enrolling ungoverned devices into NinjaOne. The device SOT pipeline (Build Computer Master List, 41 runs) provides a consistently fresh unified inventory.
DLP monitoring is operational. Google Drive external-sharing scans are running monthly, with per-user file inventories captured automatically — a meaningful risk reduction capability for a geographically distributed workforce.
###
Gaps & Opportunities
Vulnerability management ticketing is built but idle. The Rapid7 alert ingestion (58 runs) is active, but the full lifecycle pipeline — creating Jira tickets for critical vulns, SLA checking, escalation, and Automox remediation — shows 0 executions. Activating this pipeline would close the loop from detection to tracked remediation automatically.
Agentic SOC has zero production executions. The AI investigation layer (Phishing Agent, EDR Agent, Core Investigator, Unusual Login Activity Agent) is fully built with 37 playbooks and deep agent abilities but has not yet processed live cases. With alert ingestion already running at scale, enabling the agentic layer would deliver immediate analyst time savings.
EDR containment playbooks are deployed but unused. CrowdStrike RTR isolation, batch host commands, and remote agent installation are ready but show 0 runs. Integrating these into the active SOC response pipeline would enable automated containment directly from case management alerts.
IAM offboarding coverage is partial. Zoom deprovisioning (40 runs) is automated but the broader offboarding orchestrator — covering AD, Okta, Dropbox, and Zoom in a single coordinated workflow — shows 0 executions. Full offboarding automation would reduce the risk of persistent access after termination.
Microsoft licensing review is built but not scheduled. The multi-tenant license overview pipeline (6 workspaces worth of licensing flows) has 0 executions. Scheduling this monthly would surface redundant licenses and access entitlements automatically.
Integration Ecosystem
LHM operates one of the broadest integration footprints across the Blink customer base, spanning 20+ connected platforms:
| Domain | Integrations |
|---|---|
| ITSM & Ticketing | Jira |
| Endpoint & MDM | CrowdStrike (+ RTR + ThreatGraph), NinjaOne, Jamf, Automox |
| Identity | Azure Active Directory (multi-tenant), Okta |
| Email Security | Microsoft Defender XDR, Microsoft Defender for Endpoint, Abnormal Security, Exchange Online |
| Collaboration | Microsoft Outlook, Microsoft Graph, Google Workspace, Gmail, Zoom, Slack |
| Threat Intelligence | VirusTotal, AbuseIPDB, URLScan.io, Whois |
| Vulnerability | Rapid7 InsightVM |
| HRIS | UKG |
| Finance | BILL, Divvy |
| Cloud | Azure Monitor, AWS CloudTrail (example), GCP (prototype) |
| AI | Glean AI, Blink Agents (AI micro-agents) |
| Other | Apple Business Manager, GitHub, SentinelOne (staged), Wiz (staged) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 2 active | 3 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Mr. Computer User Assignerer | IT-Helpdesk | 2 | 0 | 11,351 |
| 2 | Alert Enrichment Agent | Senior Health POC | 1 | 0 | 41,863 |
| 3 | Agent Blink | Senior Health POC | 0 | 0 | 0 |
| 4 | DRAFT - Action Recommandation Parser | Senior Health POC | 0 | 0 | 0 |
| 5 | LHM Security Investigator | LHM | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| IT-Helpdesk | 2 |
| Senior Health POC | 1 |
| LHM | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Shadow-IT | 0 | 0 |
| 2 | Shadow-IT Coverage | 0 | 0 |
| 3 | Agentic SOC Dashboard | 0 | 0 |
| 4 | Test | 0 | 0 |
| 5 | Jamf Missing Devices | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | sdfsdf | 0 | 0 |
D Full Use Case Analysis 12 use cases | 41,240 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Helpdesk tickets auto-routed & assigned | 734 | Ticket Distributor v2 |
| Helpdesk tickets routed via webhook-driven routing | 475 | WIP Ticket Distributor V3 W/Webhook Trigger |
| Jira SLA monitoring checks executed | 168 | jira find breaches |
| Onboarding & purchase ticket closures auto-captured | 105 | Jira Onboarding/Purchase Request Ticket Closure Webhook |
| Rapid7 vulnerability alerts ingested & processed | 58 | Rapid7 Alerts |
| User Google Drive external-sharing exposures scanned | 52 | Dump Externally Shared Files to Table |
| Helpdesk queue management actions automated (PTO + study time) | 56 | Add and remove from Helpdesk Queue / Automated OOQ for Study Time |
| Zoom user offboarding reconciliation sweeps | 40 | Offboard Zoom User |
| Phishing & email threat scans (Abnormal Security) | 40 | Abnormal Ingest |
| Cross-platform shadow IT device coverage sweeps | 39 | Main - Shadow-IT |
| Missing endpoint device inventory reports generated | 6 | Generate Missing Jamf Devices CSV |
| Loaner laptop check-in tickets auto-created | 6 | Automated Ticket Creation for Loaner laptops |
| Monthly high-severity vulnerability status reports | 1 | Monthly Open High VULN Tickets |
Use Case Summary
| # | Use Case | Category | Playbooks |
|---|---|---|---|
| 1 | IT Helpdesk Automation | Other | 19 |
| 2 | SOC — Alert Ingestion & Case Management | SOC | 22 |
| 3 | Agentic SOC Investigation | SOC | 37 |
| 4 | SOC — Alert Enrichment & IOC Lookup | SOC | 47 |
| 5 | SOC — Phishing Detection & Response | SOC | 5 |
| 6 | SOC — EDR Containment & Response | SOC | 5 |
| 7 | Vulnerability Management | Vulnerability Mgmt | 11 |
| 8 | Shadow IT & Endpoint Coverage | Other | 13 |
| 9 | Endpoint Device Management | Other | 9 |
| 10 | IAM — Offboarding & Licensing | IAM | 15 |
| 11 | DLP — Google Drive Exposure Monitoring | GRC | 2 |
| 12 | Financial & Business Operations | Other | 4 |
| Total | 189 |
Use Cases
1. IT Helpdesk Automation
Description: End-to-end automation of the IT helpdesk ticket lifecycle — from event-driven ingestion and intelligent routing to SLA breach monitoring and dynamic agent queue management. Blink intercepts Jira ticket-created events and routes them to the correct assignment group based on ticket type, company affiliation, and technician availability.
Business problem: IT teams lose significant time manually triaging and distributing inbound Jira tickets. SLA breaches go undetected until escalation. Technician availability changes (PTO, study time) require constant manual queue intervention.
Integrations: Jira, Microsoft Outlook Calendar, Okta, NinjaOne, Jamf, UKG, Python
Category: Other | Subcategory: IT helpdesk & ticket routing
2. SOC — Alert Ingestion & Case Management
Description: Multi-source security alert ingestion pipeline feeding Blink's native Case Management system. Alerts are continuously polled from Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center, and Abnormal Security, then funneled into a unified case management pipeline for deduplication, processing, and triage.
Business problem: Security teams face alert fatigue and fragmentation when alerts arrive from disparate tools with no unified view. Manual ingestion creates lag between detection and response.
Integrations: Microsoft Defender for Endpoint, Microsoft Defender XDR, Google Workspace Alert Center, Gmail, Abnormal Security, Azure Monitor, Wiz, SentinelOne, CrowdStrike, AWS CloudTrail, Blink Case Management
Category: SOC | Subcategory: Case mgmt & SOAR, SIEM & log pipeline monitoring
3. Agentic SOC Investigation
Description: AI-driven investigation layer built on top of the case management pipeline. Autonomous agents — Phishing Agent, EDR Agent, Core Investigator, and Unusual Login Activity Agent — triage and investigate security cases using purpose-built agent abilities that query identity systems, pull enrichment context, run static analysis, and generate investigation conclusions.
Business problem: Tier-1 analysts spend the majority of their time on repetitive investigation steps (pulling user context, checking IOC reputation, reviewing similar cases). Agentic automation reduces mean time to triage by completing these steps automatically.
Integrations: Blink Case Management, Blink Agents (AI micro-agents), Okta, Microsoft Defender XDR, CrowdStrike ThreatGraph, Exchange Online, VirusTotal, system.Table
Category: SOC | Subcategory: Agentic SOC, Case mgmt & SOAR
4. SOC — Alert Enrichment & IOC Lookup
Description: A comprehensive library of enrichment flows that automatically interrogate threat intelligence sources, identity providers, and endpoint platforms to build full observable context for every alert. IP addresses, URLs, file hashes, usernames, domains, and device IDs are enriched from VirusTotal, AbuseIPDB, URLScan.io, Whois, Okta, Azure AD, Google Workspace, GitHub, CrowdStrike, Slack, and Rapid7.
Business problem: Analysts waste 10–20 minutes per alert manually pivoting across tools to collect IOC context. Automated enrichment delivers this context instantly, enabling faster and more consistent decisions.
Integrations: VirusTotal, AbuseIPDB, URLScan.io, Whois, CrowdStrike, CrowdStrike ThreatGraph, Rapid7, Okta, Azure Active Directory, Google Workspace, GitHub, Slack, Exchange Online, Blink Case Management
Category: SOC | Subcategory: Alert enrichment / IOC lookup
5. SOC — Phishing Detection & Response
Description: Automated response playbooks for phishing and malware cases surfaced by the case management pipeline. The phishing response flow retrieves the email from Outlook, inspects headers for KnowBe4 simulation signatures, and routes accordingly. Exchange Online compliance search enables cross-mailbox phishing hunting and optional purge.
Business problem: Responding to phishing reports requires multi-step manual investigation across email, identity, and endpoint platforms. Automation accelerates containment and reduces analyst toil for the highest-volume alert type.
Integrations: Microsoft Outlook, Exchange Online, Blink Case Management, Okta
Category: SOC | Subcategory: Phishing detection & response
| Playbook | Executions (12mo) |
|---|---|
| Response Subflow - Phishing | 0 |
| Response Subflow - Malware | 0 |
| Subflow - Response - Main Router | 0 |
| Response Subflow - Exchange Online Run Compliance Search | 0 |
| New Workflow 1 | 0 |
6. SOC — EDR Containment & Response
Description: CrowdStrike Real-Time Response (RTR) workflows for endpoint containment and agent deployment. Enables isolating a compromised host, batch-commanding a group of endpoints, and remotely installing Automox or NinjaOne agents on CrowdStrike-managed devices without needing direct access.
Business problem: Containment of compromised endpoints requires immediate action. Manual RTR sessions are slow and error-prone under incident conditions. Automated isolation and remediation shorten the attack dwell window.
Integrations: CrowdStrike RTR, Automox, NinjaOne
Category: SOC | Subcategory: EDR containment & response
7. Vulnerability Management
Description: End-to-end vulnerability management pipeline using Rapid7 InsightVM — from alert ingestion and asset data collection through Jira ticket creation, SLA tracking, escalation, and automated remediation via Automox. Includes a monthly executive report on open high-severity vulnerability tickets.
Business problem: Vulnerability backlogs grow when ingestion, ticketing, and SLA tracking are manual. Teams lack visibility into overdue remediation items until SLAs are already breached.
Integrations: Rapid7 InsightVM, Jira, Automox, system.Table
Category: Vulnerability Mgmt | Subcategory: Vuln lifecycle prioritize & ticket, Vuln scan lifecycle automation, CVE lookup & remediation
| Playbook | Executions (12mo) |
|---|---|
| Rapid7 Alerts | 58 |
| Monthly Open High VULN Tickets | 1 |
| Vuln tickets Management | 0 |
| Add Critical vulnerabilities to Jira | 0 |
| Mark Closed Jira Tickets | 0 |
| SLA checker | 0 |
| Nudge Ticket | 0 |
| Escalate Ticket | 0 |
| Ingest Rapid 7 Vulnerabilities | 0 |
| Rapid7 Ingestion Subflow | 0 |
| Remediate With Automox | 0 |
8. Shadow IT & Endpoint Coverage
Description: Daily automated sweep that reconciles device records across CrowdStrike, NinjaOne, Jamf, and Rapid7 to identify managed vs. unmanaged endpoints. Devices present in CrowdStrike but missing from NinjaOne are automatically enrolled. A weekly gap report identifies devices absent from Jamf. A strike system tracks policy-violation incidents per device.
Business problem: Endpoints managed by only one tool create blind spots in patching, configuration enforcement, and vulnerability coverage. Manual cross-tool reconciliation is too slow to keep pace with daily device changes.
Integrations: CrowdStrike, NinjaOne, Jamf, Rapid7 InsightVM, Email
Category: Other | Subcategory: Endpoint hygiene & MDM ops
| Playbook | Executions (12mo) |
|---|---|
| Main - Shadow-IT | 39 |
| Crowdstrike Table Fill | 39 |
| NinjaOne Table Fill | 37 |
| Rapid7 Table Fill | 37 |
| Jamf Table Fill | 32 |
| Generate Missing Jamf Devices CSV | 6 |
| Get Crowdstrike devices | 0 |
| Main - Shadow-IT (dev workspace) | 0 |
| Add Strike | 0 |
| Remove Strike | 0 |
| Get correlated devices | 0 |
| Automox collect devices | 0 |
| Crowdstrike collect devices | 0 |
9. Endpoint Device Management & Inventory
Description: Daily refresh of authoritative device sources of truth (SOT) from NinjaOne and Jamf, unified into a master computer list. Apple Business Manager warranty data is automatically synchronized for all enrolled devices. Azure AD user records are refreshed daily to keep identity and device data in sync.
Business problem: IT and security teams depend on accurate, up-to-date device inventory for support, compliance, and asset tracking. Stale or fragmented records cause missed updates, incorrect assignments, and audit failures.
Integrations: NinjaOne, Jamf, Apple Business Manager, Azure Active Directory
Category: Other | Subcategory: Endpoint hygiene & MDM ops, SaaS / IT administration
10. IAM — Offboarding & Licensing
Description: Automated user lifecycle management covering employee offboarding (Zoom deprovisioning synchronized against Okta), and Microsoft license oversight across multiple Azure AD tenants. License redundancies are identified automatically, and per-connection user licensing tables are populated for review.
Business problem: Manual offboarding leaves deprovisioned users active in downstream SaaS tools. Unreviewed Microsoft licensing wastes budget and creates compliance risk from access that outlasts employment.
Integrations: Okta, Zoom, Azure Active Directory (multiple tenants), Dropbox
Category: IAM | Subcategory: Employee offboarding, Access review & group mgmt, Identity sync & directory mgmt
11. DLP — Google Drive Exposure Monitoring
Description: Monthly automated scan of Google Workspace to identify users with files shared externally. For each flagged user, a detailed inventory of all externally shared Drive files is captured into a Blink table for review and remediation.
Business problem: Overshared Google Drive files are a persistent data leakage risk in distributed organizations. Without automated scanning, exposure goes undetected until a breach or audit.
Integrations: Google Workspace, Google Drive
Category: GRC | Subcategory: DLP triage & exposure resp
| Playbook | Executions (12mo) |
|---|---|
| Dump Externally Shared Files to Table | 52 |
| ist Users With Shared Files From Google Drive - Information | 1 |
12. Financial & Business Operations
Description: Automation supporting financial operations workflows — receipt capture and upload to BILL for expense management, and a media digest report built from Microsoft Graph communications data processed by Glean AI.
Business problem: Manual receipt collection and expense matching is time-consuming and error-prone. Automated capture and upload removes manual steps from the AP workflow.
Integrations: Microsoft Outlook, Microsoft Graph, BILL (AP automation), Glean AI
Category: Other | Subcategory: Financial & fraud operations
| Playbook | Executions (12mo) |
|---|---|
| BILL Receipt Upload Proxy | 0 |
| ITbilling Fetch and Attach Receipt from Email | 0 |
| CisionOne Workflow | 0 |
| Divvy Testing | 0 |
Key Observations
Strengths
IT Helpdesk automation is the highest-value active use case. The Jira ticket routing stack (Ticket Distributor v2 + WIP v3, 1,209 combined runs) is fully operationalized and eliminates manual triage from the entire helpdesk intake flow. Continuous SLA monitoring (jira find breaches, 168 runs) and calendar-driven queue management (56 automated queue actions) show deep process integration, not just point automation.
SOC infrastructure is comprehensively built and continuously active. Five separate alert sources (Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center ×2, Abnormal Security) are ingesting into a unified case management system on a continuous polling cadence. The enrichment library (47 playbooks) covers every observable type across 10+ intelligence and identity sources. The full agentic investigation stack — Phishing Agent, EDR Agent, Core Investigator — is deployed and ready to run on live cases.
Shadow IT coverage is actively sweeping. The Main - Shadow-IT workflow runs daily, reconciling CrowdStrike, NinjaOne, Jamf, and Rapid7 across ~39 sweeps and automatically enrolling ungoverned devices into NinjaOne. The device SOT pipeline (Build Computer Master List, 41 runs) provides a consistently fresh unified inventory.
DLP monitoring is operational. Google Drive external-sharing scans are running monthly, with per-user file inventories captured automatically — a meaningful risk reduction capability for a geographically distributed workforce.
Gaps & Opportunities
Vulnerability management ticketing is built but idle. The Rapid7 alert ingestion (58 runs) is active, but the full lifecycle pipeline — creating Jira tickets for critical vulns, SLA checking, escalation, and Automox remediation — shows 0 executions. Activating this pipeline would close the loop from detection to tracked remediation automatically.
Agentic SOC has zero production executions. The AI investigation layer (Phishing Agent, EDR Agent, Core Investigator, Unusual Login Activity Agent) is fully built with 37 playbooks and deep agent abilities but has not yet processed live cases. With alert ingestion already running at scale, enabling the agentic layer would deliver immediate analyst time savings.
EDR containment playbooks are deployed but unused. CrowdStrike RTR isolation, batch host commands, and remote agent installation are ready but show 0 runs. Integrating these into the active SOC response pipeline would enable automated containment directly from case management alerts.
IAM offboarding coverage is partial. Zoom deprovisioning (40 runs) is automated but the broader offboarding orchestrator — covering AD, Okta, Dropbox, and Zoom in a single coordinated workflow — shows 0 executions. Full offboarding automation would reduce the risk of persistent access after termination.
Microsoft licensing review is built but not scheduled. The multi-tenant license overview pipeline (6 workspaces worth of licensing flows) has 0 executions. Scheduling this monthly would surface redundant licenses and access entitlements automatically.
Integration Ecosystem
LHM operates one of the broadest integration footprints across the Blink customer base, spanning 20+ connected platforms:
| Domain | Integrations |
|---|---|
| ITSM & Ticketing | Jira |
| Endpoint & MDM | CrowdStrike (+ RTR + ThreatGraph), NinjaOne, Jamf, Automox |
| Identity | Azure Active Directory (multi-tenant), Okta |
| Email Security | Microsoft Defender XDR, Microsoft Defender for Endpoint, Abnormal Security, Exchange Online |
| Collaboration | Microsoft Outlook, Microsoft Graph, Google Workspace, Gmail, Zoom, Slack |
| Threat Intelligence | VirusTotal, AbuseIPDB, URLScan.io, Whois |
| Vulnerability | Rapid7 InsightVM |
| HRIS | UKG |
| Finance | BILL, Divvy |
| Cloud | Azure Monitor, AWS CloudTrail (example), GCP (prototype) |
| AI | Glean AI, Blink Agents (AI micro-agents) |
| Other | Apple Business Manager, GitHub, SentinelOne (staged), Wiz (staged) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.