Blink Security Automation — Confidential

LHM — Customer Success Report

Generated 2026-08-30 | lhm-value-report.md
2026-08-30Report Date
441Total Playbooks
61Unique Workflows (12m)
5,433,398Actions Automated (12m)
$1,397,479Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

441
Total playbooks built
all non-deleted workflows
192
Active playbooks
currently enabled
61
Unique workflows executed (12m)
distinct workflows that ran
5,433,398
Actions automated (12m)
completed action steps
30,185.5h
Hours saved (12m)
@ 20s per action
$1,397,479
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
2
Active AI agents
of 26 total
3
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1,209 helpdesk tickets routed and assigned without human triage - 168 Jira SLA compliance monitoring cycles executed automatically - 105 ticket lifecycle events captured and closed via automation - 58 Rapid7 vulnerability alerts ingested and triaged - 56 helpdesk queue management actions automated (PTO coverage + study time) - 52 Google Drive external file-sharing exposure scans completed per user - 40 Zoom user offboarding reconciliations run automatically - 39 cross-platform shadow IT device coverage sweeps completed - 6 missing endpoint device inventory reports generated and emailed - 6 loaner laptop check-in tickets automatically created

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
IT Helpdesk Automation
  • 734Helpdesk tickets auto-routed & assigned
  • 475Helpdesk tickets routed via webhook-driven routing
  • 168Jira SLA monitoring checks executed
3.8%
15
13 active
SOC — Alert Ingestion & Case Management
  • 40Phishing & email threat scans (Abnormal Security)
40.1%
19
16 active
Agentic SOC Investigation0 executions
0.0%
37
36 active
SOC — Alert Enrichment & IOC Lookup0 executions
0.0%
47
46 active
SOC — Phishing Detection & Response0 executions
0.0%
5
4 active
SOC — EDR Containment & Response0 executions
0.0%
5
4 active
Vulnerability Management
  • 58Rapid7 vulnerability alerts ingested & processed
  • 1Monthly high-severity vulnerability status reports
0.0%
11
11 active
Shadow IT & Endpoint Coverage
  • 39Cross-platform shadow IT device coverage sweeps
  • 6Missing endpoint device inventory reports generated
0.0%
12
12 active
Endpoint Device Management & Inventory0 executions
0.0%
5
5 active
IAM — Offboarding & Licensing
  • 40Zoom user offboarding reconciliation sweeps
0.1%
13
13 active
DLP — Google Drive Exposure Monitoring
  • 52User Google Drive external-sharing exposures scanned
0.2%
2
2 active
Financial & Business Operations0 executions
0.0%
4
4 active
Total18,217 executions100%
175
166 active

Use Case Growth Over Time

352 unique playbooks  |  12 operational use cases  |  41,240 total executions (12m)  |  2023-10 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Vulnerability Management
Automox Microsoft Teams Jira Rapid7 InsightVM Cloud
Shadow IT & Endpoint Coverage
Automox CrowdStrike Rapid7 InsightVM Cloud NinjaOne Jamf Email
IAM — Offboarding & Licensing
Azure Active Directory Okta Zoom Slack Dropbox Business Email
IT Helpdesk Automation
Jira Microsoft Outlook Google Workspace Okta Glean Jamf Email Slack OneDrive
SOC — EDR Containment & Response
CrowdStrike Automox NinjaOne
DLP — Google Drive Exposure Monitoring
Google Workspace Google Drive
SOC — Phishing Detection & Response
Zoom Microsoft Outlook Jira Asset Panda Google Workspace Okta Email Exchange Online Slack
Endpoint Device Management & Inventory
Google Workspace NinjaOne Microsoft Entra ID Jamf Apple Business Manager
SOC — Alert Ingestion & Case Management
CrowdStrike Abnormal Microsoft Defender For Endpoints SentinelOne Microsoft Defender XDR Microsoft Graph
SOC — Alert Enrichment & IOC Lookup
Agents CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan Email GitHub Slack Rapid7
Agentic SOC Investigation
Agents Okta VirusTotal Microsoft Outlook Microsoft Defender XDR
Financial & Business Operations
Microsoft Outlook Microsoft Graph Glean

04Key Observations

✓  Strengths

Strengths

IT Helpdesk automation is the highest-value active use case. The Jira ticket routing stack (Ticket Distributor v2 + WIP v3, 1,209 combined runs) is fully operationalized and eliminates manual triage from the entire helpdesk intake flow. Continuous SLA monitoring (jira find breaches, 168 runs) and calendar-driven queue management (56 automated queue actions) show deep process integration, not just point automation.

SOC infrastructure is comprehensively built and continuously active. Five separate alert sources (Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center ×2, Abnormal Security) are ingesting into a unified case management system on a continuous polling cadence. The enrichment library (47 playbooks) covers every observable type across 10+ intelligence and identity sources. The full agentic investigation stack — Phishing Agent, EDR Agent, Core Investigator — is deployed and ready to run on live cases.

Shadow IT coverage is actively sweeping. The Main - Shadow-IT workflow runs daily, reconciling CrowdStrike, NinjaOne, Jamf, and Rapid7 across ~39 sweeps and automatically enrolling ungoverned devices into NinjaOne. The device SOT pipeline (Build Computer Master List, 41 runs) provides a consistently fresh unified inventory.

DLP monitoring is operational. Google Drive external-sharing scans are running monthly, with per-user file inventories captured automatically — a meaningful risk reduction capability for a geographically distributed workforce.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Vulnerability management ticketing is built but idle. The Rapid7 alert ingestion (58 runs) is active, but the full lifecycle pipeline — creating Jira tickets for critical vulns, SLA checking, escalation, and Automox remediation — shows 0 executions. Activating this pipeline would close the loop from detection to tracked remediation automatically.

Agentic SOC has zero production executions. The AI investigation layer (Phishing Agent, EDR Agent, Core Investigator, Unusual Login Activity Agent) is fully built with 37 playbooks and deep agent abilities but has not yet processed live cases. With alert ingestion already running at scale, enabling the agentic layer would deliver immediate analyst time savings.

EDR containment playbooks are deployed but unused. CrowdStrike RTR isolation, batch host commands, and remote agent installation are ready but show 0 runs. Integrating these into the active SOC response pipeline would enable automated containment directly from case management alerts.

IAM offboarding coverage is partial. Zoom deprovisioning (40 runs) is automated but the broader offboarding orchestrator — covering AD, Okta, Dropbox, and Zoom in a single coordinated workflow — shows 0 executions. Full offboarding automation would reduce the risk of persistent access after termination.

Microsoft licensing review is built but not scheduled. The multi-tenant license overview pipeline (6 workspaces worth of licensing flows) has 0 executions. Scheduling this monthly would surface redundant licenses and access entitlements automatically.

Integration Ecosystem

LHM operates one of the broadest integration footprints across the Blink customer base, spanning 20+ connected platforms:

Domain Integrations
ITSM & Ticketing Jira
Endpoint & MDM CrowdStrike (+ RTR + ThreatGraph), NinjaOne, Jamf, Automox
Identity Azure Active Directory (multi-tenant), Okta
Email Security Microsoft Defender XDR, Microsoft Defender for Endpoint, Abnormal Security, Exchange Online
Collaboration Microsoft Outlook, Microsoft Graph, Google Workspace, Gmail, Zoom, Slack
Threat Intelligence VirusTotal, AbuseIPDB, URLScan.io, Whois
Vulnerability Rapid7 InsightVM
HRIS UKG
Finance BILL, Divvy
Cloud Azure Monitor, AWS CloudTrail (example), GCP (prototype)
AI Glean AI, Blink Agents (AI micro-agents)
Other Apple Business Manager, GitHub, SentinelOne (staged), Wiz (staged)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 2 active | 3 tasks (12m)

AI Agents

Active Agents
2
of 26 total
Tasks Executed (12m)
3
0 in last 30d
Data Usage (12m)
53,214
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Mr. Computer User Assignerer IT-Helpdesk 2 0 11,351
2 Alert Enrichment Agent Senior Health POC 1 0 41,863
3 Agent Blink Senior Health POC 0 0 0
4 DRAFT - Action Recommandation Parser Senior Health POC 0 0 0
5 LHM Security Investigator LHM 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
IT-Helpdesk2
Senior Health POC1
LHM0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
8
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Shadow-IT 00
2 Shadow-IT Coverage 00
3 Agentic SOC Dashboard 00
4 Test 00
5 Jamf Missing Devices 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 sdfsdf 00
D Full Use Case Analysis 12 use cases | 41,240 executions (12m)

Business KPIs

Metric Count Playbook
Helpdesk tickets auto-routed & assigned 734 Ticket Distributor v2
Helpdesk tickets routed via webhook-driven routing 475 WIP Ticket Distributor V3 W/Webhook Trigger
Jira SLA monitoring checks executed 168 jira find breaches
Onboarding & purchase ticket closures auto-captured 105 Jira Onboarding/Purchase Request Ticket Closure Webhook
Rapid7 vulnerability alerts ingested & processed 58 Rapid7 Alerts
User Google Drive external-sharing exposures scanned 52 Dump Externally Shared Files to Table
Helpdesk queue management actions automated (PTO + study time) 56 Add and remove from Helpdesk Queue / Automated OOQ for Study Time
Zoom user offboarding reconciliation sweeps 40 Offboard Zoom User
Phishing & email threat scans (Abnormal Security) 40 Abnormal Ingest
Cross-platform shadow IT device coverage sweeps 39 Main - Shadow-IT
Missing endpoint device inventory reports generated 6 Generate Missing Jamf Devices CSV
Loaner laptop check-in tickets auto-created 6 Automated Ticket Creation for Loaner laptops
Monthly high-severity vulnerability status reports 1 Monthly Open High VULN Tickets
In the last 12 months, Blink automated: - 1,209 helpdesk tickets routed and assigned without human triage - 168 Jira SLA compliance monitoring cycles executed automatically - 105 ticket lifecycle events captured and closed via automation - 58 Rapid7 vulnerability alerts ingested and triaged - 56 helpdesk queue management actions automated (PTO coverage + study time) - 52 Google Drive external file-sharing exposure scans completed per user - 40 Zoom user offboarding reconciliations run automatically - 39 cross-platform shadow IT device coverage sweeps completed - 6 missing endpoint device inventory reports generated and emailed - 6 loaner laptop check-in tickets automatically created

Use Case Summary

# Use Case Category Playbooks
1 IT Helpdesk Automation Other 19
2 SOC — Alert Ingestion & Case Management SOC 22
3 Agentic SOC Investigation SOC 37
4 SOC — Alert Enrichment & IOC Lookup SOC 47
5 SOC — Phishing Detection & Response SOC 5
6 SOC — EDR Containment & Response SOC 5
7 Vulnerability Management Vulnerability Mgmt 11
8 Shadow IT & Endpoint Coverage Other 13
9 Endpoint Device Management Other 9
10 IAM — Offboarding & Licensing IAM 15
11 DLP — Google Drive Exposure Monitoring GRC 2
12 Financial & Business Operations Other 4
Total 189

Use Cases

1. IT Helpdesk Automation

Description: End-to-end automation of the IT helpdesk ticket lifecycle — from event-driven ingestion and intelligent routing to SLA breach monitoring and dynamic agent queue management. Blink intercepts Jira ticket-created events and routes them to the correct assignment group based on ticket type, company affiliation, and technician availability.

Business problem: IT teams lose significant time manually triaging and distributing inbound Jira tickets. SLA breaches go undetected until escalation. Technician availability changes (PTO, study time) require constant manual queue intervention.

Integrations: Jira, Microsoft Outlook Calendar, Okta, NinjaOne, Jamf, UKG, Python

Category: Other | Subcategory: IT helpdesk & ticket routing

Playbook Executions (12mo)
Ticket Distributor v2 734
BLANK JIRA TICKET WEBHOOK YAHOO 733
WIP Ticket Distributor V3 W/Webhook Trigger 475
jira find breaches 168
Jira Onboarding/Purchase Request Ticket Closure Webhook 105
Add and remove from Helpdesk Queue based on upcoming PTO 28
Automated OOQ for Study Time 28
Automated Ticket Creation for Loaner laptops Version 1.1 6
Utility - Create Jira Ticket for Helpdesk Project version 1.1 2
New Workflow 3 1
MSE-Duplicate Ticket Reassigner 0
Remove User From Ticket Assignment Group 0
Add User To Ticket Assignment Group 0
Create Support Schedule Invites from CSV 0
Create On-Call Invites 0
Study Time remove and add back to queue automatically 0
Pull company info to use for Email request ticket assignment 0
Utility Get full Jira ticket API pull 0
WIP Blink to Jira - Submit Employee onboarding ticket 0

2. SOC — Alert Ingestion & Case Management

Description: Multi-source security alert ingestion pipeline feeding Blink's native Case Management system. Alerts are continuously polled from Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center, and Abnormal Security, then funneled into a unified case management pipeline for deduplication, processing, and triage.

Business problem: Security teams face alert fatigue and fragmentation when alerts arrive from disparate tools with no unified view. Manual ingestion creates lag between detection and response.

Integrations: Microsoft Defender for Endpoint, Microsoft Defender XDR, Google Workspace Alert Center, Gmail, Abnormal Security, Azure Monitor, Wiz, SentinelOne, CrowdStrike, AWS CloudTrail, Blink Case Management

Category: SOC | Subcategory: Case mgmt & SOAR, SIEM & log pipeline monitoring

Playbook Executions (12mo)
Microsoft Defender for endpoint ingestion 11,520
Polling New Alerts From a Given Workspace 11,520
Defender XDR - Phishing Alerts 11,520
Google Workspace Alert Center - Phishing reclassification Alert 11,520
Google Workspace Alert Center - User reported phishing Alert 11,520
Abnormal Ingest 40
EXAMPLE Ingest - Azure 1
Process Alert 0
Sentinelone ingestion 0
Ingest - trial-3825569-admin Okta 0
Utility - Close Stale Cases 0
Recovery - Handle Unprocessed Alerts 0
Recovery - Handle Unprocessed Alert 0
Subflow - Create Historical Alerts 0
EXAMPLE Ingest - Wiz 0
EXAMPLE Ingest - Microsoft Defender For Cloud Apps 0
EXAMPLE Ingest - CrowdStrike Falcon LogScale 0
EXAMPLE Ingest - CrowdStrike 0
EXAMPLE Ingest - AWS CloudTrail 0
Demo Ingest - Email Phishing Human 0
Demo Ingest - Email Phishing 0
Main - Demo Alerts 0

3. Agentic SOC Investigation

Description: AI-driven investigation layer built on top of the case management pipeline. Autonomous agents — Phishing Agent, EDR Agent, Core Investigator, and Unusual Login Activity Agent — triage and investigate security cases using purpose-built agent abilities that query identity systems, pull enrichment context, run static analysis, and generate investigation conclusions.

Business problem: Tier-1 analysts spend the majority of their time on repetitive investigation steps (pulling user context, checking IOC reputation, reviewing similar cases). Agentic automation reduces mean time to triage by completing these steps automatically.

Integrations: Blink Case Management, Blink Agents (AI micro-agents), Okta, Microsoft Defender XDR, CrowdStrike ThreatGraph, Exchange Online, VirusTotal, system.Table

Category: SOC | Subcategory: Agentic SOC, Case mgmt & SOAR

Playbook Executions (12mo)
Main - AI Investigation 0
Phishing Agent 0
EDR Agent 0
Core Investigator Agent 0
Unusual Login Activity Agent 0
Conclusion Agents 0
conclusion WF 0
Utility - Refresh investigation 0
SubFlow - Context Enrichment 0
Agent Ability - Historical Case Checks 0
Agent Ability - Micro Agent - Observables Context 0
Agent Ability - Micro Agent - Crowdstrike Threatgraph Enricher 0
Agent Ability - Micro Agent - Microsoft Defender XDR Incident Enricher 0
Agent Ability - Phishing Static Analysis 0
Agent Ability - Get Okta User Logs 0
Agent Ability - Get Okta Login Logs 0
Agent Ability - Get Next Okta Logs Page 0
Agent Ability - Find Phishing Email via Exchange Compliance Search 0
Agent Ability - Purge Mail from All Mailboxes 0
Agent Ability - Get Phishing Headers from 365 0
Agent Ability - Get Phishing Questions 0
Agent Ability - Get Malware Questions 0
Agent Ability - Get Bruteforce Questions 0
Agent Ability - Get Cases and Alerts Bulk 0
Agent Ability - Get Alert 0
Agent Ability - Get Case 0
Agent Ability - Add Investigation 0
Agent Ability - Get VIP Users 0
Agent Ability - Get Org Assets 0
Agent Ability - Get Org Technological Stack 0
Agent Ability - Query Observables by Content 0
Agent Ability - Get Case Observable's Enrichment 0
Agent Ability - Get Observable Reputations From Case Management Settings 0
Agent Ability - Get Observable Types From Case Management Settings 0
Agent Ability - Get Observable Relation Types From Case Management Settings 0
Agent Ability - Get Case Types From Case Management Settings 0
Agent Ability - Get Vendor Logo List 0

4. SOC — Alert Enrichment & IOC Lookup

Description: A comprehensive library of enrichment flows that automatically interrogate threat intelligence sources, identity providers, and endpoint platforms to build full observable context for every alert. IP addresses, URLs, file hashes, usernames, domains, and device IDs are enriched from VirusTotal, AbuseIPDB, URLScan.io, Whois, Okta, Azure AD, Google Workspace, GitHub, CrowdStrike, Slack, and Rapid7.

Business problem: Analysts waste 10–20 minutes per alert manually pivoting across tools to collect IOC context. Automated enrichment delivers this context instantly, enabling faster and more consistent decisions.

Integrations: VirusTotal, AbuseIPDB, URLScan.io, Whois, CrowdStrike, CrowdStrike ThreatGraph, Rapid7, Okta, Azure Active Directory, Google Workspace, GitHub, Slack, Exchange Online, Blink Case Management

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Playbook Executions (12mo)
Subflow - Enrich Observables - Main Router 0
Utility - Update Enrichment 0
Subflow - Update Enrichment Data 0
Recovery - Enrich Non-Enriched Observables 0
Enrich - Agent ID - Crowdstrike 0
Enrich - Username or Email - Okta 0
Get User Information Using Google Workspace 0
Enrich - Username or Email - Google Workspace 0
Get User Information Using Microsoft Entra ID 0
Enrich - Username or Email - Microsoft Entra ID 0
Get User Information Using Okta 0
Get User Information on Email Address Using Slack 0
Get User Information Using Github 0
Enrich - Username - Github 0
Enrich - Email Address - Slack 0
Enrich - IP - IPDB 0
Enrich - IP - VT 0
Enrich IP or Domain Using Whois 0
Enrich - IP or Domain - Whois 0
Enrich - URL - VT 0
Enrich - URL - URLScan 0
Enrich - Hash - VT 0
Enrich - Hash - Crowdstrike 0
Enrich - Hash - Crowdstrike copy 0
Enrich - Crowdstrike Threatgraph Enrichment 0
Enrich - Check If OBS inside ORG 0
Get Hash Info Using VirusTotal 0
Get Hash Info Using Crowdstrike 0
Analyze URL with URLScan 0
Secure URL Screenshot Capture 0
Okta Search for User Activity 0
Rapid7 - Get Host Info 0
Run Dig Command 0
Get End of Life Date for a Product 0
Utility - Set Or Update Observable Relation 0
Utility - List Observable Alert Relations 0
Utility - List Alert Observable Relations 0
Utility - Find Similar Cases Based on Observables 0
Utility - Delete Observable Relation 0
Utility - Add Observable Extraction Rule 0
Utility - Generate Observable Extraction Template (AI) 0
Table Action - Validate Observables Extraction Template 0
Get Observables by Case ID 0
Query Observable 0
Comment On Case 0
Subflow - Missing Alert Template Notification 0
Error Handling - Send Error Notification Email 0

5. SOC — Phishing Detection & Response

Description: Automated response playbooks for phishing and malware cases surfaced by the case management pipeline. The phishing response flow retrieves the email from Outlook, inspects headers for KnowBe4 simulation signatures, and routes accordingly. Exchange Online compliance search enables cross-mailbox phishing hunting and optional purge.

Business problem: Responding to phishing reports requires multi-step manual investigation across email, identity, and endpoint platforms. Automation accelerates containment and reduces analyst toil for the highest-volume alert type.

Integrations: Microsoft Outlook, Exchange Online, Blink Case Management, Okta

Category: SOC | Subcategory: Phishing detection & response

Playbook Executions (12mo)
Response Subflow - Phishing 0
Response Subflow - Malware 0
Subflow - Response - Main Router 0
Response Subflow - Exchange Online Run Compliance Search 0
New Workflow 1 0

6. SOC — EDR Containment & Response

Description: CrowdStrike Real-Time Response (RTR) workflows for endpoint containment and agent deployment. Enables isolating a compromised host, batch-commanding a group of endpoints, and remotely installing Automox or NinjaOne agents on CrowdStrike-managed devices without needing direct access.

Business problem: Containment of compromised endpoints requires immediate action. Manual RTR sessions are slow and error-prone under incident conditions. Automated isolation and remediation shorten the attack dwell window.

Integrations: CrowdStrike RTR, Automox, NinjaOne

Category: SOC | Subcategory: EDR containment & response

Playbook Executions (12mo)
Manage Endpoint Quarantine Status in Crowdstrike 0
CrowdStrike RTR to a Batch of Hosts 0
CrowdStrike RTR to a Single Host 0
Install Automox with Crowdstrike RTR 0
Install NinjaOne with Crowdstrike RTR 0

7. Vulnerability Management

Description: End-to-end vulnerability management pipeline using Rapid7 InsightVM — from alert ingestion and asset data collection through Jira ticket creation, SLA tracking, escalation, and automated remediation via Automox. Includes a monthly executive report on open high-severity vulnerability tickets.

Business problem: Vulnerability backlogs grow when ingestion, ticketing, and SLA tracking are manual. Teams lack visibility into overdue remediation items until SLAs are already breached.

Integrations: Rapid7 InsightVM, Jira, Automox, system.Table

Category: Vulnerability Mgmt | Subcategory: Vuln lifecycle prioritize & ticket, Vuln scan lifecycle automation, CVE lookup & remediation

Playbook Executions (12mo)
Rapid7 Alerts 58
Monthly Open High VULN Tickets 1
Vuln tickets Management 0
Add Critical vulnerabilities to Jira 0
Mark Closed Jira Tickets 0
SLA checker 0
Nudge Ticket 0
Escalate Ticket 0
Ingest Rapid 7 Vulnerabilities 0
Rapid7 Ingestion Subflow 0
Remediate With Automox 0

8. Shadow IT & Endpoint Coverage

Description: Daily automated sweep that reconciles device records across CrowdStrike, NinjaOne, Jamf, and Rapid7 to identify managed vs. unmanaged endpoints. Devices present in CrowdStrike but missing from NinjaOne are automatically enrolled. A weekly gap report identifies devices absent from Jamf. A strike system tracks policy-violation incidents per device.

Business problem: Endpoints managed by only one tool create blind spots in patching, configuration enforcement, and vulnerability coverage. Manual cross-tool reconciliation is too slow to keep pace with daily device changes.

Integrations: CrowdStrike, NinjaOne, Jamf, Rapid7 InsightVM, Email

Category: Other | Subcategory: Endpoint hygiene & MDM ops

Playbook Executions (12mo)
Main - Shadow-IT 39
Crowdstrike Table Fill 39
NinjaOne Table Fill 37
Rapid7 Table Fill 37
Jamf Table Fill 32
Generate Missing Jamf Devices CSV 6
Get Crowdstrike devices 0
Main - Shadow-IT (dev workspace) 0
Add Strike 0
Remove Strike 0
Get correlated devices 0
Automox collect devices 0
Crowdstrike collect devices 0

9. Endpoint Device Management & Inventory

Description: Daily refresh of authoritative device sources of truth (SOT) from NinjaOne and Jamf, unified into a master computer list. Apple Business Manager warranty data is automatically synchronized for all enrolled devices. Azure AD user records are refreshed daily to keep identity and device data in sync.

Business problem: IT and security teams depend on accurate, up-to-date device inventory for support, compliance, and asset tracking. Stale or fragmented records cause missed updates, incorrect assignments, and audit failures.

Integrations: NinjaOne, Jamf, Apple Business Manager, Azure Active Directory

Category: Other | Subcategory: Endpoint hygiene & MDM ops, SaaS / IT administration

Playbook Executions (12mo)
Build Computer Master List 41
Build Computer SOT 40
Jamf SOT Build 40
Azure Build Users Table 40
AppleBusinessManagerWarrantyUpdater 38
Add Custom Fields for Ninja Devices Table 38
Get Information for Assignment Jamf/Ninja 0
Google Past 60 Days 0
Get Apple Device Warranty 0

10. IAM — Offboarding & Licensing

Description: Automated user lifecycle management covering employee offboarding (Zoom deprovisioning synchronized against Okta), and Microsoft license oversight across multiple Azure AD tenants. License redundancies are identified automatically, and per-connection user licensing tables are populated for review.

Business problem: Manual offboarding leaves deprovisioned users active in downstream SaaS tools. Unreviewed Microsoft licensing wastes budget and creates compliance risk from access that outlasts employment.

Integrations: Okta, Zoom, Azure Active Directory (multiple tenants), Dropbox

Category: IAM | Subcategory: Employee offboarding, Access review & group mgmt, Identity sync & directory mgmt

Playbook Executions (12mo)
Offboard Zoom User 40
Offboarding Main 0
Find User AD Connection 0
Fins User Okta connection 0
Create Zoom User 0
Create Dropbox User 0
Fill All Licensing tables 0
Fill Licensing Table per connection 0
Find Microsoft License Redundancies 0
Find User Connection 0
Get User Employment Status 0
Build Microsoft License Overview Table 0
Fill Licensing Table per connection 0
Fill Total Rows in Overview table 0
Find User Connection 0

11. DLP — Google Drive Exposure Monitoring

Description: Monthly automated scan of Google Workspace to identify users with files shared externally. For each flagged user, a detailed inventory of all externally shared Drive files is captured into a Blink table for review and remediation.

Business problem: Overshared Google Drive files are a persistent data leakage risk in distributed organizations. Without automated scanning, exposure goes undetected until a breach or audit.

Integrations: Google Workspace, Google Drive

Category: GRC | Subcategory: DLP triage & exposure resp

Playbook Executions (12mo)
Dump Externally Shared Files to Table 52
ist Users With Shared Files From Google Drive - Information 1

12. Financial & Business Operations

Description: Automation supporting financial operations workflows — receipt capture and upload to BILL for expense management, and a media digest report built from Microsoft Graph communications data processed by Glean AI.

Business problem: Manual receipt collection and expense matching is time-consuming and error-prone. Automated capture and upload removes manual steps from the AP workflow.

Integrations: Microsoft Outlook, Microsoft Graph, BILL (AP automation), Glean AI

Category: Other | Subcategory: Financial & fraud operations

Playbook Executions (12mo)
BILL Receipt Upload Proxy 0
ITbilling Fetch and Attach Receipt from Email 0
CisionOne Workflow 0
Divvy Testing 0

Key Observations

Strengths

IT Helpdesk automation is the highest-value active use case. The Jira ticket routing stack (Ticket Distributor v2 + WIP v3, 1,209 combined runs) is fully operationalized and eliminates manual triage from the entire helpdesk intake flow. Continuous SLA monitoring (jira find breaches, 168 runs) and calendar-driven queue management (56 automated queue actions) show deep process integration, not just point automation.

SOC infrastructure is comprehensively built and continuously active. Five separate alert sources (Microsoft Defender for Endpoint, Defender XDR, Google Workspace Alert Center ×2, Abnormal Security) are ingesting into a unified case management system on a continuous polling cadence. The enrichment library (47 playbooks) covers every observable type across 10+ intelligence and identity sources. The full agentic investigation stack — Phishing Agent, EDR Agent, Core Investigator — is deployed and ready to run on live cases.

Shadow IT coverage is actively sweeping. The Main - Shadow-IT workflow runs daily, reconciling CrowdStrike, NinjaOne, Jamf, and Rapid7 across ~39 sweeps and automatically enrolling ungoverned devices into NinjaOne. The device SOT pipeline (Build Computer Master List, 41 runs) provides a consistently fresh unified inventory.

DLP monitoring is operational. Google Drive external-sharing scans are running monthly, with per-user file inventories captured automatically — a meaningful risk reduction capability for a geographically distributed workforce.

Gaps & Opportunities

Vulnerability management ticketing is built but idle. The Rapid7 alert ingestion (58 runs) is active, but the full lifecycle pipeline — creating Jira tickets for critical vulns, SLA checking, escalation, and Automox remediation — shows 0 executions. Activating this pipeline would close the loop from detection to tracked remediation automatically.

Agentic SOC has zero production executions. The AI investigation layer (Phishing Agent, EDR Agent, Core Investigator, Unusual Login Activity Agent) is fully built with 37 playbooks and deep agent abilities but has not yet processed live cases. With alert ingestion already running at scale, enabling the agentic layer would deliver immediate analyst time savings.

EDR containment playbooks are deployed but unused. CrowdStrike RTR isolation, batch host commands, and remote agent installation are ready but show 0 runs. Integrating these into the active SOC response pipeline would enable automated containment directly from case management alerts.

IAM offboarding coverage is partial. Zoom deprovisioning (40 runs) is automated but the broader offboarding orchestrator — covering AD, Okta, Dropbox, and Zoom in a single coordinated workflow — shows 0 executions. Full offboarding automation would reduce the risk of persistent access after termination.

Microsoft licensing review is built but not scheduled. The multi-tenant license overview pipeline (6 workspaces worth of licensing flows) has 0 executions. Scheduling this monthly would surface redundant licenses and access entitlements automatically.

Integration Ecosystem

LHM operates one of the broadest integration footprints across the Blink customer base, spanning 20+ connected platforms:

Domain Integrations
ITSM & Ticketing Jira
Endpoint & MDM CrowdStrike (+ RTR + ThreatGraph), NinjaOne, Jamf, Automox
Identity Azure Active Directory (multi-tenant), Okta
Email Security Microsoft Defender XDR, Microsoft Defender for Endpoint, Abnormal Security, Exchange Online
Collaboration Microsoft Outlook, Microsoft Graph, Google Workspace, Gmail, Zoom, Slack
Threat Intelligence VirusTotal, AbuseIPDB, URLScan.io, Whois
Vulnerability Rapid7 InsightVM
HRIS UKG
Finance BILL, Divvy
Cloud Azure Monitor, AWS CloudTrail (example), GCP (prototype)
AI Glean AI, Blink Agents (AI micro-agents)
Other Apple Business Manager, GitHub, SentinelOne (staged), Wiz (staged)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.