Blink Security Automation — Confidential

M1_Support — Customer Success Report

Generated 2026-08-30 | m1_support-value-report.md
2026-08-30Report Date
67Total Playbooks
10Unique Workflows (12m)
1,741Actions Automated (12m)
$448Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

67
Total playbooks built
all non-deleted workflows
11
Active playbooks
currently enabled
10
Unique workflows executed (12m)
distinct workflows that ran
1,741
Actions automated (12m)
completed action steps
9.7h
Hours saved (12m)
@ 20s per action
$448
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 2 total
9
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 60 Azure AD group membership lookups - 39 employee offboarding workflows (Freshservice → Entra ID) - 6 Intune compliance policy inventories - 3 bulk user provisioning runs via CSV - 2 automated security reports generated and delivered - 2 endpoint configuration and security audits (device configuration profiles + security intents) - 1 weekly deleted user account audit

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Intune MDM Policy & Configuration Auditing
  • 6Intune compliance policy inventories run
  • 1Device configuration profile audits
  • 1Endpoint security intent reviews
0.0%
5
5 active
Azure AD Group & Identity Lookup
  • 60Azure AD group membership lookups automated
  • 1Deleted user account audits automated (weekly)
0.8%
2
2 active
Employee Offboarding Automation
  • 39Employee offboarding workflows executed (Freshservice → Entra ID)
29.8%
1
1 active
Bulk Account Provisioning
  • 3Bulk user provisioning runs completed via CSV
0.0%
1
0 active
Automated Security Reporting
  • 2Automated security reports generated & delivered
0.0%
1
1 active
Platform Onboarding & Demo0 executions
0.0%
1
0 active
Total40 executions100%
11
9 active

Use Case Growth Over Time

61 unique playbooks  |  6 operational use cases  |  131 total executions (12m)  |  2026-05 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Intune MDM Policy & Configuration Auditing
Microsoft Graph
Azure AD Group & Identity Lookup
Microsoft Graph Email
Automated Security Reporting
Agents Email
Employee Offboarding Automation
Microsoft Graph Email

04Key Observations

✓  Strengths

Strengths

  • Microsoft Graph is the dominant integration. Virtually all production workflows are built on it, covering both Intune (device compliance, configuration profiles, security intents) and Entra ID (group membership, deleted user monitoring). This indicates a mature, Microsoft-first environment and provides a strong foundation for expanding MDM and IAM automation.
  • Group identity lookup is the highest-volume use case. With 60 executions in 12 months, Get group and members by ID is clearly a workhorse — likely feeding access review processes, incident investigations, or downstream provisioning logic that depends on group data.
  • AI-assisted reporting is in place. The Call Reporter Agent workflow demonstrates early adoption of Blink's agentic capabilities, positioning the team to scale security reporting and operational summaries without analyst involvement in formatting or delivery.
  • Offboarding automation now connects ITSM to identity actions. The new Freshservice to Entra offboarding workflow has already run 39 times, directly closing the previously identified employee lifecycle
△  Gaps & Growth Opportunities

gap by triggering Entra ID deprovisioning logic from Freshservice ticket intake.

Gaps

  • No event-driven or alert-triggered automation, aside from offboarding. With the exception of the new Freshservice-triggered offboarding workflow, all other workflows are on_demand or scheduled with no SIEM integration or reactive response playbooks. There are no SOC, triage, or EDR use cases — the remaining automation is query-oriented and manually initiated.
  • MDM audit playbooks are used ad hoc, not systematically. List Compliance Policies (6 runs), List Device Configuration Profiles (1 run), and List Endpoint Security Intents (1 run) show low cadence. These would deliver significantly more value if scheduled or chained into a recurring compliance hygiene workflow.
  • Two subflow playbooks have never been executed. Get Compliance Policy and Get Compliance Script have zero runs. They appear to be building blocks for a deeper compliance drill-down workflow that was never completed or wired up.
  • ITSM integration is limited to a single offboarding trigger. Freshservice is now connected via the new offboarding workflow, but compliance audit results, provisioning completions, and report deliveries still aren't fed back into the team's operational ticket queues — there's room to extend Freshservice integration beyond the single offboarding use case.

Integration Ecosystem

Integration Used In
Microsoft Graph (Intune / DeviceManagement) List Compliance Policies, Get Compliance Policy, Get Compliance Script, List Device Configuration Profiles, List Endpoint Security Intents
Microsoft Graph (Entra ID / Azure AD) Get group and members by ID, Deleted Users Weekly Automation
Freshservice (ITSM) Freshservice to Entra offboarding
Blink AI Agents (Reporter) Call Reporter Agent
File / Utility (CSV parsing, PDF conversion) Account Provisioning based on CSV, Call Reporter Agent
Core Runtime (Bash, Python) Getting Started - Hello World, Account Provisioning based on CSV, Freshservice to Entra offboarding
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 9 tasks (12m)

AI Agents

Active Agents
1
of 2 total
Tasks Executed (12m)
9
0 in last 30d
Data Usage (12m)
338,991
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Reporter PoC Workspace 9 0 338,991
2 Intune-Compliance-Analyst PoC Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
PoC Workspace9
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Operator Dashboard 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 6 use cases | 131 executions (12m)

Business KPIs

Metric Count Playbook
Azure AD group membership lookups automated 60 Get group and members by ID
Employee offboarding workflows executed (Freshservice → Entra ID) 39 Freshservice to Entra offboarding
Intune compliance policy inventories run 6 List Compliance Policies
Bulk user provisioning runs completed via CSV 3 Account Provisioning based on CSV
Automated security reports generated & delivered 2 Call Reporter Agent
Device configuration profile audits 1 List Device Configuration Profiles
Endpoint security intent reviews 1 List Endpoint Security Intents
Deleted user account audits automated (weekly) 1 Deleted Users Weekly Automation
In the last 12 months, Blink automated: - 60 Azure AD group membership lookups - 39 employee offboarding workflows (Freshservice → Entra ID) - 6 Intune compliance policy inventories - 3 bulk user provisioning runs via CSV - 2 automated security reports generated and delivered - 2 endpoint configuration and security audits (device configuration profiles + security intents) - 1 weekly deleted user account audit

Use Case Summary

Use Case Category Subcategories Total Playbooks Active Playbooks
Intune MDM Policy & Configuration Auditing GRC / Other Compliance questionnaire; Endpoint hygiene & MDM ops 5 3
Azure AD Group & Identity Lookup IAM Access review & group mgmt; Identity lifecycle automation 2 2
Employee Offboarding Automation IAM Employee offboarding 1 1
Bulk Account Provisioning IAM Employee onboarding; Identity lifecycle automation 1 1
Automated Security Reporting GRC Security metrics & reporting 1 1
Platform Onboarding & Demo Other SaaS / IT administration 1 1
Total 11 9

Use Cases

1. Intune MDM Policy & Configuration Auditing

Description: Automates querying and inventorying Microsoft Intune resources — compliance policies, configuration profiles, compliance scripts, and endpoint security intents — via the Microsoft Graph API. Provides on-demand visibility into the device management posture without requiring manual navigation of the Intune portal.

Business Problem: Security and compliance teams need continuous visibility into device compliance policies and configurations to detect drift, support audits, and ensure endpoints meet security baselines. Manual checks in the Intune UI are time-consuming and inconsistent at scale.

Integrations: Microsoft Graph (Intune / DeviceManagement)

Playbook Executions (12 mo) Category Subcategories
List Compliance Policies 6 GRC / Other Compliance questionnaire; Endpoint hygiene & MDM ops
List Device Configuration Profiles 1 Other Endpoint hygiene & MDM ops
List Endpoint Security Intents 1 Other Endpoint hygiene & MDM ops
Get Compliance Policy 0 GRC / Other Compliance questionnaire; Endpoint hygiene & MDM ops
Get Compliance Script 0 GRC / Other Compliance questionnaire; Endpoint hygiene & MDM ops

2. Azure AD Group & Identity Lookup

Description: Provides on-demand retrieval of Azure AD group details and full membership lists via Microsoft Graph, and includes a scheduled weekly check for deleted user accounts with results delivered by email. Serves as a core identity lookup and lifecycle-monitoring primitive for access review, incident investigation, and account hygiene.

Business Problem: Access reviews, incident investigations, and permission audits all require fast, reliable group membership data. Manual queries in Entra ID are slow and non-repeatable; this use case enables group data to be retrieved programmatically and fed into downstream automation, while the weekly deleted-user check gives IT recurring visibility into account lifecycle changes without a manual portal review.

Integrations: Microsoft Graph (Entra ID / Azure AD), Email delivery

Playbook Executions (12 mo) Category Subcategories
Get group and members by ID 60 IAM Access review & group mgmt
Deleted Users Weekly Automation 1 IAM Identity lifecycle automation

3. Employee Offboarding Automation

Description: Triggered by a Freshservice webhook when an offboarding ticket is raised, this workflow extracts the ticket ID, retrieves and parses the ticket details, and evaluates conditional logic to drive downstream Entra ID deprovisioning actions.

Business Problem: Manual offboarding is slow and error-prone, and delayed deprovisioning leaves departed employees with active accounts and access — a material security risk. This playbook connects the ITSM ticketing system (Freshservice) directly to identity actions in Entra ID, closing the loop between ticket creation and account deprovisioning.

Integrations: Freshservice (ITSM), Microsoft Entra ID, Python scripting

Playbook Executions (12 mo) Category Subcategories
Freshservice to Entra offboarding 39 IAM Employee offboarding

4. Bulk Account Provisioning

Description: Ingests a CSV file of user records, parses it into structured JSON, determines the required CRUD action per row (create, update, or deactivate), and executes provisioning operations iteratively via a for-loop with Python-driven formatting logic.

Business Problem: Onboarding or offboarding large cohorts of users — contractor batches, org restructuring, acquisitions — via manual IT ticketing is slow and error-prone. This playbook enforces a consistent, auditable provisioning process that scales to hundreds of accounts in a single run.

Integrations: Blink file utilities (CSV parsing, working directory), Python scripting

Playbook Executions (12 mo) Category Subcategories
Account Provisioning based on CSV 3 IAM Employee onboarding; Identity lifecycle automation

5. Automated Security Reporting

Description: Invokes a Blink AI reporter agent with structured report data, content instructions, and a title; generates a formatted HTML report; converts it to PDF; and conditionally delivers it to specified email recipients.

Business Problem: Producing recurring or ad-hoc security reports manually is time-intensive and inconsistent. This playbook enables any upstream workflow to trigger a polished, consistently formatted report delivery with no manual effort — decoupling data collection from presentation.

Integrations: Blink AI Agents (Reporter), PDF conversion utility, email delivery

Playbook Executions (12 mo) Category Subcategories
Call Reporter Agent 2 GRC Security metrics & reporting

6. Platform Onboarding & Demo

Description: A standard "Hello World" starter playbook that exercises Blink's three core runtime primitives: internal print, Bash execution, and Python execution.

Business Problem: Validates platform connectivity and confirms developer onboarding. Not a production use case.

Integrations: Core runtime (Bash, Python)

Playbook Executions (12 mo) Category Subcategories
Getting Started - Hello World 1 Other SaaS / IT administration

Key Observations

Strengths

  • Microsoft Graph is the dominant integration. Virtually all production workflows are built on it, covering both Intune (device compliance, configuration profiles, security intents) and Entra ID (group membership, deleted user monitoring). This indicates a mature, Microsoft-first environment and provides a strong foundation for expanding MDM and IAM automation.
  • Group identity lookup is the highest-volume use case. With 60 executions in 12 months, Get group and members by ID is clearly a workhorse — likely feeding access review processes, incident investigations, or downstream provisioning logic that depends on group data.
  • AI-assisted reporting is in place. The Call Reporter Agent workflow demonstrates early adoption of Blink's agentic capabilities, positioning the team to scale security reporting and operational summaries without analyst involvement in formatting or delivery.
  • Offboarding automation now connects ITSM to identity actions. The new Freshservice to Entra offboarding workflow has already run 39 times, directly closing the previously identified employee lifecycle gap by triggering Entra ID deprovisioning logic from Freshservice ticket intake.

Gaps

  • No event-driven or alert-triggered automation, aside from offboarding. With the exception of the new Freshservice-triggered offboarding workflow, all other workflows are on_demand or scheduled with no SIEM integration or reactive response playbooks. There are no SOC, triage, or EDR use cases — the remaining automation is query-oriented and manually initiated.
  • MDM audit playbooks are used ad hoc, not systematically. List Compliance Policies (6 runs), List Device Configuration Profiles (1 run), and List Endpoint Security Intents (1 run) show low cadence. These would deliver significantly more value if scheduled or chained into a recurring compliance hygiene workflow.
  • Two subflow playbooks have never been executed. Get Compliance Policy and Get Compliance Script have zero runs. They appear to be building blocks for a deeper compliance drill-down workflow that was never completed or wired up.
  • ITSM integration is limited to a single offboarding trigger. Freshservice is now connected via the new offboarding workflow, but compliance audit results, provisioning completions, and report deliveries still aren't fed back into the team's operational ticket queues — there's room to extend Freshservice integration beyond the single offboarding use case.

Integration Ecosystem

Integration Used In
Microsoft Graph (Intune / DeviceManagement) List Compliance Policies, Get Compliance Policy, Get Compliance Script, List Device Configuration Profiles, List Endpoint Security Intents
Microsoft Graph (Entra ID / Azure AD) Get group and members by ID, Deleted Users Weekly Automation
Freshservice (ITSM) Freshservice to Entra offboarding
Blink AI Agents (Reporter) Call Reporter Agent
File / Utility (CSV parsing, PDF conversion) Account Provisioning based on CSV, Call Reporter Agent
Core Runtime (Bash, Python) Getting Started - Hello World, Account Provisioning based on CSV, Freshservice to Entra offboarding
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.