01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Intune MDM Policy & Configuration Auditing |
| 0.0% | 5 5 active |
| Azure AD Group & Identity Lookup |
| 0.8% | 2 2 active |
| Employee Offboarding Automation |
| 29.8% | 1 1 active |
| Bulk Account Provisioning |
| 0.0% | 1 0 active |
| Automated Security Reporting |
| 0.0% | 1 1 active |
| Platform Onboarding & Demo | 0 executions | 0.0% | 1 0 active |
| Total | 40 executions | 100% | 11 9 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Microsoft Graph is the dominant integration. Virtually all production workflows are built on it, covering both Intune (device compliance, configuration profiles, security intents) and Entra ID (group membership, deleted user monitoring). This indicates a mature, Microsoft-first environment and provides a strong foundation for expanding MDM and IAM automation.
- Group identity lookup is the highest-volume use case. With 60 executions in 12 months,
Get group and members by IDis clearly a workhorse — likely feeding access review processes, incident investigations, or downstream provisioning logic that depends on group data. - AI-assisted reporting is in place. The Call Reporter Agent workflow demonstrates early adoption of Blink's agentic capabilities, positioning the team to scale security reporting and operational summaries without analyst involvement in formatting or delivery.
- Offboarding automation now connects ITSM to identity actions. The new
Freshservice to Entra offboardingworkflow has already run 39 times, directly closing the previously identified employee lifecycle
gap by triggering Entra ID deprovisioning logic from Freshservice ticket intake.
Gaps
- No event-driven or alert-triggered automation, aside from offboarding. With the exception of the new Freshservice-triggered offboarding workflow, all other workflows are
on_demandor scheduled with no SIEM integration or reactive response playbooks. There are no SOC, triage, or EDR use cases — the remaining automation is query-oriented and manually initiated. - MDM audit playbooks are used ad hoc, not systematically. List Compliance Policies (6 runs), List Device Configuration Profiles (1 run), and List Endpoint Security Intents (1 run) show low cadence. These would deliver significantly more value if scheduled or chained into a recurring compliance hygiene workflow.
- Two subflow playbooks have never been executed. Get Compliance Policy and Get Compliance Script have zero runs. They appear to be building blocks for a deeper compliance drill-down workflow that was never completed or wired up.
- ITSM integration is limited to a single offboarding trigger. Freshservice is now connected via the new offboarding workflow, but compliance audit results, provisioning completions, and report deliveries still aren't fed back into the team's operational ticket queues — there's room to extend Freshservice integration beyond the single offboarding use case.
Integration Ecosystem
| Integration | Used In |
|---|---|
| Microsoft Graph (Intune / DeviceManagement) | List Compliance Policies, Get Compliance Policy, Get Compliance Script, List Device Configuration Profiles, List Endpoint Security Intents |
| Microsoft Graph (Entra ID / Azure AD) | Get group and members by ID, Deleted Users Weekly Automation |
| Freshservice (ITSM) | Freshservice to Entra offboarding |
| Blink AI Agents (Reporter) | Call Reporter Agent |
| File / Utility (CSV parsing, PDF conversion) | Account Provisioning based on CSV, Call Reporter Agent |
| Core Runtime (Bash, Python) | Getting Started - Hello World, Account Provisioning based on CSV, Freshservice to Entra offboarding |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 9 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Reporter | PoC Workspace | 9 | 0 | 338,991 |
| 2 | Intune-Compliance-Analyst | PoC Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| PoC Workspace | 9 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Operator Dashboard | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 6 use cases | 131 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Azure AD group membership lookups automated | 60 | Get group and members by ID |
| Employee offboarding workflows executed (Freshservice → Entra ID) | 39 | Freshservice to Entra offboarding |
| Intune compliance policy inventories run | 6 | List Compliance Policies |
| Bulk user provisioning runs completed via CSV | 3 | Account Provisioning based on CSV |
| Automated security reports generated & delivered | 2 | Call Reporter Agent |
| Device configuration profile audits | 1 | List Device Configuration Profiles |
| Endpoint security intent reviews | 1 | List Endpoint Security Intents |
| Deleted user account audits automated (weekly) | 1 | Deleted Users Weekly Automation |
Use Case Summary
| Use Case | Category | Subcategories | Total Playbooks | Active Playbooks |
|---|---|---|---|---|
| Intune MDM Policy & Configuration Auditing | GRC / Other | Compliance questionnaire; Endpoint hygiene & MDM ops | 5 | 3 |
| Azure AD Group & Identity Lookup | IAM | Access review & group mgmt; Identity lifecycle automation | 2 | 2 |
| Employee Offboarding Automation | IAM | Employee offboarding | 1 | 1 |
| Bulk Account Provisioning | IAM | Employee onboarding; Identity lifecycle automation | 1 | 1 |
| Automated Security Reporting | GRC | Security metrics & reporting | 1 | 1 |
| Platform Onboarding & Demo | Other | SaaS / IT administration | 1 | 1 |
| Total | 11 | 9 |
Use Cases
1. Intune MDM Policy & Configuration Auditing
Description: Automates querying and inventorying Microsoft Intune resources — compliance policies, configuration profiles, compliance scripts, and endpoint security intents — via the Microsoft Graph API. Provides on-demand visibility into the device management posture without requiring manual navigation of the Intune portal.
Business Problem: Security and compliance teams need continuous visibility into device compliance policies and configurations to detect drift, support audits, and ensure endpoints meet security baselines. Manual checks in the Intune UI are time-consuming and inconsistent at scale.
Integrations: Microsoft Graph (Intune / DeviceManagement)
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| List Compliance Policies | 6 | GRC / Other | Compliance questionnaire; Endpoint hygiene & MDM ops |
| List Device Configuration Profiles | 1 | Other | Endpoint hygiene & MDM ops |
| List Endpoint Security Intents | 1 | Other | Endpoint hygiene & MDM ops |
| Get Compliance Policy | 0 | GRC / Other | Compliance questionnaire; Endpoint hygiene & MDM ops |
| Get Compliance Script | 0 | GRC / Other | Compliance questionnaire; Endpoint hygiene & MDM ops |
2. Azure AD Group & Identity Lookup
Description: Provides on-demand retrieval of Azure AD group details and full membership lists via Microsoft Graph, and includes a scheduled weekly check for deleted user accounts with results delivered by email. Serves as a core identity lookup and lifecycle-monitoring primitive for access review, incident investigation, and account hygiene.
Business Problem: Access reviews, incident investigations, and permission audits all require fast, reliable group membership data. Manual queries in Entra ID are slow and non-repeatable; this use case enables group data to be retrieved programmatically and fed into downstream automation, while the weekly deleted-user check gives IT recurring visibility into account lifecycle changes without a manual portal review.
Integrations: Microsoft Graph (Entra ID / Azure AD), Email delivery
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Get group and members by ID | 60 | IAM | Access review & group mgmt |
| Deleted Users Weekly Automation | 1 | IAM | Identity lifecycle automation |
3. Employee Offboarding Automation
Description: Triggered by a Freshservice webhook when an offboarding ticket is raised, this workflow extracts the ticket ID, retrieves and parses the ticket details, and evaluates conditional logic to drive downstream Entra ID deprovisioning actions.
Business Problem: Manual offboarding is slow and error-prone, and delayed deprovisioning leaves departed employees with active accounts and access — a material security risk. This playbook connects the ITSM ticketing system (Freshservice) directly to identity actions in Entra ID, closing the loop between ticket creation and account deprovisioning.
Integrations: Freshservice (ITSM), Microsoft Entra ID, Python scripting
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Freshservice to Entra offboarding | 39 | IAM | Employee offboarding |
4. Bulk Account Provisioning
Description: Ingests a CSV file of user records, parses it into structured JSON, determines the required CRUD action per row (create, update, or deactivate), and executes provisioning operations iteratively via a for-loop with Python-driven formatting logic.
Business Problem: Onboarding or offboarding large cohorts of users — contractor batches, org restructuring, acquisitions — via manual IT ticketing is slow and error-prone. This playbook enforces a consistent, auditable provisioning process that scales to hundreds of accounts in a single run.
Integrations: Blink file utilities (CSV parsing, working directory), Python scripting
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Account Provisioning based on CSV | 3 | IAM | Employee onboarding; Identity lifecycle automation |
5. Automated Security Reporting
Description: Invokes a Blink AI reporter agent with structured report data, content instructions, and a title; generates a formatted HTML report; converts it to PDF; and conditionally delivers it to specified email recipients.
Business Problem: Producing recurring or ad-hoc security reports manually is time-intensive and inconsistent. This playbook enables any upstream workflow to trigger a polished, consistently formatted report delivery with no manual effort — decoupling data collection from presentation.
Integrations: Blink AI Agents (Reporter), PDF conversion utility, email delivery
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Call Reporter Agent | 2 | GRC | Security metrics & reporting |
6. Platform Onboarding & Demo
Description: A standard "Hello World" starter playbook that exercises Blink's three core runtime primitives: internal print, Bash execution, and Python execution.
Business Problem: Validates platform connectivity and confirms developer onboarding. Not a production use case.
Integrations: Core runtime (Bash, Python)
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Getting Started - Hello World | 1 | Other | SaaS / IT administration |
Key Observations
Strengths
- Microsoft Graph is the dominant integration. Virtually all production workflows are built on it, covering both Intune (device compliance, configuration profiles, security intents) and Entra ID (group membership, deleted user monitoring). This indicates a mature, Microsoft-first environment and provides a strong foundation for expanding MDM and IAM automation.
- Group identity lookup is the highest-volume use case. With 60 executions in 12 months,
Get group and members by IDis clearly a workhorse — likely feeding access review processes, incident investigations, or downstream provisioning logic that depends on group data. - AI-assisted reporting is in place. The Call Reporter Agent workflow demonstrates early adoption of Blink's agentic capabilities, positioning the team to scale security reporting and operational summaries without analyst involvement in formatting or delivery.
- Offboarding automation now connects ITSM to identity actions. The new
Freshservice to Entra offboardingworkflow has already run 39 times, directly closing the previously identified employee lifecycle gap by triggering Entra ID deprovisioning logic from Freshservice ticket intake.
Gaps
- No event-driven or alert-triggered automation, aside from offboarding. With the exception of the new Freshservice-triggered offboarding workflow, all other workflows are
on_demandor scheduled with no SIEM integration or reactive response playbooks. There are no SOC, triage, or EDR use cases — the remaining automation is query-oriented and manually initiated. - MDM audit playbooks are used ad hoc, not systematically. List Compliance Policies (6 runs), List Device Configuration Profiles (1 run), and List Endpoint Security Intents (1 run) show low cadence. These would deliver significantly more value if scheduled or chained into a recurring compliance hygiene workflow.
- Two subflow playbooks have never been executed. Get Compliance Policy and Get Compliance Script have zero runs. They appear to be building blocks for a deeper compliance drill-down workflow that was never completed or wired up.
- ITSM integration is limited to a single offboarding trigger. Freshservice is now connected via the new offboarding workflow, but compliance audit results, provisioning completions, and report deliveries still aren't fed back into the team's operational ticket queues — there's room to extend Freshservice integration beyond the single offboarding use case.
Integration Ecosystem
| Integration | Used In |
|---|---|
| Microsoft Graph (Intune / DeviceManagement) | List Compliance Policies, Get Compliance Policy, Get Compliance Script, List Device Configuration Profiles, List Endpoint Security Intents |
| Microsoft Graph (Entra ID / Azure AD) | Get group and members by ID, Deleted Users Weekly Automation |
| Freshservice (ITSM) | Freshservice to Entra offboarding |
| Blink AI Agents (Reporter) | Call Reporter Agent |
| File / Utility (CSV parsing, PDF conversion) | Account Provisioning based on CSV, Call Reporter Agent |
| Core Runtime (Bash, Python) | Getting Started - Hello World, Account Provisioning based on CSV, Freshservice to Entra offboarding |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.