01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Platform Onboarding | 0 executions | 0.0% | 1 0 active |
| Agentic SOC — AI-Driven Case Investigation | 0 executions | 0.0% | 14 13 active |
| Case Management & SOAR |
| 2.2% | 4 4 active |
| Threat Intel Ingest & Curation |
| 0.0% | 2 2 active |
| SOC Analyst Response Actions — Identity & Endpoint | 0 executions | 0.0% | 4 4 active |
| Security Reporting Dashboard (POC) | 0 executions | 0.0% | 1 1 active |
| Access Review & Identity Reconciliation |
| 0.0% | 1 1 active |
| Total | 10,678 executions | 100% | 27 25 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- CrowdStrike case management is now a core automated capability — a 5-minute polling pipeline (Crowdstrike Messages) processed nearly 10,000 case-modification checks in the last 12 months.
- An AI-driven "Agentic SOC" case investigation framework is deployed in parallel across two workspaces, including an evaluation harness (Main Evaluation - Evaluate On Cases dataset) that scores agent predictions against analyst-labeled outcomes before wider rollout.
- Daily SOC shift pass-down reporting and CTI curation metrics reporting are automated end-to-end into email and Jira, cutting manual reporting overhead.
- Standardized on-demand response actions now exist for common identity and endpoint containment steps (session revocation, MFA removal, host isolation).
###
Gaps
- The Agentic SOC investigation framework and the identity/EDR response playbooks show 0 recorded executions — they appear built and tested but not yet in active production use.
- Coverage remains concentrated in SOC; Cloud Security and Vulnerability Management are still unpopulated.
- The Security Reporting Dashboard is a single proof-of-concept with no executions — no production security metrics dashboard exists yet.
Recommended Next Steps
- Move the Agentic SOC framework and the identity/EDR response playbooks from built-but-idle to production use, and track execution volume against the evaluation harness's accuracy scoring.
- Expand automation coverage into Cloud Security and Vulnerability Management, which remain unaddressed.
- Operationalize the HTML dashboard proof-of-concept into a scheduled security metrics reporting playbook.
A Case Management 121 cases (12m) | MTTR 37d 15h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Cyber Defense - Special Projects | 7,622 | 90 | 88 | 37d 15h |
| Cyber Defense - Incident Response | 24 | 24 | 0 | N/A |
| Cloud Team - IOMs | 18 | 0 | 0 | N/A |
| AI SOC Test Workspace | 5 | 5 | 0 | N/A |
| ori@blinkops.com | 2 | 2 | 0 | N/A |
B AI Agents 20 active | 480,310 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | JSON Summarizers | Incident Response (2026) - Automation Hub | 201,589 | 841 | 4,130,415,371 |
| 2 | Stephen (6/22/2026 updated) | Incident Response (2026) - Automation Hub | 83,469 | 2,456 | 12,538,974,224 |
| 3 | Summarize | Cyber Defense - Incident Response | 62,390 | 0 | 944,316,799 |
| 4 | MITRE Finder | Incident Response (2026) - Automation Hub | 49,707 | 625 | 3,588,520,511 |
| 5 | StephenAI - Alert Verdict | Cyber Defense - Incident Response | 36,961 | 0 | 614,347,926 |
| Workspace | Tasks (12m) |
|---|---|
| Incident Response (2026) - Automation Hub | 354,342 |
| Cyber Defense - Incident Response | 125,873 |
| Threat Vulnerability Management Workspace | 71 |
| AI SOC Test Workspace | 23 |
| slacey@mgmresorts.com | 1 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Microsoft Purview - Incoming | 0 | 0 |
| 2 | Blackhat 2024 | 0 | 0 |
| 3 | MGM YTD - 2024 | 0 | 0 |
| 4 | Dashboard Test | 0 | 0 |
| 5 | Automation Weekly | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Static WebForm | 0 | 0 |
| 2 | Automation or Jira Incident is Broken | 0 | 0 |
| 3 | header | 0 | 0 |
| 4 | Workday Employee Lookup | 0 | 0 |
| 5 | Stephen is in his office, ask him anything! | 0 | 0 |
D Full Use Case Analysis 7 use cases | 491,420 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| CrowdStrike case-modification checks processed | 9,920 | Crowdstrike Messages |
| Domain takedown requests monitored | 40 | Domain Takedown Monitor |
| Daily SOC shift pass-down reports generated | 29 | Daily Pass Down |
| Threat intel curation updates posted to Jira | 21 | CTI Metrics - Daily TVM Passdown Updates via Jira Comment Submissions |
| Identity/role access reconciliations processed | 13 | BaselinToBackdoorAutomation |
| Case management data-integrity repairs run | 4 | Alert Glossary - Bidirectional Repair |
Use Case Summary
| Use Case | Category | Subcategory | Playbook Count | Total Executions |
|---|---|---|---|---|
| Platform Onboarding | Other | DevOps & release automation | 1 | 0 |
| Agentic SOC — AI-Driven Case Investigation | SOC | Agentic SOC | 28 | 0 |
| Case Management & SOAR | SOC | Case mgmt & SOAR | 4 | 9,953 |
| Threat Intel Ingest & Curation | SOC | Threat intel ingest & curation | 2 | 61 |
| SOC Analyst Response Actions — Identity & Endpoint | SOC | Identity threat response; EDR containment & response | 4 | 0 |
| Security Reporting Dashboard (POC) | GRC | Security metrics & reporting | 1 | 0 |
| Access Review & Identity Reconciliation | IAM | Access review & group mgmt | 1 | 13 |
Use Cases
1. Platform Onboarding
Description: A starter template used during initial platform onboarding to verify that the Blink automation environment is operational. It exercises core runtime primitives (print, Bash, Python) to confirm the workspace is healthy.
Business problem solved: Validates that the automation platform is correctly configured and accessible before any production workflows are deployed.
Integrations: Core runtime only (internal print, Bash shell, Python interpreter — no external integrations).
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Getting Started - Hello World | 0 | Other | DevOps & release automation |
2. Agentic SOC — AI-Driven Case Investigation
Description: An end-to-end agentic framework that investigates SOC cases autonomously: retrieving case and alert context, sanitizing and truncating payloads to fit model context budgets, pulling organizational context (asset inventory, VIP users, technology stack, investigation guidelines), running AI-driven investigations through subflows, and evaluating agent predictions against analyst-labeled case outcomes. The identical framework is deployed in parallel across two workspaces.
Business problem solved: Reduces manual SOC analyst triage time by equipping an AI agent with the same case context, asset inventory, and guidelines a human analyst would use, then automatically running and scoring its investigations before wider production rollout.
Integrations: Blink Tables, HTTP, internal case management system, Python, agent/subflow framework (automations.*).
Playbooks
3. Case Management & SOAR
Description: Keeps CrowdStrike case data synchronized and actionable across the SOC: polling for newly modified cases on a 5-minute cadence, triaging Message Center alerts by reporter and status, repairing broken bidirectional case links, and generating an AI-summarized daily shift pass-down that is emailed to the team.
Business problem solved: Reduces manual case triage and shift-handoff overhead by keeping the case queue current and by automatically producing the daily pass-down report analysts previously had to compile by hand.
Integrations: CrowdStrike (Identity Protection / case API), Jira, Blink Core Email and SMTP (SendGrid), an AI summarization agent, and the internal case management system.
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Crowdstrike Messages | 9920 | SOC | Case mgmt & SOAR |
| Daily Pass Down | 29 | SOC | Case mgmt & SOAR |
| Alert Glossary - Bidirectional Repair | 4 | SOC | Case mgmt & SOAR |
| New Message Center alert | 0 | SOC | Case mgmt & SOAR |
4. Threat Intel Ingest & Curation
Description: Automates recurring threat intelligence operational tasks — monitoring ThreatQuotient for domain takedown requests and posting daily curation metrics as Jira comments on the intel-curation tracking ticket.
Business problem solved: Keeps threat intel program metrics and takedown status current without manual reporting, and gives stakeholders a running audit trail directly in Jira.
Integrations: ThreatQuotient, Falcon LogScale, Jira.
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Domain Takedown Monitor | 40 | SOC | Threat intel ingest & curation |
| CTI Metrics - Daily TVM Passdown Updates via Jira Comment Submissions | 21 | SOC | Threat intel ingest & curation |
5. SOC Analyst Response Actions — Identity & Endpoint
Description: On-demand response actions an analyst can trigger during an identity or endpoint incident: looking up a user's CrowdStrike Identity Protection alert history, revoking an Azure AD session, removing MFA devices, or isolating an endpoint by computer name.
Business problem solved: Standardizes common containment steps for identity and endpoint incidents into single-click, on-demand playbooks instead of manual console work across multiple tools.
Integrations: Falcon LogScale, CrowdStrike (device management), Microsoft Entra ID / Active Directory.
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Crowdstrike IDP History Lookup | 0 | SOC | Identity threat response |
| Revoke Azure AD Session By Emp ID | 0 | SOC | Identity threat response |
| Remove MFA Devices by Employee ID | 0 | SOC | Identity threat response |
| CrowdStrike Isolate a Computer By Name | 0 | SOC | EDR containment & response |
6. Security Reporting Dashboard (POC)
Description: A proof-of-concept workflow that generates an HTML dashboard from Python and stores it, evaluating dashboard generation as a delivery mechanism for future security reporting.
Business problem solved: Tests the feasibility of an automation-generated security metrics dashboard before committing to a production reporting playbook.
Integrations: Core Python only (no external integrations yet — proof-of-concept).
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| HTML Dashboard Test | 0 | GRC | Security metrics & reporting |
7. Access Review & Identity Reconciliation
Description: Pulls a role/identity CSV from SharePoint, parses each row, and makes an API call per identity to reconcile baseline access against current state, flagging drift between expected and actual access before emailing the results to the security team.
Business problem solved: Automates detection of unauthorized or drifted access ("baseline-to-backdoor" checks) that would otherwise require manually cross-referencing SharePoint-tracked access baselines against live systems.
Integrations: SharePoint, internal/HTTP API calls, Blink Core Email.
Playbooks
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| BaselinToBackdoorAutomation | 13 | IAM | Access review & group mgmt |
Key Observations
Strengths
- CrowdStrike case management is now a core automated capability — a 5-minute polling pipeline (Crowdstrike Messages) processed nearly 10,000 case-modification checks in the last 12 months.
- An AI-driven "Agentic SOC" case investigation framework is deployed in parallel across two workspaces, including an evaluation harness (Main Evaluation - Evaluate On Cases dataset) that scores agent predictions against analyst-labeled outcomes before wider rollout.
- Daily SOC shift pass-down reporting and CTI curation metrics reporting are automated end-to-end into email and Jira, cutting manual reporting overhead.
- Standardized on-demand response actions now exist for common identity and endpoint containment steps (session revocation, MFA removal, host isolation).
Gaps
- The Agentic SOC investigation framework and the identity/EDR response playbooks show 0 recorded executions — they appear built and tested but not yet in active production use.
- Coverage remains concentrated in SOC; Cloud Security and Vulnerability Management are still unpopulated.
- The Security Reporting Dashboard is a single proof-of-concept with no executions — no production security metrics dashboard exists yet.
Recommended Next Steps
- Move the Agentic SOC framework and the identity/EDR response playbooks from built-but-idle to production use, and track execution volume against the evaluation harness's accuracy scoring.
- Expand automation coverage into Cloud Security and Vulnerability Management, which remain unaddressed.
- Operationalize the HTML dashboard proof-of-concept into a scheduled security metrics reporting playbook.
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| mgm | microsoft-teams | my_microsoft_teams_connection | 2026-08-20 |
| mgm | microsoft-outlook | my_microsoft_outlook_connection | 2026-08-20 |