Blink Security Automation — Confidential

mgm — Customer Success Report

Generated 2026-08-30 | mgm-value-report.md
2026-08-30Report Date
1426Total Playbooks
376Unique Workflows (12m)
317,410,059Actions Automated (12m)
$81,638,390Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

1426
Total playbooks built
all non-deleted workflows
661
Active playbooks
currently enabled
376
Unique workflows executed (12m)
distinct workflows that ran
317,410,059
Actions automated (12m)
completed action steps
1,763,389.2h
Hours saved (12m)
@ 20s per action
$81,638,390
Money saved (12m)
@ $100K avg salary
33
New active workflows (last 30d)
recently created & enabled
7,671
Total cases managed
121 opened in last 12m
37d 15h
MTTR — mean time to resolve
closed cases, last 12m
20
Active AI agents
of 58 total
480,310
AI agent tasks executed (12m)
3,960 in last 30d
In the last 12 months, Blink automated: - 9,920 CrowdStrike case-modification checks via a 5-minute polling pipeline feeding the SOC case queue. - 40 domain takedown requests monitored through a ThreatQuotient integration. - 29 daily SOC shift pass-down reports summarized by an AI agent and emailed to the team. - 21 threat intelligence curation updates posted automatically as Jira comments. - 13 identity/role access reconciliations processed from SharePoint-sourced baseline data. - 4 case management data-integrity repairs run to fix broken bidirectional case links.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Platform Onboarding0 executions
0.0%
1
0 active
Agentic SOC — AI-Driven Case Investigation0 executions
0.0%
14
13 active
Case Management & SOAR
  • 9,920CrowdStrike case-modification checks processed
  • 29Daily SOC shift pass-down reports generated
  • 4Case management data-integrity repairs run
2.2%
4
4 active
Threat Intel Ingest & Curation
  • 40Domain takedown requests monitored
  • 21Threat intel curation updates posted to Jira
0.0%
2
2 active
SOC Analyst Response Actions — Identity & Endpoint0 executions
0.0%
4
4 active
Security Reporting Dashboard (POC)0 executions
0.0%
1
1 active
Access Review & Identity Reconciliation
  • 13Identity/role access reconciliations processed
0.0%
1
1 active
Total10,678 executions100%
27
25 active

Use Case Growth Over Time

1060 unique playbooks  |  7 operational use cases  |  491,420 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Threat Intel Ingest & Curation
ThreatQuotient Cisco Umbrella Falcon LogScale Jira
SOC Analyst Response Actions — Identity & Endpoint
Falcon LogScale CrowdStrike Microsoft Entra ID
Case Management & SOAR
Jira Agents Email CrowdStrike
Access Review & Identity Reconciliation
SharePoint Email

04Key Observations

✓  Strengths

Strengths

  • CrowdStrike case management is now a core automated capability — a 5-minute polling pipeline (Crowdstrike Messages) processed nearly 10,000 case-modification checks in the last 12 months.
  • An AI-driven "Agentic SOC" case investigation framework is deployed in parallel across two workspaces, including an evaluation harness (Main Evaluation - Evaluate On Cases dataset) that scores agent predictions against analyst-labeled outcomes before wider rollout.
  • Daily SOC shift pass-down reporting and CTI curation metrics reporting are automated end-to-end into email and Jira, cutting manual reporting overhead.
  • Standardized on-demand response actions now exist for common identity and endpoint containment steps (session revocation, MFA removal, host isolation).

###

△  Gaps & Growth Opportunities

Gaps

  • The Agentic SOC investigation framework and the identity/EDR response playbooks show 0 recorded executions — they appear built and tested but not yet in active production use.
  • Coverage remains concentrated in SOC; Cloud Security and Vulnerability Management are still unpopulated.
  • The Security Reporting Dashboard is a single proof-of-concept with no executions — no production security metrics dashboard exists yet.

Recommended Next Steps

  • Move the Agentic SOC framework and the identity/EDR response playbooks from built-but-idle to production use, and track execution volume against the evaluation harness's accuracy scoring.
  • Expand automation coverage into Cloud Security and Vulnerability Management, which remain unaddressed.
  • Operationalize the HTML dashboard proof-of-concept into a scheduled security metrics reporting playbook.
Appendices
A Case Management 121 cases (12m) | MTTR 37d 15h

Case Management

Total Cases (all-time)
7,671
121 opened in last 12m
Cases Opened (30d)
4
2 closed in last 30d
Cases Closed (12m)
88
of 121 opened
MTTR
37d 15h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Cyber Defense - Special Projects 7,622 90 88 37d 15h
Cyber Defense - Incident Response 24 24 0 N/A
Cloud Team - IOMs 18 0 0 N/A
AI SOC Test Workspace 5 5 0 N/A
ori@blinkops.com 2 2 0 N/A
B AI Agents 20 active | 480,310 tasks (12m)

AI Agents

Active Agents
20
of 58 total
Tasks Executed (12m)
480,310
3,960 in last 30d
Data Usage (12m)
28,171,320,129
617,753,452 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 JSON Summarizers Incident Response (2026) - Automation Hub 201,589 841 4,130,415,371
2 Stephen (6/22/2026 updated) Incident Response (2026) - Automation Hub 83,469 2,456 12,538,974,224
3 Summarize Cyber Defense - Incident Response 62,390 0 944,316,799
4 MITRE Finder Incident Response (2026) - Automation Hub 49,707 625 3,588,520,511
5 StephenAI - Alert Verdict Cyber Defense - Incident Response 36,961 0 614,347,926
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Incident Response (2026) - Automation Hub354,342
Cyber Defense - Incident Response125,873
Threat Vulnerability Management Workspace71
AI SOC Test Workspace23
slacey@mgmresorts.com1
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
43
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Microsoft Purview - Incoming 00
2 Blackhat 2024 00
3 MGM YTD - 2024 00
4 Dashboard Test 00
5 Automation Weekly 00

Webforms

Forms
11
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Static WebForm 00
2 Automation or Jira Incident is Broken 00
3 header 00
4 Workday Employee Lookup 00
5 Stephen is in his office, ask him anything! 00
D Full Use Case Analysis 7 use cases | 491,420 executions (12m)

Business KPIs

Metric Count Playbook
CrowdStrike case-modification checks processed 9,920 Crowdstrike Messages
Domain takedown requests monitored 40 Domain Takedown Monitor
Daily SOC shift pass-down reports generated 29 Daily Pass Down
Threat intel curation updates posted to Jira 21 CTI Metrics - Daily TVM Passdown Updates via Jira Comment Submissions
Identity/role access reconciliations processed 13 BaselinToBackdoorAutomation
Case management data-integrity repairs run 4 Alert Glossary - Bidirectional Repair
In the last 12 months, Blink automated: - 9,920 CrowdStrike case-modification checks via a 5-minute polling pipeline feeding the SOC case queue. - 40 domain takedown requests monitored through a ThreatQuotient integration. - 29 daily SOC shift pass-down reports summarized by an AI agent and emailed to the team. - 21 threat intelligence curation updates posted automatically as Jira comments. - 13 identity/role access reconciliations processed from SharePoint-sourced baseline data. - 4 case management data-integrity repairs run to fix broken bidirectional case links.

Use Case Summary

Use Case Category Subcategory Playbook Count Total Executions
Platform Onboarding Other DevOps & release automation 1 0
Agentic SOC — AI-Driven Case Investigation SOC Agentic SOC 28 0
Case Management & SOAR SOC Case mgmt & SOAR 4 9,953
Threat Intel Ingest & Curation SOC Threat intel ingest & curation 2 61
SOC Analyst Response Actions — Identity & Endpoint SOC Identity threat response; EDR containment & response 4 0
Security Reporting Dashboard (POC) GRC Security metrics & reporting 1 0
Access Review & Identity Reconciliation IAM Access review & group mgmt 1 13

Use Cases

1. Platform Onboarding

Description: A starter template used during initial platform onboarding to verify that the Blink automation environment is operational. It exercises core runtime primitives (print, Bash, Python) to confirm the workspace is healthy.

Business problem solved: Validates that the automation platform is correctly configured and accessible before any production workflows are deployed.

Integrations: Core runtime only (internal print, Bash shell, Python interpreter — no external integrations).

Playbooks

Playbook Executions (12 mo) Category Subcategory
Getting Started - Hello World 0 Other DevOps & release automation

2. Agentic SOC — AI-Driven Case Investigation

Description: An end-to-end agentic framework that investigates SOC cases autonomously: retrieving case and alert context, sanitizing and truncating payloads to fit model context budgets, pulling organizational context (asset inventory, VIP users, technology stack, investigation guidelines), running AI-driven investigations through subflows, and evaluating agent predictions against analyst-labeled case outcomes. The identical framework is deployed in parallel across two workspaces.

Business problem solved: Reduces manual SOC analyst triage time by equipping an AI agent with the same case context, asset inventory, and guidelines a human analyst would use, then automatically running and scoring its investigations before wider production rollout.

Integrations: Blink Tables, HTTP, internal case management system, Python, agent/subflow framework (automations.*).

Playbooks

Playbook Executions (12 mo) Category Subcategory
Agent Ability - Get Org Assets 0 SOC Agentic SOC
Agent Ability - Get VIP Users 0 SOC Agentic SOC
Agent Ability - Get Investigation Guidelines 0 SOC Agentic SOC
Agent Ability - Get Org Technological Stack 0 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 0 SOC Agentic SOC
Utility - Truncate Case & Alert 0 SOC Agentic SOC
Utility - Sanitize Case From Prior Investigation 0 SOC Agentic SOC
Utility - Refresh investigation 0 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 0 SOC Agentic SOC
Webhook - Run AI Investigation 0 SOC Agentic SOC
Load cases taggings from csv 0 SOC Agentic SOC
Load cases predictions from conclusions 0 SOC Agentic SOC
Refresh investigations on case dataset 0 SOC Agentic SOC
Main Evaluation - Evaluate On Cases dataset 0 SOC Agentic SOC
Agent Ability - Get Org Assets 0 SOC Agentic SOC
Agent Ability - Get VIP Users 0 SOC Agentic SOC
Agent Ability - Get Investigation Guidelines 0 SOC Agentic SOC
Agent Ability - Get Org Technological Stack 0 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 0 SOC Agentic SOC
Utility - Truncate Case & Alert 0 SOC Agentic SOC
Utility - Sanitize Case From Prior Investigation 0 SOC Agentic SOC
Utility - Refresh investigation 0 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 0 SOC Agentic SOC
Webhook - Run AI Investigation 0 SOC Agentic SOC
Load cases taggings from csv 0 SOC Agentic SOC
Load cases predictions from conclusions 0 SOC Agentic SOC
Refresh investigations on case dataset 0 SOC Agentic SOC
Main Evaluation - Evaluate On Cases dataset 0 SOC Agentic SOC

3. Case Management & SOAR

Description: Keeps CrowdStrike case data synchronized and actionable across the SOC: polling for newly modified cases on a 5-minute cadence, triaging Message Center alerts by reporter and status, repairing broken bidirectional case links, and generating an AI-summarized daily shift pass-down that is emailed to the team.

Business problem solved: Reduces manual case triage and shift-handoff overhead by keeping the case queue current and by automatically producing the daily pass-down report analysts previously had to compile by hand.

Integrations: CrowdStrike (Identity Protection / case API), Jira, Blink Core Email and SMTP (SendGrid), an AI summarization agent, and the internal case management system.

Playbooks

Playbook Executions (12 mo) Category Subcategory
Crowdstrike Messages 9920 SOC Case mgmt & SOAR
Daily Pass Down 29 SOC Case mgmt & SOAR
Alert Glossary - Bidirectional Repair 4 SOC Case mgmt & SOAR
New Message Center alert 0 SOC Case mgmt & SOAR

4. Threat Intel Ingest & Curation

Description: Automates recurring threat intelligence operational tasks — monitoring ThreatQuotient for domain takedown requests and posting daily curation metrics as Jira comments on the intel-curation tracking ticket.

Business problem solved: Keeps threat intel program metrics and takedown status current without manual reporting, and gives stakeholders a running audit trail directly in Jira.

Integrations: ThreatQuotient, Falcon LogScale, Jira.

Playbooks

Playbook Executions (12 mo) Category Subcategory
Domain Takedown Monitor 40 SOC Threat intel ingest & curation
CTI Metrics - Daily TVM Passdown Updates via Jira Comment Submissions 21 SOC Threat intel ingest & curation

5. SOC Analyst Response Actions — Identity & Endpoint

Description: On-demand response actions an analyst can trigger during an identity or endpoint incident: looking up a user's CrowdStrike Identity Protection alert history, revoking an Azure AD session, removing MFA devices, or isolating an endpoint by computer name.

Business problem solved: Standardizes common containment steps for identity and endpoint incidents into single-click, on-demand playbooks instead of manual console work across multiple tools.

Integrations: Falcon LogScale, CrowdStrike (device management), Microsoft Entra ID / Active Directory.

Playbooks

Playbook Executions (12 mo) Category Subcategory
Crowdstrike IDP History Lookup 0 SOC Identity threat response
Revoke Azure AD Session By Emp ID 0 SOC Identity threat response
Remove MFA Devices by Employee ID 0 SOC Identity threat response
CrowdStrike Isolate a Computer By Name 0 SOC EDR containment & response

6. Security Reporting Dashboard (POC)

Description: A proof-of-concept workflow that generates an HTML dashboard from Python and stores it, evaluating dashboard generation as a delivery mechanism for future security reporting.

Business problem solved: Tests the feasibility of an automation-generated security metrics dashboard before committing to a production reporting playbook.

Integrations: Core Python only (no external integrations yet — proof-of-concept).

Playbooks

Playbook Executions (12 mo) Category Subcategory
HTML Dashboard Test 0 GRC Security metrics & reporting

7. Access Review & Identity Reconciliation

Description: Pulls a role/identity CSV from SharePoint, parses each row, and makes an API call per identity to reconcile baseline access against current state, flagging drift between expected and actual access before emailing the results to the security team.

Business problem solved: Automates detection of unauthorized or drifted access ("baseline-to-backdoor" checks) that would otherwise require manually cross-referencing SharePoint-tracked access baselines against live systems.

Integrations: SharePoint, internal/HTTP API calls, Blink Core Email.

Playbooks

Playbook Executions (12 mo) Category Subcategory
BaselinToBackdoorAutomation 13 IAM Access review & group mgmt

Key Observations

Strengths

  • CrowdStrike case management is now a core automated capability — a 5-minute polling pipeline (Crowdstrike Messages) processed nearly 10,000 case-modification checks in the last 12 months.
  • An AI-driven "Agentic SOC" case investigation framework is deployed in parallel across two workspaces, including an evaluation harness (Main Evaluation - Evaluate On Cases dataset) that scores agent predictions against analyst-labeled outcomes before wider rollout.
  • Daily SOC shift pass-down reporting and CTI curation metrics reporting are automated end-to-end into email and Jira, cutting manual reporting overhead.
  • Standardized on-demand response actions now exist for common identity and endpoint containment steps (session revocation, MFA removal, host isolation).

Gaps

  • The Agentic SOC investigation framework and the identity/EDR response playbooks show 0 recorded executions — they appear built and tested but not yet in active production use.
  • Coverage remains concentrated in SOC; Cloud Security and Vulnerability Management are still unpopulated.
  • The Security Reporting Dashboard is a single proof-of-concept with no executions — no production security metrics dashboard exists yet.

Recommended Next Steps

  • Move the Agentic SOC framework and the identity/EDR response playbooks from built-but-idle to production use, and track execution volume against the evaluation harness's accuracy scoring.
  • Expand automation coverage into Cloud Security and Vulnerability Management, which remain unaddressed.
  • Operationalize the HTML dashboard proof-of-concept into a scheduled security metrics reporting playbook.
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
mgm microsoft-teams my_microsoft_teams_connection 2026-08-20
mgm microsoft-outlook my_microsoft_outlook_connection 2026-08-20