01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — AI-Driven Alert Triage & Case Investigation |
| 0.4% | 18 18 active |
| Alert & IOC Enrichment Pipeline | 170 executions | 0.3% | 29 29 active |
| Identity & Endpoint Context Lookup for SOC Investigations | 2 executions | 0.0% | 15 15 active |
| Identity Threat Response — Compromised Account Remediation (RADAR) |
| 0.4% | 9 9 active |
| Authentication Event Monitoring & Log Pipeline | 42,412 executions | 86.0% | 1 1 active |
| Security Agent Health Validation (ServiceNow Self-Service) |
| 3.3% | 9 8 active |
| On-Demand Vulnerability Scan Requests (Qualys via ServiceNow) |
| 0.2% | 1 1 active |
| API Security Findings & Application Ownership Enrichment |
| 6.4% | 19 18 active |
| Zero Trust Access Inventory & Provisioning (Akamai EAA) |
| 0.5% | 12 11 active |
| AI-Assisted Firewall & Network Policy Risk Review |
| 0.3% | 3 3 active |
| GitHub Exposed Secret Detection & Owner Notification |
| 0.6% | 2 2 active |
| Teams Notification & Workflow Failure Alerting Infrastructure |
| 0.7% | 11 10 active |
| Blink Platform Administration & Self-Documentation |
| 0.8% | 30 26 active |
| Infrastructure Uptime & Availability Monitoring | 0 executions | 0.0% | 1 1 active |
| Total | 49,242 executions | 100% | 160 152 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Agentic SOC is the deployment's center of gravity. The three SOC-focused use cases (Alert Triage & Case Investigation, Alert & IOC Enrichment Pipeline, Identity & Endpoint Context Lookup) together span 61 playbooks and represent the most architecturally mature part of the deployment — a full case-management lifecycle (ingest → enrich → investigate → decide → close/escalate) built on reusable subflows and dedicated "Agent Ability" building blocks that expose enrichment and case-context actions directly to an AI decision layer.
- Identity remediation is fully self-service and bidirectional. The RADAR use case covers both single-user and bulk compromised-account response (MFA reset, password reset, token revocation, emergency termination) across production and pre-production Entra ID tenants, indicating the automation is trusted for high-stakes, high-blast-radius identity actions rather than read-only investigation.
- Deep, purpose-built integration with Maersk's internal platforms. Beyond commercial security tools, Blink integrates natively with Maersk-proprietary systems — MRMP (Resource Management Plane), MAC (Application Catalog), MSA (Service Atlas), and Stargate (internal identity/API gateway) — to enrich API security findings and Zero Trust access requests with application-ownership context. This is a meaningfully deeper integration footprint than typical out-of-the-box SOAR connectors.
- Broad third-party ecosystem already wired in. Twenty-plus distinct integrations are active across the deployment, spanning EDR (CrowdStrike), vulnerability management (Qualys, Trend Micro Deep Security), API security (NoName Security), threat intel/enrichment (VirusTotal, AbuseIPDB, URLScan, Whois), network/cloud security (FireMon, Check Point, Akamai EAA, Zscaler ZIA, Forescout), identity (Entra ID/Active Directory, Okta, Google Workspace), and collaboration/ITSM (ServiceNow, GitHub, Jira, Confluence, Microsoft Teams, SendGrid, Slack) — giving Blink a genuine cross-domain orchestration role rather than sitting inside a single tool silo.
- Operational self-sufficiency. A dedicated set of platform-administration playbooks keeps Confluence documentation, connection health, and table/data infrastructure in sync automatically, and failures in any Blink automation are proactively routed to the engineering team via Teams — reducing the operational overhead of running the platform itself.
Gaps / opportunities
- Vulnerability management is comparatively thin. Only one use case (Qualys scan requests via ServiceNow) is mapped to the Vulnerability Mgmt category. Given Qualys and Trend Micro Deep Security are already integrated for agent-health checks, there is clear headroom to extend automation into scan-result triage, remediation ticketing, or SLA tracking rather than just scan initiation.
- GRC coverage is narrow. Only the GitHub exposed-secret detection/notification workflow is currently classified under GRC. Compliance-control monitoring, audit evidence collection, and policy-exception tracking appear to be white space relative to the SOC investment.
- No dedicated IAM-category use case. Identity actions today are scoped specifically to threat response (RADAR) and investigative lookups rather than broader lifecycle IAM (joiner/mover/leaver, access reviews, entitlement certification) — a natural adjacent expansion given the strength of the existing Entra ID/Okta integrations.
- High-volume "Authentication Event Monitoring" workflow is a thin filter, not a full pipeline. At 42,412 executions it is by far the highest-volume workflow in the tenant, but it currently performs a single filtering step against Azure Monitor events rather than downstream enrichment or case creation — a candidate for building out into a fuller detection pipeline.
- Environment sprawl. Most playbooks are deployed near-identically across up to 8 workspaces (production, pre-production, various dev/Eng-Dev, and "Connections & Runners" environments). This is expected for safe change management, but the ~22 leftover test/example/scratch workflows (e.g.,
EXAMPLE - *,Funny AI,New Test Workflow) identified during this analysis represent a small, low-risk cleanup opportunity to keep production workspaces lean.
Integration ecosystem summary
Security tooling: CrowdStrike · Qualys · Trend Micro Deep Security · NoName Security · VirusTotal · AbuseIPDB · URLScan · FireMon · Check Point · Akamai EAA · Zscaler ZIA · Forescout
Identity: Microsoft Entra ID / Active Directory · Okta · Google Workspace
ITSM & collaboration: ServiceNow · GitHub · Jira · Confluence · Microsoft Teams · Slack · SendGrid
Cloud & internal platforms: Azure Monitor · Azure Blob Storage · Maersk MRMP · Maersk MAC · Maersk MSA · Stargate
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 6 active | 94 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink - Decision Maker | guy.gurman@blinkops.com | 44 | 0 | 3,248,195 |
| 2 | CTI Report Helper | guy.gurman@blinkops.com | 22 | 0 | 987,538 |
| 3 | RFI Submission Expert | guy.gurman@blinkops.com | 17 | 0 | 1,882,164 |
| 4 | Micro Agent - Historical Case Check | guy.gurman@blinkops.com | 5 | 0 | 170,751 |
| 5 | SOC Agent - Phishing Agent | guy.gurman@blinkops.com | 4 | 0 | 304,910 |
| Workspace | Tasks (12m) |
|---|---|
| guy.gurman@blinkops.com | 94 |
| Maersk - Eng. - Prod - Privileged | 0 |
| Maersk - CTI - Test - Privileged | 0 |
| Demo | 0 |
| Maersk - Eng - Dev | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 14 use cases | 49,329 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security agent health checks completed via ServiceNow self-service | 1,259 | ServiceNow Agent Health Check |
| Compromised-account remediation actions executed for a single user (MFA reset, password reset, token revoke) | 173 | RADAR: Single User Remediation - Form |
| Bulk compromised-account remediation requests processed | 26 | RADAR: Bulk User Remediation - Form |
| Firewall rule sets analyzed by AI for risk before deployment | 150 | Firemon - AI Risk Analysis |
| GitHub secret-exposure scans processed and routed toward application owners | 148 | Process Github Exposed Secret CEA |
| Application-owner Teams alerts sent for exposed secrets | 131 | Create CEA group chat and send notifications |
| Vulnerability scans requested and orchestrated via ServiceNow self-service | 113 | Qualys ServiceNow Vulnerability Scan Request |
| AI-driven SOC decisions rendered on open security cases | 42 | Agentic SOC - Decision Layer |
| New Zero Trust application-access requests automatically evaluated | 40 | EAA Application Request Orchestration |
| AI-enriched API-security posture reports generated | 96 | Main - NoName - AI Analysis |
| AI-generated incident enrichment reports created and emailed | 15 | Response - Generate a report |
| Request-for-Information submissions logged as security cases | 14 | WebForm - Create RFI Submission |
| Platform documentation pages kept in sync in Confluence automatically | 183 | Document BlinkOps Workflows into Confluence |
| Automation failure alerts sent to the engineering team | 96 | Notify Group Chat On BlinkOps Workflow Failure |
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12mo) |
|---|---|---|---|---|
| 1 | Agentic SOC — AI-Driven Alert Triage & Case Investigation | SOC | 18 | 178 |
| 2 | Alert & IOC Enrichment Pipeline | SOC | 28 | 170 |
| 3 | Identity & Endpoint Context Lookup for SOC Investigations | SOC | 15 | 2 |
| 4 | Identity Threat Response — Compromised Account Remediation (RADAR) | SOC | 9 | 202 |
| 5 | Authentication Event Monitoring & Log Pipeline | SOC | 1 | 42,412 |
| 6 | Security Agent Health Validation (ServiceNow Self-Service) | Other | 9 | 1,621 |
| 7 | On-Demand Vulnerability Scan Requests (Qualys via ServiceNow) | Vulnerability Mgmt | 1 | 113 |
| 8 | API Security Findings & Application Ownership Enrichment | Cloud Security | 19 | 3,230 |
| 9 | Zero Trust Access Inventory & Provisioning (Akamai EAA) | Cloud Security | 12 | 393 |
| 10 | AI-Assisted Firewall & Network Policy Risk Review | Cloud Security | 3 | 155 |
| 11 | GitHub Exposed Secret Detection & Owner Notification | GRC | 2 | 279 |
| 12 | Teams Notification & Workflow Failure Alerting Infrastructure | Other | 11 | 418 |
| 13 | Blink Platform Administration & Self-Documentation | Other | 30 | 387 |
| 14 | Infrastructure Uptime & Availability Monitoring | Other | 1 | 0 |
Use Cases
1. Agentic SOC — AI-Driven Alert Triage & Case Investigation
Category: SOC
Subcategories: Agentic SOC, Case mgmt & SOAR
Description:
An AI decision layer investigates every new security alert, decides the next action, and drives the case through triage, escalation, or closure with minimal analyst intervention.
Business problem solved:
Analysts were spending the bulk of their shift on repetitive first-pass triage instead of genuine threats, and case handling was inconsistent across shifts and analysts.
Integrations: Blink Case Management (SOAR) · Blink AI Agents · Jira · Email
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Process Alert | 19 | Ingests each new alert, extracts observables, de-duplicates into a new or existing case, and hands off to enrichment and response |
| Agentic SOC - Decision Layer | 42 | Core AI reasoning step that decides the next investigative or response action for an open case |
| Agentic SOC - Expert Agents | 21 | Routes a case to the specialized AI expert agent best suited to the alert type |
| Subflow - Agentic SOC - Main - AI Investigation | 21 | Orchestrates the end-to-end AI investigation cycle for a case |
| Agent Ability - Historical Case Checks | 21 | AI tool call that checks whether similar cases have been seen and handled before |
| Subflow - Response - Main Router | 20 | Routes every newly created case into the automated response pipeline |
| Response - Generate a report | 15 | Has an AI agent write an IOC enrichment report, renders it to PDF, and emails it out |
| WebForm - Create RFI Submission | 14 | Self-service form for analysts/teams to submit a Request for Information, auto-logged as a case |
| Utility - Refresh investigation | 5 | Re-triggers the AI investigation on a case when new information arrives |
| Agentic SOC - Close Case | 0 | Closes a case once the decision layer reaches a final disposition |
| Utility - Close Stale Cases | 0 | Housekeeping job that auto-closes cases that have gone inactive past SLA |
| SubFlow - Context Enrichment | 0 | Gathers the case and alert context the decision layer needs before it reasons about next steps |
| Comment On Case | 0 | AI tool call that posts analyst-facing commentary and findings onto a case |
| Jira Ticket - Ingestion | 0 | Ingests security tickets raised in Jira as new alerts into the case pipeline |
| Error Handling - Send Error Notification Email | 0 | Notifies the team by email when a step in the SOC pipeline fails |
| Agent Ability - Recommendation for case | 0 | AI tool call that generates a recommended response for a case |
| Agent Ability - Get Case | 0 | AI tool call that retrieves case details for the reasoning agent |
| Agent Ability - Get Alert | 0 | AI tool call that retrieves alert details for the reasoning agent |
2. Alert & IOC Enrichment Pipeline
Category: SOC
Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation
Description:
Automatically enriches every indicator of compromise (IP, URL, hash, domain) surfaced on an alert with threat-intelligence context before an analyst or AI agent ever looks at it.
Business problem solved:
Manually pivoting to VirusTotal, AbuseIPDB and internal asset data for every observable on every alert was the single biggest time sink in triage.
Integrations: VirusTotal · AbuseIPDB · URLScan · Whois · CrowdStrike · Crible SIEM
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Enrich Observables - Main Router | 53 | Central router that fans an alert's observables out to the right enrichment source by type |
| Subflow - Update Enrichment Data | 41 | Writes enrichment results back onto the observable/case record |
| Utility - Update Enrichment | 0 | Supporting utility that merges new enrichment data into an existing record |
| Enrich - Hash - VT | 11 | Looks up a file hash's reputation in VirusTotal |
| Enrich - IP - VT | 7 | Looks up an IP's reputation in VirusTotal |
| Enrich - IP - IPDB | 16 | Looks up an IP's reputation in AbuseIPDB |
| Enrich - URL - VT | 7 | Looks up a URL's reputation in VirusTotal |
| Enrich IP or Domain Using Whois | 0 | Pulls Whois registration data for an IP or domain observable |
| Enrich - Check If Observable inside Organization | 0 | Flags whether an observable belongs to Maersk's own IP/asset space before treating it as external |
| Analyze URL with URLScan | 0 | Submits a URL to URLScan for behavioral/visual analysis |
| Get Hash Info Using Crowdstrike | 0 | Looks up a file hash against CrowdStrike threat intelligence |
| Get Hash Info Using VirusTotal | 0 | Looks up a file hash against VirusTotal |
| Get End of Life Date for a Product | 0 | Checks whether a software product/version on an alert is past its end-of-life date |
| Get Observables by Case ID | 17 | AI tool call that retrieves all observables tied to a case for analysis |
| Query Observable | 0 | AI tool call that looks up a single observable's stored record |
| Utility - List Alert Observable Relations | 0 | Lists which observables are linked to a given alert |
| Utility - List Observable Alert Relations | 0 | Lists which alerts a given observable is linked to |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates a relation between an observable and an alert/case |
| Utility - Delete Observable Relation | 0 | Removes a relation between an observable and an alert/case |
| Utility - Add Observable Extraction Rule | 0 | Adds a new rule for how observables are extracted from a given alert template |
| Utility - Find Similar Cases Based on Observables | 0 | Searches for other cases sharing the same observables |
| Table Action - Validate Observables Extraction Template | 0 | Validates that an alert template is correctly configured to extract observables |
| Subflow - Missing Alert Template Notification | 0 | Alerts the team when an incoming alert type has no observable-extraction template configured |
| Agent Ability - Query Crible Siem for IOCs | 10 | AI tool call that queries the Crible SIEM for related indicators |
| Agent Ability - Query Observables by Content | 4 | AI tool call that searches observables by content/value |
| Agent Ability - Enrich using Virus Total | 4 | AI tool call that triggers VirusTotal enrichment on demand |
| Secure URL Screenshot Capture | 0 | Takes a sandboxed screenshot of a suspicious URL for analyst review |
| Run Dig Command | 0 | Runs a DNS lookup (dig) against a domain observable |
3. Identity & Endpoint Context Lookup for SOC Investigations
Category: SOC
Subcategories: Identity threat response, EDR containment & response
Description:
Gives the agentic SOC direct, on-demand access to identity providers and CrowdStrike so it can pull user context and take containment actions without an analyst switching consoles.
Business problem solved:
Confirming who a user is and whether their device needs to be isolated required analysts to log into four or five separate admin consoles per case.
Integrations: Microsoft Entra ID · Okta · GitHub · Google Workspace · Slack · CrowdStrike
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Get User Information Using Microsoft Entra ID | 0 | Looks up a user's identity and attributes in Entra ID for case context |
| Get User Information Using Okta | 0 | Looks up a user's identity and attributes in Okta for case context |
| Get User Information Using Github | 0 | Looks up a user's identity on GitHub for case context |
| Get User Information Using Google Workspace | 0 | Looks up a user's identity in Google Workspace for case context |
| Get User Information on Email Address Using Slack | 0 | Resolves a Slack user's identity from an email address |
| Okta Search for User Activity | 0 | Pulls a user's recent Okta activity/sign-in history for investigation |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Isolates or releases a host in CrowdStrike as a containment action |
| CrowdStrike RTR to a Single Host | 0 | Runs a real-time-response command on a single host for investigation or remediation |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a real-time-response command across a batch of hosts |
| Agent Ability - Get Org Assets | 2 | AI tool call that retrieves known organizational assets for context |
| Agent Ability - Get Org Technological Stack | 0 | AI tool call that retrieves the organization's technology stack for context |
| Agent Ability - Get Vendor Logo List | 0 | Supplies vendor logos used to render enrichment reports |
| Agent Ability - Get Observable Types From Case Management Settings | 0 | AI tool call that reads the configured observable types from case management settings |
| Agent Ability - Get Observable Reputations From Case Management Settings | 0 | AI tool call that reads configured reputation scoring from case management settings |
| Agent Ability - Get Observable Relation Types From Case Management Settings | 0 | AI tool call that reads configured relation types from case management settings |
4. Identity Threat Response — Compromised Account Remediation (RADAR)
Category: SOC
Subcategories: Identity threat response
Description:
Self-service RADAR forms let the SOC or helpdesk force a password reset, revoke tokens, or reset MFA for one user or a whole CSV list of users in a single submission.
Business problem solved:
Responding to a confirmed account compromise required manual, sequential admin-console work per affected user, slowing containment during active incidents.
Integrations: Microsoft Entra ID · Jira · Azure Automation
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| RADAR: Single User Remediation - Form | 173 | Self-service form to reset MFA, reset password, and/or revoke tokens for a single user |
| RADAR: Bulk User Remediation - Form | 26 | Self-service form to apply the same remediation actions to a CSV list of users at once |
| RADAR: Single User Remediation copy | 2 | Backend logic that executes the requested remediation actions for a single user |
| RADAR: Bulk User Remediation | 0 | Backend logic that executes the requested remediation actions across a batch of users |
| RADAR: Single User Emergency Termination | 0 | Immediately disables a single compromised account and its access |
| RADAR: Bulk User Emergency Termination | 0 | Immediately disables a batch of compromised accounts and their access |
| Entra ID: Read User from Production Tenant | 0 | Looks up a user's record in the production Entra ID tenant before remediation |
| Entra ID: Read User from Pre-Production tenant | 1 | Looks up a user's record in the pre-production Entra ID tenant before remediation |
| Respond - Reset Password | 0 | Triggers an Azure Automation runbook to reset a user's password and reports back the result |
5. Authentication Event Monitoring & Log Pipeline
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Description:
Continuously polls Azure Monitor for new events and filters out the authentication-related activity that matters to the SOC, feeding a high-volume log pipeline.
Business problem solved:
Authentication telemetry from Azure needed continuous, low-latency filtering so downstream detections only fire on relevant sign-in activity rather than the full event firehose.
Integrations: Azure Monitor
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| New Workflow 2 | 42,412 | Polls Azure Monitor for new events and filters for authentication-related activity |
6. Security Agent Health Validation (ServiceNow Self-Service)
Category: Other
Subcategories: Endpoint hygiene & MDM ops
Description:
When someone raises a ServiceNow request about a missing or outdated endpoint security agent, this automation checks CrowdStrike, Qualys and Trend Micro directly and writes the answer back onto the ticket.
Business problem solved:
IT operations were manually cross-referencing three separate security-agent consoles for every ServiceNow ticket about endpoint agent health, delaying ticket resolution.
Integrations: ServiceNow · CrowdStrike · Qualys · Trend Micro Deep Security
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| ServiceNow Agent Health Check | 1,259 | Validates whether the required security agents are installed and healthy on the hosts named in a ServiceNow request, then comments and updates the ticket |
| Validate Agent Health | 86 | Runs the underlying health checks against a host across the relevant security agents |
| Retrieve ServiceNow Request Variables V2 | 161 | Parses the submitted catalog-item variables off a ServiceNow request so downstream steps can act on them |
| Search Crowdstrike for Host Details | 29 | Looks up a host's CrowdStrike sensor status and details |
| Search for Trend Deep Security Computer | 29 | Looks up a host's Trend Micro Deep Security agent status |
| Search Qualys Global IT Asset Inventory | 35 | Looks up a host's Qualys agent status in the global IT asset inventory |
| Update CS Agent Threshold Versions | 12 | Weekly job that refreshes the accepted CrowdStrike sensor version thresholds from CrowdStrike's own policy list |
| Update Qualys Agent Version Thresholds | 7 | Refreshes the accepted Qualys agent version thresholds used by the health check |
| Update Qualys Network Scanners List | 3 | Keeps the list of Qualys network scanners used for validation up to date |
7. On-Demand Vulnerability Scan Requests (Qualys via ServiceNow)
Category: Vulnerability Mgmt
Subcategories: Vuln scan lifecycle automation
Description:
Lets requesters submit a ServiceNow catalog item with a list of IPs and have Blink validate the addresses and kick off a Qualys vulnerability scan automatically.
Business problem solved:
Ad-hoc vulnerability scan requests sat in a queue for the vulnerability management team to manually validate and launch in Qualys.
Integrations: ServiceNow · Qualys
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Qualys ServiceNow Vulnerability Scan Request | 113 | Validates the requested IP addresses from a ServiceNow catalog item and triggers the corresponding Qualys scan |
8. API Security Findings & Application Ownership Enrichment
Category: Cloud Security
Subcategories: CSPM ingest & triage, Cloud asset coverage & inventory
Description:
Pulls API security findings from NoName, cross-references them against Maersk's internal resource and application-catalog platforms (MRMP/MAC/MSA), and produces an AI-enriched report mapping every finding to an owning application and team.
Business problem solved:
API security findings arrived without any link to the owning application or team, so nothing could be routed or actioned without hours of manual cross-referencing.
Integrations: NoName Security · Maersk Resource Management Plane (MRMP) · Maersk Application Catalog (MAC) · Maersk Service Atlas (MSA) · Azure Blob Storage
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| NoName - Get All Findings | 1,153 | Pages through the NoName API and pulls all current API security findings |
| NoName - Get All APIs | 98 | Pages through the NoName API and pulls the full inventory of discovered APIs |
| Main - NoName - AI Analysis | 96 | Twice-daily job that aggregates NoName findings, enriches them with MRMP/MAC ownership data, has AI reason over the results, and publishes the report |
| NoName - Get All Incidents | 0 | Pulls the full list of NoName-flagged incidents |
| NoName - Get Finding by ID | 0 | Retrieves the full detail of a single NoName finding |
| NoName - Get Incident by ID | 0 | Retrieves the full detail of a single NoName incident |
| NoName - Update Status of Findings | 0 | Updates the disposition/status of a NoName finding |
| NoName - Update Status of Incidents | 0 | Updates the disposition/status of a NoName incident |
| MRMP - Get Inventory Resources | 846 | Looks up cloud/application resources in the Maersk Resource Management Plane |
| MRMP - Get Metadata Labels | 731 | Looks up ownership and metadata labels for a resource in MRMP |
| MRMP - Get Metadata Application Labels | 0 | Looks up application-level metadata labels in MRMP |
| Retrieve Maersk Application Catalog List | 149 | Retrieves the current list of applications from the Maersk Application Catalog |
| Set Maersk Application Catalog Table | 148 | Refreshes the internal Blink table mirror of the Maersk Application Catalog |
| Get Maersk MAC Application | 0 | Looks up a single application's record in the Maersk Application Catalog |
| Share MSA table records via Azure Blob Storage (Maersk - Eng - Dev) | 9 | Exports Maersk Service Atlas table data to Azure Blob Storage for downstream consumption |
| Maersk Application Catalog (MAC) Custom Actions | 0 | Reusable custom action definitions for calling the Maersk Application Catalog API |
| Maersk Resource Management Plane (MRMP) Custom Actions | 0 | Reusable custom action definitions for calling the MRMP API |
| Maersk Service Atlas (MSA) Custom Actions | 0 | Reusable custom action definitions for calling the Maersk Service Atlas API |
| Maersk Service Atlas Custom Actions | 0 | Additional reusable custom action definitions for the Maersk Service Atlas API |
9. Zero Trust Access Inventory & Provisioning (Akamai EAA)
Category: Cloud Security
Subcategories: Cloud asset coverage & inventory, Cloud access & SaaS policy mgmt
Description:
Keeps a full inventory of Akamai Enterprise Application Access (Zero Trust) coverage and lets requesters check and request new host/port access through a self-service form instead of a manual network-security ticket.
Business problem solved:
There was no single source of truth for what was already covered by Zero Trust access, so every new access request required manual investigation before it could be approved.
Integrations: Akamai EAA · Maersk Stargate
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Akamai - Sign API Request (Maersk - Connections & Runners) | 200 | Shared helper that signs outbound requests to the Akamai API |
| Akamai EAA Inventory Report | 60 | Builds a full inventory report of Akamai EAA applications, groups, and owners |
| Schedule - Akamai EAA Inventory Report | 30 | Scheduled trigger that keeps the EAA inventory report current |
| OnDemand - Akamai EAA Inventory Report | 10 | On-demand trigger to regenerate the EAA inventory report |
| OnDemand - Akamai EAA Full Inventory Report | 4 | On-demand trigger to regenerate the full EAA inventory report |
| EAA Application Request Orchestration | 40 | Self-service form where a requester enters a destination host/port, gets an automatic coverage lookup, and — if needed — submits the request to Network Security |
| Stargate API Identity Request (Maersk - Connections & Runners) | 49 | Authenticates to the internal Stargate identity API on behalf of other workflows |
| Stargate - List Application Resources | 0 | Lists application resources known to Stargate |
| Stargate - API Proxy Search | 0 | Searches Stargate's API proxy inventory |
| Stargate - Get API Details | 0 | Retrieves detail on a specific API registered in Stargate |
| Stargate - List domains | 0 | Lists domains known to Stargate |
| Stargate - List sub domains | 0 | Lists subdomains known to Stargate |
10. AI-Assisted Firewall & Network Policy Risk Review
Category: Cloud Security
Subcategories: Config audit & remediation
Description:
Security engineers upload a FireMon firewall rule export (or another supported file type) and get back an AI-scored risk analysis of every rule, emailed directly to them.
Business problem solved:
Manually reviewing large firewall rule-base exports for risky or redundant rules before a change window was slow and inconsistent between reviewers.
Integrations: FireMon · Check Point
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Firemon - AI Risk Analysis | 150 | Self-service form to upload a FireMon rule export and receive an AI-scored risk analysis by email |
| Generic AI File Review | 5 | Generalized version of the AI file-review form supporting both FireMon and Akamai API Security file uploads |
| Check Point Show Threat Protections | 0 | Retrieves configured threat-protection profiles from Check Point for review |
11. GitHub Exposed Secret Detection & Owner Notification
Category: GRC
Subcategories: DevSecOps compliance
Description:
Twice a day, scans GitHub's exposed-secrets feed, filters down to secrets that are publicly leaked and still valid, matches each one to its owning application, and posts a Teams alert to the responsible team.
Business problem solved:
Leaked credentials in public repositories had no automatic path to the team that owned the affected application, leaving exposure windows open far longer than necessary.
Integrations: GitHub · Maersk Application Catalog (MAC) · Azure Blob Storage · Microsoft Teams
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Process Github Exposed Secret CEA | 148 | Downloads GitHub's exposed-secrets export, enriches it with application ownership data, and stages it for notification |
| Create CEA group chat and send notifications | 131 | Filters to publicly leaked, still-valid secrets and creates/notifies a Teams group chat with the owning application team |
12. Teams Notification & Workflow Failure Alerting Infrastructure
Category: Other
Subcategories: SaaS / IT administration
Description:
The shared messaging layer that every other use case relies on to post Teams messages, approvals, and emails, plus a standing safety net that pages the engineering team whenever an automation itself fails.
Business problem solved:
Without a common, reliable notification layer and failure-alerting safety net, individual automations would fail silently and no one would know until a downstream process broke.
Integrations: Microsoft Teams · SendGrid
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Notify Group Chat On BlinkOps Workflow Failure | 96 | Posts an alert to the engineering Teams chat whenever another automation fails, preventing silent breakages |
| Maersk Send MS Teams Message using caai-msg template | 94 | Shared action to post a standard-template Teams message from any workflow |
| Maersk Update MS Teams Adaptive Card Message using caai-msg-no-button template | 84 | Shared action to update a previously posted Teams adaptive card |
| Maersk Send MS Teams Error Event Message | 67 | Shared action to post an error event message to Teams |
| Maersk Send MS Teams Markdown Message | 39 | Shared action to post a free-form Markdown-formatted Teams message |
| Maersk Update MS Teams Markdown Message | 0 | Shared action to update a previously posted Markdown Teams message |
| Maersk Perform MS Teams Action | 16 | Shared action to perform a generic Teams action (e.g. approvals) from any workflow |
| Maersk Send MS Teams Adaptive Card Message | 0 | Shared action to post a rich adaptive-card Teams message |
| Maersk Send MS Teams HTML Message | 0 | Shared action to post an HTML-formatted Teams message |
| Notify MS Teams Group Chat on Runner Notifications | 0 | Alerts a Teams group chat about automation-runner-level notifications |
| Send Email via SendGrid | 22 | Shared action to send outbound email notifications through SendGrid |
13. Blink Platform Administration & Self-Documentation
Category: Other
Subcategories: SaaS / IT administration
Description:
The Center-of-Excellence team's own tooling: automatically documents every workflow, connection, table and global variable into Confluence, monitors connection health, and tracks platform usage and audit trails.
Business problem solved:
Keeping Confluence documentation and platform health visibility current for a 300+ workflow estate by hand was not sustainable as the program scaled.
Integrations: Confluence · Blink Tables · Azure Blob Storage
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Document BlinkOps Workflows into Confluence | 11 | Auto-generates/updates Confluence documentation for Blink workflows |
| Document BlinkOps Global Variables into Confluence | 10 | Auto-generates/updates Confluence documentation for global variables |
| Document BlinkOps Tables into Confluence | 10 | Auto-generates/updates Confluence documentation for Blink tables |
| Document BlinkOps Custom Actions into Confluence | 10 | Auto-generates/updates Confluence documentation for custom actions |
| Document BlinkOps Dashboards into Confluence | 10 | Auto-generates/updates Confluence documentation for dashboards |
| Document BlinkOps Connection into Confluence | 7 | Auto-generates/updates Confluence documentation for a connection |
| Document BlinkOps Features into Confluence | 5 | Scheduled job that documents platform feature usage into Confluence |
| Document BlinkOps Workspace Features into Confluence | 3 | Documents workspace-level feature configuration into Confluence |
| Set Blink Confluence Page Structure | 61 | Creates/maintains the page hierarchy used by the documentation automations |
| Set Blink Confluence Feature Page | 56 | Publishes the feature-level Confluence page content |
| Test All BlinkOps Connections | 41 | Scheduled health check across every configured connection in the workspace |
| Test Blink Connection | 1 | Tests the health of a single named connection |
| Set Connection Health Notes Field | 2 | Writes health-check results back onto the connection's tracking record |
| Add Connection Exclusion | 3 | Excludes a connection from the automated health-check sweep |
| Remove Connection Exclusion | 0 | Removes a connection from the health-check exclusion list |
| Update Runner Group Status Table | 40 | Refreshes the tracking table of automation-runner group status |
| Update Audit Log Table | 37 | Refreshes the platform audit-log tracking table |
| Age records out of table | 37 | Purges aged-out records from tracking tables on a schedule |
| Update Workflow Executions Table V2 | 33 | Refreshes the tracking table of workflow execution volumes |
| Bulk Import CSV to New or Existing Blink Table (Maersk - Eng - Dev) | 6 | Utility to bulk-load a CSV into a new or existing Blink table |
| Create table from existing table data (Maersk - Eng - Dev) | 0 | Utility to spin up a new Blink table from existing table data |
| Update table from table data (Maersk - Eng - Dev) | 0 | Utility to bulk-update a Blink table from another table's data |
| Convert Blink Table Export CSV to Blink Table JSON (Maersk - Eng - Dev) | 0 | Utility to convert a table export into the JSON import format |
| Get Table JSON (Maersk - Eng - Dev) | 0 | Utility to export a Blink table's contents as JSON |
| Parse CSV to JSON Batches | 3 | Utility to chunk a large CSV into JSON batches for processing |
| Data Conversion Utilities | 0 | Shared library of data-format conversion helpers |
| Delete Table Record | 1 | Utility to delete a single record from a Blink table |
| Deploy Global Variables into Workspace | 0 | Utility to push a set of global variables into a workspace |
| Table Custom Actions | 0 | Reusable custom action definitions for Blink table operations |
| Secret Server Custom Actions | 0 | Reusable custom action definitions for retrieving secrets from Secret Server |
14. Infrastructure Uptime & Availability Monitoring
Category: Other
Subcategories: IT/OT & network infra monitoring
Description:
Pulls uptime and availability alerts from StatusCake so infrastructure monitoring data can be consumed alongside other security and IT signals.
Business problem solved:
Uptime/availability alerts lived in a standalone monitoring tool disconnected from the rest of the security and IT automation estate.
Integrations: StatusCake
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Gather StatusCake Alerts | 0 | Pulls current uptime-check alerts from StatusCake |
Key Observations
Strengths
- Agentic SOC is the deployment's center of gravity. The three SOC-focused use cases (Alert Triage & Case Investigation, Alert & IOC Enrichment Pipeline, Identity & Endpoint Context Lookup) together span 61 playbooks and represent the most architecturally mature part of the deployment — a full case-management lifecycle (ingest → enrich → investigate → decide → close/escalate) built on reusable subflows and dedicated "Agent Ability" building blocks that expose enrichment and case-context actions directly to an AI decision layer.
- Identity remediation is fully self-service and bidirectional. The RADAR use case covers both single-user and bulk compromised-account response (MFA reset, password reset, token revocation, emergency termination) across production and pre-production Entra ID tenants, indicating the automation is trusted for high-stakes, high-blast-radius identity actions rather than read-only investigation.
- Deep, purpose-built integration with Maersk's internal platforms. Beyond commercial security tools, Blink integrates natively with Maersk-proprietary systems — MRMP (Resource Management Plane), MAC (Application Catalog), MSA (Service Atlas), and Stargate (internal identity/API gateway) — to enrich API security findings and Zero Trust access requests with application-ownership context. This is a meaningfully deeper integration footprint than typical out-of-the-box SOAR connectors.
- Broad third-party ecosystem already wired in. Twenty-plus distinct integrations are active across the deployment, spanning EDR (CrowdStrike), vulnerability management (Qualys, Trend Micro Deep Security), API security (NoName Security), threat intel/enrichment (VirusTotal, AbuseIPDB, URLScan, Whois), network/cloud security (FireMon, Check Point, Akamai EAA, Zscaler ZIA, Forescout), identity (Entra ID/Active Directory, Okta, Google Workspace), and collaboration/ITSM (ServiceNow, GitHub, Jira, Confluence, Microsoft Teams, SendGrid, Slack) — giving Blink a genuine cross-domain orchestration role rather than sitting inside a single tool silo.
- Operational self-sufficiency. A dedicated set of platform-administration playbooks keeps Confluence documentation, connection health, and table/data infrastructure in sync automatically, and failures in any Blink automation are proactively routed to the engineering team via Teams — reducing the operational overhead of running the platform itself.
Gaps / opportunities
- Vulnerability management is comparatively thin. Only one use case (Qualys scan requests via ServiceNow) is mapped to the Vulnerability Mgmt category. Given Qualys and Trend Micro Deep Security are already integrated for agent-health checks, there is clear headroom to extend automation into scan-result triage, remediation ticketing, or SLA tracking rather than just scan initiation.
- GRC coverage is narrow. Only the GitHub exposed-secret detection/notification workflow is currently classified under GRC. Compliance-control monitoring, audit evidence collection, and policy-exception tracking appear to be white space relative to the SOC investment.
- No dedicated IAM-category use case. Identity actions today are scoped specifically to threat response (RADAR) and investigative lookups rather than broader lifecycle IAM (joiner/mover/leaver, access reviews, entitlement certification) — a natural adjacent expansion given the strength of the existing Entra ID/Okta integrations.
- High-volume "Authentication Event Monitoring" workflow is a thin filter, not a full pipeline. At 42,412 executions it is by far the highest-volume workflow in the tenant, but it currently performs a single filtering step against Azure Monitor events rather than downstream enrichment or case creation — a candidate for building out into a fuller detection pipeline.
- Environment sprawl. Most playbooks are deployed near-identically across up to 8 workspaces (production, pre-production, various dev/Eng-Dev, and "Connections & Runners" environments). This is expected for safe change management, but the ~22 leftover test/example/scratch workflows (e.g.,
EXAMPLE - *,Funny AI,New Test Workflow) identified during this analysis represent a small, low-risk cleanup opportunity to keep production workspaces lean.
Integration ecosystem summary
Security tooling: CrowdStrike · Qualys · Trend Micro Deep Security · NoName Security · VirusTotal · AbuseIPDB · URLScan · FireMon · Check Point · Akamai EAA · Zscaler ZIA · Forescout
Identity: Microsoft Entra ID / Active Directory · Okta · Google Workspace
ITSM & collaboration: ServiceNow · GitHub · Jira · Confluence · Microsoft Teams · Slack · SendGrid
Cloud & internal platforms: Azure Monitor · Azure Blob Storage · Maersk MRMP · Maersk MAC · Maersk MSA · Stargate
E New Integrations (detail) 8 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Maersk | sharepoint | sharepoint_oci_prod | 2026-08-28 |
| Maersk | blink | blinkops_table_viewer | 2026-08-26 |
| Maersk | blink | blinkops_global_variable_manager | 2026-08-26 |
| Maersk | blink | blinkops_health_monitoring | 2026-08-26 |
| Maersk | blink | blinkops_production_viewer | 2026-08-25 |
| Maersk | check-point-management | checkpoint_management_blade_prod | 2026-08-10 |
| Maersk | confluence | confluence_prod | 2026-08-04 |
| Maersk | confluence | confluence_prod | 2026-08-03 |