Blink Security Automation — Confidential

Maersk — Customer Success Report

Generated 2026-08-30 | maersk-value-report.md
2026-08-30Report Date
535Total Playbooks
142Unique Workflows (12m)
104,813Actions Automated (12m)
$26,958Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

535
Total playbooks built
all non-deleted workflows
339
Active playbooks
currently enabled
142
Unique workflows executed (12m)
distinct workflows that ran
104,813
Actions automated (12m)
completed action steps
582.3h
Hours saved (12m)
@ 20s per action
$26,958
Money saved (12m)
@ $100K avg salary
54
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
6
Active AI agents
of 16 total
94
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1,259 security agent health checks completed via ServiceNow self-service - 173 compromised-account remediation actions executed for a single user - 150 firewall rule sets analyzed by AI for risk before deployment - 148 GitHub secret-exposure scans processed and routed toward application owners - 113 vulnerability scans requested and orchestrated via ServiceNow self-service

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — AI-Driven Alert Triage & Case Investigation
  • 42AI-driven SOC decisions rendered on open security cases
  • 15AI-generated incident enrichment reports created and emailed
  • 14Request-for-Information submissions logged as security cases
0.4%
18
18 active
Alert & IOC Enrichment Pipeline170 executions
0.3%
29
29 active
Identity & Endpoint Context Lookup for SOC Investigations2 executions
0.0%
15
15 active
Identity Threat Response — Compromised Account Remediation (RADAR)
  • 173Compromised-account remediation actions executed for a single user (MFA reset, password reset, token revoke)
  • 26Bulk compromised-account remediation requests processed
0.4%
9
9 active
Authentication Event Monitoring & Log Pipeline42,412 executions
86.0%
1
1 active
Security Agent Health Validation (ServiceNow Self-Service)
  • 1,259Security agent health checks completed via ServiceNow self-service
3.3%
9
8 active
On-Demand Vulnerability Scan Requests (Qualys via ServiceNow)
  • 113Vulnerability scans requested and orchestrated via ServiceNow self-service
0.2%
1
1 active
API Security Findings & Application Ownership Enrichment
  • 96AI-enriched API-security posture reports generated
6.4%
19
18 active
Zero Trust Access Inventory & Provisioning (Akamai EAA)
  • 40New Zero Trust application-access requests automatically evaluated
0.5%
12
11 active
AI-Assisted Firewall & Network Policy Risk Review
  • 150Firewall rule sets analyzed by AI for risk before deployment
0.3%
3
3 active
GitHub Exposed Secret Detection & Owner Notification
  • 148GitHub secret-exposure scans processed and routed toward application owners
  • 131Application-owner Teams alerts sent for exposed secrets
0.6%
2
2 active
Teams Notification & Workflow Failure Alerting Infrastructure
  • 96Automation failure alerts sent to the engineering team
0.7%
11
10 active
Blink Platform Administration & Self-Documentation
  • 183Platform documentation pages kept in sync in Confluence automatically
0.8%
30
26 active
Infrastructure Uptime & Availability Monitoring0 executions
0.0%
1
1 active
Total49,242 executions100%
160
152 active

Use Case Growth Over Time

271 unique playbooks  |  14 operational use cases  |  49,329 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Agentic SOC — AI-Driven Alert Triage & Case Investigation
Agents Email Web Form
Authentication Event Monitoring & Log Pipeline
Azure Microsoft Sentinel
Identity Threat Response — Compromised Account Remediation (RADAR)
Azure Microsoft Entra ID Jira
On-Demand Vulnerability Scan Requests (Qualys via ServiceNow)
Web Form Qualys ServiceNow
Security Agent Health Validation (ServiceNow Self-Service)
ServiceNow Qualys CrowdStrike Azure
AI-Assisted Firewall & Network Policy Risk Review
Azure Foundry Email Check Point Management
Zero Trust Access Inventory & Provisioning (Akamai EAA)
Azure Storage Email Web Form
Identity & Endpoint Context Lookup for SOC Investigations
Google Workspace Microsoft Entra ID Okta Slack GitHub CrowdStrike
Alert & IOC Enrichment Pipeline
AbuseIPDB VirusTotal CrowdStrike Email URLScan
API Security Findings & Application Ownership Enrichment
Microsoft Foundry Azure Storage Email Maersk Service Atlas (MSA) Maersk Resource Management Plane (MRMP)
Blink Platform Administration & Self-Documentation
Confluence Maersk Resource Management Plane (MRMP)

04Key Observations

✓  Strengths

Strengths

  • Agentic SOC is the deployment's center of gravity. The three SOC-focused use cases (Alert Triage & Case Investigation, Alert & IOC Enrichment Pipeline, Identity & Endpoint Context Lookup) together span 61 playbooks and represent the most architecturally mature part of the deployment — a full case-management lifecycle (ingest → enrich → investigate → decide → close/escalate) built on reusable subflows and dedicated "Agent Ability" building blocks that expose enrichment and case-context actions directly to an AI decision layer.
  • Identity remediation is fully self-service and bidirectional. The RADAR use case covers both single-user and bulk compromised-account response (MFA reset, password reset, token revocation, emergency termination) across production and pre-production Entra ID tenants, indicating the automation is trusted for high-stakes, high-blast-radius identity actions rather than read-only investigation.
  • Deep, purpose-built integration with Maersk's internal platforms. Beyond commercial security tools, Blink integrates natively with Maersk-proprietary systems — MRMP (Resource Management Plane), MAC (Application Catalog), MSA (Service Atlas), and Stargate (internal identity/API gateway) — to enrich API security findings and Zero Trust access requests with application-ownership context. This is a meaningfully deeper integration footprint than typical out-of-the-box SOAR connectors.
  • Broad third-party ecosystem already wired in. Twenty-plus distinct integrations are active across the deployment, spanning EDR (CrowdStrike), vulnerability management (Qualys, Trend Micro Deep Security), API security (NoName Security), threat intel/enrichment (VirusTotal, AbuseIPDB, URLScan, Whois), network/cloud security (FireMon, Check Point, Akamai EAA, Zscaler ZIA, Forescout), identity (Entra ID/Active Directory, Okta, Google Workspace), and collaboration/ITSM (ServiceNow, GitHub, Jira, Confluence, Microsoft Teams, SendGrid, Slack) — giving Blink a genuine cross-domain orchestration role rather than sitting inside a single tool silo.
  • Operational self-sufficiency. A dedicated set of platform-administration playbooks keeps Confluence documentation, connection health, and table/data infrastructure in sync automatically, and failures in any Blink automation are proactively routed to the engineering team via Teams — reducing the operational overhead of running the platform itself.

△  Gaps & Growth Opportunities

Gaps / opportunities

  • Vulnerability management is comparatively thin. Only one use case (Qualys scan requests via ServiceNow) is mapped to the Vulnerability Mgmt category. Given Qualys and Trend Micro Deep Security are already integrated for agent-health checks, there is clear headroom to extend automation into scan-result triage, remediation ticketing, or SLA tracking rather than just scan initiation.
  • GRC coverage is narrow. Only the GitHub exposed-secret detection/notification workflow is currently classified under GRC. Compliance-control monitoring, audit evidence collection, and policy-exception tracking appear to be white space relative to the SOC investment.
  • No dedicated IAM-category use case. Identity actions today are scoped specifically to threat response (RADAR) and investigative lookups rather than broader lifecycle IAM (joiner/mover/leaver, access reviews, entitlement certification) — a natural adjacent expansion given the strength of the existing Entra ID/Okta integrations.
  • High-volume "Authentication Event Monitoring" workflow is a thin filter, not a full pipeline. At 42,412 executions it is by far the highest-volume workflow in the tenant, but it currently performs a single filtering step against Azure Monitor events rather than downstream enrichment or case creation — a candidate for building out into a fuller detection pipeline.
  • Environment sprawl. Most playbooks are deployed near-identically across up to 8 workspaces (production, pre-production, various dev/Eng-Dev, and "Connections & Runners" environments). This is expected for safe change management, but the ~22 leftover test/example/scratch workflows (e.g., EXAMPLE - *, Funny AI, New Test Workflow) identified during this analysis represent a small, low-risk cleanup opportunity to keep production workspaces lean.

Integration ecosystem summary

Security tooling: CrowdStrike · Qualys · Trend Micro Deep Security · NoName Security · VirusTotal · AbuseIPDB · URLScan · FireMon · Check Point · Akamai EAA · Zscaler ZIA · Forescout

Identity: Microsoft Entra ID / Active Directory · Okta · Google Workspace

ITSM & collaboration: ServiceNow · GitHub · Jira · Confluence · Microsoft Teams · Slack · SendGrid

Cloud & internal platforms: Azure Monitor · Azure Blob Storage · Maersk MRMP · Maersk MAC · Maersk MSA · Stargate

Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 6 active | 94 tasks (12m)

AI Agents

Active Agents
6
of 16 total
Tasks Executed (12m)
94
0 in last 30d
Data Usage (12m)
6,756,077
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink - Decision Maker guy.gurman@blinkops.com 44 0 3,248,195
2 CTI Report Helper guy.gurman@blinkops.com 22 0 987,538
3 RFI Submission Expert guy.gurman@blinkops.com 17 0 1,882,164
4 Micro Agent - Historical Case Check guy.gurman@blinkops.com 5 0 170,751
5 SOC Agent - Phishing Agent guy.gurman@blinkops.com 4 0 304,910
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
guy.gurman@blinkops.com94
Maersk - Eng. - Prod - Privileged0
Maersk - CTI - Test - Privileged0
Demo0
Maersk - Eng - Dev0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 14 use cases | 49,329 executions (12m)

Business KPIs

Metric Count Playbook
Security agent health checks completed via ServiceNow self-service 1,259 ServiceNow Agent Health Check
Compromised-account remediation actions executed for a single user (MFA reset, password reset, token revoke) 173 RADAR: Single User Remediation - Form
Bulk compromised-account remediation requests processed 26 RADAR: Bulk User Remediation - Form
Firewall rule sets analyzed by AI for risk before deployment 150 Firemon - AI Risk Analysis
GitHub secret-exposure scans processed and routed toward application owners 148 Process Github Exposed Secret CEA
Application-owner Teams alerts sent for exposed secrets 131 Create CEA group chat and send notifications
Vulnerability scans requested and orchestrated via ServiceNow self-service 113 Qualys ServiceNow Vulnerability Scan Request
AI-driven SOC decisions rendered on open security cases 42 Agentic SOC - Decision Layer
New Zero Trust application-access requests automatically evaluated 40 EAA Application Request Orchestration
AI-enriched API-security posture reports generated 96 Main - NoName - AI Analysis
AI-generated incident enrichment reports created and emailed 15 Response - Generate a report
Request-for-Information submissions logged as security cases 14 WebForm - Create RFI Submission
Platform documentation pages kept in sync in Confluence automatically 183 Document BlinkOps Workflows into Confluence
Automation failure alerts sent to the engineering team 96 Notify Group Chat On BlinkOps Workflow Failure
In the last 12 months, Blink automated: - 1,259 security agent health checks completed via ServiceNow self-service - 173 compromised-account remediation actions executed for a single user - 150 firewall rule sets analyzed by AI for risk before deployment - 148 GitHub secret-exposure scans processed and routed toward application owners - 113 vulnerability scans requested and orchestrated via ServiceNow self-service

Use Case Summary

# Use Case Category Playbooks Executions (12mo)
1 Agentic SOC — AI-Driven Alert Triage & Case Investigation SOC 18 178
2 Alert & IOC Enrichment Pipeline SOC 28 170
3 Identity & Endpoint Context Lookup for SOC Investigations SOC 15 2
4 Identity Threat Response — Compromised Account Remediation (RADAR) SOC 9 202
5 Authentication Event Monitoring & Log Pipeline SOC 1 42,412
6 Security Agent Health Validation (ServiceNow Self-Service) Other 9 1,621
7 On-Demand Vulnerability Scan Requests (Qualys via ServiceNow) Vulnerability Mgmt 1 113
8 API Security Findings & Application Ownership Enrichment Cloud Security 19 3,230
9 Zero Trust Access Inventory & Provisioning (Akamai EAA) Cloud Security 12 393
10 AI-Assisted Firewall & Network Policy Risk Review Cloud Security 3 155
11 GitHub Exposed Secret Detection & Owner Notification GRC 2 279
12 Teams Notification & Workflow Failure Alerting Infrastructure Other 11 418
13 Blink Platform Administration & Self-Documentation Other 30 387
14 Infrastructure Uptime & Availability Monitoring Other 1 0

Use Cases

1. Agentic SOC — AI-Driven Alert Triage & Case Investigation

Category: SOC

Subcategories: Agentic SOC, Case mgmt & SOAR

Description:

An AI decision layer investigates every new security alert, decides the next action, and drives the case through triage, escalation, or closure with minimal analyst intervention.

Business problem solved:

Analysts were spending the bulk of their shift on repetitive first-pass triage instead of genuine threats, and case handling was inconsistent across shifts and analysts.

Integrations: Blink Case Management (SOAR) · Blink AI Agents · Jira · Email

Playbooks

Playbook Executions Role
Process Alert 19 Ingests each new alert, extracts observables, de-duplicates into a new or existing case, and hands off to enrichment and response
Agentic SOC - Decision Layer 42 Core AI reasoning step that decides the next investigative or response action for an open case
Agentic SOC - Expert Agents 21 Routes a case to the specialized AI expert agent best suited to the alert type
Subflow - Agentic SOC - Main - AI Investigation 21 Orchestrates the end-to-end AI investigation cycle for a case
Agent Ability - Historical Case Checks 21 AI tool call that checks whether similar cases have been seen and handled before
Subflow - Response - Main Router 20 Routes every newly created case into the automated response pipeline
Response - Generate a report 15 Has an AI agent write an IOC enrichment report, renders it to PDF, and emails it out
WebForm - Create RFI Submission 14 Self-service form for analysts/teams to submit a Request for Information, auto-logged as a case
Utility - Refresh investigation 5 Re-triggers the AI investigation on a case when new information arrives
Agentic SOC - Close Case 0 Closes a case once the decision layer reaches a final disposition
Utility - Close Stale Cases 0 Housekeeping job that auto-closes cases that have gone inactive past SLA
SubFlow - Context Enrichment 0 Gathers the case and alert context the decision layer needs before it reasons about next steps
Comment On Case 0 AI tool call that posts analyst-facing commentary and findings onto a case
Jira Ticket - Ingestion 0 Ingests security tickets raised in Jira as new alerts into the case pipeline
Error Handling - Send Error Notification Email 0 Notifies the team by email when a step in the SOC pipeline fails
Agent Ability - Recommendation for case 0 AI tool call that generates a recommended response for a case
Agent Ability - Get Case 0 AI tool call that retrieves case details for the reasoning agent
Agent Ability - Get Alert 0 AI tool call that retrieves alert details for the reasoning agent

2. Alert & IOC Enrichment Pipeline

Category: SOC

Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation

Description:

Automatically enriches every indicator of compromise (IP, URL, hash, domain) surfaced on an alert with threat-intelligence context before an analyst or AI agent ever looks at it.

Business problem solved:

Manually pivoting to VirusTotal, AbuseIPDB and internal asset data for every observable on every alert was the single biggest time sink in triage.

Integrations: VirusTotal · AbuseIPDB · URLScan · Whois · CrowdStrike · Crible SIEM

Playbooks

Playbook Executions Role
Subflow - Enrich Observables - Main Router 53 Central router that fans an alert's observables out to the right enrichment source by type
Subflow - Update Enrichment Data 41 Writes enrichment results back onto the observable/case record
Utility - Update Enrichment 0 Supporting utility that merges new enrichment data into an existing record
Enrich - Hash - VT 11 Looks up a file hash's reputation in VirusTotal
Enrich - IP - VT 7 Looks up an IP's reputation in VirusTotal
Enrich - IP - IPDB 16 Looks up an IP's reputation in AbuseIPDB
Enrich - URL - VT 7 Looks up a URL's reputation in VirusTotal
Enrich IP or Domain Using Whois 0 Pulls Whois registration data for an IP or domain observable
Enrich - Check If Observable inside Organization 0 Flags whether an observable belongs to Maersk's own IP/asset space before treating it as external
Analyze URL with URLScan 0 Submits a URL to URLScan for behavioral/visual analysis
Get Hash Info Using Crowdstrike 0 Looks up a file hash against CrowdStrike threat intelligence
Get Hash Info Using VirusTotal 0 Looks up a file hash against VirusTotal
Get End of Life Date for a Product 0 Checks whether a software product/version on an alert is past its end-of-life date
Get Observables by Case ID 17 AI tool call that retrieves all observables tied to a case for analysis
Query Observable 0 AI tool call that looks up a single observable's stored record
Utility - List Alert Observable Relations 0 Lists which observables are linked to a given alert
Utility - List Observable Alert Relations 0 Lists which alerts a given observable is linked to
Utility - Set Or Update Observable Relation 0 Creates or updates a relation between an observable and an alert/case
Utility - Delete Observable Relation 0 Removes a relation between an observable and an alert/case
Utility - Add Observable Extraction Rule 0 Adds a new rule for how observables are extracted from a given alert template
Utility - Find Similar Cases Based on Observables 0 Searches for other cases sharing the same observables
Table Action - Validate Observables Extraction Template 0 Validates that an alert template is correctly configured to extract observables
Subflow - Missing Alert Template Notification 0 Alerts the team when an incoming alert type has no observable-extraction template configured
Agent Ability - Query Crible Siem for IOCs 10 AI tool call that queries the Crible SIEM for related indicators
Agent Ability - Query Observables by Content 4 AI tool call that searches observables by content/value
Agent Ability - Enrich using Virus Total 4 AI tool call that triggers VirusTotal enrichment on demand
Secure URL Screenshot Capture 0 Takes a sandboxed screenshot of a suspicious URL for analyst review
Run Dig Command 0 Runs a DNS lookup (dig) against a domain observable

3. Identity & Endpoint Context Lookup for SOC Investigations

Category: SOC

Subcategories: Identity threat response, EDR containment & response

Description:

Gives the agentic SOC direct, on-demand access to identity providers and CrowdStrike so it can pull user context and take containment actions without an analyst switching consoles.

Business problem solved:

Confirming who a user is and whether their device needs to be isolated required analysts to log into four or five separate admin consoles per case.

Integrations: Microsoft Entra ID · Okta · GitHub · Google Workspace · Slack · CrowdStrike

Playbooks

Playbook Executions Role
Get User Information Using Microsoft Entra ID 0 Looks up a user's identity and attributes in Entra ID for case context
Get User Information Using Okta 0 Looks up a user's identity and attributes in Okta for case context
Get User Information Using Github 0 Looks up a user's identity on GitHub for case context
Get User Information Using Google Workspace 0 Looks up a user's identity in Google Workspace for case context
Get User Information on Email Address Using Slack 0 Resolves a Slack user's identity from an email address
Okta Search for User Activity 0 Pulls a user's recent Okta activity/sign-in history for investigation
Manage Endpoint Quarantine Status in Crowdstrike 0 Isolates or releases a host in CrowdStrike as a containment action
CrowdStrike RTR to a Single Host 0 Runs a real-time-response command on a single host for investigation or remediation
CrowdStrike RTR to a Batch of Hosts 0 Runs a real-time-response command across a batch of hosts
Agent Ability - Get Org Assets 2 AI tool call that retrieves known organizational assets for context
Agent Ability - Get Org Technological Stack 0 AI tool call that retrieves the organization's technology stack for context
Agent Ability - Get Vendor Logo List 0 Supplies vendor logos used to render enrichment reports
Agent Ability - Get Observable Types From Case Management Settings 0 AI tool call that reads the configured observable types from case management settings
Agent Ability - Get Observable Reputations From Case Management Settings 0 AI tool call that reads configured reputation scoring from case management settings
Agent Ability - Get Observable Relation Types From Case Management Settings 0 AI tool call that reads configured relation types from case management settings

4. Identity Threat Response — Compromised Account Remediation (RADAR)

Category: SOC

Subcategories: Identity threat response

Description:

Self-service RADAR forms let the SOC or helpdesk force a password reset, revoke tokens, or reset MFA for one user or a whole CSV list of users in a single submission.

Business problem solved:

Responding to a confirmed account compromise required manual, sequential admin-console work per affected user, slowing containment during active incidents.

Integrations: Microsoft Entra ID · Jira · Azure Automation

Playbooks

Playbook Executions Role
RADAR: Single User Remediation - Form 173 Self-service form to reset MFA, reset password, and/or revoke tokens for a single user
RADAR: Bulk User Remediation - Form 26 Self-service form to apply the same remediation actions to a CSV list of users at once
RADAR: Single User Remediation copy 2 Backend logic that executes the requested remediation actions for a single user
RADAR: Bulk User Remediation 0 Backend logic that executes the requested remediation actions across a batch of users
RADAR: Single User Emergency Termination 0 Immediately disables a single compromised account and its access
RADAR: Bulk User Emergency Termination 0 Immediately disables a batch of compromised accounts and their access
Entra ID: Read User from Production Tenant 0 Looks up a user's record in the production Entra ID tenant before remediation
Entra ID: Read User from Pre-Production tenant 1 Looks up a user's record in the pre-production Entra ID tenant before remediation
Respond - Reset Password 0 Triggers an Azure Automation runbook to reset a user's password and reports back the result

5. Authentication Event Monitoring & Log Pipeline

Category: SOC

Subcategories: SIEM & log pipeline monitoring

Description:

Continuously polls Azure Monitor for new events and filters out the authentication-related activity that matters to the SOC, feeding a high-volume log pipeline.

Business problem solved:

Authentication telemetry from Azure needed continuous, low-latency filtering so downstream detections only fire on relevant sign-in activity rather than the full event firehose.

Integrations: Azure Monitor

Playbooks

Playbook Executions Role
New Workflow 2 42,412 Polls Azure Monitor for new events and filters for authentication-related activity

6. Security Agent Health Validation (ServiceNow Self-Service)

Category: Other

Subcategories: Endpoint hygiene & MDM ops

Description:

When someone raises a ServiceNow request about a missing or outdated endpoint security agent, this automation checks CrowdStrike, Qualys and Trend Micro directly and writes the answer back onto the ticket.

Business problem solved:

IT operations were manually cross-referencing three separate security-agent consoles for every ServiceNow ticket about endpoint agent health, delaying ticket resolution.

Integrations: ServiceNow · CrowdStrike · Qualys · Trend Micro Deep Security

Playbooks

Playbook Executions Role
ServiceNow Agent Health Check 1,259 Validates whether the required security agents are installed and healthy on the hosts named in a ServiceNow request, then comments and updates the ticket
Validate Agent Health 86 Runs the underlying health checks against a host across the relevant security agents
Retrieve ServiceNow Request Variables V2 161 Parses the submitted catalog-item variables off a ServiceNow request so downstream steps can act on them
Search Crowdstrike for Host Details 29 Looks up a host's CrowdStrike sensor status and details
Search for Trend Deep Security Computer 29 Looks up a host's Trend Micro Deep Security agent status
Search Qualys Global IT Asset Inventory 35 Looks up a host's Qualys agent status in the global IT asset inventory
Update CS Agent Threshold Versions 12 Weekly job that refreshes the accepted CrowdStrike sensor version thresholds from CrowdStrike's own policy list
Update Qualys Agent Version Thresholds 7 Refreshes the accepted Qualys agent version thresholds used by the health check
Update Qualys Network Scanners List 3 Keeps the list of Qualys network scanners used for validation up to date

7. On-Demand Vulnerability Scan Requests (Qualys via ServiceNow)

Category: Vulnerability Mgmt

Subcategories: Vuln scan lifecycle automation

Description:

Lets requesters submit a ServiceNow catalog item with a list of IPs and have Blink validate the addresses and kick off a Qualys vulnerability scan automatically.

Business problem solved:

Ad-hoc vulnerability scan requests sat in a queue for the vulnerability management team to manually validate and launch in Qualys.

Integrations: ServiceNow · Qualys

Playbooks

Playbook Executions Role
Qualys ServiceNow Vulnerability Scan Request 113 Validates the requested IP addresses from a ServiceNow catalog item and triggers the corresponding Qualys scan

8. API Security Findings & Application Ownership Enrichment

Category: Cloud Security

Subcategories: CSPM ingest & triage, Cloud asset coverage & inventory

Description:

Pulls API security findings from NoName, cross-references them against Maersk's internal resource and application-catalog platforms (MRMP/MAC/MSA), and produces an AI-enriched report mapping every finding to an owning application and team.

Business problem solved:

API security findings arrived without any link to the owning application or team, so nothing could be routed or actioned without hours of manual cross-referencing.

Integrations: NoName Security · Maersk Resource Management Plane (MRMP) · Maersk Application Catalog (MAC) · Maersk Service Atlas (MSA) · Azure Blob Storage

Playbooks

Playbook Executions Role
NoName - Get All Findings 1,153 Pages through the NoName API and pulls all current API security findings
NoName - Get All APIs 98 Pages through the NoName API and pulls the full inventory of discovered APIs
Main - NoName - AI Analysis 96 Twice-daily job that aggregates NoName findings, enriches them with MRMP/MAC ownership data, has AI reason over the results, and publishes the report
NoName - Get All Incidents 0 Pulls the full list of NoName-flagged incidents
NoName - Get Finding by ID 0 Retrieves the full detail of a single NoName finding
NoName - Get Incident by ID 0 Retrieves the full detail of a single NoName incident
NoName - Update Status of Findings 0 Updates the disposition/status of a NoName finding
NoName - Update Status of Incidents 0 Updates the disposition/status of a NoName incident
MRMP - Get Inventory Resources 846 Looks up cloud/application resources in the Maersk Resource Management Plane
MRMP - Get Metadata Labels 731 Looks up ownership and metadata labels for a resource in MRMP
MRMP - Get Metadata Application Labels 0 Looks up application-level metadata labels in MRMP
Retrieve Maersk Application Catalog List 149 Retrieves the current list of applications from the Maersk Application Catalog
Set Maersk Application Catalog Table 148 Refreshes the internal Blink table mirror of the Maersk Application Catalog
Get Maersk MAC Application 0 Looks up a single application's record in the Maersk Application Catalog
Share MSA table records via Azure Blob Storage (Maersk - Eng - Dev) 9 Exports Maersk Service Atlas table data to Azure Blob Storage for downstream consumption
Maersk Application Catalog (MAC) Custom Actions 0 Reusable custom action definitions for calling the Maersk Application Catalog API
Maersk Resource Management Plane (MRMP) Custom Actions 0 Reusable custom action definitions for calling the MRMP API
Maersk Service Atlas (MSA) Custom Actions 0 Reusable custom action definitions for calling the Maersk Service Atlas API
Maersk Service Atlas Custom Actions 0 Additional reusable custom action definitions for the Maersk Service Atlas API

9. Zero Trust Access Inventory & Provisioning (Akamai EAA)

Category: Cloud Security

Subcategories: Cloud asset coverage & inventory, Cloud access & SaaS policy mgmt

Description:

Keeps a full inventory of Akamai Enterprise Application Access (Zero Trust) coverage and lets requesters check and request new host/port access through a self-service form instead of a manual network-security ticket.

Business problem solved:

There was no single source of truth for what was already covered by Zero Trust access, so every new access request required manual investigation before it could be approved.

Integrations: Akamai EAA · Maersk Stargate

Playbooks

Playbook Executions Role
Akamai - Sign API Request (Maersk - Connections & Runners) 200 Shared helper that signs outbound requests to the Akamai API
Akamai EAA Inventory Report 60 Builds a full inventory report of Akamai EAA applications, groups, and owners
Schedule - Akamai EAA Inventory Report 30 Scheduled trigger that keeps the EAA inventory report current
OnDemand - Akamai EAA Inventory Report 10 On-demand trigger to regenerate the EAA inventory report
OnDemand - Akamai EAA Full Inventory Report 4 On-demand trigger to regenerate the full EAA inventory report
EAA Application Request Orchestration 40 Self-service form where a requester enters a destination host/port, gets an automatic coverage lookup, and — if needed — submits the request to Network Security
Stargate API Identity Request (Maersk - Connections & Runners) 49 Authenticates to the internal Stargate identity API on behalf of other workflows
Stargate - List Application Resources 0 Lists application resources known to Stargate
Stargate - API Proxy Search 0 Searches Stargate's API proxy inventory
Stargate - Get API Details 0 Retrieves detail on a specific API registered in Stargate
Stargate - List domains 0 Lists domains known to Stargate
Stargate - List sub domains 0 Lists subdomains known to Stargate

10. AI-Assisted Firewall & Network Policy Risk Review

Category: Cloud Security

Subcategories: Config audit & remediation

Description:

Security engineers upload a FireMon firewall rule export (or another supported file type) and get back an AI-scored risk analysis of every rule, emailed directly to them.

Business problem solved:

Manually reviewing large firewall rule-base exports for risky or redundant rules before a change window was slow and inconsistent between reviewers.

Integrations: FireMon · Check Point

Playbooks

Playbook Executions Role
Firemon - AI Risk Analysis 150 Self-service form to upload a FireMon rule export and receive an AI-scored risk analysis by email
Generic AI File Review 5 Generalized version of the AI file-review form supporting both FireMon and Akamai API Security file uploads
Check Point Show Threat Protections 0 Retrieves configured threat-protection profiles from Check Point for review

11. GitHub Exposed Secret Detection & Owner Notification

Category: GRC

Subcategories: DevSecOps compliance

Description:

Twice a day, scans GitHub's exposed-secrets feed, filters down to secrets that are publicly leaked and still valid, matches each one to its owning application, and posts a Teams alert to the responsible team.

Business problem solved:

Leaked credentials in public repositories had no automatic path to the team that owned the affected application, leaving exposure windows open far longer than necessary.

Integrations: GitHub · Maersk Application Catalog (MAC) · Azure Blob Storage · Microsoft Teams

Playbooks

Playbook Executions Role
Process Github Exposed Secret CEA 148 Downloads GitHub's exposed-secrets export, enriches it with application ownership data, and stages it for notification
Create CEA group chat and send notifications 131 Filters to publicly leaked, still-valid secrets and creates/notifies a Teams group chat with the owning application team

12. Teams Notification & Workflow Failure Alerting Infrastructure

Category: Other

Subcategories: SaaS / IT administration

Description:

The shared messaging layer that every other use case relies on to post Teams messages, approvals, and emails, plus a standing safety net that pages the engineering team whenever an automation itself fails.

Business problem solved:

Without a common, reliable notification layer and failure-alerting safety net, individual automations would fail silently and no one would know until a downstream process broke.

Integrations: Microsoft Teams · SendGrid

Playbooks

Playbook Executions Role
Notify Group Chat On BlinkOps Workflow Failure 96 Posts an alert to the engineering Teams chat whenever another automation fails, preventing silent breakages
Maersk Send MS Teams Message using caai-msg template 94 Shared action to post a standard-template Teams message from any workflow
Maersk Update MS Teams Adaptive Card Message using caai-msg-no-button template 84 Shared action to update a previously posted Teams adaptive card
Maersk Send MS Teams Error Event Message 67 Shared action to post an error event message to Teams
Maersk Send MS Teams Markdown Message 39 Shared action to post a free-form Markdown-formatted Teams message
Maersk Update MS Teams Markdown Message 0 Shared action to update a previously posted Markdown Teams message
Maersk Perform MS Teams Action 16 Shared action to perform a generic Teams action (e.g. approvals) from any workflow
Maersk Send MS Teams Adaptive Card Message 0 Shared action to post a rich adaptive-card Teams message
Maersk Send MS Teams HTML Message 0 Shared action to post an HTML-formatted Teams message
Notify MS Teams Group Chat on Runner Notifications 0 Alerts a Teams group chat about automation-runner-level notifications
Send Email via SendGrid 22 Shared action to send outbound email notifications through SendGrid

13. Blink Platform Administration & Self-Documentation

Category: Other

Subcategories: SaaS / IT administration

Description:

The Center-of-Excellence team's own tooling: automatically documents every workflow, connection, table and global variable into Confluence, monitors connection health, and tracks platform usage and audit trails.

Business problem solved:

Keeping Confluence documentation and platform health visibility current for a 300+ workflow estate by hand was not sustainable as the program scaled.

Integrations: Confluence · Blink Tables · Azure Blob Storage

Playbooks

Playbook Executions Role
Document BlinkOps Workflows into Confluence 11 Auto-generates/updates Confluence documentation for Blink workflows
Document BlinkOps Global Variables into Confluence 10 Auto-generates/updates Confluence documentation for global variables
Document BlinkOps Tables into Confluence 10 Auto-generates/updates Confluence documentation for Blink tables
Document BlinkOps Custom Actions into Confluence 10 Auto-generates/updates Confluence documentation for custom actions
Document BlinkOps Dashboards into Confluence 10 Auto-generates/updates Confluence documentation for dashboards
Document BlinkOps Connection into Confluence 7 Auto-generates/updates Confluence documentation for a connection
Document BlinkOps Features into Confluence 5 Scheduled job that documents platform feature usage into Confluence
Document BlinkOps Workspace Features into Confluence 3 Documents workspace-level feature configuration into Confluence
Set Blink Confluence Page Structure 61 Creates/maintains the page hierarchy used by the documentation automations
Set Blink Confluence Feature Page 56 Publishes the feature-level Confluence page content
Test All BlinkOps Connections 41 Scheduled health check across every configured connection in the workspace
Test Blink Connection 1 Tests the health of a single named connection
Set Connection Health Notes Field 2 Writes health-check results back onto the connection's tracking record
Add Connection Exclusion 3 Excludes a connection from the automated health-check sweep
Remove Connection Exclusion 0 Removes a connection from the health-check exclusion list
Update Runner Group Status Table 40 Refreshes the tracking table of automation-runner group status
Update Audit Log Table 37 Refreshes the platform audit-log tracking table
Age records out of table 37 Purges aged-out records from tracking tables on a schedule
Update Workflow Executions Table V2 33 Refreshes the tracking table of workflow execution volumes
Bulk Import CSV to New or Existing Blink Table (Maersk - Eng - Dev) 6 Utility to bulk-load a CSV into a new or existing Blink table
Create table from existing table data (Maersk - Eng - Dev) 0 Utility to spin up a new Blink table from existing table data
Update table from table data (Maersk - Eng - Dev) 0 Utility to bulk-update a Blink table from another table's data
Convert Blink Table Export CSV to Blink Table JSON (Maersk - Eng - Dev) 0 Utility to convert a table export into the JSON import format
Get Table JSON (Maersk - Eng - Dev) 0 Utility to export a Blink table's contents as JSON
Parse CSV to JSON Batches 3 Utility to chunk a large CSV into JSON batches for processing
Data Conversion Utilities 0 Shared library of data-format conversion helpers
Delete Table Record 1 Utility to delete a single record from a Blink table
Deploy Global Variables into Workspace 0 Utility to push a set of global variables into a workspace
Table Custom Actions 0 Reusable custom action definitions for Blink table operations
Secret Server Custom Actions 0 Reusable custom action definitions for retrieving secrets from Secret Server

14. Infrastructure Uptime & Availability Monitoring

Category: Other

Subcategories: IT/OT & network infra monitoring

Description:

Pulls uptime and availability alerts from StatusCake so infrastructure monitoring data can be consumed alongside other security and IT signals.

Business problem solved:

Uptime/availability alerts lived in a standalone monitoring tool disconnected from the rest of the security and IT automation estate.

Integrations: StatusCake

Playbooks

Playbook Executions Role
Gather StatusCake Alerts 0 Pulls current uptime-check alerts from StatusCake

Key Observations

Strengths

  • Agentic SOC is the deployment's center of gravity. The three SOC-focused use cases (Alert Triage & Case Investigation, Alert & IOC Enrichment Pipeline, Identity & Endpoint Context Lookup) together span 61 playbooks and represent the most architecturally mature part of the deployment — a full case-management lifecycle (ingest → enrich → investigate → decide → close/escalate) built on reusable subflows and dedicated "Agent Ability" building blocks that expose enrichment and case-context actions directly to an AI decision layer.
  • Identity remediation is fully self-service and bidirectional. The RADAR use case covers both single-user and bulk compromised-account response (MFA reset, password reset, token revocation, emergency termination) across production and pre-production Entra ID tenants, indicating the automation is trusted for high-stakes, high-blast-radius identity actions rather than read-only investigation.
  • Deep, purpose-built integration with Maersk's internal platforms. Beyond commercial security tools, Blink integrates natively with Maersk-proprietary systems — MRMP (Resource Management Plane), MAC (Application Catalog), MSA (Service Atlas), and Stargate (internal identity/API gateway) — to enrich API security findings and Zero Trust access requests with application-ownership context. This is a meaningfully deeper integration footprint than typical out-of-the-box SOAR connectors.
  • Broad third-party ecosystem already wired in. Twenty-plus distinct integrations are active across the deployment, spanning EDR (CrowdStrike), vulnerability management (Qualys, Trend Micro Deep Security), API security (NoName Security), threat intel/enrichment (VirusTotal, AbuseIPDB, URLScan, Whois), network/cloud security (FireMon, Check Point, Akamai EAA, Zscaler ZIA, Forescout), identity (Entra ID/Active Directory, Okta, Google Workspace), and collaboration/ITSM (ServiceNow, GitHub, Jira, Confluence, Microsoft Teams, SendGrid, Slack) — giving Blink a genuine cross-domain orchestration role rather than sitting inside a single tool silo.
  • Operational self-sufficiency. A dedicated set of platform-administration playbooks keeps Confluence documentation, connection health, and table/data infrastructure in sync automatically, and failures in any Blink automation are proactively routed to the engineering team via Teams — reducing the operational overhead of running the platform itself.

Gaps / opportunities

  • Vulnerability management is comparatively thin. Only one use case (Qualys scan requests via ServiceNow) is mapped to the Vulnerability Mgmt category. Given Qualys and Trend Micro Deep Security are already integrated for agent-health checks, there is clear headroom to extend automation into scan-result triage, remediation ticketing, or SLA tracking rather than just scan initiation.
  • GRC coverage is narrow. Only the GitHub exposed-secret detection/notification workflow is currently classified under GRC. Compliance-control monitoring, audit evidence collection, and policy-exception tracking appear to be white space relative to the SOC investment.
  • No dedicated IAM-category use case. Identity actions today are scoped specifically to threat response (RADAR) and investigative lookups rather than broader lifecycle IAM (joiner/mover/leaver, access reviews, entitlement certification) — a natural adjacent expansion given the strength of the existing Entra ID/Okta integrations.
  • High-volume "Authentication Event Monitoring" workflow is a thin filter, not a full pipeline. At 42,412 executions it is by far the highest-volume workflow in the tenant, but it currently performs a single filtering step against Azure Monitor events rather than downstream enrichment or case creation — a candidate for building out into a fuller detection pipeline.
  • Environment sprawl. Most playbooks are deployed near-identically across up to 8 workspaces (production, pre-production, various dev/Eng-Dev, and "Connections & Runners" environments). This is expected for safe change management, but the ~22 leftover test/example/scratch workflows (e.g., EXAMPLE - *, Funny AI, New Test Workflow) identified during this analysis represent a small, low-risk cleanup opportunity to keep production workspaces lean.

Integration ecosystem summary

Security tooling: CrowdStrike · Qualys · Trend Micro Deep Security · NoName Security · VirusTotal · AbuseIPDB · URLScan · FireMon · Check Point · Akamai EAA · Zscaler ZIA · Forescout

Identity: Microsoft Entra ID / Active Directory · Okta · Google Workspace

ITSM & collaboration: ServiceNow · GitHub · Jira · Confluence · Microsoft Teams · Slack · SendGrid

Cloud & internal platforms: Azure Monitor · Azure Blob Storage · Maersk MRMP · Maersk MAC · Maersk MSA · Stargate

E New Integrations (detail) 8 added in last 30d

New Integrations Added - Last 30 Days

8 new connections
TenantIntegrationConnection NameAdded
Maersk sharepoint sharepoint_oci_prod 2026-08-28
Maersk blink blinkops_table_viewer 2026-08-26
Maersk blink blinkops_global_variable_manager 2026-08-26
Maersk blink blinkops_health_monitoring 2026-08-26
Maersk blink blinkops_production_viewer 2026-08-25
Maersk check-point-management checkpoint_management_blade_prod 2026-08-10
Maersk confluence confluence_prod 2026-08-04
Maersk confluence confluence_prod 2026-08-03