01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SIEM Log Intelligence & Search |
| 77.5% | 11 11 active |
| Domain & URL Threat Intelligence |
| 1.2% | 12 12 active |
| Agentic SOC Investigation |
| 0.5% | 23 23 active |
| SOC Case Management & Alert Routing |
| 2.2% | 14 14 active |
| Cloud Resource Utilization Reporting |
| 0.4% | 4 4 active |
| Compromised Credential Response |
| 0.2% | 4 4 active |
| Travel Authorization Sync |
| 0.2% | 1 1 active |
| Endpoint & Asset Visibility | 234 executions | 1.4% | 5 5 active |
| SIEM Detection Engineering | 92 executions | 0.6% | 3 3 active |
| Firewall Change Request Automation |
| 0.0% | 1 1 active |
| Total | 13,804 executions | 100% | 78 78 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Chronicle-centric SIEM posture. Mercury Insurance has deeply integrated Google Chronicle as its primary SIEM. The 6,903 UDM Log Search executions — by far the highest single-workflow count — confirm that Chronicle query automation is the backbone of the SOC investigation workflow. The adjacent UURR pipeline also reads Chronicle for cloud activity reporting, making it a multi-purpose analytical hub.
Dual-SIEM coverage. In parallel with Chronicle, the team runs CrowdStrike LogScale (384 executions) as a second SIEM tier. The coexistence of both SIEM query workflows suggests active usage of LogScale for CrowdStrike-native telemetry while Chronicle handles broader log coverage.
Mature threat intelligence pipeline. The domain/URL investigation cluster (URLScan, VirusTotal, Falcon Sandbox, ThreatConnect, GitHub, IP-API) represents one of the most sophisticated multi-source IOC enrichment setups in the Blink customer base. The separate "Downstream Aggregator" subflow (65 executions) confirms that results from all five upstream sources are being synthesized into unified verdicts.
Agentic SOC in active production. The 391 executions of SubFlow - Agentic - User or Admin Info Search combined with 23 completed Agentic SOC - Main - AI Investigation runs confirms that Mercury has moved beyond piloting AI-assisted triage — it is running in production with an active decision layer, expert agent layer, and case management integration.
Operational discipline around false-positive suppression. The Chronicle COC travel table update workflow (40 executions) is a notable operational maturity signal: the team is proactively syncing travel authorization data into the SIEM to contextualize geolocation anomalies, rather than relying on analysts to manually validate each alert.
ATG alert routing framework. The existence of ATG - Email Switch Case as a unified router for CrowdStrike, Proofpoint, and Varonis escalation paths indicates the team has built a standardized alert ingestion and routing framework — rather than one-off integrations for each source.
###
Gaps & Opportunities
Phishing response not yet automated. Despite having Proofpoint connected (via ATG escalation) and phishing response subflows defined in the case management workspace (with 0 executions), there is no active phishing investigation or remediation pipeline in production. Mercury has the infrastructure for it but has not yet wired it end-to-end.
Identity threat response (Okta) is dormant. Okta enrichment workflows are deployed across multiple workspaces but have 0 executions. If Okta is the primary IdP, this is a significant gap — identity-based threats are not being enriched from the IdP directly.
Vulnerability management is absent. No vulnerability scanning ingestion, CVE lookup, or vuln ticketing workflows are present. This is a common expansion area for teams that have matured their SOC operations.
DLP response not in production. A DLP - Open and Investigate Incident - ITM workflow (Proofpoint ITM) exists but has never run. Data exposure response is unautomated.
Multiple workflow versions in parallel. The UURR pipeline has v4 and v5 variants deployed simultaneously; the password response workflow has both prod and test variants active. Consolidating and deprecating unused versions would reduce operational clutter and confusion.
Error handling at scale. The On Workflow Failure handler ran 179 times — suggesting a meaningful number of workflow failures. This warrants a review of which workflows are generating the failures and whether they represent fixable reliability issues.
Integration Ecosystem
| Integration | Role | Active |
|---|---|---|
| Google Chronicle | Primary SIEM — UDM search, raw log retrieval, detection rules, cloud reporting | ✓ |
| CrowdStrike LogScale | Secondary SIEM — Falcon-native telemetry queries | ✓ |
| CrowdStrike Falcon | EDR — endpoint enrichment, sandbox analysis, alert ingestion | ✓ |
| ServiceNow | ITSM/SOAR — SIR lifecycle, SOC alert polling, firewall requests | ✓ |
| Glean | Enterprise search — internal context enrichment for agentic investigations | ✓ |
| Microsoft Entra ID / Active Directory | Identity — user lookup, login history, credential hygiene | ✓ |
| URLScan | URL threat intelligence | ✓ |
| VirusTotal | Hash / domain / IP reputation | ✓ |
| ThreatConnect | Threat intelligence platform — IOC investigation | ✓ |
| GitHub | Code/threat intelligence search | ✓ |
| Microsoft SharePoint | SOC record export and documentation | ✓ |
| Microsoft Outlook | Notification and alert delivery | ✓ |
| Microsoft XDR | Extended detection queries | ✓ |
| Absolute | Endpoint security and asset tracking | ✓ |
| Proofpoint | Email security — ATG routing (active), ITM/DLP (not yet active) | Partial |
| Varonis | MDDR escalation routing | ✓ |
| Okta | Identity enrichment — deployed but inactive | ✗ |
| AbuseIPDB | IP reputation | ✗ |
A Case Management 1,138 cases (12m) | MTTR 3d 19h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 1,095 | 1,095 | 0 | N/A |
| 1 - Production | 23 | 23 | 22 | 3d 11h |
| POC Workspace | 17 | 16 | 6 | 4d 23h |
| Caduceus | 4 | 4 | 0 | N/A |
B AI Agents 7 active | 180 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Absolute Travel Verifier | 1 - Production | 105 | 40 | 2,429,469 |
| 2 | Agent TI | Caduceus | 23 | 0 | 2,198,855 |
| 3 | Agent Blink - Decision Maker | Caduceus | 18 | 0 | 1,365,796 |
| 4 | Report Generator Agent | POC Workspace | 13 | 0 | 152,054 |
| 5 | Intelligence Normalization Agent | Caduceus | 7 | 7 | 734,195 |
| Workspace | Tasks (12m) |
|---|---|
| 1 - Production | 105 |
| Caduceus | 62 |
| POC Workspace | 13 |
| Infosec (Private) Workspace | 0 |
| 3 - Development | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Phibby Tracking | 0 | 0 |
| 2 | My 1st Dashboard | 0 | 0 |
| 3 | test | 0 | 0 |
| 4 | asdasda | 0 | 0 |
| 5 | CM Dashboard | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Demo Web Form | 0 | 0 |
D Full Use Case Analysis 10 use cases | 16,372 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Chronicle UDM log searches powering analyst investigations | 6,903 | UDM Log Search |
| LogScale SIEM queries executed | 384 | LogScale SIEM Search |
| ServiceNow investigation records retrieved on-demand | 316 | Pull individual Records - Verbose |
| Cloud resource utilization report batches processed | 201 | UURR v4 - Stage 3-1 |
| SOC active alerts polled & processed from ServiceNow | 199 | ServiceNow - SOC Active Alerts - Blink Polling |
| Security alerts automatically routed to response teams | 55 | ATG - Email Switch Case |
| Compromised password detection runs (daily scheduled) | 40 | (Prod-working) Compromised PW SNOW |
| Daily SIR batches exported to SOC SharePoint | 40 | uploading SIRs to SOC sharepoint |
| Travel authorizations synced to Chronicle SIEM | 40 | Chronicle COC travel table update |
| Agentic AI-driven SOC investigations completed | 23 | Subflow - Agentic SOC - Main - AI Investigation |
| Firewall change requests processed with AI recommendations | 19 | Firewall request recommendations copy |
| ThreatConnect IOC domain alerts automatically triaged | 19 | ThreatConnect - Domain Investigation |
| URL & domain full-pipeline investigations orchestrated | 16 | URL Investigation |
| AWS IAM user creation alerts triaged via Glean | 12 | Glean Triage - AWS IAM USER - Trigger |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks | Total Executions |
|---|---|---|---|---|---|
| 1 | SIEM Log Intelligence & Search | SOC | SIEM & log pipeline monitoring | 12 | 8,088 |
| 2 | Domain & URL Threat Intelligence | SOC | Alert enrichment / IOC lookup | 12 | 619 |
| 3 | Agentic SOC Investigation | SOC | Agentic SOC, Alert enrichment / IOC lookup | 24 | 750 |
| 4 | SOC Case Management & Alert Routing | SOC | Case mgmt & SOAR | 15 | 451 |
| 5 | Cloud Resource Utilization Reporting | GRC | Security metrics & reporting | 4 | 269 |
| 6 | Compromised Credential Response | IAM | Password & credential lifecycle | 4 | 45 |
| 7 | Travel Authorization Sync | SOC | SIEM & log pipeline monitoring | 1 | 40 |
| 8 | Endpoint & Asset Visibility | Other | Endpoint hygiene & MDM ops | 5 | 128 |
| 9 | SIEM Detection Engineering | SOC | SIEM & log pipeline monitoring | 3 | 8 |
| 10 | Firewall Change Request Automation | Other | IT helpdesk & ticket routing | 1 | 19 |
Total across all active workflows: 10,417 executions across 82 active workflows (251 total defined)
Use Cases
1. SIEM Log Intelligence & Search
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: The SOC team relies on automated query workflows spanning two SIEM platforms — Google Chronicle (UDM) and CrowdStrike LogScale — to retrieve structured event data, raw logs, and detection artifacts during investigations. These workflows function as the primary data retrieval layer for every analyst investigation, enabling fast on-demand and programmatic log access without manual console queries.
Business Problem Solved: Eliminates manual SIEM console navigation during active investigations; standardizes log retrieval across Chronicle and LogScale into reusable, auditable workflows callable by analysts and other automations alike.
Integrations: Google Chronicle (UDM), CrowdStrike LogScale, ServiceNow, Microsoft Entra ID, Microsoft XDR
| Playbook | Executions (12mo) | Link |
|---|---|---|
| UDM Log Search | 6,903 | |
| LogScale SIEM Search | 384 | |
| Pull individual Records - Verbose | 316 | |
| Raw Log Search | 145 | |
| ServiceNow Query - Records | 135 | |
| Pull raw logs from Crhonicle | 128 | |
| SubFlow - Chronicle Detection ID to raw | 46 | |
| chronicle parser review (random logs) | 9 | |
| Entra ID logins | 8 | |
| Microsoft XDR Query | 6 | |
| SubFlow - Entra ID All Login Types | 1 | |
| Function - Last 1000 failed logins | 1 |
2. Domain & URL Threat Intelligence
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: A coordinated multi-source threat intelligence pipeline that investigates suspicious domains, URLs, and IPs across URLScan, VirusTotal, CrowdStrike Falcon Sandbox, ThreatConnect, GitHub, and IP reputation APIs. Each source contributes a distinct signal — sandboxing, reputation scoring, WHOIS, company attribution — which are aggregated downstream into a unified verdict.
Business Problem Solved: Removes the need for analysts to manually query five or more threat intel platforms per alert; standardizes domain/URL triage into a repeatable pipeline that delivers consistent, comprehensive context in seconds.
Integrations: URLScan, VirusTotal, CrowdStrike Falcon Sandbox, ThreatConnect, GitHub, IP-API, Microsoft Teams
3. Agentic SOC Investigation
Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup
Description: Mercury Insurance has deployed Blink's AI-powered agentic SOC capability — an autonomous multi-step investigation layer that combines Glean enterprise search for internal context, Active Directory / Entra ID for user history, CrowdStrike for endpoint telemetry, and Blink's case management for case state. The agent reasons across these sources to triage alerts, determine severity, and reach automated disposition decisions.
Business Problem Solved: Reduces analyst workload on Tier-1 alert triage by enabling autonomous investigation that can gather context across six or more systems, synthesize findings, and produce an investigation summary — all without human intervention on routine alerts.
Integrations: Glean, Microsoft Active Directory, Microsoft Entra ID, CrowdStrike, Blink Case Management
4. SOC Case Management & Alert Routing
Category: SOC | Subcategory: Case mgmt & SOAR
Description: The ATG (Alert Triage & Gateway) framework automatically routes incoming security alerts from multiple sources — CrowdStrike, Proofpoint, Varonis MDDR, and Glean — into the correct ServiceNow SIR queues, attaching screenshots and enrichment artifacts. A continuous polling workflow monitors ServiceNow for active SOC alerts, and a daily export uploads all open SIRs to SharePoint for leadership visibility.
Business Problem Solved: Eliminates manual SIR creation, routing, and documentation steps for incoming alerts from five distinct detection systems; ensures consistent escalation paths and maintains a living SharePoint record of all open investigations.
Integrations: ServiceNow, CrowdStrike, Proofpoint, Varonis, Glean, Microsoft SharePoint, URLScan, Microsoft Outlook
5. Cloud Resource Utilization Reporting
Category: GRC | Subcategory: Security metrics & reporting
Description: A three-stage automated pipeline (UURR v4) that queries Chronicle for cloud user activity data, processes it in configurable weekly batches, and generates under-utilized cloud resource reports. Stage 1 initializes the report structure, Stage 2 pulls activity data, and Stage 3 handles large-scale parallel processing of resource batches — enabling reports that span thousands of cloud assets.
Business Problem Solved: Automates what would otherwise be a manual weekly analysis of cloud resource utilization across hundreds or thousands of assets; delivers consistent reports that can surface dormant accounts, unused instances, and over-provisioned resources for remediation and cost savings.
Integrations: Google Chronicle, HTTP (cloud APIs), Microsoft Active Directory
| Playbook | Executions (12mo) | Link |
|---|---|---|
| UURR v4 - Stage 3-1 | 201 | |
| UURR v4 - Stage 2 | 35 | |
| UURR-Access | 28 | |
| UURR v4 - Stage 1 | 5 |
6. Compromised Credential Response
Category: IAM | Subcategory: Password & credential lifecycle
Description: A daily scheduled workflow that checks for compromised passwords across Active Directory, cross-references CrowdStrike for endpoint exposure, and automatically creates ServiceNow incidents for any confirmed compromised credential. Supporting functions enumerate all AD users and retrieve detailed user profiles to enrich the incident record.
Business Problem Solved: Closes the gap between compromised credential intelligence and remediation action; eliminates the daily manual credential hygiene review by automating detection, enrichment, and ticket creation in a single scheduled pipeline.
Integrations: Microsoft Active Directory, CrowdStrike, ServiceNow, Microsoft Outlook
| Playbook | Executions (12mo) | Link |
|---|---|---|
| (Prod-working) Compromised PW SNOW | 40 | |
| Function - List all AD Users | 2 | |
| Function - UserDetails | 2 | |
| Function - Last 1000 failed logins | 1 |
7. Travel Authorization Sync
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: A nightly scheduled workflow that pulls approved travel request RITMs from ServiceNow and synchronizes the authorized traveler list into Chronicle. This ensures that SIEM geolocation-based alerts are automatically contextualized against known approved travel, suppressing false positives for analysts when employees access systems from foreign locations.
Business Problem Solved: Prevents false positive geolocation anomaly alerts from flooding the SOC queue during employee travel; integrates HR/administrative travel approvals directly into the SIEM detection layer without manual analyst intervention.
Integrations: ServiceNow, Google Chronicle
| Playbook | Executions (12mo) | Link |
|---|---|---|
| Chronicle COC travel table update | 40 |
8. Endpoint & Asset Visibility
Category: Other | Subcategory: Endpoint hygiene & MDM ops
Description: A collection of reusable access and search workflows for three endpoint/asset management platforms — Absolute (endpoint security and asset tracking), Maven, and WSS — that are queried as part of broader SOC and cloud reporting investigations. These workflows provide the authenticated connectivity layer that other investigation pipelines call when they need endpoint telemetry.
Business Problem Solved: Standardizes cross-platform endpoint and asset queries into reusable, auditable Blink workflows; makes endpoint context available to automated investigations without requiring analysts to manually navigate each platform's console.
Integrations: Absolute, ServiceNow, Maven, WSS
| Playbook | Executions (12mo) | Link |
|---|---|---|
| ServiceNow - Access | 41 | |
| Absolute - Access | 40 | |
| WSS - Access copy | 20 | |
| Maven - Access | 14 | |
| Absolute Search | 13 |
9. SIEM Detection Engineering
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: Workflows supporting the creation, scoping, and validation of Chronicle detection rules, enabling the security engineering team to programmatically manage SIEM rule lifecycles without manual console access.
Business Problem Solved: Accelerates the detection engineering cycle by embedding rule validation and creation into automated, reusable workflows that can be called on demand or integrated into CI/CD-style detection pipelines.
Integrations: Google Chronicle
| Playbook | Executions (12mo) | Link |
|---|---|---|
| Rule Validate | 5 | |
| Need Scope - Rule Creation | 2 | |
| Get Rules | 1 |
10. Firewall Change Request Automation
Category: Other | Subcategory: IT helpdesk & ticket routing
Description: An event-driven workflow that monitors ServiceNow for firewall change request catalog items and automatically generates AI-powered firewall rule recommendations. When a new matching request is created, Blink retrieves context, applies policy logic, and produces actionable guidance to accelerate the network security review process.
Business Problem Solved: Removes the manual triage step where network security engineers first read the change request, look up context, and draft recommendations; automates the initial analysis so engineers receive a pre-populated recommendation and can focus on approval/adjustment.
Integrations: ServiceNow
| Playbook | Executions (12mo) | Link |
|---|---|---|
| Firewall request recommendations copy | 19 |
Key Observations
Strengths
Chronicle-centric SIEM posture. Mercury Insurance has deeply integrated Google Chronicle as its primary SIEM. The 6,903 UDM Log Search executions — by far the highest single-workflow count — confirm that Chronicle query automation is the backbone of the SOC investigation workflow. The adjacent UURR pipeline also reads Chronicle for cloud activity reporting, making it a multi-purpose analytical hub.
Dual-SIEM coverage. In parallel with Chronicle, the team runs CrowdStrike LogScale (384 executions) as a second SIEM tier. The coexistence of both SIEM query workflows suggests active usage of LogScale for CrowdStrike-native telemetry while Chronicle handles broader log coverage.
Mature threat intelligence pipeline. The domain/URL investigation cluster (URLScan, VirusTotal, Falcon Sandbox, ThreatConnect, GitHub, IP-API) represents one of the most sophisticated multi-source IOC enrichment setups in the Blink customer base. The separate "Downstream Aggregator" subflow (65 executions) confirms that results from all five upstream sources are being synthesized into unified verdicts.
Agentic SOC in active production. The 391 executions of SubFlow - Agentic - User or Admin Info Search combined with 23 completed Agentic SOC - Main - AI Investigation runs confirms that Mercury has moved beyond piloting AI-assisted triage — it is running in production with an active decision layer, expert agent layer, and case management integration.
Operational discipline around false-positive suppression. The Chronicle COC travel table update workflow (40 executions) is a notable operational maturity signal: the team is proactively syncing travel authorization data into the SIEM to contextualize geolocation anomalies, rather than relying on analysts to manually validate each alert.
ATG alert routing framework. The existence of ATG - Email Switch Case as a unified router for CrowdStrike, Proofpoint, and Varonis escalation paths indicates the team has built a standardized alert ingestion and routing framework — rather than one-off integrations for each source.
Gaps & Opportunities
Phishing response not yet automated. Despite having Proofpoint connected (via ATG escalation) and phishing response subflows defined in the case management workspace (with 0 executions), there is no active phishing investigation or remediation pipeline in production. Mercury has the infrastructure for it but has not yet wired it end-to-end.
Identity threat response (Okta) is dormant. Okta enrichment workflows are deployed across multiple workspaces but have 0 executions. If Okta is the primary IdP, this is a significant gap — identity-based threats are not being enriched from the IdP directly.
Vulnerability management is absent. No vulnerability scanning ingestion, CVE lookup, or vuln ticketing workflows are present. This is a common expansion area for teams that have matured their SOC operations.
DLP response not in production. A DLP - Open and Investigate Incident - ITM workflow (Proofpoint ITM) exists but has never run. Data exposure response is unautomated.
Multiple workflow versions in parallel. The UURR pipeline has v4 and v5 variants deployed simultaneously; the password response workflow has both prod and test variants active. Consolidating and deprecating unused versions would reduce operational clutter and confusion.
Error handling at scale. The On Workflow Failure handler ran 179 times — suggesting a meaningful number of workflow failures. This warrants a review of which workflows are generating the failures and whether they represent fixable reliability issues.
Integration Ecosystem
| Integration | Role | Active |
|---|---|---|
| Google Chronicle | Primary SIEM — UDM search, raw log retrieval, detection rules, cloud reporting | ✓ |
| CrowdStrike LogScale | Secondary SIEM — Falcon-native telemetry queries | ✓ |
| CrowdStrike Falcon | EDR — endpoint enrichment, sandbox analysis, alert ingestion | ✓ |
| ServiceNow | ITSM/SOAR — SIR lifecycle, SOC alert polling, firewall requests | ✓ |
| Glean | Enterprise search — internal context enrichment for agentic investigations | ✓ |
| Microsoft Entra ID / Active Directory | Identity — user lookup, login history, credential hygiene | ✓ |
| URLScan | URL threat intelligence | ✓ |
| VirusTotal | Hash / domain / IP reputation | ✓ |
| ThreatConnect | Threat intelligence platform — IOC investigation | ✓ |
| GitHub | Code/threat intelligence search | ✓ |
| Microsoft SharePoint | SOC record export and documentation | ✓ |
| Microsoft Outlook | Notification and alert delivery | ✓ |
| Microsoft XDR | Extended detection queries | ✓ |
| Absolute | Endpoint security and asset tracking | ✓ |
| Proofpoint | Email security — ATG routing (active), ITM/DLP (not yet active) | Partial |
| Varonis | MDDR escalation routing | ✓ |
| Okta | Identity enrichment — deployed but inactive | ✗ |
| AbuseIPDB | IP reputation | ✗ |
E New Integrations (detail) 9 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| mercury-insurance | chronicle | chronicle_iam_connection | 2026-08-13 |
| mercury-insurance | glean | my_glean_connection | 2026-08-12 |
| mercury-insurance | bearer-token | cyderes_tsi_authentication | 2026-08-12 |
| mercury-insurance | aws | aws_s3_northstar_metrics_qa | 2026-08-11 |
| mercury-insurance | aws | aws_s3_northstar_metrics_dev | 2026-08-11 |
| mercury-insurance | aws | my_aws_connection | 2026-08-11 |
| mercury-insurance | glean | eric_glean_key | 2026-08-11 |
| mercury-insurance | confluence | my_confluence_connection | 2026-08-11 |
| mercury-insurance | jira | my_jira_connection | 2026-08-11 |