Blink Security Automation — Confidential

mercury-insurance — Customer Success Report

Generated 2026-08-30 | mercury-insurance-value-report.md
2026-08-30Report Date
823Total Playbooks
16,563Unique Workflows (12m)
2,489,708Actions Automated (12m)
$640,357Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

823
Total playbooks built
all non-deleted workflows
480
Active playbooks
currently enabled
16,563
Unique workflows executed (12m)
distinct workflows that ran
2,489,708
Actions automated (12m)
completed action steps
13,831.7h
Hours saved (12m)
@ 20s per action
$640,357
Money saved (12m)
@ $100K avg salary
55
New active workflows (last 30d)
recently created & enabled
1,139
Total cases managed
1,138 opened in last 12m
3d 19h
MTTR — mean time to resolve
closed cases, last 12m
7
Active AI agents
of 29 total
180
AI agent tasks executed (12m)
47 in last 30d
In the last 12 months, Blink automated: - 6,903 Chronicle UDM log searches powering SOC analyst investigations - 384 CrowdStrike LogScale SIEM queries executed across detection pipelines - 316 ServiceNow investigation records retrieved on demand - 201 cloud resource utilization report batches processed - 199 SOC active alerts continuously polled and processed from ServiceNow - 55 security alerts automatically routed to the correct response teams - 40 daily compromised password detection cycles run end-to-end - 40 daily SIR batches uploaded to SOC SharePoint for record-keeping - 40 travel authorization lists synced into Chronicle to suppress false positives - 23 agentic AI-driven SOC investigations completed autonomously - 19 firewall change requests processed with AI-generated recommendations - 19 ThreatConnect IOC domain alerts automatically triaged and enriched - 12 AWS IAM user creation alerts triaged with Glean enterprise context

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SIEM Log Intelligence & Search
  • 6,903Chronicle UDM log searches powering analyst investigations
  • 384LogScale SIEM queries executed
  • 316ServiceNow investigation records retrieved on-demand
77.5%
11
11 active
Domain & URL Threat Intelligence
  • 19ThreatConnect IOC domain alerts automatically triaged
  • 16URL & domain full-pipeline investigations orchestrated
1.2%
12
12 active
Agentic SOC Investigation
  • 23Agentic AI-driven SOC investigations completed
0.5%
23
23 active
SOC Case Management & Alert Routing
  • 199SOC active alerts polled & processed from ServiceNow
  • 55Security alerts automatically routed to response teams
  • 40Daily SIR batches exported to SOC SharePoint
2.2%
14
14 active
Cloud Resource Utilization Reporting
  • 201Cloud resource utilization report batches processed
0.4%
4
4 active
Compromised Credential Response
  • 40Compromised password detection runs (daily scheduled)
0.2%
4
4 active
Travel Authorization Sync
  • 40Travel authorizations synced to Chronicle SIEM
0.2%
1
1 active
Endpoint & Asset Visibility234 executions
1.4%
5
5 active
SIEM Detection Engineering92 executions
0.6%
3
3 active
Firewall Change Request Automation
  • 19Firewall change requests processed with AI recommendations
0.0%
1
1 active
Total13,804 executions100%
78
78 active

Use Case Growth Over Time

623 unique playbooks  |  10 operational use cases  |  16,372 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Agentic SOC Investigation
Microsoft Entra ID Glean Agents Chronicle CrowdStrike
Domain & URL Threat Intelligence
Extraction Utilities String Utilities AbuseIPDB IP API Glean CrowdStrike ServiceNow URLScan VirusTotal GitHub
Cloud Resource Utilization Reporting
Chronicle Email CrowdStrike
Compromised Credential Response
Microsoft Outlook CrowdStrike ServiceNow Microsoft Entra ID Email Chronicle Microsoft Graph
SOC Case Management & Alert Routing
ServiceNow Email Microsoft Teams Chronicle Glean SharePoint URLScan Microsoft Outlook
SIEM Log Intelligence & Search
Microsoft Entra ID Glean Chronicle ServiceNow CrowdStrike Microsoft Outlook
Travel Authorization Sync
ServiceNow Chronicle
Firewall Change Request Automation
ServiceNow Glean
SIEM Detection Engineering
Chronicle
Endpoint & Asset Visibility
Absolute

04Key Observations

✓  Strengths

Strengths

Chronicle-centric SIEM posture. Mercury Insurance has deeply integrated Google Chronicle as its primary SIEM. The 6,903 UDM Log Search executions — by far the highest single-workflow count — confirm that Chronicle query automation is the backbone of the SOC investigation workflow. The adjacent UURR pipeline also reads Chronicle for cloud activity reporting, making it a multi-purpose analytical hub.

Dual-SIEM coverage. In parallel with Chronicle, the team runs CrowdStrike LogScale (384 executions) as a second SIEM tier. The coexistence of both SIEM query workflows suggests active usage of LogScale for CrowdStrike-native telemetry while Chronicle handles broader log coverage.

Mature threat intelligence pipeline. The domain/URL investigation cluster (URLScan, VirusTotal, Falcon Sandbox, ThreatConnect, GitHub, IP-API) represents one of the most sophisticated multi-source IOC enrichment setups in the Blink customer base. The separate "Downstream Aggregator" subflow (65 executions) confirms that results from all five upstream sources are being synthesized into unified verdicts.

Agentic SOC in active production. The 391 executions of SubFlow - Agentic - User or Admin Info Search combined with 23 completed Agentic SOC - Main - AI Investigation runs confirms that Mercury has moved beyond piloting AI-assisted triage — it is running in production with an active decision layer, expert agent layer, and case management integration.

Operational discipline around false-positive suppression. The Chronicle COC travel table update workflow (40 executions) is a notable operational maturity signal: the team is proactively syncing travel authorization data into the SIEM to contextualize geolocation anomalies, rather than relying on analysts to manually validate each alert.

ATG alert routing framework. The existence of ATG - Email Switch Case as a unified router for CrowdStrike, Proofpoint, and Varonis escalation paths indicates the team has built a standardized alert ingestion and routing framework — rather than one-off integrations for each source.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Phishing response not yet automated. Despite having Proofpoint connected (via ATG escalation) and phishing response subflows defined in the case management workspace (with 0 executions), there is no active phishing investigation or remediation pipeline in production. Mercury has the infrastructure for it but has not yet wired it end-to-end.

Identity threat response (Okta) is dormant. Okta enrichment workflows are deployed across multiple workspaces but have 0 executions. If Okta is the primary IdP, this is a significant gap — identity-based threats are not being enriched from the IdP directly.

Vulnerability management is absent. No vulnerability scanning ingestion, CVE lookup, or vuln ticketing workflows are present. This is a common expansion area for teams that have matured their SOC operations.

DLP response not in production. A DLP - Open and Investigate Incident - ITM workflow (Proofpoint ITM) exists but has never run. Data exposure response is unautomated.

Multiple workflow versions in parallel. The UURR pipeline has v4 and v5 variants deployed simultaneously; the password response workflow has both prod and test variants active. Consolidating and deprecating unused versions would reduce operational clutter and confusion.

Error handling at scale. The On Workflow Failure handler ran 179 times — suggesting a meaningful number of workflow failures. This warrants a review of which workflows are generating the failures and whether they represent fixable reliability issues.

Integration Ecosystem

Integration Role Active
Google Chronicle Primary SIEM — UDM search, raw log retrieval, detection rules, cloud reporting ✓
CrowdStrike LogScale Secondary SIEM — Falcon-native telemetry queries ✓
CrowdStrike Falcon EDR — endpoint enrichment, sandbox analysis, alert ingestion ✓
ServiceNow ITSM/SOAR — SIR lifecycle, SOC alert polling, firewall requests ✓
Glean Enterprise search — internal context enrichment for agentic investigations ✓
Microsoft Entra ID / Active Directory Identity — user lookup, login history, credential hygiene ✓
URLScan URL threat intelligence ✓
VirusTotal Hash / domain / IP reputation ✓
ThreatConnect Threat intelligence platform — IOC investigation ✓
GitHub Code/threat intelligence search ✓
Microsoft SharePoint SOC record export and documentation ✓
Microsoft Outlook Notification and alert delivery ✓
Microsoft XDR Extended detection queries ✓
Absolute Endpoint security and asset tracking ✓
Proofpoint Email security — ATG routing (active), ITM/DLP (not yet active) Partial
Varonis MDDR escalation routing ✓
Okta Identity enrichment — deployed but inactive ✗
AbuseIPDB IP reputation ✗
Appendices
A Case Management 1,138 cases (12m) | MTTR 3d 19h

Case Management

Total Cases (all-time)
1,139
1,138 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
28
of 1,138 opened
MTTR
3d 19h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 1,095 1,095 0 N/A
1 - Production 23 23 22 3d 11h
POC Workspace 17 16 6 4d 23h
Caduceus 4 4 0 N/A
B AI Agents 7 active | 180 tasks (12m)

AI Agents

Active Agents
7
of 29 total
Tasks Executed (12m)
180
47 in last 30d
Data Usage (12m)
7,558,050
1,701,330 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Absolute Travel Verifier 1 - Production 105 40 2,429,469
2 Agent TI Caduceus 23 0 2,198,855
3 Agent Blink - Decision Maker Caduceus 18 0 1,365,796
4 Report Generator Agent POC Workspace 13 0 152,054
5 Intelligence Normalization Agent Caduceus 7 7 734,195
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
1 - Production105
Caduceus62
POC Workspace13
Infosec (Private) Workspace0
3 - Development0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
7
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Phibby Tracking 00
2 My 1st Dashboard 00
3 test 00
4 asdasda 00
5 CM Dashboard 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Demo Web Form 00
D Full Use Case Analysis 10 use cases | 16,372 executions (12m)

Business KPIs

Metric Count Playbook
Chronicle UDM log searches powering analyst investigations 6,903 UDM Log Search
LogScale SIEM queries executed 384 LogScale SIEM Search
ServiceNow investigation records retrieved on-demand 316 Pull individual Records - Verbose
Cloud resource utilization report batches processed 201 UURR v4 - Stage 3-1
SOC active alerts polled & processed from ServiceNow 199 ServiceNow - SOC Active Alerts - Blink Polling
Security alerts automatically routed to response teams 55 ATG - Email Switch Case
Compromised password detection runs (daily scheduled) 40 (Prod-working) Compromised PW SNOW
Daily SIR batches exported to SOC SharePoint 40 uploading SIRs to SOC sharepoint
Travel authorizations synced to Chronicle SIEM 40 Chronicle COC travel table update
Agentic AI-driven SOC investigations completed 23 Subflow - Agentic SOC - Main - AI Investigation
Firewall change requests processed with AI recommendations 19 Firewall request recommendations copy
ThreatConnect IOC domain alerts automatically triaged 19 ThreatConnect - Domain Investigation
URL & domain full-pipeline investigations orchestrated 16 URL Investigation
AWS IAM user creation alerts triaged via Glean 12 Glean Triage - AWS IAM USER - Trigger
In the last 12 months, Blink automated: - 6,903 Chronicle UDM log searches powering SOC analyst investigations - 384 CrowdStrike LogScale SIEM queries executed across detection pipelines - 316 ServiceNow investigation records retrieved on demand - 201 cloud resource utilization report batches processed - 199 SOC active alerts continuously polled and processed from ServiceNow - 55 security alerts automatically routed to the correct response teams - 40 daily compromised password detection cycles run end-to-end - 40 daily SIR batches uploaded to SOC SharePoint for record-keeping - 40 travel authorization lists synced into Chronicle to suppress false positives - 23 agentic AI-driven SOC investigations completed autonomously - 19 firewall change requests processed with AI-generated recommendations - 19 ThreatConnect IOC domain alerts automatically triaged and enriched - 12 AWS IAM user creation alerts triaged with Glean enterprise context

Use Case Summary

# Use Case Category Subcategories Playbooks Total Executions
1 SIEM Log Intelligence & Search SOC SIEM & log pipeline monitoring 12 8,088
2 Domain & URL Threat Intelligence SOC Alert enrichment / IOC lookup 12 619
3 Agentic SOC Investigation SOC Agentic SOC, Alert enrichment / IOC lookup 24 750
4 SOC Case Management & Alert Routing SOC Case mgmt & SOAR 15 451
5 Cloud Resource Utilization Reporting GRC Security metrics & reporting 4 269
6 Compromised Credential Response IAM Password & credential lifecycle 4 45
7 Travel Authorization Sync SOC SIEM & log pipeline monitoring 1 40
8 Endpoint & Asset Visibility Other Endpoint hygiene & MDM ops 5 128
9 SIEM Detection Engineering SOC SIEM & log pipeline monitoring 3 8
10 Firewall Change Request Automation Other IT helpdesk & ticket routing 1 19

Total across all active workflows: 10,417 executions across 82 active workflows (251 total defined)

Use Cases

1. SIEM Log Intelligence & Search

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: The SOC team relies on automated query workflows spanning two SIEM platforms — Google Chronicle (UDM) and CrowdStrike LogScale — to retrieve structured event data, raw logs, and detection artifacts during investigations. These workflows function as the primary data retrieval layer for every analyst investigation, enabling fast on-demand and programmatic log access without manual console queries.

Business Problem Solved: Eliminates manual SIEM console navigation during active investigations; standardizes log retrieval across Chronicle and LogScale into reusable, auditable workflows callable by analysts and other automations alike.

Integrations: Google Chronicle (UDM), CrowdStrike LogScale, ServiceNow, Microsoft Entra ID, Microsoft XDR

Playbook Executions (12mo) Link
UDM Log Search 6,903
LogScale SIEM Search 384
Pull individual Records - Verbose 316
Raw Log Search 145
ServiceNow Query - Records 135
Pull raw logs from Crhonicle 128
SubFlow - Chronicle Detection ID to raw 46
chronicle parser review (random logs) 9
Entra ID logins 8
Microsoft XDR Query 6
SubFlow - Entra ID All Login Types 1
Function - Last 1000 failed logins 1

2. Domain & URL Threat Intelligence

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: A coordinated multi-source threat intelligence pipeline that investigates suspicious domains, URLs, and IPs across URLScan, VirusTotal, CrowdStrike Falcon Sandbox, ThreatConnect, GitHub, and IP reputation APIs. Each source contributes a distinct signal — sandboxing, reputation scoring, WHOIS, company attribution — which are aggregated downstream into a unified verdict.

Business Problem Solved: Removes the need for analysts to manually query five or more threat intel platforms per alert; standardizes domain/URL triage into a repeatable pipeline that delivers consistent, comprehensive context in seconds.

Integrations: URLScan, VirusTotal, CrowdStrike Falcon Sandbox, ThreatConnect, GitHub, IP-API, Microsoft Teams

Playbook Executions (12mo) Link
SubFlow - Domain Company Search 133
SubFlow - URLScan URL Triage 111
SubFlow - VirusTotal - Domain Investigation 89
SubFlow - Falcon Sandbox - Domain Investigation 88
Github Search 69
SubFlow - Domain Investigation Downstream Aggregator 65
ThreatConnect - Domain Investigation 19
URL Investigation 16
SubFlow - Max Accuracy IP Investigation 14
IP API Lookup 9
SubFlow - URL - Raw Log Investigator 4
Secure URL Screenshot Capture 2

3. Agentic SOC Investigation

Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup

Description: Mercury Insurance has deployed Blink's AI-powered agentic SOC capability — an autonomous multi-step investigation layer that combines Glean enterprise search for internal context, Active Directory / Entra ID for user history, CrowdStrike for endpoint telemetry, and Blink's case management for case state. The agent reasons across these sources to triage alerts, determine severity, and reach automated disposition decisions.

Business Problem Solved: Reduces analyst workload on Tier-1 alert triage by enabling autonomous investigation that can gather context across six or more systems, synthesize findings, and produce an investigation summary — all without human intervention on routine alerts.

Integrations: Glean, Microsoft Active Directory, Microsoft Entra ID, CrowdStrike, Blink Case Management

Playbook Executions (12mo) Link
SubFlow - Agentic - User or Admin Info Search 391
SubFlow - Increment Global Variable 171
Glean Search - Internal Context 42
Subflow - Agentic SOC - Main - AI Investigation 23
Agent Ability - Get VIP Users 20
Agentic SOC - Decision Layer 13
Subflow - Enrich Observables - Main Router 11
SubFlow - Entra ID - User Info 10
Enrich - Username or Email - Microsoft Entra ID 9
Get User Information Using Microsoft Entra ID 9
Subflow - Update Enrichment Data 9
AI Workflow Validation - Find All Workflow Execution IDs for a Workflow 8
Agentic SOC - Expert Agents 7
Agent Ability - Get Org Assets 7
Agent Ability - Get Case Observable's Enrichment 7
Subflow - Response - Main Router 4
Utility - Refresh investigation 2
Get Observables by Case ID 2
Reclose previously investigated cases 1
Pull Alerts - Crowdstrike 1
Process Alert 1
Query Observable 1
Ingest Alert Example 1
SubFlow - Extract Chronicle Event From payload-case_id 1

4. SOC Case Management & Alert Routing

Category: SOC | Subcategory: Case mgmt & SOAR

Description: The ATG (Alert Triage & Gateway) framework automatically routes incoming security alerts from multiple sources — CrowdStrike, Proofpoint, Varonis MDDR, and Glean — into the correct ServiceNow SIR queues, attaching screenshots and enrichment artifacts. A continuous polling workflow monitors ServiceNow for active SOC alerts, and a daily export uploads all open SIRs to SharePoint for leadership visibility.

Business Problem Solved: Eliminates manual SIR creation, routing, and documentation steps for incoming alerts from five distinct detection systems; ensures consistent escalation paths and maintains a living SharePoint record of all open investigations.

Integrations: ServiceNow, CrowdStrike, Proofpoint, Varonis, Glean, Microsoft SharePoint, URLScan, Microsoft Outlook

Playbook Executions (12mo) Link
ServiceNow - SOC Active Alerts - Blink Polling 199
ATG - Email Switch Case 55
SubFlow Dev - URLScan Image to SNOW 45
SubFlow - CrowdStrike Escalation ATG 41
uploading SIRs to SOC sharepoint 40
Subflow - Get Records - to JSON/CSV 15
SubFlow - Proofpoint ATG 14
Individual - Pull Investigation Details SNOW 13
Glean Triage - AWS IAM USER - Trigger 12
En Masse - ServiceNow Records 6
SubFlow - Varonis MDDR Escalation ATG 5
SubFLow - Email a csv via table_name 2
Glean Triage - Group Policy Change Detected 2
SubFlow - Prod_SNOW SIR Creation and Dedup 1
SubFLow - Attach csv-table to SIR/INC 1

5. Cloud Resource Utilization Reporting

Category: GRC | Subcategory: Security metrics & reporting

Description: A three-stage automated pipeline (UURR v4) that queries Chronicle for cloud user activity data, processes it in configurable weekly batches, and generates under-utilized cloud resource reports. Stage 1 initializes the report structure, Stage 2 pulls activity data, and Stage 3 handles large-scale parallel processing of resource batches — enabling reports that span thousands of cloud assets.

Business Problem Solved: Automates what would otherwise be a manual weekly analysis of cloud resource utilization across hundreds or thousands of assets; delivers consistent reports that can surface dormant accounts, unused instances, and over-provisioned resources for remediation and cost savings.

Integrations: Google Chronicle, HTTP (cloud APIs), Microsoft Active Directory

Playbook Executions (12mo) Link
UURR v4 - Stage 3-1 201
UURR v4 - Stage 2 35
UURR-Access 28
UURR v4 - Stage 1 5

6. Compromised Credential Response

Category: IAM | Subcategory: Password & credential lifecycle

Description: A daily scheduled workflow that checks for compromised passwords across Active Directory, cross-references CrowdStrike for endpoint exposure, and automatically creates ServiceNow incidents for any confirmed compromised credential. Supporting functions enumerate all AD users and retrieve detailed user profiles to enrich the incident record.

Business Problem Solved: Closes the gap between compromised credential intelligence and remediation action; eliminates the daily manual credential hygiene review by automating detection, enrichment, and ticket creation in a single scheduled pipeline.

Integrations: Microsoft Active Directory, CrowdStrike, ServiceNow, Microsoft Outlook

Playbook Executions (12mo) Link
(Prod-working) Compromised PW SNOW 40
Function - List all AD Users 2
Function - UserDetails 2
Function - Last 1000 failed logins 1

7. Travel Authorization Sync

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: A nightly scheduled workflow that pulls approved travel request RITMs from ServiceNow and synchronizes the authorized traveler list into Chronicle. This ensures that SIEM geolocation-based alerts are automatically contextualized against known approved travel, suppressing false positives for analysts when employees access systems from foreign locations.

Business Problem Solved: Prevents false positive geolocation anomaly alerts from flooding the SOC queue during employee travel; integrates HR/administrative travel approvals directly into the SIEM detection layer without manual analyst intervention.

Integrations: ServiceNow, Google Chronicle

Playbook Executions (12mo) Link
Chronicle COC travel table update 40

8. Endpoint & Asset Visibility

Category: Other | Subcategory: Endpoint hygiene & MDM ops

Description: A collection of reusable access and search workflows for three endpoint/asset management platforms — Absolute (endpoint security and asset tracking), Maven, and WSS — that are queried as part of broader SOC and cloud reporting investigations. These workflows provide the authenticated connectivity layer that other investigation pipelines call when they need endpoint telemetry.

Business Problem Solved: Standardizes cross-platform endpoint and asset queries into reusable, auditable Blink workflows; makes endpoint context available to automated investigations without requiring analysts to manually navigate each platform's console.

Integrations: Absolute, ServiceNow, Maven, WSS

Playbook Executions (12mo) Link
ServiceNow - Access 41
Absolute - Access 40
WSS - Access copy 20
Maven - Access 14
Absolute Search 13

9. SIEM Detection Engineering

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: Workflows supporting the creation, scoping, and validation of Chronicle detection rules, enabling the security engineering team to programmatically manage SIEM rule lifecycles without manual console access.

Business Problem Solved: Accelerates the detection engineering cycle by embedding rule validation and creation into automated, reusable workflows that can be called on demand or integrated into CI/CD-style detection pipelines.

Integrations: Google Chronicle

Playbook Executions (12mo) Link
Rule Validate 5
Need Scope - Rule Creation 2
Get Rules 1

10. Firewall Change Request Automation

Category: Other | Subcategory: IT helpdesk & ticket routing

Description: An event-driven workflow that monitors ServiceNow for firewall change request catalog items and automatically generates AI-powered firewall rule recommendations. When a new matching request is created, Blink retrieves context, applies policy logic, and produces actionable guidance to accelerate the network security review process.

Business Problem Solved: Removes the manual triage step where network security engineers first read the change request, look up context, and draft recommendations; automates the initial analysis so engineers receive a pre-populated recommendation and can focus on approval/adjustment.

Integrations: ServiceNow

Playbook Executions (12mo) Link
Firewall request recommendations copy 19

Key Observations

Strengths

Chronicle-centric SIEM posture. Mercury Insurance has deeply integrated Google Chronicle as its primary SIEM. The 6,903 UDM Log Search executions — by far the highest single-workflow count — confirm that Chronicle query automation is the backbone of the SOC investigation workflow. The adjacent UURR pipeline also reads Chronicle for cloud activity reporting, making it a multi-purpose analytical hub.

Dual-SIEM coverage. In parallel with Chronicle, the team runs CrowdStrike LogScale (384 executions) as a second SIEM tier. The coexistence of both SIEM query workflows suggests active usage of LogScale for CrowdStrike-native telemetry while Chronicle handles broader log coverage.

Mature threat intelligence pipeline. The domain/URL investigation cluster (URLScan, VirusTotal, Falcon Sandbox, ThreatConnect, GitHub, IP-API) represents one of the most sophisticated multi-source IOC enrichment setups in the Blink customer base. The separate "Downstream Aggregator" subflow (65 executions) confirms that results from all five upstream sources are being synthesized into unified verdicts.

Agentic SOC in active production. The 391 executions of SubFlow - Agentic - User or Admin Info Search combined with 23 completed Agentic SOC - Main - AI Investigation runs confirms that Mercury has moved beyond piloting AI-assisted triage — it is running in production with an active decision layer, expert agent layer, and case management integration.

Operational discipline around false-positive suppression. The Chronicle COC travel table update workflow (40 executions) is a notable operational maturity signal: the team is proactively syncing travel authorization data into the SIEM to contextualize geolocation anomalies, rather than relying on analysts to manually validate each alert.

ATG alert routing framework. The existence of ATG - Email Switch Case as a unified router for CrowdStrike, Proofpoint, and Varonis escalation paths indicates the team has built a standardized alert ingestion and routing framework — rather than one-off integrations for each source.

Gaps & Opportunities

Phishing response not yet automated. Despite having Proofpoint connected (via ATG escalation) and phishing response subflows defined in the case management workspace (with 0 executions), there is no active phishing investigation or remediation pipeline in production. Mercury has the infrastructure for it but has not yet wired it end-to-end.

Identity threat response (Okta) is dormant. Okta enrichment workflows are deployed across multiple workspaces but have 0 executions. If Okta is the primary IdP, this is a significant gap — identity-based threats are not being enriched from the IdP directly.

Vulnerability management is absent. No vulnerability scanning ingestion, CVE lookup, or vuln ticketing workflows are present. This is a common expansion area for teams that have matured their SOC operations.

DLP response not in production. A DLP - Open and Investigate Incident - ITM workflow (Proofpoint ITM) exists but has never run. Data exposure response is unautomated.

Multiple workflow versions in parallel. The UURR pipeline has v4 and v5 variants deployed simultaneously; the password response workflow has both prod and test variants active. Consolidating and deprecating unused versions would reduce operational clutter and confusion.

Error handling at scale. The On Workflow Failure handler ran 179 times — suggesting a meaningful number of workflow failures. This warrants a review of which workflows are generating the failures and whether they represent fixable reliability issues.

Integration Ecosystem

Integration Role Active
Google Chronicle Primary SIEM — UDM search, raw log retrieval, detection rules, cloud reporting ✓
CrowdStrike LogScale Secondary SIEM — Falcon-native telemetry queries ✓
CrowdStrike Falcon EDR — endpoint enrichment, sandbox analysis, alert ingestion ✓
ServiceNow ITSM/SOAR — SIR lifecycle, SOC alert polling, firewall requests ✓
Glean Enterprise search — internal context enrichment for agentic investigations ✓
Microsoft Entra ID / Active Directory Identity — user lookup, login history, credential hygiene ✓
URLScan URL threat intelligence ✓
VirusTotal Hash / domain / IP reputation ✓
ThreatConnect Threat intelligence platform — IOC investigation ✓
GitHub Code/threat intelligence search ✓
Microsoft SharePoint SOC record export and documentation ✓
Microsoft Outlook Notification and alert delivery ✓
Microsoft XDR Extended detection queries ✓
Absolute Endpoint security and asset tracking ✓
Proofpoint Email security — ATG routing (active), ITM/DLP (not yet active) Partial
Varonis MDDR escalation routing ✓
Okta Identity enrichment — deployed but inactive ✗
AbuseIPDB IP reputation ✗
E New Integrations (detail) 9 added in last 30d

New Integrations Added - Last 30 Days

9 new connections
TenantIntegrationConnection NameAdded
mercury-insurance chronicle chronicle_iam_connection 2026-08-13
mercury-insurance glean my_glean_connection 2026-08-12
mercury-insurance bearer-token cyderes_tsi_authentication 2026-08-12
mercury-insurance aws aws_s3_northstar_metrics_qa 2026-08-11
mercury-insurance aws aws_s3_northstar_metrics_dev 2026-08-11
mercury-insurance aws my_aws_connection 2026-08-11
mercury-insurance glean eric_glean_key 2026-08-11
mercury-insurance confluence my_confluence_connection 2026-08-11
mercury-insurance jira my_jira_connection 2026-08-11