Blink Security Automation — Confidential

motivhealth — Customer Success Report

Generated 2026-08-30 | motivhealth-value-report.md
2026-08-30Report Date
160Total Playbooks
20Unique Workflows (12m)
5,182Actions Automated (12m)
$1,333Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

160
Total playbooks built
all non-deleted workflows
78
Active playbooks
currently enabled
20
Unique workflows executed (12m)
distinct workflows that ran
5,182
Actions automated (12m)
completed action steps
28.8h
Hours saved (12m)
@ 20s per action
$1,333
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
1
Total cases managed
1 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 5 total
16
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 38 IT service requests captured from Microsoft Teams and queued for automated triage - 27 IT requests AI-analyzed by Claude, automatically ticketed in ClickUp, and routed to the appropriate team - 8 automated patch runs executed across 4 network gateway nodes without manual intervention - 2 IT asset lifecycle events synced between ClickUp and Snipe-IT - 1 WordPress multisite plugin compliance audit completed automatically

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic IT Helpdesk & AI Request Triage
  • 38IT service requests captured and queued for automated AI triage
  • 27IT requests AI-analyzed by Claude, ticketed in ClickUp, and routed to the team
86.0%
6
6 active
SOC Automation & Case Management3 executions
6.0%
16
16 active
Alert Enrichment & IOC Lookup0 executions
0.0%
34
34 active
EDR Containment & Endpoint Response0 executions
0.0%
5
5 active
Employee Onboarding & Identity Management0 executions
0.0%
8
8 active
Network Infrastructure Automated Patching0 executions
0.0%
4
0 active
IT Asset & SaaS Administration
  • 2IT asset lifecycle events synced between ClickUp and Snipe-IT
  • 1WordPress multisite plugin compliance audits completed automatically
8.0%
3
2 active
Vulnerability Notification0 executions
0.0%
1
1 active
Total50 executions100%
77
72 active

Use Case Growth Over Time

134 unique playbooks  |  8 operational use cases  |  50 total executions (12m)  |  2024-09 to 2026-06
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Slack
SOC Automation & Case Management
Microsoft Outlook Email Anthropic Microsoft Teams
Employee Onboarding & Identity Management
Microsoft Teams Email ClickUp Microsoft Entra ID Snipe-IT Active Directory On-Prem Web Form Microsoft SQL Server
Vulnerability Notification
Microsoft Outlook
EDR Containment & Endpoint Response
CrowdStrike ClickUp Microsoft Entra ID Snipe-IT Microsoft Teams Cylance Microsoft Intune
Agentic IT Helpdesk & AI Request Triage
ClickUp Microsoft Teams Anthropic
IT Asset & SaaS Administration
Snipe-IT ClickUp Microsoft Teams
Network Infrastructure Automated Patching
Microsoft Teams

04Key Observations

✓  Strengths

Strengths

Deep SOC investment, fully built but not yet in production. The largest portion of the automation estate — a complete alert-to-case pipeline (Process Alert → Extract Observables → Enrich → Respond) with 50+ supporting playbooks — is fully built but shows zero executions over 12 months. This represents significant platform investment and readiness; the infrastructure is in place to handle high-volume SOC operations the moment the pipeline is activated.

Agentic AI is the only live, high-volume use case. The Microsoft Teams DM triage workflow (Incoming Message Tagged → Process Incoming DM) is the most active automation in the environment, processing 65 events in 12 months using Claude for classification and ClickUp for ticket creation. This is a genuinely differentiated, AI-native use case demonstrating that the team is comfortable with agentic automation patterns.

Broad enrichment coverage across 8+ sources. The enrichment library covers CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. Once the SOC pipeline goes live, this enrichment depth will provide immediate, multi-source context on every observable without analyst effort.

Dual-platform EDR readiness. The environment has containment playbooks for both CrowdStrike (RTR, isolation) and Aurora/Cylance, covering both real-time response and device lockdown — giving the SOC flexibility regardless of which EDR is primary on a given endpoint.

Infrastructure automation running reliably. The four PWR-GTWY auto-update workflows are executing on schedule, demonstrating that Blink is trusted for production-level operational automation, not just security tooling.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

SOC pipeline activation is the highest-value near-term action. The Process Alert workflow and all downstream enrichment/response playbooks are at zero executions. If CrowdStrike and Okta alerts are currently being processed manually, activating this pipeline could be the single highest-ROI change available — turning the entire existing SOC automation investment into production value.

Employee onboarding has no executions despite being fully built. Both the BambooHR webhook-triggered and web-form-triggered onboarding workflows are at zero. Given the complexity of the Onboard New Employee playbook (Entra ID provisioning, Local AD creation, Snipe-IT hardware checkout, ClickUp ticketing, Teams notifications), activating this would deliver significant time savings per hire.

Vulnerability notification is a single, on-demand playbook with no executions. Intruder is connected but the workflow runs only when manually triggered. Converting this to a scheduled or webhook-triggered flow would ensure findings are distributed automatically after every scan.

No cloud security coverage. There are no automations in the CSPM, cloud config audit, or cloud asset inventory categories. If MotivHealth operates cloud workloads (AWS, Azure, GCP), this is an unaddressed area for platform expansion.

Duplicate active workflows suggest ongoing iteration. The "(Eyes emoji) Process Incoming DM copy" workflow running alongside "Process Incoming DM (Push-Pin)" suggests a version-in-progress. Consolidating these reduces operational risk from split execution counts and divergent logic.

Integration Ecosystem

Category Integrations in Use
EDR & Endpoint CrowdStrike, Aurora/Cylance
Identity & IAM Microsoft Entra ID (Azure AD), Okta, Local AD (WinRM)
Threat Intelligence VirusTotal, URLScan, AbuseIPDB, Whois
Productivity & Comms Microsoft Teams, Microsoft Outlook, Email (core)
Ticketing & ITSM ClickUp
HR BambooHR
Asset Management Snipe-IT
Collaboration Slack (enrichment), GitHub (enrichment)
AI Anthropic Claude
Directory Google Workspace
Vulnerability Scanning Intruder
Web/SaaS WordPress API
Case Management Blink Case Management (native)
Appendices
A Case Management 1 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
1
1 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 1 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
IT Workspace 1 1 0 N/A
B AI Agents 1 active | 16 tasks (12m)

AI Agents

Active Agents
1
of 5 total
Tasks Executed (12m)
16
0 in last 30d
Data Usage (12m)
1,270,392
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Clicky UpShot Blink Hackathon 16 0 1,270,392
2 Agent Blink IT Workspace 0 0 0
3 Agent Smith vschill@motivhealth.com 0 0 0
4 New Agent Blink Hackathon 0 0 0
5 Test Agent chill@motivhealth.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Blink Hackathon16
IT Workspace0
vschill@motivhealth.com0
chill@motivhealth.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Hello World 00
2 Case Management 00

Webforms

Forms
5
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Onboarding 00
2 New employee onboarding 00
3 Refresh Environment Databases 00
4 Add User to a group in Entra 00
5 Self-service Demo 00
D Full Use Case Analysis 8 use cases | 50 executions (12m)

Business KPIs

Metric Count Playbook
IT service requests captured and queued for automated AI triage 38 Incoming Message Tagged
IT requests AI-analyzed by Claude, ticketed in ClickUp, and routed to the team 27 Process Incoming DM (Push-Pin) + Process Incoming DM copy
Automated patch runs executed across network gateway nodes 8 PWR-GTWY-01/02/03/04 Auto-Update
IT asset lifecycle events synced between ClickUp and Snipe-IT 2 ClickUp to Snipe-IT: Asset Management Sync
WordPress multisite plugin compliance audits completed automatically 1 Wordpress API Multisite Main
In the last 12 months, Blink automated: - 38 IT service requests captured from Microsoft Teams and queued for automated triage - 27 IT requests AI-analyzed by Claude, automatically ticketed in ClickUp, and routed to the appropriate team - 8 automated patch runs executed across 4 network gateway nodes without manual intervention - 2 IT asset lifecycle events synced between ClickUp and Snipe-IT - 1 WordPress multisite plugin compliance audit completed automatically

Use Case Summary

# Use Case Category Playbooks Executions (12 mo)
1 Agentic IT Helpdesk & AI Request Triage SOC / Other 6 65
2 SOC Automation & Case Management SOC 16 0
3 Alert Enrichment & IOC Lookup SOC 34 0
4 EDR Containment & Endpoint Response SOC 5 0
5 Employee Onboarding & Identity Management IAM 8 0
6 Network Infrastructure Automated Patching Other 4 8
7 IT Asset & SaaS Administration Other 3 3
8 Vulnerability Notification Vulnerability Mgmt 1 0
Total 77 76

Use Cases

1. Agentic IT Helpdesk & AI Request Triage

Description: AI-powered triage of inbound IT service requests arriving via Microsoft Teams. When a team member pins or tags a message, Blink captures it, invokes Claude to classify the request and extract key context, creates a ClickUp task, and notifies the requester — removing the manual intake step entirely.

Business Problem Solved: IT teams spend significant time manually reading, categorizing, and routing inbound requests from Teams DMs. This use case eliminates that triage overhead, ensuring every flagged message is processed consistently, logged in a tracking system, and acknowledged within minutes.

Integrations: Microsoft Teams, Anthropic Claude, ClickUp, Blink Tables

Playbook Type Executions Category Subcategory
Incoming Message Tagged Event (Webhook) 38 SOC Agentic SOC
Process Incoming DM (Push-Pin) Event (Polling) 21 SOC Agentic SOC
(Eyes emoji) Process Incoming DM copy Event (Polling) 6 SOC Agentic SOC
Self-service Demo Event (Web Form) 0 Other IT helpdesk & ticket routing
Self-service URL On-demand 0 Other IT helpdesk & ticket routing
ClickUp Ticket Search On-demand 0 Other IT helpdesk & ticket routing

2. SOC Automation & Case Management

Description: A full case management and SOAR pipeline built natively in Blink. New alerts from any source are ingested, observables are extracted, cases are deduplicated and created, enrichment is triggered in parallel, and automated response playbooks are dispatched based on alert type (phishing, malware). Utility workflows support observable relationship tracking, stale case hygiene, and recovery handling for missed alerts. A Claude-powered triage module is available for AI-assisted analyst support.

Business Problem Solved: Security teams face alert fatigue and inconsistent incident handling when alert processing is manual. This pipeline automates the full alert-to-case lifecycle — ensuring every alert is processed, deduplicated against existing cases, enriched, and routed to the appropriate response workflow within minutes of detection.

Integrations: Blink Case Management, CrowdStrike, Okta, Microsoft Outlook, Anthropic Claude, Darktrace

Playbook Type Executions Category Subcategory
Process Alert Event (Polling) 0 SOC Case mgmt & SOAR
Ingest Alert Darktrace Event 0 SOC SIEM & log pipeline monitoring
Response Subflow - Phishing On-demand (Subflow) 0 SOC Phishing detection & response
Response Subflow - Malware On-demand (Subflow) 0 SOC Case mgmt & SOAR
Subflow - Response - Main Router On-demand (Subflow) 0 SOC Case mgmt & SOAR
Subflow - Missing Alert Template Notification On-demand (Subflow) 0 SOC Case mgmt & SOAR
Claude Alert Triage On-demand 0 SOC Agentic SOC
Utility - Close Stale Cases On-demand 0 SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables On-demand 0 SOC Case mgmt & SOAR
Table Action - Validate Observables Extraction Template On-demand 0 SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts On-demand 0 SOC Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables On-demand 0 SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email On-demand (Utility) 0 SOC Case mgmt & SOAR
Simulate Crowdstrike Alert On-demand 0 SOC Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources On-demand 0 SOC Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment On-demand (Admin) 0 SOC Case mgmt & SOAR

3. Alert Enrichment & IOC Lookup

Description: A comprehensive library of enrichment playbooks that look up observables — IP addresses, domains, URLs, file hashes, usernames, and email addresses — across 8+ threat intelligence and identity sources, storing structured results back into the case management system. Observable relationship utilities support linking and querying connections between alerts and observables.

Business Problem Solved: Manual IOC lookup across multiple tools is time-consuming and inconsistent. This enrichment layer automatically queries multiple data sources for every observable in a case, giving analysts a complete threat picture within seconds of alert creation, without leaving the case management interface.

Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois, Blink Case Management

Playbook Type Executions Category Subcategory
Subflow - Enrich Observables - Main Router On-demand (Subflow) 0 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data On-demand (Subflow) 0 SOC Alert enrichment / IOC lookup
Utility - Update Enrichment On-demand (Utility) 0 SOC Alert enrichment / IOC lookup
Utility - Set Or Update Observable Relation On-demand (Utility) 0 SOC Alert enrichment / IOC lookup
Utility - List Alert Observable Relations On-demand (Utility) 0 SOC Alert enrichment / IOC lookup
Utility - List Observable Alert Relations On-demand (Utility) 0 SOC Alert enrichment / IOC lookup
Utility - Delete Observable Relation On-demand (Utility) 0 SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - URL - VT On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Username - Github On-demand 0 SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack On-demand 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information Using Github On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information On-demand 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike On-demand 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal On-demand 0 SOC Alert enrichment / IOC lookup
Okta Search for User Activity On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack On-demand 0 SOC Alert enrichment / IOC lookup
Get User Information Using Okta On-demand 0 SOC Alert enrichment / IOC lookup
Run Dig Command On-demand 0 SOC Alert enrichment / IOC lookup
Analyze URL with URLScan On-demand 0 SOC Phishing detection & response
Secure URL Screenshot Capture On-demand 0 SOC Phishing detection & response
Get End of Life Date for a Product On-demand 0 Vulnerability Mgmt CVE lookup & remediation

4. EDR Containment & Endpoint Response

Description: Playbooks for containing compromised or lost endpoints via CrowdStrike and Aurora (Cylance), including remote triage commands, host isolation, device lock/wipe workflows, and coordinated lost/stolen laptop response that spans identity revocation, asset tracking, and management approval.

Business Problem Solved: When an endpoint is compromised or a device is lost, response time is critical. These playbooks enable instant isolation and containment actions from Blink, removing the need for analysts to manually navigate multiple EDR consoles, and ensure that lost/stolen device incidents are handled with a consistent, documented, multi-step response.

Integrations: CrowdStrike (RTR & Host Actions), Aurora/Cylance, Microsoft Entra ID, Snipe-IT, ClickUp, Microsoft Teams

Playbook Type Executions Category Subcategory
CrowdStrike RTR to a Batch of Hosts On-demand 0 SOC EDR containment & response
CrowdStrike RTR to a Single Host On-demand 0 SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike On-demand 0 SOC EDR containment & response
Aurora Lockdown Device On-demand 0 SOC EDR containment & response
Lost/Stolen Laptop On-demand 0 SOC EDR containment & response

5. Employee Onboarding & Identity Management

Description: End-to-end employee lifecycle automation covering new hire provisioning and access management. The onboarding workflows span BambooHR-triggered and web-form-triggered flows, provisioning accounts in both cloud (Microsoft Entra ID) and on-premises (Local AD) environments, assigning security groups by department, checking out hardware in Snipe-IT, and notifying stakeholders via Teams and email. Supporting workflows handle access group management and disable offboarded accounts in Local AD.

Business Problem Solved: Manual employee onboarding involves coordinating across HR systems, Active Directory, IT asset management, and multiple communications channels — creating delays and risk of missed steps. These workflows codify the entire checklist into a repeatable, auditable process that executes within minutes of a new hire trigger.

Integrations: BambooHR (webhook), Microsoft Entra ID (Azure AD), Local AD (WinRM), Snipe-IT, ClickUp, Microsoft Teams, Email

Playbook Type Executions Category Subcategory
Onboarding Event (Webhook — BambooHR) 0 IAM Employee onboarding
Onboard New Employee Event (Web Form) 0 IAM Employee onboarding
Create user in Local AD On-demand (Subflow) 0 IAM Employee onboarding
Disable User in Local AD On-demand 0 IAM Employee offboarding
Add New User to Entra Group Event (Web Form) 0 IAM Access review & group mgmt
Get All Security Groups On-demand 0 IAM Access review & group mgmt
Refresh Environment Databases Event (Web Form) 0 IAM Identity lifecycle automation
ScratchPad - Entra Group Management On-demand 0 IAM Access review & group mgmt

6. Network Infrastructure Automated Patching

Description: Scheduled workflows that run automated Windows Update commands over WinRM on four named network gateway servers (PWR-GTWY-01 through 04), verifying patch status and conditionally taking action after each run. All four execute on the same monthly schedule.

Business Problem Solved: Manually patching network infrastructure devices requires scheduling maintenance windows and manual SSH/RDP access. These workflows automate patch execution and verification on a fixed schedule, reducing operational burden and ensuring gateways stay current without analyst involvement.

Integrations: WinRM (Windows Remote Management)

Playbook Type Executions Category Subcategory
PWR-GTWY-01 Auto-Update Scheduled (Monthly) 2 Other IT/OT & network infra monitoring
PWR-GTWY-02 Auto-Update Scheduled (Monthly) 2 Other IT/OT & network infra monitoring
PWR-GTWY-03 Auto-Update Scheduled (Monthly) 2 Other IT/OT & network infra monitoring
PWR-GTWY-04 Auto-Update Scheduled (Monthly) 2 Other IT/OT & network infra monitoring

7. IT Asset & SaaS Administration

Description: Automations that keep IT asset data and SaaS platforms in sync. The ClickUp-to-Snipe-IT sync updates asset statuses in the hardware tracking system whenever a ClickUp ticket is updated. The WordPress workflows audit plugins across a multisite installation on a weekly schedule, and allow on-demand plugin inspection by IT staff via a Teams-based interactive selector.

Business Problem Solved: Keeping asset inventory and SaaS platform state synchronized across tools manually is error-prone and time-consuming. These automations ensure asset lifecycle changes in the ticketing system are reflected in hardware inventory in real time, and that WordPress plugin hygiene is audited regularly without manual effort.

Integrations: ClickUp, Snipe-IT, WordPress API, Microsoft Teams

Playbook Type Executions Category Subcategory
ClickUp to Snipe-IT: Asset Management Sync Event (ClickUp Webhook) 2 Other SaaS / IT administration
Wordpress API Multisite Main Scheduled (Weekly) 1 Other SaaS / IT administration
WP Plugins On-demand 0 Other SaaS / IT administration

8. Vulnerability Notification

Description: Fetches vulnerability data from the Intruder scanning platform, formats it into a summary report, and sends a notification email to designated recipients.

Business Problem Solved: Security teams need to distribute vulnerability scan results to stakeholders without requiring manual export and formatting. This automation ensures findings are pushed to the right people immediately after a scan, reducing time-to-awareness for newly discovered exposures.

Integrations: Intruder, SendGrid, Microsoft Outlook

Playbook Type Executions Category Subcategory
Intruder Notification On-demand 0 Vulnerability Mgmt Vuln scanning ingest & report

Key Observations

Strengths

Deep SOC investment, fully built but not yet in production. The largest portion of the automation estate — a complete alert-to-case pipeline (Process Alert → Extract Observables → Enrich → Respond) with 50+ supporting playbooks — is fully built but shows zero executions over 12 months. This represents significant platform investment and readiness; the infrastructure is in place to handle high-volume SOC operations the moment the pipeline is activated.

Agentic AI is the only live, high-volume use case. The Microsoft Teams DM triage workflow (Incoming Message Tagged → Process Incoming DM) is the most active automation in the environment, processing 65 events in 12 months using Claude for classification and ClickUp for ticket creation. This is a genuinely differentiated, AI-native use case demonstrating that the team is comfortable with agentic automation patterns.

Broad enrichment coverage across 8+ sources. The enrichment library covers CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. Once the SOC pipeline goes live, this enrichment depth will provide immediate, multi-source context on every observable without analyst effort.

Dual-platform EDR readiness. The environment has containment playbooks for both CrowdStrike (RTR, isolation) and Aurora/Cylance, covering both real-time response and device lockdown — giving the SOC flexibility regardless of which EDR is primary on a given endpoint.

Infrastructure automation running reliably. The four PWR-GTWY auto-update workflows are executing on schedule, demonstrating that Blink is trusted for production-level operational automation, not just security tooling.

Gaps & Opportunities

SOC pipeline activation is the highest-value near-term action. The Process Alert workflow and all downstream enrichment/response playbooks are at zero executions. If CrowdStrike and Okta alerts are currently being processed manually, activating this pipeline could be the single highest-ROI change available — turning the entire existing SOC automation investment into production value.

Employee onboarding has no executions despite being fully built. Both the BambooHR webhook-triggered and web-form-triggered onboarding workflows are at zero. Given the complexity of the Onboard New Employee playbook (Entra ID provisioning, Local AD creation, Snipe-IT hardware checkout, ClickUp ticketing, Teams notifications), activating this would deliver significant time savings per hire.

Vulnerability notification is a single, on-demand playbook with no executions. Intruder is connected but the workflow runs only when manually triggered. Converting this to a scheduled or webhook-triggered flow would ensure findings are distributed automatically after every scan.

No cloud security coverage. There are no automations in the CSPM, cloud config audit, or cloud asset inventory categories. If MotivHealth operates cloud workloads (AWS, Azure, GCP), this is an unaddressed area for platform expansion.

Duplicate active workflows suggest ongoing iteration. The "(Eyes emoji) Process Incoming DM copy" workflow running alongside "Process Incoming DM (Push-Pin)" suggests a version-in-progress. Consolidating these reduces operational risk from split execution counts and divergent logic.

Integration Ecosystem

Category Integrations in Use
EDR & Endpoint CrowdStrike, Aurora/Cylance
Identity & IAM Microsoft Entra ID (Azure AD), Okta, Local AD (WinRM)
Threat Intelligence VirusTotal, URLScan, AbuseIPDB, Whois
Productivity & Comms Microsoft Teams, Microsoft Outlook, Email (core)
Ticketing & ITSM ClickUp
HR BambooHR
Asset Management Snipe-IT
Collaboration Slack (enrichment), GitHub (enrichment)
AI Anthropic Claude
Directory Google Workspace
Vulnerability Scanning Intruder
Web/SaaS WordPress API
Case Management Blink Case Management (native)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.