Blink Security Automation — Confidential

pm-group — Customer Success Report

Generated 2026-08-30 | pm-group-value-report.md
2026-08-30Report Date
246Total Playbooks
163Unique Workflows (12m)
264,637Actions Automated (12m)
$68,065Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

246
Total playbooks built
all non-deleted workflows
190
Active playbooks
currently enabled
163
Unique workflows executed (12m)
distinct workflows that ran
264,637
Actions automated (12m)
completed action steps
1,470.2h
Hours saved (12m)
@ 20s per action
$68,065
Money saved (12m)
@ $100K avg salary
31
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 4 total
3
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 2,063 employee HR lifecycle events automatically routed and actioned from HiBob - 1,175 access requests processed end-to-end without manual intervention - 1,577 group membership changes executed across Active Directory and AMS - 367 employee accounts provisioned across AD, Google Workspace, AMS, and SecHub - 97 new-hire onboardings fully orchestrated across 6+ identity systems - 44 employee offboarding events triggered and executed automatically - 127 M365 E3 license assignments processed without manual ticketing - 93 Google Drive data-transfer steps completed to preserve departing-employee files - 68 dismissal compliance checks executed (34 AMIS role reviews + 34 Finance license reviews) - 36 access request webhook events auto-routed into the ticketing pipeline - 31 post-onboarding access verifications completed - 26 Slack channels auto-created and provisioned for new hires

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Automated Employee Onboarding
  • 2,063Employee HR lifecycle events automatically routed
  • 103Google Workspace accounts provisioned
  • 99Active Directory accounts created
9.7%
43
43 active
Employee Offboarding & Termination
  • 44Employee offboarding events processed
  • 40Google Drive transfers completed during offboarding
  • 34AMIS role checks executed on dismissal
2.4%
27
27 active
Access Request & Group Provisioning
  • 1,175Access requests processed end-to-end
  • 948AD group membership changes executed
  • 629AMS group membership changes executed
74.0%
29
29 active
Temporary Access Control68 executions
0.1%
18
18 active
Identity Directory Sync & Maintenance504 executions
0.8%
26
26 active
Google Workspace Administration451 executions
0.7%
21
21 active
Access Operations SLA & Reporting298 executions
0.5%
14
14 active
Audit Log Pipeline & Platform Health6,806 executions
11.3%
2
2 active
Total60,201 executions100%
180
180 active

Use Case Growth Over Time

204 unique playbooks  |  8 operational use cases  |  60,457 total executions (12m)  |  2025-11 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Access Request & Group Provisioning
Asana LDAP Microsoft Entra ID 1Password Atlassian Organizations HiBob Google Admin Console Email
Access Operations SLA & Reporting
Email Dashboards Agents
Identity Directory Sync & Maintenance
Email Google Admin Console Dashboards Azure Google Sheets Microsoft Entra ID Web Form LDAP
Google Workspace Administration
Google Admin Console Google Drive Email Web Form
Automated Employee Onboarding
Asana Email LDAP Google Admin Console Web Form HiBob Microsoft Entra ID Gmail
Audit Log Pipeline & Platform Health
AWS Email
Employee Offboarding & Termination
LDAP Asana Google Admin Console Web Form Google Drive
Temporary Access Control
Web Form LDAP Google Admin Console Microsoft Entra ID 1Password Asana

04Key Observations

✓  Strengths

Strengths

Deeply integrated end-to-end lifecycle automation. PM Group has built one of the most complete IAM lifecycle automation stacks observed — new hire events in HiBob propagate through account creation in six systems, group assignments, SecHub identity linking, welcome email, and SLA tracking with no manual handoffs. The HiBob webhook parser alone processed 2,063 lifecycle events in 12 months.

High-volume access request throughput at scale. The access request flow (Process Access Request Ticket + AD/AMS Group flows) handled 1,175 requests and executed 1,577 group membership changes autonomously. The SLA tracking layer (20,806 events) provides real-time operational visibility that would be impossible to maintain manually.

Custom identity platform integration (SecHub & AMS). Unlike most customers who work with off-the-shelf directories, PM Group has built deep automation around two proprietary internal systems — SecHub (their HR/identity registry) and AMS (GR8Tech access management). The depth of integration (create, link, status sync, manual review, delete) is a significant implementation investment.

Proactive scheduling and operational resilience. Multiple scheduled safety nets exist — pre-activation checks 1 day and same-day before start dates, morning/evening termination checks, daily webhook monitoring, and weekly SLA data quality runs — demonstrating mature operational thinking beyond simple reactive automation.

Audit log compliance pipeline. Running 4,885 times in 12 months (every 30 minutes), the S3 audit backup is one of the most execution-heavy playbooks and reflects a clear compliance or regulatory driver for long-term log retention.

Google Drive data custody now automated during offboarding. New Drive-transfer workflows (Google Drive Transfer, transfer status check, bridge-account finish, person-transfer finish) handled 93 combined executions, ensuring departing employees' files are preserved and reassigned rather than orphaned — closing a common offboarding

△  Gaps & Growth Opportunities

gap.

Expanding investment in identity data quality. PM Group added a substantial suite of scheduled and on-demand data-integrity tooling — duplicate employee/account detection and merge, SecHub ambiguous-ownership scanning, account-mismatch scanning and auto-patch, and removed-account cleanup — reflecting growing maturity in keeping SecHub and directory data clean without manual audits.

Gaps & Opportunities

Temporary access control is beginning to see production use, but adoption is uneven. The Block/Reinstate use case has grown to 19 playbooks, and the Daily Reinstate check (37 executions) plus a new InfoSec-driven block path (InfoSec Block webhook, 6 executions) show real activity. However, most of the underlying per-system Block/Reinstate subflows (AD, AMS, Google Workspace, Slack, Asana, 1Password) still show 0 executions, meaning many block/reinstate actions may still be handled outside the orchestrator.

No automated Atlassian offboarding. Atlassian user operations (Suspend, Remove, group management) appear in the access request flow but are absent from the Master Dismissal orchestration. Atlassian suspension must currently be handled manually during terminations.

Re-hire volume is low but the flow exists. Only 13 re-hire setups were completed via the automated flow, and the re-hire subflows (AD Re-hire Update, AMS re-hire) show single-digit usage. If re-hires are being processed partially manually, this is an opportunity to drive all volume through the automated path.

Agent-generated compliance playbooks are unused. Three AI agent–generated playbooks (Asana/HiBob reconciliation, user count) have 0 executions. The compliance reconciliation use case (cross-referencing Asana users against HiBob active employees) is high value and worth operationalizing.

Azure group changes are minimal (12 executions) vs. AD (948) and AMS (629). Either Azure AD group management is handled elsewhere, or there is underutilization of the existing Azure Groups Add\Remove automation.

A growing volume of 0-execution SecHub/directory maintenance tooling. Roughly half of the new Identity Directory Sync & Maintenance playbooks (SecHub - Entity Migration, AD Employee Patch, SecHub Ambiguous Ownership Scan, Open CSV file, AD email update (asana), sechub delete by integration ID, duplicated employee merge, Duplicated accounts per employee, Patch employee status, Account_mismatches) have not yet run. These appear to be recently built maintenance/data-quality tools awaiting rollout or first use.

Integration Ecosystem

Integration Use Cases
HiBob Onboarding trigger, offboarding trigger, user status check, email group sync
Active Directory (LDAP) Account create/delete/modify, group management, re-hire, email/data patch and reconciliation
Google Workspace Account create/delete/block/unblock, group management, OU sync, device management, Drive transfer
AMS (GR8Tech) Account create/delete/block, group management, user export, re-hire
SecHub Identity record create/delete/link, status sync, manual review, entity migration, dedup/cleanup
Asana Access request intake, ticket management, user provisioning/deprovisioning, onboarding Slack channel setup
Atlassian User suspend/remove/activate, group management, email update, Confluence inactivity suspension
Slack User invite, account disable/reinstate, channel create/archive
Azure AD / Entra ID Account disable/reinstate/block, session revocation, group management, VDI data
1Password User suspend, group management
Azure Blob Storage AMS user export, JSON data store for onboarding blobs
AWS S3 Audit log long-term retention
Google Sheets AVD reporting, SecHub manual review, employee lookup
N8N Webhook source for E3 license automation
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 3 tasks (12m)

AI Agents

Active Agents
1
of 4 total
Tasks Executed (12m)
3
0 in last 30d
Data Usage (12m)
415,239
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Asana Access Auditor Access_team 3 0 415,239
2 Agent Blink Access_team 0 0 0
3 Agent Blink oleksii.b@pm.group 0 0 0
4 Software review agent InfoSec 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Access_team3
oleksii.b@pm.group0
InfoSec0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 8 use cases | 60,457 executions (12m)

Business KPIs

Metric Count Playbook
Employee HR lifecycle events automatically routed 2,063 HiBob webhook parser
Access requests processed end-to-end 1,175 Process Access Request Ticket
AD group membership changes executed 948 AD Groups Add\Remove
AMS group membership changes executed 629 AMS Groups Add\Remove
M365 E3 license assignments automated 127 E3 License automation
Google Workspace accounts provisioned 103 Create GW Account
Active Directory accounts created 99 Create AD Account
New-hire onboarding flows initiated 97 Onboarding
SecHub identity records created 94 Create SecHub account
Asana users deprovisioned 92 Asana User Remove
Full onboarding provisioning sequences completed 86 Onboarding - Master Provisioning
Access profiles reviewed & approved 73 Onboarding - Manage Access
AMS accounts provisioned 71 Create AMS account
Atlassian users suspended 52 Atlassian Suspend User
Employee offboarding events processed 44 Offboarding webhook
Google Drive transfers completed during offboarding 40 Google Drive Transfer
Access request webhook events auto-routed 36 Access Request Router
AMIS role checks executed on dismissal 34 AMIS approvers
Finance license checks executed on dismissal 34 Asana Finance licenses check
Post-onboarding access verifications completed 31 post-onboarding verification
Slack channels created for new hires 26 Create Slack Channel
Employee terminations fully executed 16 Master Dismissal
Re-hire identity setups completed 13 Re-hire Identity Accounts
In the last 12 months, Blink automated: - 2,063 employee HR lifecycle events automatically routed and actioned from HiBob - 1,175 access requests processed end-to-end without manual intervention - 1,577 group membership changes executed across Active Directory and AMS - 367 employee accounts provisioned across AD, Google Workspace, AMS, and SecHub - 97 new-hire onboardings fully orchestrated across 6+ identity systems - 44 employee offboarding events triggered and executed automatically - 127 M365 E3 license assignments processed without manual ticketing - 93 Google Drive data-transfer steps completed to preserve departing-employee files - 68 dismissal compliance checks executed (34 AMIS role reviews + 34 Finance license reviews) - 36 access request webhook events auto-routed into the ticketing pipeline - 31 post-onboarding access verifications completed - 26 Slack channels auto-created and provisioned for new hires

Use Case Summary

# Use Case Category Total Playbooks Active Playbooks
1 Automated Employee Onboarding IAM 41 33
2 Employee Offboarding & Termination IAM 29 24
3 Access Request & Group Provisioning IAM 29 24
4 Temporary Access Control IAM 19 4
5 Identity Directory Sync & Maintenance IAM 28 16
6 Google Workspace Administration Other 21 16
7 Access Operations SLA & Reporting GRC 16 10
8 Audit Log Pipeline & Platform Health Cloud Security 2 2
Total 185 129

Use Cases

1. Automated Employee Onboarding

Description: End-to-end onboarding automation triggered by HiBob HR events. Creates accounts across AD, Google Workspace, AMS (GR8Tech), SecHub, Slack, and Asana; resolves role-based access profiles; and manages start-date activation through scheduled pre-activation checks and a structured human-approval web form flow.

Business Problem: Manual onboarding across six-plus identity systems creates multi-day delays, inconsistency, and security gaps. A single new hire requires coordinated account creation, group assignments, and a welcome experience across every platform simultaneously.

Category: IAM

Subcategories: Employee onboarding · Identity lifecycle automation · Full employee lifecycle

Key Integrations: HiBob · Active Directory (LDAP) · Google Workspace · AMS (GR8Tech) · SecHub · Slack · Asana · Atlassian · Azure Blob Storage · Blink Web Forms

Playbook Executions Role
HiBob webhook parser 2,063 Primary event trigger — routes all HiBob lifecycle events to onboarding and offboarding flows
Onboarding 97 Orchestrator — initiates onboarding sequence from HiBob hire event
Onboarding - Master Provisioning 86 Orchestrator — provisions accounts, assigns groups, sends welcome email
Onboarding - Manage Access 73 Web form — interactive access profile review and approval
Create Identity Accounts 69 Web form — human-guided identity account creation with conflict detection
Create Identity Accounts (Auto) 53 On-demand — automated version of identity account creation
Start Date Trigger 76 Scheduled — triggers provisioning for all employees starting today
Onboarding - Pre-Activation Check (1 Day Ahead) 76 Scheduled — readiness check for employees starting the next day
Onboarding - Pre-Activation Check (Same Day) 76 Scheduled — same-day activation check for employees starting today
Provide onboarding instructions 76 Subflow — adds employee to Google instruction groups
Remove onboarding instructions 54 Subflow — removes temporary instruction group access
Create GW Account 103 Subflow — creates Google Workspace account with dynamic connection
Create AD Account 99 Subflow — creates Active Directory account via LDAP
Create SecHub account 94 Subflow — creates SecHub identity record and sets hiring status
Create AMS account 71 Subflow — creates AMS (GR8Tech) account
Onboarding - Cancellation 30 Web form — cancels a pending onboarding with confirmation
Re-hire Identity Accounts 13 Web form — manages identity account setup for returning employees
Create Custom Account 10 Web form — manual account creation bypass for contractors or edge cases
AD Re-hire Update 10 Subflow — updates existing AD account for re-hire (enable, OU, password)
Onboarding - Start date update 6 Web form — updates start date for a pending onboarding
Re-hire password update 6 Subflow — resets SecHub passwords for re-hired employees
AMS re-hire 3 Subflow — unblocks AMS account and restores groups for re-hires
secHub create and link accounts from google sheet 24 On-demand — bulk imports and links accounts from a Google Sheet
Assign AD groups 169 Subflow — assigns AD group memberships during provisioning
SecHub - Link Accounts 192 Subflow — links all created accounts to the SecHub identity record
Slack Invite 79 Subflow — invites user to Slack workspace and handles re-activation
Resolve Access Profile 89 Subflow — resolves role-based group/app access from profile name
SecHub - Check 86 Subflow — verifies SecHub employee record exists
Build Access Plan and Asana comment 69 Subflow — builds provisioning plan and posts to Asana ticket
Notify HR Webhook 68 Subflow — notifies HR system of completion
Trigger SecHub webhook 62 Subflow — sets EMPLOYED status and triggers SecHub webhook
Daily webhook check 48 Scheduled — monitors for missed HiBob hire events
Assign GW Groups 15 Subflow — assigns Google Workspace group memberships
Asana invite 4 Subflow — invites user to Asana workspace
Create SecHub Employee and Link Accouts 1 Subflow — creates SecHub employee and links all accounts in one call
HiBob_Fetch_Status 0 Utility — fetches HiBob employee statuses (data-fetch helper)
SecHub_Fetch_Registry 0 Utility — fetches full SecHub registry (data-fetch helper)
Create Slack Channel 26 Subflow — creates an onboarding Slack channel and invites employee, HR, manager, and accountant
Archive Slack channel 23 Subflow — archives the onboarding Slack channel once no longer needed
post-onboarding verification 31 On-demand — verifies all provisioned account access after onboarding completes
Create custom AD account 0 Web form — manual AD account creation across all PM Group business entities
(NON PROD VERSION)Asana invite 0 On-demand — non-production test variant of the Asana invite subflow
Activate AD account 0 On-demand — activates an existing AD account by SAM/email lookup (re-hire/reactivation)

2. Employee Offboarding & Termination

Description: Automated employee termination workflow triggered by HiBob lifecycle events or manual web forms. Disables accounts and revokes group memberships across AD, AMS, Google Workspace, Azure, Slack, and Asana; decommissions the SecHub identity record; and runs scheduled morning/evening checks to ensure timely execution on the last working day.

Business Problem: Incomplete or delayed offboarding leaves terminated employees with active access across multiple systems, creating critical security and compliance exposure. Manual cross-system deprovisioning is error-prone and often takes days.

Category: IAM

Subcategories: Employee offboarding · Full employee lifecycle · Identity lifecycle automation

Key Integrations: HiBob · Active Directory (LDAP) · Google Workspace · AMS (GR8Tech) · Azure AD / Entra ID · Slack · Asana · SecHub · Blink Web Forms

Playbook Executions Role
Offboarding webhook 44 Orchestrator — initiates offboarding sequence from webhook event
Master Dismissal 16 Orchestrator — executes full cross-system termination sequence
Termination - Morning Check 29 Scheduled — morning review of pending terminations, Slack alerts
Termination - Evening Check 29 Scheduled — evening review and last-working-day processing
Change position SecHub 50 On-demand — updates employee entity/position in SecHub
Termination - Manage 10 Web form — HR-initiated termination management interface
Daily Dismissal Ticket Check 8 Scheduled — ensures Asana termination tickets are created on time
Dismissal manual run (without HiBob) 5 Web form — manual termination bypass when HiBob event is unavailable
Update Dismissal date 3 On-demand — updates last working day in blob and Asana
Cancel Dismissal 0 On-demand — cancels a pending dismissal record
Reinstate Dismissal 0 On-demand — reinstates a previously cancelled dismissal
Disable AD Account and Remove Groups 17 Subflow — disables AD account and removes all group memberships
Disable Slack Account 24 Subflow — deactivates Slack account via SCIM
Delete SecHub Account 24 Subflow — removes employee record from SecHub
Disable Google Workspace 19 Subflow — suspends and signs out Google Workspace user
Delete AD Account 19 Subflow — deletes Active Directory account via LDAP
Disable AMS Account and Remove Groups 15 Subflow — blocks AMS account and removes group memberships
Sync SecHub Account Status 15 Subflow — syncs termination status back to SecHub
Disable Azure account 16 Subflow — disables Entra ID account and revokes sessions
Delete GW Account 17 Subflow — deletes Google Workspace account
Disable Asana Account 13 Subflow — deactivates Asana workspace membership
Delete AMS account 12 Subflow — deletes AMS account
Create Asana Tickets from AMIS 12 Subflow — creates Asana child tickets for AMIS-specific actions
Google Drive Transfer 40 On-demand — initiates Google Drive file transfer for a departing employee
check google drive transfer status 31 On-demand — monitors an in-progress Drive transfer and routes to person or bridge-account completion
Google Drive Bridge account finish 3 On-demand — completes bridge-account Drive transfer (folder recreation, file move, cleanup)
Google Drive Person transfer finish 19 On-demand — completes person-to-person Drive transfer with optional account deletion
Asana Finance licenses check 34 On-demand — pulls licenses held by a departing employee and opens a Finance ticket
AMIS approvers 34 On-demand — checks AMIS approver roles held by a departing employee on dismissal

3. Access Request & Group Provisioning

Description: Automated handling of access requests submitted through Asana tickets. Processes group membership additions and removals across AD, AMS, Azure, Atlassian, 1Password, and Asana; automates M365 E3 license assignments from N8N webhook events; and tracks SLA compliance for every request in real time.

Business Problem: High-volume access request management (1,175+ per year) across seven identity platforms cannot scale with manual processing. Every delay increases both security risk and employee productivity loss.

Category: IAM

Subcategories: Access review & group mgmt · JIT & temporary access

Key Integrations: Asana · Active Directory · AMS (GR8Tech) · Azure AD · Atlassian · 1Password · Slack · SecHub · N8N (webhook source)

Playbook Executions Role
Process Access Request Ticket 1,175 Orchestrator — processes Asana access tickets end-to-end
Access Operation - SLA update 20,806 Event — records SLA data on every access ticket status change
AD Groups Add\Remove 948 Orchestrator — processes AD group add/remove operations
AMS Groups Add\Remove 629 Orchestrator — processes AMS group add/remove operations
E3 License automation 127 Event — automates M365 E3 license assignment from N8N webhook
Asana User Remove 92 On-demand — removes user from Asana workspaces
Atlassian Suspend User 52 On-demand — suspends Atlassian user across org
Update users in Google email groups 46 Scheduled — syncs HiBob employment status to Google email groups
Access Look up 45 On-demand — looks up current user accesses across all systems
1Password Groups Add\Remove 26 On-demand — processes 1Password group membership changes
1Password Suspend User. Dynamic spaces 25 On-demand — suspends 1Password user with dynamic instance lookup
Azure Groups Add\Remove 12 On-demand — processes Azure AD group membership changes
Atlassian Add user to group 9 On-demand — adds user to Atlassian group
Atlassian Update User Email 7 On-demand — updates Atlassian user email address
1Password Suspend User 6 On-demand — suspends 1Password user (static space config)
AMS - Remove Specific groups 6 On-demand — removes specific AMS group memberships by email
Atlassian Remove User 5 On-demand — removes user from Atlassian organization
Atlassian Activate User 3 On-demand — re-activates a suspended Atlassian user
Slack remove users from channel 3 Subflow — removes users from Slack channels
Confluence 60-days suspend 1 Scheduled — suspends Confluence users inactive for 60+ days
Atlassian Remove user from group 1 On-demand — removes user from Atlassian group
Get Users ID by email 77 Subflow — resolves Atlassian user IDs from email addresses
Atlassian Define OrgID and DirectoryID 77 Subflow — resolves Atlassian org and directory IDs by name
Get Group ID by name 10 Subflow — resolves Atlassian group IDs from group names
List converter 7 Utility — converts email list formats for downstream steps
Clear table by ticket ID 1 Utility — clears table records by ticket ID
Add users to project/portfolio 0 On-demand — adds users to Asana projects/portfolios (unused)
Confluence NUC 60-days suspend 3 Scheduled (weekly) — suspends NUC-organization Confluence users inactive 60+ days
Access Request Router 36 Event — parses inbound access-request webhook and computes final ticket status/comment

4. Temporary Access Control

Description: A complete workflow suite for temporarily blocking and reinstating employee access across all identity systems — AD, AMS, Google Workspace, Azure, Slack, Asana, and 1Password — without triggering a full offboarding. Includes a unified management web form, per-system block/reinstate subflows, a daily reinstatement check, and an InfoSec-triggered block path for security-driven access suspensions.

Business Problem: Employees on leave, under HR review, or in dispute resolution need a reversible access suspension mechanism that doesn't permanently delete accounts or trigger the full termination process. Security incidents also require a fast, auditable way to suspend access outside the standard offboarding flow.

Category: IAM

Subcategories: JIT & temporary access

Key Integrations: Active Directory · AMS · Google Workspace · Azure AD · Slack · Asana · 1Password · SecHub

Note: Most of the per-system Block/Reinstate subflows still show 0 executions, but the capability is beginning to see production use — the Daily Reinstate check now runs 37 times/year, and a new InfoSec-driven block path (InfoSec Block webhook + resolve/update Asana subflow) has started routing security-driven access suspensions through this use case rather than a fully manual process.
Playbook Executions Role
Temporary block - Manage 0 Web form — unified interface: Block / Reinstate / Start Dismissal / Update date
Master Block 0 Orchestrator — blocks access across all identity systems
Master Reinstate 0 Orchestrator — reinstates access across all identity systems
Block AD 0 Subflow — blocks Active Directory account
Block AMS 0 Subflow — blocks AMS account
Block Google Workspace 0 Subflow — suspends Google Workspace account
Disable 1Password 0 Subflow — suspends 1Password account
Reinstate AD 0 Subflow — re-enables Active Directory account
Reinstate AMS 0 Subflow — re-enables AMS account
Reinstate Azure 0 Subflow — re-enables Azure account
Reinstate 1Password 0 Subflow — re-enables 1Password account
Remove Manual Override 0 On-demand — removes manual block flag from table record
Daily Reinstate check 37 Scheduled (daily) — checks for pending reinstatements and triggers per-system reinstate flows
Reinstate Google Workspace 0 Subflow — re-activates a suspended Google Workspace account
Reinstate Slack 0 Subflow — re-activates a deactivated Slack account via SCIM
Reinstate Asana 0 Subflow — re-invites a removed user to the Asana workspace
Block Azure account 2 On-demand — disables Azure/Entra ID account and revokes active sessions
InfoSec Block webhook 6 Event — receives InfoSec block requests, opens an AMIS ticket, and triggers access block
Infosec - Resolve access and update Asana ticket 4 Subflow — resolves flagged access and updates the related Asana ticket

5. Identity Directory Sync & Maintenance

Description: Scheduled and on-demand workflows that keep identity data consistent across systems. Covers OU management in Google Admin, Azure VDI reporting, daily AMS-to-Azure data exports, SecHub manual review reporting, employee lookup tooling, and a growing suite of data-quality automation — duplicate employee/account detection and merge, account-mismatch scanning and patching, entity migration, and removed-account cleanup.

Business Problem: Identity directories drift apart without continuous synchronization. Stale OU assignments, outdated VDI data, duplicate or ambiguously-owned accounts, and inconsistent employment records across HR and identity systems create audit failures and access anomalies.

Category: IAM

Subcategories: Identity sync & directory mgmt · Identity lifecycle automation

Key Integrations: AMS (GR8Tech) · Azure Blob Storage · Azure AD / Entra ID · Google Workspace · Active Directory (LDAP) · HiBob · SecHub · Google Sheets

Playbook Executions Role
AMS Users Export to Azure 147 Scheduled (daily) — exports AMS user data to Azure Blob Storage
AVD Info 80 Scheduled (daily) — syncs Azure Virtual Desktop data to Google Sheets
SecHub - Get Manual Review 34 On-demand — fetches SecHub manual review items and writes to Google Sheet
OU Updater 44 Scheduled (daily) — updates Google Workspace user OU assignments
hiBob user status check 23 On-demand — checks HiBob employment status for a list of emails
Search Employee 21 On-demand — searches employee data from Google Sheets with a web form
secHub employee\accounts search 3 On-demand — looks up SecHub employee records and linked accounts
Asana_Export_Users 0 Utility — exports full Asana user list (data-fetch helper)
Azure JSON view 0 Utility — reads JSON files from Azure Blob Storage
Sechub - Delete from account matches 5 On-demand — bulk-removes SecHub accounts matching a supplied email list
SecHub - Entity (Company) Migration 0 On-demand — migrates employee records between company entities in SecHub
AD Employee Patch 0 On-demand — reconciles HiBob and SecHub employee data into AD
Daily PATCH check 15 Scheduled (daily) — scans identity data for patch-worthy discrepancies
SecHub Ambiguous Ownership Scan 0 On-demand — scans for accounts with ambiguous SecHub ownership
SecHub Re-link Account 10 On-demand — re-links an account to a different SecHub identity
Open CSV file 0 Utility — reads and parses an uploaded CSV file (data-fetch helper)
Email change 2 Event — routes an email-change webhook to the correct per-system update flow
AD email update 1 On-demand — updates AD email/SAM mappings in bulk
AD email update (asana) 0 On-demand — updates a single AD account's email and posts result to Asana
sechub delete accounts by integration ID 0 On-demand — deletes all SecHub accounts tied to a given integration ID
duplicated employee merge 0 On-demand — merges duplicate employee records and their linked accounts
Duplicated accounts per employee 0 On-demand — detects and cleans up duplicate/mis-assigned accounts per employee
Patch employee status 0 On-demand — patches an employee's status field in SecHub
SecHub-Removed-Account-Cleanup 2 Scheduled (daily) — cleans up accounts already removed from source systems
daily duplicated employee\accounts scan 2 Scheduled (daily) — scans for duplicated employees/accounts and alerts if found
Account_mismatches 0 Scheduled — scans for account/employee data mismatches and alerts if needed
PATCH accounts for Account_mismatches 7 Event — patches accounts flagged by the Account_mismatches scan
OU Updater 16 Scheduled (daily) — second OU assignment sync job across available Google Workspace suites

6. Google Workspace Administration

Description: On-demand IT administration toolkit for Google Workspace covering user lifecycle management (create, block, unblock, delete, OU change, password reset), group management, 2FA code generation, device management, and audit log retrieval. Serves as a self-service operations layer for the access team.

Business Problem: Access team members need a reliable, auditable interface for routine Google Workspace operations without direct admin console access. Each action needs to be logged, repeatable, and executable by non-admin staff.

Category: Other

Subcategories: SaaS / IT administration

Key Integrations: Google Workspace (Admin Console) · Google Drive · Google Groups · Blink Web Forms

Playbook Executions Role
User Devices Manager - Main 46 On-demand — interactive device management with web form actions
Get User Info 34 On-demand — retrieves full GWS user profile information
Create User 28 On-demand — creates a new Google Workspace user
View G-Drive link information 23 On-demand — inspects Google Drive file sharing and access details
Reset User Password 16 On-demand — generates and sets a random GWS user password
Get Group Info 16 On-demand — retrieves Google group details and membership list
User 2FA Codes Generation 13 On-demand — generates 2FA backup codes for a GWS user
Block User 11 On-demand — suspends a Google Workspace user account
Change User OU 9 On-demand — moves a GWS user to a different organizational unit
Add Users to Group 8 On-demand — adds one or more users to a Google group
Create Group & Add Users 7 On-demand — creates a new Google group and adds initial members
Check Transfer and Delete User 5 On-demand — handles Drive transfer and conditional user deletion
Remove Users From Group 5 On-demand — removes users from a Google group
Delete Group 3 On-demand — deletes a Google Workspace group
Get Admin Logs 3 On-demand — retrieves Google Workspace admin audit logs
User Devices Manager - Subflow 46 Subflow — device action loop for User Devices Manager - Main
View User Drive Log 0 On-demand — retrieves user Google Drive activity log (unused)
Log Manager 0 On-demand — retrieves various GWS activity logs (unused)
Create: user\fille\delete 0 Test — prototype test playbook (unused)
Unblock User 1 On-demand — re-activates (unblocks) a suspended Google Workspace user account
Create User copy 1 On-demand — creates a Google Workspace user with try/catch error handling

7. Access Operations SLA & Reporting

Description: Real-time SLA monitoring and reporting for the access request operation, tracking ticket open/close rates, processing time, and per-analyst performance via Blink dashboard widgets. Includes Asana ticket search/export tooling, data quality checks, quarterly P90 completion-time reporting, and AI agent–generated compliance reports.

Business Problem: Access operations teams need visibility into request volumes, SLA adherence, and individual workload distribution. Without automated reporting, management relies on manual spreadsheet aggregation that is always stale.

Category: GRC

Subcategories: Security metrics & reporting · RBAC review & access mgmt

Key Integrations: Asana · Blink Tables · Blink Dashboards (widget update) · Google Sheets · Email

Playbook Executions Role
SLA - General 86 Event — updates general SLA dashboard widgets (open/closed/AMIS)
Asana tickets search 86 On-demand — searches all Asana tickets associated with user emails
SLA - Sofiia Shepelieva 13 Event — per-analyst SLA dashboard update
SLA - Data Quality 9 Scheduled (weekly) — monitors SLA table data quality and flags anomalies
SLA - Sergey Troyan 8 Event — per-analyst SLA dashboard update
SLA - Daria Puhakova 7 Event — per-analyst SLA dashboard update
Asana tickets export 7 On-demand — exports Asana ticket data for a date range to email
SLA - Iryna Kril 5 Event — per-analyst SLA dashboard update
Total update 0 On-demand — bulk recalculation of SLA totals (maintenance tool)
Update type field 0 On-demand — backfills empty ticket type fields (maintenance tool)
Run review 0 On-demand — runs AI agent–based Asana access audit (unused)
Agent Generated: count_asana_users 0 Agent-generated — counts active Asana users (unused)
Agent Generated: count_asana_users_v2 0 Agent-generated — counts active Asana users v2 (unused)
Agent Generated: asana_hibob_compliance_report 0 Agent-generated — reconciles Asana users against HiBob status (unused)
SLA - P90 quater 0 On-demand — calculates quarterly P90 SLA completion time for tickets
SLA - Check open tickets in Asana 1 Scheduled (daily) — checks open Asana tickets against SLA thresholds

8. Audit Log Pipeline & Platform Health

Description: Continuous Blink audit log backup running every 30 minutes, shipping logs to AWS S3 for long-term retention and compliance. Paired with automated failure notification that emails the team on any workflow execution error.

Business Problem: Blink-native audit logs have limited retention. A compliance-driven need to retain audit trails for regulatory and forensic purposes requires continuous export to a durable external store. Workflow failures need immediate team visibility without manual log monitoring.

Category: Cloud Security

Subcategories: SIEM & log pipeline monitoring

Key Integrations: AWS S3 · Email (Blink native)

Playbook Executions Role
Blink Audit Log S3 Backup 4,885 Scheduled (every 30 min) — exports Blink audit logs to AWS S3
Blink Error Messaging 42 Event — sends email notification on any workflow execution failure

Key Observations

Strengths

Deeply integrated end-to-end lifecycle automation. PM Group has built one of the most complete IAM lifecycle automation stacks observed — new hire events in HiBob propagate through account creation in six systems, group assignments, SecHub identity linking, welcome email, and SLA tracking with no manual handoffs. The HiBob webhook parser alone processed 2,063 lifecycle events in 12 months.

High-volume access request throughput at scale. The access request flow (Process Access Request Ticket + AD/AMS Group flows) handled 1,175 requests and executed 1,577 group membership changes autonomously. The SLA tracking layer (20,806 events) provides real-time operational visibility that would be impossible to maintain manually.

Custom identity platform integration (SecHub & AMS). Unlike most customers who work with off-the-shelf directories, PM Group has built deep automation around two proprietary internal systems — SecHub (their HR/identity registry) and AMS (GR8Tech access management). The depth of integration (create, link, status sync, manual review, delete) is a significant implementation investment.

Proactive scheduling and operational resilience. Multiple scheduled safety nets exist — pre-activation checks 1 day and same-day before start dates, morning/evening termination checks, daily webhook monitoring, and weekly SLA data quality runs — demonstrating mature operational thinking beyond simple reactive automation.

Audit log compliance pipeline. Running 4,885 times in 12 months (every 30 minutes), the S3 audit backup is one of the most execution-heavy playbooks and reflects a clear compliance or regulatory driver for long-term log retention.

Google Drive data custody now automated during offboarding. New Drive-transfer workflows (Google Drive Transfer, transfer status check, bridge-account finish, person-transfer finish) handled 93 combined executions, ensuring departing employees' files are preserved and reassigned rather than orphaned — closing a common offboarding gap.

Expanding investment in identity data quality. PM Group added a substantial suite of scheduled and on-demand data-integrity tooling — duplicate employee/account detection and merge, SecHub ambiguous-ownership scanning, account-mismatch scanning and auto-patch, and removed-account cleanup — reflecting growing maturity in keeping SecHub and directory data clean without manual audits.

Gaps & Opportunities

Temporary access control is beginning to see production use, but adoption is uneven. The Block/Reinstate use case has grown to 19 playbooks, and the Daily Reinstate check (37 executions) plus a new InfoSec-driven block path (InfoSec Block webhook, 6 executions) show real activity. However, most of the underlying per-system Block/Reinstate subflows (AD, AMS, Google Workspace, Slack, Asana, 1Password) still show 0 executions, meaning many block/reinstate actions may still be handled outside the orchestrator.

No automated Atlassian offboarding. Atlassian user operations (Suspend, Remove, group management) appear in the access request flow but are absent from the Master Dismissal orchestration. Atlassian suspension must currently be handled manually during terminations.

Re-hire volume is low but the flow exists. Only 13 re-hire setups were completed via the automated flow, and the re-hire subflows (AD Re-hire Update, AMS re-hire) show single-digit usage. If re-hires are being processed partially manually, this is an opportunity to drive all volume through the automated path.

Agent-generated compliance playbooks are unused. Three AI agent–generated playbooks (Asana/HiBob reconciliation, user count) have 0 executions. The compliance reconciliation use case (cross-referencing Asana users against HiBob active employees) is high value and worth operationalizing.

Azure group changes are minimal (12 executions) vs. AD (948) and AMS (629). Either Azure AD group management is handled elsewhere, or there is underutilization of the existing Azure Groups Add\Remove automation.

A growing volume of 0-execution SecHub/directory maintenance tooling. Roughly half of the new Identity Directory Sync & Maintenance playbooks (SecHub - Entity Migration, AD Employee Patch, SecHub Ambiguous Ownership Scan, Open CSV file, AD email update (asana), sechub delete by integration ID, duplicated employee merge, Duplicated accounts per employee, Patch employee status, Account_mismatches) have not yet run. These appear to be recently built maintenance/data-quality tools awaiting rollout or first use.

Integration Ecosystem

Integration Use Cases
HiBob Onboarding trigger, offboarding trigger, user status check, email group sync
Active Directory (LDAP) Account create/delete/modify, group management, re-hire, email/data patch and reconciliation
Google Workspace Account create/delete/block/unblock, group management, OU sync, device management, Drive transfer
AMS (GR8Tech) Account create/delete/block, group management, user export, re-hire
SecHub Identity record create/delete/link, status sync, manual review, entity migration, dedup/cleanup
Asana Access request intake, ticket management, user provisioning/deprovisioning, onboarding Slack channel setup
Atlassian User suspend/remove/activate, group management, email update, Confluence inactivity suspension
Slack User invite, account disable/reinstate, channel create/archive
Azure AD / Entra ID Account disable/reinstate/block, session revocation, group management, VDI data
1Password User suspend, group management
Azure Blob Storage AMS user export, JSON data store for onboarding blobs
AWS S3 Audit log long-term retention
Google Sheets AVD reporting, SecHub manual review, employee lookup
N8N Webhook source for E3 license automation
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
pm-group asana asana_steppro_connection 2026-08-12
pm-group google-drive google_drive_parimatch 2026-08-05