Blink Security Automation — Confidential

neurocrine — Customer Success Report

Generated 2026-08-30 | neurocrine-value-report.md
2026-08-30Report Date
194Total Playbooks
107Unique Workflows (12m)
706,996Actions Automated (12m)
$181,841Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

194
Total playbooks built
all non-deleted workflows
96
Active playbooks
currently enabled
107
Unique workflows executed (12m)
distinct workflows that ran
706,996
Actions automated (12m)
completed action steps
3,927.8h
Hours saved (12m)
@ 20s per action
$181,841
Money saved (12m)
@ $100K avg salary
11
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 1 total
92
AI agent tasks executed (12m)
57 in last 30d
In the last 12 months, Blink automated: - 785 security alert enrichments with IOC intelligence, automatically updating tickets in JIRA and PagerDuty - 337 CI/CD security scan findings triaged and routed to engineering and security teams via Wiz - 241 threat intel feed updates delivered to Splunk and Microsoft Defender to keep defenses current - 199 token expiration events detected and security teams automatically notified - 166 ad hoc SOC investigations powered by on-demand IOC, user, and file lookup tools - 140 SIEM threshold breach events automatically monitored and tracked to resolution - 96 vendor questionnaire status check-ins fully automated - 84 elevated endpoint privilege management events automatically detected and the security team notified - 59 third-party vendor risk assessments initiated end-to-end from ServiceNow service requests - 41 departing employees automatically placed under legal hold in Microsoft Purview on departure

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
IOC Enrichment & Automated Ticket Management1,695 executions
10.6%
12
12 active
Threat Intelligence Feed Management
  • 241Threat intel feed updates pushed to Splunk and Microsoft Defender
  • 28Ransomware threat actor targeting checks
2.0%
2
2 active
SIEM Threshold Monitoring262 executions
1.6%
3
3 active
Identity Threat Response — High-Risk Travel
  • 29High-risk travel security alerts automatically processed and routed
0.2%
1
1 active
Phishing Detection & Response0 executions
0.0%
2
2 active
Credential Exposure Monitoring
  • 6Credential breach checks executed against HaveIBeenPwned
0.0%
1
1 active
CI/CD Security Scanning & Alert Routing
  • 337CI/CD security scan findings triaged and routed to stakeholders
1.7%
2
2 active
Third Party Risk Management (TPRM)
  • 96Vendor questionnaire status check-ins automated
  • 59Third-party vendor risk assessments initiated end-to-end
  • 21Vendor risks automatically created in AuditBoard
1.4%
6
0 active
Data Privacy, Legal Hold & Compliance Reporting
  • 40Legal hold and eDiscovery compliance reports generated
  • 29Press release MNPI monitoring runs executed
70.3%
4
4 active
Identity Directory Sync & BYOD Management
  • 30Entra security groups automatically assigned to applications based on naming convention
0.4%
5
3 active
Employee Offboarding Automation
  • 41Departing employees automatically placed under legal hold in Microsoft Purview
0.2%
1
1 active
Inactive User & Access Hygiene Reporting12 executions
0.1%
2
1 active
MFA Security & Duo Management
  • 41Duo MFA bypass events automatically investigated
0.2%
2
2 active
Entra Credential Lifecycle Management6 executions
0.0%
1
1 active
Endpoint Security, MDM & Network Access
  • 84Elevated endpoint privilege management events detected and teams notified
  • 29Endpoint security dashboard data automated refreshes
  • 29Unassigned Windows device alerts sent to IT support leadership
1.3%
19
19 active
IT Platform Operations & Monitoring
  • 199Token expiration events automatically detected and teams notified
1.8%
9
9 active
Total14,749 executions100%
72
63 active

Use Case Growth Over Time

149 unique playbooks  |  16 operational use cases  |  16,048 total executions (12m)  |  2025-05 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

IOC Enrichment & Automated Ticket Management
VirusTotal Microsoft Entra ID Extraction Utilities Jira Splunk Agents Microsoft Teams Duo Microsoft Graph Microsoft Defender XDR Abnormal ServiceNow PagerDuty Microsoft Defender For Endpoints IPinfo String Utilities Array Utilities Wiz
Third Party Risk Management (TPRM)
AuditBoard ServiceNow Microsoft Outlook Email
Identity Directory Sync & BYOD Management
Microsoft Entra ID Okta Splunk Microsoft Graph
Identity Threat Response — High-Risk Travel
Microsoft Outlook Microsoft Teams
IT Platform Operations & Monitoring
String Utilities GitHub Microsoft Teams Microsoft Defender For Cloud Apps Microsoft Entra ID Email Microsoft Outlook
Inactive User & Access Hygiene Reporting
Email Microsoft Entra ID
Data Privacy, Legal Hold & Compliance Reporting
Microsoft Graph Email Splunk
Threat Intelligence Feed Management
Splunk Microsoft Defender for Endpoint Microsoft Teams Microsoft Outlook
Credential Exposure Monitoring
Have I Been Pwned Microsoft Entra ID Email
Endpoint Security, MDM & Network Access
Microsoft Graph Microsoft Defender For Endpoints Zscaler Internet Access Splunk OpenAI Microsoft Intune Microsoft Entra ID Microsoft Outlook Microsoft Defender XDR Email Microsoft Teams
SIEM Threshold Monitoring
Splunk Jira Microsoft Teams
Phishing Detection & Response
Microsoft Outlook Microsoft Graph Microsoft Teams
Entra Credential Lifecycle Management
Microsoft Graph Email
MFA Security & Duo Management
Duo Microsoft Entra ID Microsoft Graph Email
CI/CD Security Scanning & Alert Routing
Wiz Microsoft Outlook

04Key Observations

✓  Strengths

Strengths

Mature IOC Enrichment Engine: The most-executed automation is the IOC enrichment framework — 930 IP cache lookups in 12 months indicates a high-volume, production-grade deployment. The layered architecture (extraction → deduplication → caching → enrichment → ticket update) reflects significant engineering investment and operational maturity. Shared subflows reused across JIRA, PagerDuty, and Splunk pipelines is a strong design pattern.

Broad Security Stack Coverage: The automation stack spans Splunk, Microsoft Defender for Endpoints, Microsoft XDR, Wiz, Okta, Entra ID, Zscaler, Duo, VirusTotal, HaveIBeenPwned, Ransomware.live, PagerDuty, and JIRA. The breadth of integration coverage across SOC, IAM, endpoint, and cloud security signals a mature, multi-stakeholder automation program.

Compliance Automation Depth: The GRC use cases are unusually well-developed. The ServiceNow → AuditBoard → questionnaire → risk creation pipeline represents a fully automated TPRM lifecycle. The Purview legal hold, Workday offboarding, and BigID labeling automations demonstrate regulatory-grade compliance investment — particularly relevant for a life sciences company.

DevSecOps Coverage: 337 Wiz CI/CD scan events automatically triaged and routed in 12 months places this program ahead of most peers in operationalizing DevSecOps alerting without manual security review queues.

Platform Self-Management: Automating Blink's own workflow backups, error handling, and platform health checks reflects a mature team that treats their SOAR platform as production infrastructure — not just a tool.

Expanding Analyst Self-Service Toolkit: A growing set of on-demand lookup tools (IP reputation, VirusTotal IOC checks, Entra user lookups, Defender file retrieval, Intune device lookups) saw 176 combined executions, indicating analysts are increasingly using Blink as a manual investigation aid alongside the fully automated pipelines.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Phishing Response Gap: The phishing detection workflow (0 executions) is built and deployed but not receiving Outlook webhook events. Activating this would extend automated IOC enrichment to user-reported phishing at no additional development cost, adding another high-volume enrichment channel.

Browser Extension Visibility: Six browser extension inventory workflows exist across multiple development iterations but have never been executed. Given the active Intune and Defender investment, activating extension auditing would close a meaningful endpoint hygiene gap — particularly relevant for detecting unauthorized AI tools or data exfiltration browser extensions.

AI Governance Gap: An "Update AI Usage Data" workflow using Reco AI exists but has never been executed. With OpenAI already integrated in the Zscaler checker and AI tool usage a growing compliance concern in life sciences, activating AI governance monitoring would be a natural next step.

Duo Unenrolled Users: The Duo unenrolled user reporting workflow (0 executions) exists but has not been activated. Given the active Duo bypass monitoring, pairing it with enrollment gap reporting would provide complete MFA coverage.

Wiz Secrets Posture: "Get Secrets from Wiz" (0 executions) could complement the active CI/CD scanning pipeline with periodic full secrets posture reviews rather than only event-driven coverage.

Integration Ecosystem

Domain Integrations
SIEM / Logging Splunk
Ticketing / Case Mgmt JIRA (Cloud), PagerDuty, ServiceNow
EDR / XDR Microsoft Defender for Endpoints, Microsoft XDR Defender
Cloud Security Wiz
Network Security Zscaler (ZIA, Client Connector / OneAPI)
Browser Security SquareX
Identity Microsoft Entra ID, Okta, Duo
Compliance / GRC AuditBoard, Microsoft Purview (via MS Graph)
DLP / Data BigID
Threat Intel VirusTotal (via IOC subflows), IPInfo, HaveIBeenPwned, Ransomware.live
Communication Microsoft Outlook, Microsoft Teams, Email
HR / Offboarding Workday (via HTTP)
Source Control GitHub
AI OpenAI (GPT), Reco AI
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 92 tasks (12m)

AI Agents

Active Agents
1
of 1 total
Tasks Executed (12m)
92
57 in last 30d
Data Usage (12m)
5,113,785
3,186,371 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Ticket Enhancer Agent DevCyberSecurity 92 57 5,113,785
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
DevCyberSecurity92
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
6
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Ori Test 00
2 Browser Extensions 00
3 Defender/Entra/Intune/Zscaler Dashboard 00
4 test 00
5 BlinkOps Classes 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Training Web Form - Print a nice message! 00
D Full Use Case Analysis 16 use cases | 16,048 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-enriched with IOC intelligence and ticket updates driven 785 JIRA - Lookup all IOCs and Update Ticket with Formatting (+694), Pager Duty - Lookup all IOCs and Update Ticket (+45), Ingest Splunk Alerts via Webhook and create JIRA ticket (+46)
CI/CD security scan findings triaged and routed to stakeholders 337 Get CI/CD Scan and alert parties - Events
Threat intel feed updates pushed to Splunk and Microsoft Defender 241 Update IOCs in Splunk and Defender
Token expiration events automatically detected and teams notified 199 Token Refresh Alerting
Ad hoc SOC investigations supported via on-demand IOC, user, and file lookups 166 Lookup User in Entra (+112), Look up IP in IPInfo (+30), Lookup IOC in VirusTotal (+23), Defender Getfile by Hostname and Path (+1)
SIEM threshold breach events monitored and tracked through resolution 140 Check for Splunk Beyond Threshold - New Records Trigger (+49), Check for Splunk Beyond Threshold - Updated Records Trigger (+91)
Vendor questionnaire status check-ins automated 96 Update Questionnaire Status
Elevated endpoint privilege management events detected and teams notified 84 Elevated Endpoint Privilege Management Notification
Third-party vendor risk assessments initiated end-to-end 59 Assessment Service Request Trigger - Prod
Departing employees automatically placed under legal hold in Microsoft Purview 41 Push Departing Users to Purview
Duo MFA bypass events automatically investigated 41 Duo Bypass Lookup
Legal hold and eDiscovery compliance reports generated 40 Generate and Email MBrewer a report on new Mailboxes & SharePoint Sites(New)
Entra security groups automatically assigned to applications based on naming convention 30 Auto Assign Entra Groups to App Based On Group Name
High-risk travel security alerts automatically processed and routed 29 Process new High Risk Travel emails
Endpoint security dashboard data automated refreshes 29 Update Data for Defender/Intune/Zscaler Dashboard
Press release MNPI monitoring runs executed 29 Update Press Releases V2
Unassigned Windows device alerts sent to IT support leadership 29 Send Email to IT Support Leadership of Unassigned Windows Devices in Intune every weekday morning at 9am
Ransomware threat actor targeting checks 28 Daily Ransomware.live First Party Monitor
Vendor risks automatically created in AuditBoard 21 Create AuditBoard Risk
On-demand device lookups performed against Intune for investigations 10 Look up Device in Intune
Credential breach checks executed against HaveIBeenPwned 6 Check HaveIBeenPwnd Report for Neurocrine Emails
In the last 12 months, Blink automated: - 785 security alert enrichments with IOC intelligence, automatically updating tickets in JIRA and PagerDuty - 337 CI/CD security scan findings triaged and routed to engineering and security teams via Wiz - 241 threat intel feed updates delivered to Splunk and Microsoft Defender to keep defenses current - 199 token expiration events detected and security teams automatically notified - 166 ad hoc SOC investigations powered by on-demand IOC, user, and file lookup tools - 140 SIEM threshold breach events automatically monitored and tracked to resolution - 96 vendor questionnaire status check-ins fully automated - 84 elevated endpoint privilege management events automatically detected and the security team notified - 59 third-party vendor risk assessments initiated end-to-end from ServiceNow service requests - 41 departing employees automatically placed under legal hold in Microsoft Purview on departure

Use Case Summary

# Use Case Category Subcategory Playbooks Active
1 IOC Enrichment & Automated Ticket Management SOC Alert enrichment / IOC lookup, Case mgmt & SOAR 13 13
2 Threat Intelligence Feed Management SOC Threat intel ingest & curation 3 2
3 SIEM Threshold Monitoring SOC SIEM & log pipeline monitoring 3 3
4 Identity Threat Response — High-Risk Travel SOC Identity threat response 1 1
5 Phishing Detection & Response SOC Phishing detection & response 2 0
6 Credential Exposure Monitoring SOC Identity threat response, Threat intel ingest & curation 1 1
7 CI/CD Security Scanning & Alert Routing Cloud Security CSPM ingest & triage, DevSecOps compliance 3 1
8 Third Party Risk Management (TPRM) GRC Vendor risk & TPRM, Compliance questionnaire 12 10
9 Data Privacy, Legal Hold & Compliance Reporting GRC DLP triage & exposure resp, DSAR & privacy automation, Security metrics & reporting 7 5
10 Identity Directory Sync & BYOD Management IAM Identity sync & directory mgmt, Access review & group mgmt 5 4
11 Employee Offboarding Automation IAM Employee offboarding 1 1
12 Inactive User & Access Hygiene Reporting IAM Access review & group mgmt 2 1
13 MFA Security & Duo Management IAM Identity lifecycle automation, Privileged account mgmt 2 1
14 Entra Credential Lifecycle Management IAM Password & credential lifecycle 1 1
15 Endpoint Security, MDM & Network Access Other Endpoint hygiene & MDM ops 20 9
16 IT Platform Operations & Monitoring Other DevOps & release automation, SaaS / IT administration 9 6
Total 86 59

Use Cases

1. IOC Enrichment & Automated Ticket Management

Category: SOC

Subcategories: Alert enrichment / IOC lookup, Case mgmt & SOAR

Description: Neurocrine's primary SOC automation enriches incoming security events from JIRA, PagerDuty, and Splunk with IOC intelligence — IP reputation (with caching), URL scanning, file hash lookups, and user country resolution via Entra ID — and writes findings back to the originating ticket. A shared extraction engine filters false positives and normalizes IOC formats before delegating to specialized subflows, enabling a single automated investigation framework across multiple ticketing platforms. A complementary suite of on-demand tools lets analysts manually look up IP reputation, IOC verdicts, and user identity during ad hoc investigations, and retrieve files directly from Defender-managed endpoints by hostname and path.

Business problem solved: Manual IOC triage is one of the most repetitive analyst tasks in a SOC. Every alert containing IPs, URLs, or hashes requires looking up each indicator against threat intel databases and adding context to the ticket. This automation runs that process end-to-end — no analyst involvement required for the enrichment phase. The on-demand lookup tools extend the same enrichment coverage to manual investigations that fall outside the automated ticket pipelines.

Key integrations: Splunk, JIRA, PagerDuty, VirusTotal, IPInfo, Microsoft Entra ID, Microsoft Defender for Endpoints, Blink Tables (IP cache)

Playbook Executions (12m) Type
JIRA - Lookup all IOCs and Update Ticket with Formatting 694 Top-level (event)
Pager Duty - Lookup all IOCs and Update Ticket 45 Top-level (event)
Ingest Splunk Alerts via Webhook and create JIRA ticket 46 Top-level (event)
Extract - Filter and Enhance IP, Url, User, Hash IOCs 454 Subflow
IP Lookup Table Check Subflow 930 Subflow
IP lookup with caching subflow 233 Subflow
URL lookup subflow 149 Subflow
Hash lookup subflow 112 Subflow
Lookup user Country in Entra 9 Subflow
Lookup User in Entra 112 Top-level (on-demand)
Look up IP in IPInfo 30 Top-level (on-demand)
Lookup IOC in VirusTotal 23 Top-level (on-demand)
Defender Getfile by Hostname and Path 1 Top-level (on-demand)

2. Threat Intelligence Feed Management

Category: SOC

Subcategories: Threat intel ingest & curation

Description: Automated ingestion and distribution of external threat intelligence into the security stack. A scheduled workflow pulls STIX 2.1 IOC feeds every four hours and propagates them to both Splunk and Microsoft Defender, keeping detection surfaces current without manual curation. A twice-daily ransomware monitoring workflow checks Ransomware.live for mentions of Neurocrine and key third-party partners.

Business problem solved: Keeping SIEM and EDR IOC blocklists current is operationally demanding and often delayed without automation. The ransomware monitoring provides proactive first-party and supply-chain threat awareness against active threat actors.

Key integrations: Splunk, Microsoft Defender for Endpoints, Ransomware.live API

Playbook Executions (12m) Type
Update IOCs in Splunk and Defender 241 Top-level (scheduled)
Daily Ransomware.live First Party Monitor 28 Top-level (scheduled)
New Workflow (Ransomware Monitoring Prototype) 0 Top-level (on-demand)

3. SIEM Threshold Monitoring

Category: SOC

Subcategories: SIEM & log pipeline monitoring

Description: Event-driven monitoring of a Splunk "beyond threshold" alerting table. When new records are inserted or existing records are updated in the monitoring table, Blink automatically dispatches a Splunk re-query to verify the threshold condition is still met, creating a closed-loop triage workflow that continues retrying on a configurable delay until the condition resolves.

Business problem solved: Prevents analysts from manually polling Splunk for threshold-based alerts. Triggered by table changes, this automation reduces mean time to verify threshold violations and ensures nothing sits unaddressed.

Key integrations: Splunk, Blink Tables

Playbook Executions (12m) Type
Check for Splunk Beyond Threshold - New Records Trigger 49 Top-level (event)
Check for Splunk Beyond Threshold - Updated Records Trigger 91 Top-level (event)
Check for Splunk Beyond Threshold v2 137 Subflow

4. Identity Threat Response — High-Risk Travel

Category: SOC

Subcategories: Identity threat response

Description: A weekday-scheduled automation processes incoming security alerts around employee travel to high-risk regions. Uses a global variable as a cursor to consume new alerts incrementally and avoid reprocessing, providing continuous visibility into potential identity risk from travel to sensitive geographies.

Business problem solved: Ensures high-risk travel alerts are consistently reviewed and never pile up unread, reducing the window for undetected account compromise or insider threat risk arising from employee travel.

Key integrations: Email/Outlook, Blink global variables

Playbook Executions (12m) Type
Process new High Risk Travel emails 29 Top-level (scheduled)

5. Phishing Detection & Response

Category: SOC

Subcategories: Phishing detection & response

Description: A Microsoft Outlook webhook subscription feeds user-reported phishing emails into an automated analysis workflow that extracts URLs from the email body HTML and routes them through inspection. A companion workflow manages the Outlook subscription lifecycle — listing, deleting expired subscriptions, and recreating them — to ensure the webhook remains active. Currently built and deployed but not yet receiving events.

Business problem solved: Reduces the manual burden of analyzing user-reported phishing emails, enabling faster triage of suspicious links at scale without requiring analyst involvement for initial inspection.

Key integrations: Microsoft Outlook, Microsoft Graph, Blink platform API

Playbook Executions (12m) Type
Phishing Email 0 Top-level (event)
Phishing Email - Create Subscription 0 Top-level (on-demand)

6. Credential Exposure Monitoring

Category: SOC

Subcategories: Identity threat response, Threat intel ingest & curation

Description: A weekly workflow queries HaveIBeenPwned for new breach events involving corporate email domains since the last run. Uses a global variable as a cursor to avoid re-processing historical breaches, ensuring only new exposure events trigger notifications.

Business problem solved: Gives the security team early warning when corporate credentials appear in external breach data, enabling faster password resets and compromise investigation before attackers can operationalize stolen credentials.

Key integrations: HaveIBeenPwned API, Blink global variables

Playbook Executions (12m) Type
Check HaveIBeenPwnd Report for Neurocrine Emails 6 Top-level (scheduled)

7. CI/CD Security Scanning & Alert Routing

Category: Cloud Security

Subcategories: CSPM ingest & triage, DevSecOps compliance

Description: An event-driven pipeline ingests Wiz CI/CD security scan webhooks and categorizes findings by type (IaC, SAST, secrets, data vulnerabilities), then routes email notifications to the relevant engineering and security stakeholders per finding category. A secondary workflow can query Wiz for secrets findings on demand.

Business problem solved: Brings security visibility into the CI/CD pipeline without requiring developers to manually check a security portal. 337 automated scan-result routings in 12 months represents continuous DevSecOps coverage for every scan event generated.

Key integrations: Wiz, Microsoft Outlook, HTTP

Playbook Executions (12m) Type
Get CI/CD Scan and alert parties - Events 337 Top-level (event)
Get Secrets from Wiz 0 Top-level (on-demand)
wiz-Blink-3 0 Top-level (event)

8. Third Party Risk Management (TPRM)

Category: GRC

Subcategories: Vendor risk & TPRM, Compliance questionnaire

Description: End-to-end automation of the third-party vendor risk assessment lifecycle. When a ServiceNow service request triggers an assessment, Blink sanitizes the input, looks up the vendor in AuditBoard, creates or updates the vendor record with business owner context, evaluates whether a questionnaire is required, and initiates it automatically. A three-times-daily status-polling workflow monitors all open questionnaires and updates their statuses. A separate risk-creation workflow translates questionnaire responses (including AI-specific risk categorization) into AuditBoard risks, with manual override capabilities via on-demand workflows.

Business problem solved: Eliminates manual handoffs between the GRC team, ServiceNow, and AuditBoard. The full assessment lifecycle from intake to risk creation runs autonomously, ensuring consistent vendor risk coverage with no process gaps.

Key integrations: ServiceNow, AuditBoard, Microsoft Outlook, Blink Tables

Playbook Executions (12m) Type
Assessment Service Request Trigger - Prod 37 Top-level (event)
Third Party Risk Management (TPRM) - Prod 37 Subflow
Update Questionnaire Status 87 Top-level (scheduled)
Create AuditBoard Risk 16 Subflow
Manually create risks given vendor name 2 Top-level (on-demand)
manually create questionaire 1 Top-level (on-demand)
CSV Input - Create Vendor Risks 0 Top-level (on-demand)
Assessment Service Request Trigger - Prod 22 Top-level (event)
Update Questionnaire Status 9 Top-level (scheduled)
Create AuditBoard Risk 5 Subflow
Manually create risks given vendor name 4 Top-level (on-demand)
manually create questionaire 0 Top-level (on-demand)

9. Data Privacy, Legal Hold & Compliance Reporting

Category: GRC

Subcategories: DLP triage & exposure resp, DSAR & privacy automation, Security metrics & reporting

Description: A suite of automations covering Microsoft Purview eDiscovery and legal hold reporting, BigID data labeling compliance metrics, and Splunk-based MNPI monitoring for press releases. The Purview legal hold workflow generates weekly reports on mailbox and SharePoint site coverage across active cases and highest-priority holds. BigID workflows track document labeling progress across four data repositories (NBIFiler, OneDrive, SharePoint, Box) and record metrics weekly. Press release monitoring pushes an updated corpus to Splunk daily to support insider threat and MNPI detection use cases.

Business problem solved: Manual Purview legal hold audits are time-consuming and error-prone. Automating these checks ensures legal and compliance teams have current coverage data. Data labeling tracking provides measurable progress metrics for the DLP program.

Key integrations: Microsoft Purview (via MS Graph), BigID, Splunk

Playbook Executions (12m) Type
Generate and Email MBrewer a report on new Mailboxes & SharePoint Sites(New) 40 Top-level (scheduled)
Update Purview via MS Graph 242 Subflow/utility
BigID Label Report (workspace A) 2 Top-level (scheduled)
BigID Label Report (workspace B) 2 Top-level (scheduled)
Update Press Releases V2 29 Top-level (scheduled)
Update Press Releases 0 Top-level (on-demand)
BigID ACI Search 0 Top-level (on-demand)

10. Identity Directory Sync & BYOD Management

Category: IAM

Subcategories: Identity sync & directory mgmt, Access review & group mgmt

Description: Maintains synchronized user lookup tables sourced from Microsoft Entra ID (daily) and Okta (weekly), providing a fast-query user repository that powers IOC enrichment lookups and access reporting across the platform. A weekly BYOD workflow syncs the BYOD device enrollment group, cross-references the user lookup table to identify enrollment gaps, and pushes the results to Splunk for dashboard visibility. A daily workflow (with an on-demand variant) automatically assigns Entra security groups to applications based on group naming convention, removing a manual provisioning step from access management.

Business problem solved: Many workflows need to quickly look up user attributes (country, manager, status) without making real-time API calls to identity providers. These scheduled sync workflows maintain a local cache that accelerates IOC investigation and supports access compliance reporting.

Key integrations: Microsoft Entra ID, Okta, Splunk, Blink Tables

Playbook Executions (12m) Type
Populate User Lookup Table Daily V2 31 Top-level (scheduled)
Populate Okta User Lookup Table Weekly 6 Top-level (scheduled)
Update BYOD Users 6 Top-level (scheduled)
Auto Assign Entra Groups to App Based On Group Name 30 Top-level (scheduled)
SCK's Auto Assign Entra Groups to App Based on Group Name 0 Top-level (on-demand)

11. Employee Offboarding Automation

Category: IAM

Subcategories: Employee offboarding

Description: A daily workflow pulls the departing employee report from Workday and automatically updates Microsoft Purview with departure records to ensure legal hold and eDiscovery coverage is maintained throughout the notice period and post-departure window.

Business problem solved: Ensures no departing employee falls through the cracks for legal hold compliance. Manual Purview updates are error-prone and often delayed, creating compliance and litigation risk. Daily automation provides consistent, auditable coverage.

Key integrations: Workday (via HTTP/basic-auth), Microsoft Purview (via Blink subflow)

Playbook Executions (12m) Type
Push Departing Users to Purview 41 Top-level (scheduled)

12. Inactive User & Access Hygiene Reporting

Category: IAM

Subcategories: Access review & group mgmt

Description: A scheduled monthly report (second Tuesday of each month) segments inactive users across three populations — US employees with EmployeeIDs, non-US employees, and service accounts — and emails a consolidated CSV report per segment. Identifies accounts inactive beyond 90 days by comparing last-login epoch times against the user lookup table.

Business problem solved: Inactive accounts represent a persistent attack surface. Automated reporting gives the IAM team regular visibility to perform hygiene reviews without running manual Entra queries.

Key integrations: Blink Tables (user_lookup), Email

Playbook Executions (12m) Type
Inactive User Report v2 (SCK) 15 Top-level (scheduled)
Inactive User Report 0 Top-level (on-demand)

13. MFA Security & Duo Management

Category: IAM

Subcategories: Identity lifecycle automation, Privileged account mgmt

Description: A daily automation queries Duo for all users with active bypass codes, then cross-references recent authentication events in Splunk to surface anomalous usage patterns, delivering a daily bypass digest to the security team. A companion workflow identifies and emails a list of unenrolled Duo users for enrollment follow-up.

Business problem solved: Duo bypass codes are a temporary MFA bypass that, if left unchecked, become standing privileged-access mechanisms. Daily automated monitoring ensures bypass exposure windows are visible and acted on promptly.

Key integrations: Duo (via HTTP), Splunk

Playbook Executions (12m) Type
Duo Bypass Lookup 41 Top-level (scheduled)
Duo Email Unenerolled Users 0 Top-level (on-demand)

14. Entra Credential Lifecycle Management

Category: IAM

Subcategories: Password & credential lifecycle

Description: A weekly workflow scans all Microsoft Entra ID application registrations for secrets and certificates approaching expiration, generates a CSV report, and emails it to security contacts. Runs on a fixed weekly schedule to provide consistent advance warning before any credential expires.

Business problem solved: Expired application secrets in Entra ID cause service outages and can create security gaps if not rotated on schedule. Automated weekly monitoring eliminates manual checks across potentially hundreds of app registrations.

Key integrations: Microsoft Entra ID, Email

Playbook Executions (12m) Type
Microsoft Entra Secret Expiration 6 Top-level (scheduled)

15. Endpoint Security, MDM & Network Access

Category: Other

Subcategories: Endpoint hygiene & MDM ops

Description: A comprehensive set of automations for endpoint visibility and network security management. Scheduled workflows merge device records from Microsoft Defender for Endpoints, Intune, and Zscaler into a unified dashboard dataset pushed to Splunk. A daily Defender AV change report surfaces hosts with non-healthy antivirus status. Zscaler tooling provides OTP generation for help-desk scenarios, a weekly disabled-reason audit with OpenAI scoring to prioritize outreach, and blocked-country management. Browser extension inventory workflows (multiple development iterations) provide on-demand visibility into installed extensions with permission data across the device fleet. A weekday-morning workflow emails IT support leadership a list of unassigned Windows devices in Intune, and an on-demand workflow consolidates machine records from Defender, Intune, and Entra to surface devices older than 30 days. On-demand lookup tools support quick Intune device checks, a scheduled workflow notifies teams of elevated endpoint privilege management events, and a webhook-driven workflow handles SquareX browser security exception requests.

Business problem solved: Maintaining up-to-date visibility across three distinct endpoint and network security tools without automation requires constant manual data exports. The dashboard automation provides fresh posture data daily, and the AV change report catches Defender health degradations before they become incidents. Proactive unassigned-device and privilege-elevation notifications close visibility gaps before they become support or security incidents.

Key integrations: Microsoft Defender for Endpoints, Microsoft XDR Defender, Microsoft Intune, Zscaler (ZIA, Client Connector/OneAPI), Microsoft Graph, Splunk, OpenAI, Microsoft Teams, SquareX

Playbook Executions (12m) Type
Update Data for Defender/Intune/Zscaler Dashboard 29 Top-level (scheduled)
Entra/Intune/Defender/ZScaler Report Generator 11 Top-level (on-demand)
ZScaler Diable Reasons Checker 5 Top-level (scheduled)
Zscaler OTPs 5 Top-level (on-demand)
Report on Defender AV changes 1 Top-level (scheduled)
Zscaler OTPs WebhookTrigger 0 Top-level (event)
Zscaler - Blocked Countries 0 Top-level (on-demand)
Offboard Defender via API 0 Top-level (on-demand)
Run a Full Scan on AV hosts 0 Top-level (on-demand)
Pull Browser Extensions 0 Top-level (on-demand)
Pull Browser Extensions with Permissions 0 Top-level (on-demand)
Pull Browser Extensions with Permissions from Intune 0 Top-level (on-demand)
Pull Browser Extensions with Permissions copy 0 Top-level (on-demand)
Pull Browser Extensions with Permissions from Intune copy 0 Top-level (on-demand)
Pull Browser Extensions with Permissions from Intune via API call 0 Top-level (on-demand)
Elevated Endpoint Privilege Management Notification 84 Top-level (scheduled)
Send Email to IT Support Leadership of Unassigned Windows Devices in Intune every weekday morning at 9am 29 Top-level (scheduled)
Look up Device in Intune 10 Top-level (on-demand)
On SquareX Exception Request 1 Top-level (event)
Look for older than 30 day machines 0 Top-level (on-demand)

16. IT Platform Operations & Monitoring

Category: Other

Subcategories: DevOps & release automation, SaaS / IT administration

Description: Infrastructure automation supporting the Blink platform itself and general IT operations. Backup workflows automatically commit published workflow configurations to GitHub daily for version control and disaster recovery. A webhook-driven error handler captures and routes workflow failures. Token refresh alerting notifies security teams of authentication token events received via webhook. Mailbox usage reporting delivers a weekly top-20 mailbox capacity analysis. QR code generation automates a recurring operational task on demand. A platform health check workflow identifies published-but-abandoned workflow drafts.

Business problem solved: Keeps the SOAR platform healthy, auditable, and recoverable. Source-controlled workflow backups ensure no automation logic is lost. Error handling prevents silent failures. Token alerting provides lightweight integration health monitoring.

Key integrations: GitHub, Microsoft Entra ID, Microsoft Graph, Microsoft Outlook, Email, Blink platform API

Playbook Executions (12m) Type
Token Refresh Alerting 199 Top-level (event)
Backup Published Workflows 44 Top-level (scheduled)
Backup file to GitHub 110 Subflow/utility
Workflow Error Handler 53 Top-level (event)
Mailbox Usage Report 6 Top-level (scheduled)
Generate and Email QR Codes 15 Top-level (on-demand)
Look for Unpublished Workflows 0 Top-level (on-demand)
Push IP Subnets to Defender 0 Top-level (on-demand)
Test for getting a response via email 0 Top-level (on-demand)

Key Observations

Strengths

Mature IOC Enrichment Engine: The most-executed automation is the IOC enrichment framework — 930 IP cache lookups in 12 months indicates a high-volume, production-grade deployment. The layered architecture (extraction → deduplication → caching → enrichment → ticket update) reflects significant engineering investment and operational maturity. Shared subflows reused across JIRA, PagerDuty, and Splunk pipelines is a strong design pattern.

Broad Security Stack Coverage: The automation stack spans Splunk, Microsoft Defender for Endpoints, Microsoft XDR, Wiz, Okta, Entra ID, Zscaler, Duo, VirusTotal, HaveIBeenPwned, Ransomware.live, PagerDuty, and JIRA. The breadth of integration coverage across SOC, IAM, endpoint, and cloud security signals a mature, multi-stakeholder automation program.

Compliance Automation Depth: The GRC use cases are unusually well-developed. The ServiceNow → AuditBoard → questionnaire → risk creation pipeline represents a fully automated TPRM lifecycle. The Purview legal hold, Workday offboarding, and BigID labeling automations demonstrate regulatory-grade compliance investment — particularly relevant for a life sciences company.

DevSecOps Coverage: 337 Wiz CI/CD scan events automatically triaged and routed in 12 months places this program ahead of most peers in operationalizing DevSecOps alerting without manual security review queues.

Platform Self-Management: Automating Blink's own workflow backups, error handling, and platform health checks reflects a mature team that treats their SOAR platform as production infrastructure — not just a tool.

Expanding Analyst Self-Service Toolkit: A growing set of on-demand lookup tools (IP reputation, VirusTotal IOC checks, Entra user lookups, Defender file retrieval, Intune device lookups) saw 176 combined executions, indicating analysts are increasingly using Blink as a manual investigation aid alongside the fully automated pipelines.

Gaps & Opportunities

Phishing Response Gap: The phishing detection workflow (0 executions) is built and deployed but not receiving Outlook webhook events. Activating this would extend automated IOC enrichment to user-reported phishing at no additional development cost, adding another high-volume enrichment channel.

Browser Extension Visibility: Six browser extension inventory workflows exist across multiple development iterations but have never been executed. Given the active Intune and Defender investment, activating extension auditing would close a meaningful endpoint hygiene gap — particularly relevant for detecting unauthorized AI tools or data exfiltration browser extensions.

AI Governance Gap: An "Update AI Usage Data" workflow using Reco AI exists but has never been executed. With OpenAI already integrated in the Zscaler checker and AI tool usage a growing compliance concern in life sciences, activating AI governance monitoring would be a natural next step.

Duo Unenrolled Users: The Duo unenrolled user reporting workflow (0 executions) exists but has not been activated. Given the active Duo bypass monitoring, pairing it with enrollment gap reporting would provide complete MFA coverage.

Wiz Secrets Posture: "Get Secrets from Wiz" (0 executions) could complement the active CI/CD scanning pipeline with periodic full secrets posture reviews rather than only event-driven coverage.

Integration Ecosystem

Domain Integrations
SIEM / Logging Splunk
Ticketing / Case Mgmt JIRA (Cloud), PagerDuty, ServiceNow
EDR / XDR Microsoft Defender for Endpoints, Microsoft XDR Defender
Cloud Security Wiz
Network Security Zscaler (ZIA, Client Connector / OneAPI)
Browser Security SquareX
Identity Microsoft Entra ID, Okta, Duo
Compliance / GRC AuditBoard, Microsoft Purview (via MS Graph)
DLP / Data BigID
Threat Intel VirusTotal (via IOC subflows), IPInfo, HaveIBeenPwned, Ransomware.live
Communication Microsoft Outlook, Microsoft Teams, Email
HR / Offboarding Workday (via HTTP)
Source Control GitHub
AI OpenAI (GPT), Reco AI
E New Integrations (detail) 3 added in last 30d

New Integrations Added - Last 30 Days

3 new connections
TenantIntegrationConnection NameAdded
neurocrine bearer-token zscaler_zero_trust_browser_api_key 2026-08-14
neurocrine openai grc_openai 2026-08-10
neurocrine microsoft-graph microsoft_graph_entra_id_permissions 2026-07-31