Blink Security Automation — Confidential

Project-Retail — Customer Success Report

Generated 2026-08-30 | project-retail-value-report.md
2026-08-30Report Date
32Total Playbooks
13Unique Workflows (12m)
28,992Actions Automated (12m)
$7,457Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

32
Total playbooks built
all non-deleted workflows
6
Active playbooks
currently enabled
13
Unique workflows executed (12m)
distinct workflows that ran
28,992
Actions automated (12m)
completed action steps
161.1h
Hours saved (12m)
@ 20s per action
$7,457
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - No automated actions were recorded. All workflows show 0 executions in the last 12 months, indicating the automation library is built and configured but has not yet been activated in production.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Alert Enrichment — IP, Domain & Hash0 executions
0.0%
5
5 active
CrowdStrike NGSIEM Case Intake0 executions
0.0%
1
1 active
Total0 executions100%
6
6 active

Use Case Growth Over Time

16 unique playbooks  |  2 operational use cases  |  0 total executions (12m)  |  2025-10 to 2026-03
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment — IP, Domain & Hash
CrowdStrike AbuseIPDB VirusTotal Email Hybrid Analysis
CrowdStrike NGSIEM Case Intake
CrowdStrike Email

04Key Observations

✓  Strengths

Strengths

  • Modular enrichment architecture. The separation of Main orchestrators from enrichment Subflows (IP / Domain / Hash) is a strong design pattern. Subflows can be reused across multiple alert types and triggers without duplication, and the architecture scales cleanly as more indicator types are added.
  • Organizational context awareness. The IP and Domain enrichment mains query Blink Tables for organization-owned assets before querying external threat intelligence. This avoids false positives on internally routed IPs and org-controlled domains — a production-quality refinement that reflects real-world operational maturity.
  • CrowdStrike-native integration. Both the NGSIEM Cases intake and the enrichment subflows call crowdstrike.GetAlertDetails, meaning alert context is fetched directly from the authoritative source rather than relying on potentially truncated webhook payloads.
  • Confidence scoring logic. The IP Enrichment subflow includes a Python step explicitly named "Evaluate threat confidence," indicating the automation produces a risk score rather than raw data — directly supporting analyst decision-making.

###

△  Gaps & Growth Opportunities

Gaps

  • Zero production executions. All 6 workflows show 0 executions in the last 12 months. The automation layer is built and configured but has not yet been activated in a live alert pipeline. The value of this investment is currently unrealized.
  • No active trigger on enrichment mains. Both Main - IP Enrichment v2.0 and Main - Domain Enrichment v2.0 are on_demand with no event trigger wired. They are designed to be called from a parent workflow (e.g., NGSIEM Cases) but that connection has not been made — the NGSIEM Cases workflow routes through conditions but does not visibly invoke the enrichment mains.
  • No alert closure or ticketing step. The pipeline enriches and scores indicators but there is no visible step that creates a ticket, updates a case status, or closes an alert. Adding a case-update action (e.g., back to CrowdStrike or a ITSM tool) would complete the loop and enable full automation of the triage cycle.
  • Hash enrichment not connected. Subflow - Hash Enrichment exists but no top-level Main - Hash Enrichment orchestrator is present. Hash-based indicators would need a main flow to be operationalized.
  • Email as sole output. The Domain Enrichment main sends results via Blink email. For a SOC use case, enrichment output is better delivered into the case management system (CrowdStrike case comments, a SIEM annotation, or a Slack/Teams alert) to keep the analyst in a single pane.

Integration Ecosystem

Integration Usage
CrowdStrike Alert detail retrieval (GetAlertDetails), webhook event source (NGSIEM)
Blink HTTP Tables Organizational IP and domain allow-lists
Blink Email (core.emailV2) Enrichment result delivery
Python (core.python / core.pythonV2) Alert ID extraction, IP classification, threat confidence scoring, data formatting
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 2 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
— — No playbooks recorded executions in the last 12 months
In the last 12 months, Blink automated: - No automated actions were recorded. All workflows show 0 executions in the last 12 months, indicating the automation library is built and configured but has not yet been activated in production.

Use Case Summary

Use Case Category Subcategory Playbook Count Executions (12 mo)
Alert Enrichment — IP, Domain & Hash SOC Alert enrichment / IOC lookup 5 0
CrowdStrike NGSIEM Case Intake SOC Case mgmt & SOAR, SIEM & log pipeline monitoring 1 0

Total: 6 playbooks across 2 use cases.

Use Cases

1. Alert Enrichment — IP, Domain & Hash

Description: A layered enrichment pipeline that classifies and investigates indicators of compromise — IP addresses, domains, and file hashes — surfaced by CrowdStrike alerts. The architecture separates orchestration (Main playbooks) from enrichment logic (Subflows), enabling reuse across different alert types.

Business problem solved: Analysts spend significant time manually looking up whether an IP, domain, or file hash is malicious. This use case automates that investigation, classifies indicators as internal/external/organizational, queries threat intelligence, and delivers a formatted enrichment summary — removing manual lookup work from the alert triage loop.

Integrations observed: CrowdStrike (alert detail retrieval), Blink HTTP Tables (organizational IP/domain allow-lists), Blink Email (enrichment delivery), Python (IP classification logic, threat confidence scoring).

Playbook Role Executions (12 mo)
Main - IP Enrichment v2.0 Top-level orchestrator for IP indicator enrichment; classifies IPs as private, org-owned, or external before enriching 0
Main - Domain Enrichment v2.0 Top-level orchestrator for domain indicator enrichment; checks org domain list then sends enrichment email 0
Subflow - IP Enrichment Enrichment subflow invoked by Main; queries threat intel, scores confidence, formats output 0
Subflow - Domain Enrichment Enrichment subflow for domain indicators 0
Subflow - Hash Enrichment Enrichment subflow for SHA-256 file hash indicators 0

Taxonomy: SOC › Alert enrichment / IOC lookup

2. CrowdStrike NGSIEM Case Intake

Description: An event-driven workflow that ingests CrowdStrike NGSIEM alerts via webhook, extracts the alert ID, retrieves full alert details, and routes the case through conditional logic for triage or downstream action.

Business problem solved: Security cases generated in CrowdStrike NGSIEM need to be captured, normalized, and acted upon quickly. This workflow provides the intake layer — ensuring that every inbound CrowdStrike case is received, enriched with alert detail, and evaluated against triage conditions without manual intervention.

Integrations observed: CrowdStrike (webhook trigger, GetAlertDetails), Python (alert ID extraction), conditional branching logic.

Playbook Role Executions (12 mo)
NGSIEM Cases Event-driven intake for CrowdStrike NGSIEM alerts; extracts, retrieves, and conditionally routes cases 0

Taxonomy: SOC › Case mgmt & SOAR, SIEM & log pipeline monitoring

Key Observations

Strengths

  • Modular enrichment architecture. The separation of Main orchestrators from enrichment Subflows (IP / Domain / Hash) is a strong design pattern. Subflows can be reused across multiple alert types and triggers without duplication, and the architecture scales cleanly as more indicator types are added.
  • Organizational context awareness. The IP and Domain enrichment mains query Blink Tables for organization-owned assets before querying external threat intelligence. This avoids false positives on internally routed IPs and org-controlled domains — a production-quality refinement that reflects real-world operational maturity.
  • CrowdStrike-native integration. Both the NGSIEM Cases intake and the enrichment subflows call crowdstrike.GetAlertDetails, meaning alert context is fetched directly from the authoritative source rather than relying on potentially truncated webhook payloads.
  • Confidence scoring logic. The IP Enrichment subflow includes a Python step explicitly named "Evaluate threat confidence," indicating the automation produces a risk score rather than raw data — directly supporting analyst decision-making.

Gaps

  • Zero production executions. All 6 workflows show 0 executions in the last 12 months. The automation layer is built and configured but has not yet been activated in a live alert pipeline. The value of this investment is currently unrealized.
  • No active trigger on enrichment mains. Both Main - IP Enrichment v2.0 and Main - Domain Enrichment v2.0 are on_demand with no event trigger wired. They are designed to be called from a parent workflow (e.g., NGSIEM Cases) but that connection has not been made — the NGSIEM Cases workflow routes through conditions but does not visibly invoke the enrichment mains.
  • No alert closure or ticketing step. The pipeline enriches and scores indicators but there is no visible step that creates a ticket, updates a case status, or closes an alert. Adding a case-update action (e.g., back to CrowdStrike or a ITSM tool) would complete the loop and enable full automation of the triage cycle.
  • Hash enrichment not connected. Subflow - Hash Enrichment exists but no top-level Main - Hash Enrichment orchestrator is present. Hash-based indicators would need a main flow to be operationalized.
  • Email as sole output. The Domain Enrichment main sends results via Blink email. For a SOC use case, enrichment output is better delivered into the case management system (CrowdStrike case comments, a SIEM annotation, or a Slack/Teams alert) to keep the analyst in a single pane.

Integration Ecosystem

Integration Usage
CrowdStrike Alert detail retrieval (GetAlertDetails), webhook event source (NGSIEM)
Blink HTTP Tables Organizational IP and domain allow-lists
Blink Email (core.emailV2) Enrichment result delivery
Python (core.python / core.pythonV2) Alert ID extraction, IP classification, threat confidence scoring, data formatting
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.