01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Dormant Account Monitoring & Reporting |
| 22.1% | 5 4 active |
| Leave / Access Request (LAR) | 0 executions | 0.0% | 6 6 active |
| Password Expiry Notification |
| 77.9% | 10 10 active |
| AWS Cloud Account Posture |
| 0.0% | 5 5 active |
| SOC Workflow | 0 executions | 0.0% | 1 1 active |
| Total | 253 executions | 100% | 27 26 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Active IAM automation foundation. Three of the five use cases are in active production — dormant account lifecycle, password expiry notification, and AWS posture. The daily scheduling across Sin
gapore and Manila timezones indicates these are fully embedded in operational workflows, not experimental.
Mature, modular automation design. The Password Expiry Notification use case demonstrates strong architectural discipline: a single parent workflow delegates to purpose-built subflows for user-type resolution, license validation, and differentiated email delivery. This pattern reduces duplication and makes each component independently testable.
AWS cloud governance coverage. The posture assessment workflow spans multiple dimensions in a single run — user password expiry, access key rotation, and account inventory delta — with output delivered to both email recipients and SharePoint for audit trail. A second deployment of the full pipeline (AWS Account Posture, Generate AWS Account Reports, Get Accounts Added and Deleted, Upload file to sharepoint) has since been rolled out to the production workspace on a monthly schedule (31st, 10:00 MNL) — first execution pending as of this report.
Multi-deployment LAR framework. Three deployment variants of the Leave/Access Request workflow exist (standard, Deployment 2, Deployment 3 rerouted to IS), indicating a phased rollout strategy across different business units. The subflow architecture means routing logic can be updated in one place.
Gaps
LAR workflows are built but not running. All 11 playbooks in the Leave/Access Request use case have zero executions. This is the most complex use case in the portfolio — PAM-grade access certification with dynamic web forms and multi-department routing — but it is not yet active. Clarifying whether this reflects a deployment pause, a trigger dependency (e.g., an ITSM event that hasn't fired), or decommissioning is a priority.
Dormant account automation is relatively recent. With 40 daily runs across a 12-month window, the Daily Warning Notifications workflow has been operating for roughly 6–7 weeks. Long-term trend data will strengthen the compliance narrative; scheduling a review after 6 months of operation would provide meaningful before/after metrics.
SOC WF has no execution history. The credential provisioning workflow exists but has not been used. It may be an early-stage proof-of-concept, or it may have been superseded by a manual process.
No vulnerability management automation visible. The current portfolio is entirely IAM and cloud-focused. If vulnerability scanning, ticketing, or remediation tracking is handled elsewhere, there is an opportunity to centralize those workflows within Blink to complete the security operations picture.
Integration Ecosystem
| Integration | Used In |
|---|---|
| Active Directory / Entra ID | Dormant Account Monitoring, Password Expiry Notification |
| WinRM (on-premises AD) | Password Expiry Notification |
| AWS (Organization API) | AWS Cloud Account Posture |
| SharePoint | AWS Cloud Account Posture |
| SMTP (multi-server) | Dormant Account Reporting, Password Expiry Notification |
| Email (Blink native) | LAR, AWS Account Posture, SOC Workflow |
| Blink Tables | LAR, AWS Account Posture, SOC Workflow |
| Blink Web Forms | LAR |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 5 use cases | 253 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Daily dormant account warning notification runs | 40 | Daily Workflow - Warning notifications 2.2 |
| Password expiry notification campaigns dispatched | 40 | Password Expiry Notification |
| Service account lifecycle events processed | 11 | Service Accounts Handling |
| Bi-monthly dormant account compliance reports delivered | 3 | Bi-Monthly - 15th / Bi-Monthly - 30th |
| AWS account posture assessments completed | 1 | AWS Account Posture |
Use Case Summary
| # | Use Case | Category | Subcategory | Total Playbooks | Playbooks with Executions |
|---|---|---|---|---|---|
| 1 | Dormant Account Monitoring & Reporting | IAM | Access review & group mgmt, Identity lifecycle automation | 7 | 4 |
| 2 | Leave / Access Request (LAR) | IAM | Privileged account mgmt, Access review & group mgmt | 11 | 0 |
| 3 | Password Expiry Notification | IAM | Password & credential lifecycle, Identity lifecycle automation | 10 | 5 |
| 4 | AWS Cloud Account Posture | Cloud Security | Cloud asset coverage & inventory, Config audit & remediation | 9 | 5 |
| 5 | SOC Workflow | SOC | Case mgmt & SOAR | 1 | 0 |
| Total | 38 | 14 |
Use Cases
1. Dormant Account Monitoring & Reporting
Description: Automated daily monitoring of Active Directory accounts that have been inactive for 83 or 90+ days, with differentiated warning notifications and bi-monthly formal compliance reports delivered to the AD team. Service accounts follow a separate handling path.
Business problem: Inactive AD accounts represent a persistent attack surface and a common compliance finding. This use case enforces a consistent dormancy policy — warning users at 83 days, acting at 91 days, and providing audit-ready reports on the 15th and 30th of each month — eliminating the manual effort required to identify and track stale identities at scale.
Category: IAM
Subcategories: Access review & group mgmt, Identity lifecycle automation
Integrations: Active Directory, SMTP, Blink Tables
| Playbook | Type | Executions (12 mo.) |
|---|---|---|
| Bi-Monthly - 15th: Dormant Reporting to AD Team 2.2 | Scheduled (cron: 15th, 17:00 SGT) | 2 |
| Bi-Monthly - 30th: Dormant Reporting to AD Team 2.2 | Scheduled (cron: 30th, 17:00 SGT) | 1 |
| Daily Workflow - Warning notifications 2.2 | Scheduled (daily, 17:00 SGT) | 40 |
| Service Accounts Handling | On-demand subflow | 11 |
| Service Accounts Handling | On-demand subflow | 0 |
| Re-Run Reporting to CIT AD Team 2.2 | On-demand (manual re-run) | 0 |
| Re-Run Reporting to CIT AD Team 2.2 | On-demand (manual re-run) | 0 |
2. Leave / Access Request (LAR)
Description: A multi-deployment access certification workflow for employees on leave or exiting the organization. Administrators receive dynamic web forms listing the user's active assets and are prompted to approve or revoke each item. Three deployment variants exist to route certifications to different business units (standard, Deployment 2, and rerouted to Information Security).
Business problem: Unreviewed access during employee leave periods is a common compliance gap that creates insider risk and audit findings. This use case automates the generation and routing of access certification requests, reducing manual coordination and ensuring every affected account is reviewed before a PAM violation window opens.
Category: IAM
Subcategories: Privileged account mgmt, Access review & group mgmt
Integrations: Blink Tables, Blink Web Forms, SMTP, Email
| Playbook | Type | Executions (12 mo.) |
|---|---|---|
| Main - LAR | On-demand | 0 |
| Main - LAR | On-demand | 0 |
| Subflow - LAR | Subflow | 0 |
| Subflow - LAR | Subflow | 0 |
| UC3 LAR PAM - Send receipt and Update Table | Subflow | 0 |
| Main - LAR: Deployment 2 | On-demand | 0 |
| Main - LAR: Deployment 2 | On-demand | 0 |
| Main - LAR Deployment 3 Reroute to IS | On-demand | 0 |
| Main - LAR Deployment 3 Reroute to IS | On-demand | 0 |
| Subflow - LAR Reroute to IS | Subflow | 0 |
| Subflow - LAR Reroute to IS | Subflow | 0 |
3. Password Expiry Notification
Description: Daily automated monitoring of Active Directory password expiry windows, sending targeted notifications to regular users at 1, 10, 14, 25, and 40-day thresholds and routing service account alerts to designated owners. Entra ID is queried to validate user type and mailbox license eligibility before dispatching each notification.
Business problem: Expired passwords cause account lockouts, helpdesk tickets, and service disruptions — particularly for service accounts where the impact can be system-wide. Automating the full notification lifecycle, differentiated by account type and expiry urgency, eliminates manual tracking and reduces lockout-related incidents.
Category: IAM
Subcategories: Password & credential lifecycle, Identity lifecycle automation
Integrations: Active Directory (WinRM), Entra ID, SMTP, Email
| Playbook | Type | Executions (12 mo.) |
|---|---|---|
| Password Expiry Notification | Scheduled (daily, 22:00 MNL) | 40 |
| EntraID - Check userType | Subflow | 40 |
| EntraID - Check user mailbox license | Subflow | 40 |
| Regular User Email Notification | Subflow | 40 |
| Service Account Email Notification | Subflow | 40 |
| Daily Password Expiry | Scheduled | 0 |
| Entra ID - Check user mailbox license | Subflow | 0 |
| Entra ID - Check UserType | Subflow | 0 |
| Regular User Notification | Subflow | 0 |
| Service Account Notification | Subflow | 0 |
4. AWS Cloud Account Posture
Description: On-demand reporting workflow that scans the entire AWS Organization to assess account health — covering password expiry, access key rotation age, and account inventory changes (additions and deletions). Outputs an Excel report uploaded to SharePoint and HTML email summaries delivered to stakeholders.
Business problem: Managing AWS account hygiene across a large organization is operationally complex without automation. This use case provides a single-run audit that consolidates password expiry, access key rotation status, and account turnover into a shareable report, enabling proactive remediation and supporting cloud governance obligations.
Category: Cloud Security
Subcategories: Cloud asset coverage & inventory, Config audit & remediation
Integrations: AWS (Organization scan), SharePoint, Blink Tables, Email, SMTP
| Playbook | Type | Executions (12 mo.) |
|---|---|---|
| AWS Account Posture | On-demand (parent) | 1 |
| Generate AWS Account Reports | Subflow | 1 |
| Get Accounts Added and Deleted | Subflow | 1 |
| Upload file to sharepoint | Subflow | 1 |
| Get CSV to Table | Utility | 1 |
| AWS Account Posture | Scheduled (parent, cron: 31st, 10:00 MNL) | 0 |
| Generate AWS Account Reports | Subflow | 0 |
| Get Accounts Added and Deleted | Subflow | 0 |
| Upload file to sharepoint | Subflow | 0 |
5. SOC Workflow
Description: A credential generation and distribution workflow for SOC operations — generates a secure password, renders it as an image, stores a record in a Blink Table, and delivers it via email.
Business problem: Automates manual SOC credential provisioning steps to ensure consistent, auditable handling of sensitive access credentials.
Category: SOC
Subcategories: Case mgmt & SOAR
Integrations: Blink Tables, Email
| Playbook | Type | Executions (12 mo.) |
|---|---|---|
| SOC WF | On-demand | 0 |
Key Observations
Strengths
Active IAM automation foundation. Three of the five use cases are in active production — dormant account lifecycle, password expiry notification, and AWS posture. The daily scheduling across Singapore and Manila timezones indicates these are fully embedded in operational workflows, not experimental.
Mature, modular automation design. The Password Expiry Notification use case demonstrates strong architectural discipline: a single parent workflow delegates to purpose-built subflows for user-type resolution, license validation, and differentiated email delivery. This pattern reduces duplication and makes each component independently testable.
AWS cloud governance coverage. The posture assessment workflow spans multiple dimensions in a single run — user password expiry, access key rotation, and account inventory delta — with output delivered to both email recipients and SharePoint for audit trail. A second deployment of the full pipeline (AWS Account Posture, Generate AWS Account Reports, Get Accounts Added and Deleted, Upload file to sharepoint) has since been rolled out to the production workspace on a monthly schedule (31st, 10:00 MNL) — first execution pending as of this report.
Multi-deployment LAR framework. Three deployment variants of the Leave/Access Request workflow exist (standard, Deployment 2, Deployment 3 rerouted to IS), indicating a phased rollout strategy across different business units. The subflow architecture means routing logic can be updated in one place.
Gaps
LAR workflows are built but not running. All 11 playbooks in the Leave/Access Request use case have zero executions. This is the most complex use case in the portfolio — PAM-grade access certification with dynamic web forms and multi-department routing — but it is not yet active. Clarifying whether this reflects a deployment pause, a trigger dependency (e.g., an ITSM event that hasn't fired), or decommissioning is a priority.
Dormant account automation is relatively recent. With 40 daily runs across a 12-month window, the Daily Warning Notifications workflow has been operating for roughly 6–7 weeks. Long-term trend data will strengthen the compliance narrative; scheduling a review after 6 months of operation would provide meaningful before/after metrics.
SOC WF has no execution history. The credential provisioning workflow exists but has not been used. It may be an early-stage proof-of-concept, or it may have been superseded by a manual process.
No vulnerability management automation visible. The current portfolio is entirely IAM and cloud-focused. If vulnerability scanning, ticketing, or remediation tracking is handled elsewhere, there is an opportunity to centralize those workflows within Blink to complete the security operations picture.
Integration Ecosystem
| Integration | Used In |
|---|---|
| Active Directory / Entra ID | Dormant Account Monitoring, Password Expiry Notification |
| WinRM (on-premises AD) | Password Expiry Notification |
| AWS (Organization API) | AWS Cloud Account Posture |
| SharePoint | AWS Cloud Account Posture |
| SMTP (multi-server) | Dormant Account Reporting, Password Expiry Notification |
| Email (Blink native) | LAR, AWS Account Posture, SOC Workflow |
| Blink Tables | LAR, AWS Account Posture, SOC Workflow |
| Blink Web Forms | LAR |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.