Blink Security Automation — Confidential

Project-Tokyo — Customer Success Report

Generated 2026-08-30 | project-tokyo-value-report.md
2026-08-30Report Date
264Total Playbooks
31Unique Workflows (12m)
34,264Actions Automated (12m)
$8,813Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

264
Total playbooks built
all non-deleted workflows
38
Active playbooks
currently enabled
31
Unique workflows executed (12m)
distinct workflows that ran
34,264
Actions automated (12m)
completed action steps
190.4h
Hours saved (12m)
@ 20s per action
$8,813
Money saved (12m)
@ $100K avg salary
4
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 40 daily dormant account warning notification cycles run across Active Directory - 40 password expiry notification campaigns dispatched to users and service account owners - 11 service account lifecycle events processed without manual intervention - 3 bi-monthly dormant account compliance reports generated and delivered to the AD team - 1 AWS cloud account posture assessment completed and uploaded to SharePoint

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Dormant Account Monitoring & Reporting
  • 40Daily dormant account warning notification runs
  • 11Service account lifecycle events processed
22.1%
5
4 active
Leave / Access Request (LAR)0 executions
0.0%
6
6 active
Password Expiry Notification
  • 40Password expiry notification campaigns dispatched
77.9%
10
10 active
AWS Cloud Account Posture
  • 1AWS account posture assessments completed
0.0%
5
5 active
SOC Workflow0 executions
0.0%
1
1 active
Total253 executions100%
27
26 active

Use Case Growth Over Time

134 unique playbooks  |  5 operational use cases  |  253 total executions (12m)  |  2024-05 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Leave / Access Request (LAR)
Web Form Email
AWS Cloud Account Posture
Email SharePoint AWS
Dormant Account Monitoring & Reporting
Email Microsoft Entra ID
Password Expiry Notification
Microsoft Entra ID Email
SOC Workflow
Email

04Key Observations

✓  Strengths

Strengths

Active IAM automation foundation. Three of the five use cases are in active production — dormant account lifecycle, password expiry notification, and AWS posture. The daily scheduling across Sin

△  Gaps & Growth Opportunities

gapore and Manila timezones indicates these are fully embedded in operational workflows, not experimental.

Mature, modular automation design. The Password Expiry Notification use case demonstrates strong architectural discipline: a single parent workflow delegates to purpose-built subflows for user-type resolution, license validation, and differentiated email delivery. This pattern reduces duplication and makes each component independently testable.

AWS cloud governance coverage. The posture assessment workflow spans multiple dimensions in a single run — user password expiry, access key rotation, and account inventory delta — with output delivered to both email recipients and SharePoint for audit trail. A second deployment of the full pipeline (AWS Account Posture, Generate AWS Account Reports, Get Accounts Added and Deleted, Upload file to sharepoint) has since been rolled out to the production workspace on a monthly schedule (31st, 10:00 MNL) — first execution pending as of this report.

Multi-deployment LAR framework. Three deployment variants of the Leave/Access Request workflow exist (standard, Deployment 2, Deployment 3 rerouted to IS), indicating a phased rollout strategy across different business units. The subflow architecture means routing logic can be updated in one place.

Gaps

LAR workflows are built but not running. All 11 playbooks in the Leave/Access Request use case have zero executions. This is the most complex use case in the portfolio — PAM-grade access certification with dynamic web forms and multi-department routing — but it is not yet active. Clarifying whether this reflects a deployment pause, a trigger dependency (e.g., an ITSM event that hasn't fired), or decommissioning is a priority.

Dormant account automation is relatively recent. With 40 daily runs across a 12-month window, the Daily Warning Notifications workflow has been operating for roughly 6–7 weeks. Long-term trend data will strengthen the compliance narrative; scheduling a review after 6 months of operation would provide meaningful before/after metrics.

SOC WF has no execution history. The credential provisioning workflow exists but has not been used. It may be an early-stage proof-of-concept, or it may have been superseded by a manual process.

No vulnerability management automation visible. The current portfolio is entirely IAM and cloud-focused. If vulnerability scanning, ticketing, or remediation tracking is handled elsewhere, there is an opportunity to centralize those workflows within Blink to complete the security operations picture.

Integration Ecosystem

Integration Used In
Active Directory / Entra ID Dormant Account Monitoring, Password Expiry Notification
WinRM (on-premises AD) Password Expiry Notification
AWS (Organization API) AWS Cloud Account Posture
SharePoint AWS Cloud Account Posture
SMTP (multi-server) Dormant Account Reporting, Password Expiry Notification
Email (Blink native) LAR, AWS Account Posture, SOC Workflow
Blink Tables LAR, AWS Account Posture, SOC Workflow
Blink Web Forms LAR
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 5 use cases | 253 executions (12m)

Business KPIs

Metric Count Playbook
Daily dormant account warning notification runs 40 Daily Workflow - Warning notifications 2.2
Password expiry notification campaigns dispatched 40 Password Expiry Notification
Service account lifecycle events processed 11 Service Accounts Handling
Bi-monthly dormant account compliance reports delivered 3 Bi-Monthly - 15th / Bi-Monthly - 30th
AWS account posture assessments completed 1 AWS Account Posture
In the last 12 months, Blink automated: - 40 daily dormant account warning notification cycles run across Active Directory - 40 password expiry notification campaigns dispatched to users and service account owners - 11 service account lifecycle events processed without manual intervention - 3 bi-monthly dormant account compliance reports generated and delivered to the AD team - 1 AWS cloud account posture assessment completed and uploaded to SharePoint

Use Case Summary

# Use Case Category Subcategory Total Playbooks Playbooks with Executions
1 Dormant Account Monitoring & Reporting IAM Access review & group mgmt, Identity lifecycle automation 7 4
2 Leave / Access Request (LAR) IAM Privileged account mgmt, Access review & group mgmt 11 0
3 Password Expiry Notification IAM Password & credential lifecycle, Identity lifecycle automation 10 5
4 AWS Cloud Account Posture Cloud Security Cloud asset coverage & inventory, Config audit & remediation 9 5
5 SOC Workflow SOC Case mgmt & SOAR 1 0
Total 38 14

Use Cases

1. Dormant Account Monitoring & Reporting

Description: Automated daily monitoring of Active Directory accounts that have been inactive for 83 or 90+ days, with differentiated warning notifications and bi-monthly formal compliance reports delivered to the AD team. Service accounts follow a separate handling path.

Business problem: Inactive AD accounts represent a persistent attack surface and a common compliance finding. This use case enforces a consistent dormancy policy — warning users at 83 days, acting at 91 days, and providing audit-ready reports on the 15th and 30th of each month — eliminating the manual effort required to identify and track stale identities at scale.

Category: IAM

Subcategories: Access review & group mgmt, Identity lifecycle automation

Integrations: Active Directory, SMTP, Blink Tables

Playbook Type Executions (12 mo.)
Bi-Monthly - 15th: Dormant Reporting to AD Team 2.2 Scheduled (cron: 15th, 17:00 SGT) 2
Bi-Monthly - 30th: Dormant Reporting to AD Team 2.2 Scheduled (cron: 30th, 17:00 SGT) 1
Daily Workflow - Warning notifications 2.2 Scheduled (daily, 17:00 SGT) 40
Service Accounts Handling On-demand subflow 11
Service Accounts Handling On-demand subflow 0
Re-Run Reporting to CIT AD Team 2.2 On-demand (manual re-run) 0
Re-Run Reporting to CIT AD Team 2.2 On-demand (manual re-run) 0

2. Leave / Access Request (LAR)

Description: A multi-deployment access certification workflow for employees on leave or exiting the organization. Administrators receive dynamic web forms listing the user's active assets and are prompted to approve or revoke each item. Three deployment variants exist to route certifications to different business units (standard, Deployment 2, and rerouted to Information Security).

Business problem: Unreviewed access during employee leave periods is a common compliance gap that creates insider risk and audit findings. This use case automates the generation and routing of access certification requests, reducing manual coordination and ensuring every affected account is reviewed before a PAM violation window opens.

Category: IAM

Subcategories: Privileged account mgmt, Access review & group mgmt

Integrations: Blink Tables, Blink Web Forms, SMTP, Email

Playbook Type Executions (12 mo.)
Main - LAR On-demand 0
Main - LAR On-demand 0
Subflow - LAR Subflow 0
Subflow - LAR Subflow 0
UC3 LAR PAM - Send receipt and Update Table Subflow 0
Main - LAR: Deployment 2 On-demand 0
Main - LAR: Deployment 2 On-demand 0
Main - LAR Deployment 3 Reroute to IS On-demand 0
Main - LAR Deployment 3 Reroute to IS On-demand 0
Subflow - LAR Reroute to IS Subflow 0
Subflow - LAR Reroute to IS Subflow 0

3. Password Expiry Notification

Description: Daily automated monitoring of Active Directory password expiry windows, sending targeted notifications to regular users at 1, 10, 14, 25, and 40-day thresholds and routing service account alerts to designated owners. Entra ID is queried to validate user type and mailbox license eligibility before dispatching each notification.

Business problem: Expired passwords cause account lockouts, helpdesk tickets, and service disruptions — particularly for service accounts where the impact can be system-wide. Automating the full notification lifecycle, differentiated by account type and expiry urgency, eliminates manual tracking and reduces lockout-related incidents.

Category: IAM

Subcategories: Password & credential lifecycle, Identity lifecycle automation

Integrations: Active Directory (WinRM), Entra ID, SMTP, Email

Playbook Type Executions (12 mo.)
Password Expiry Notification Scheduled (daily, 22:00 MNL) 40
EntraID - Check userType Subflow 40
EntraID - Check user mailbox license Subflow 40
Regular User Email Notification Subflow 40
Service Account Email Notification Subflow 40
Daily Password Expiry Scheduled 0
Entra ID - Check user mailbox license Subflow 0
Entra ID - Check UserType Subflow 0
Regular User Notification Subflow 0
Service Account Notification Subflow 0

4. AWS Cloud Account Posture

Description: On-demand reporting workflow that scans the entire AWS Organization to assess account health — covering password expiry, access key rotation age, and account inventory changes (additions and deletions). Outputs an Excel report uploaded to SharePoint and HTML email summaries delivered to stakeholders.

Business problem: Managing AWS account hygiene across a large organization is operationally complex without automation. This use case provides a single-run audit that consolidates password expiry, access key rotation status, and account turnover into a shareable report, enabling proactive remediation and supporting cloud governance obligations.

Category: Cloud Security

Subcategories: Cloud asset coverage & inventory, Config audit & remediation

Integrations: AWS (Organization scan), SharePoint, Blink Tables, Email, SMTP

Playbook Type Executions (12 mo.)
AWS Account Posture On-demand (parent) 1
Generate AWS Account Reports Subflow 1
Get Accounts Added and Deleted Subflow 1
Upload file to sharepoint Subflow 1
Get CSV to Table Utility 1
AWS Account Posture Scheduled (parent, cron: 31st, 10:00 MNL) 0
Generate AWS Account Reports Subflow 0
Get Accounts Added and Deleted Subflow 0
Upload file to sharepoint Subflow 0

5. SOC Workflow

Description: A credential generation and distribution workflow for SOC operations — generates a secure password, renders it as an image, stores a record in a Blink Table, and delivers it via email.

Business problem: Automates manual SOC credential provisioning steps to ensure consistent, auditable handling of sensitive access credentials.

Category: SOC

Subcategories: Case mgmt & SOAR

Integrations: Blink Tables, Email

Playbook Type Executions (12 mo.)
SOC WF On-demand 0

Key Observations

Strengths

Active IAM automation foundation. Three of the five use cases are in active production — dormant account lifecycle, password expiry notification, and AWS posture. The daily scheduling across Singapore and Manila timezones indicates these are fully embedded in operational workflows, not experimental.

Mature, modular automation design. The Password Expiry Notification use case demonstrates strong architectural discipline: a single parent workflow delegates to purpose-built subflows for user-type resolution, license validation, and differentiated email delivery. This pattern reduces duplication and makes each component independently testable.

AWS cloud governance coverage. The posture assessment workflow spans multiple dimensions in a single run — user password expiry, access key rotation, and account inventory delta — with output delivered to both email recipients and SharePoint for audit trail. A second deployment of the full pipeline (AWS Account Posture, Generate AWS Account Reports, Get Accounts Added and Deleted, Upload file to sharepoint) has since been rolled out to the production workspace on a monthly schedule (31st, 10:00 MNL) — first execution pending as of this report.

Multi-deployment LAR framework. Three deployment variants of the Leave/Access Request workflow exist (standard, Deployment 2, Deployment 3 rerouted to IS), indicating a phased rollout strategy across different business units. The subflow architecture means routing logic can be updated in one place.

Gaps

LAR workflows are built but not running. All 11 playbooks in the Leave/Access Request use case have zero executions. This is the most complex use case in the portfolio — PAM-grade access certification with dynamic web forms and multi-department routing — but it is not yet active. Clarifying whether this reflects a deployment pause, a trigger dependency (e.g., an ITSM event that hasn't fired), or decommissioning is a priority.

Dormant account automation is relatively recent. With 40 daily runs across a 12-month window, the Daily Warning Notifications workflow has been operating for roughly 6–7 weeks. Long-term trend data will strengthen the compliance narrative; scheduling a review after 6 months of operation would provide meaningful before/after metrics.

SOC WF has no execution history. The credential provisioning workflow exists but has not been used. It may be an early-stage proof-of-concept, or it may have been superseded by a manual process.

No vulnerability management automation visible. The current portfolio is entirely IAM and cloud-focused. If vulnerability scanning, ticketing, or remediation tracking is handled elsewhere, there is an opportunity to centralize those workflows within Blink to complete the security operations picture.

Integration Ecosystem

Integration Used In
Active Directory / Entra ID Dormant Account Monitoring, Password Expiry Notification
WinRM (on-premises AD) Password Expiry Notification
AWS (Organization API) AWS Cloud Account Posture
SharePoint AWS Cloud Account Posture
SMTP (multi-server) Dormant Account Reporting, Password Expiry Notification
Email (Blink native) LAR, AWS Account Posture, SOC Workflow
Blink Tables LAR, AWS Account Posture, SOC Workflow
Blink Web Forms LAR
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.