Blink Security Automation — Confidential

oxford — Customer Success Report

Generated 2026-08-30 | oxford-value-report.md
2026-08-30Report Date
134Total Playbooks
54Unique Workflows (12m)
842,619Actions Automated (12m)
$216,723Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

134
Total playbooks built
all non-deleted workflows
56
Active playbooks
currently enabled
54
Unique workflows executed (12m)
distinct workflows that ran
842,619
Actions automated (12m)
completed action steps
4,681.2h
Hours saved (12m)
@ 20s per action
$216,723
Money saved (12m)
@ $100K avg salary
14
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 2 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 23,081 security events detected and triaged across EDR and IOC pipelines — without analyst triage - 1,986 employee and contractor identity records synchronized from Ranger and Workday to drive onboarding automation - 961 application access requests processed via ServiceNow without manual IT involvement - 321 temporary workforce accounts provisioned automatically from HR system data - 156 employee and contractor offboarding events orchestrated end-to-end across 8+ business systems - 59 full employee onboardings completed across Oxford and Tommy Bahama brands, end-to-end with Jira-tracked fulfillment - 41 retail training access records synced on schedule

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOC Threat Detection & IOC Processing
  • 11,541Security threat events detected and triaged
  • 11,540IOC investigations automatically processed
76.6%
3
3 active
Employee Offboarding — Full Lifecycle
  • 129Employee offboardings completed (full lifecycle)
  • 17Manual ad-hoc leaver flows executed
  • 10Workday-triggered automated offboarding runs
7.5%
14
12 active
Temporary Workforce Lifecycle (Joiner & Leaver)
  • 321Temporary warehouse staff accounts provisioned
  • 41Temporary warehouse staff accounts deprovisioned
1.1%
2
1 active
Identity Lifecycle & Health Monitoring205 executions
0.7%
8
5 active
Cloud Access & Entra Governance10 executions
0.0%
2
2 active
IT Service Request Automation
  • 961Application access requests processed
3.2%
1
1 active
Connection Health Monitoring40 executions
0.1%
1
1 active
Retail Workforce Training Provisioning
  • 41Retail training access records synced
0.1%
1
1 active
Employee Onboarding — Full Lifecycle
  • 1,986Employee and contractor identity records synced (Ranger & Workday)
  • 33Ranger contractor onboarding accounts provisioned
  • 18Full employee onboardings completed (Oxford & Tommy Bahama)
10.5%
16
14 active
Total30,052 executions100%
48
40 active

Use Case Growth Over Time

103 unique playbooks  |  9 operational use cases  |  30,102 total executions (12m)  |  2025-11 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

SOC Threat Detection & IOC Processing
Expel SentinelOne Jira
IT Service Request Automation
ServiceNow
Temporary Workforce Lifecycle (Joiner & Leaver)
Microsoft Entra ID Jira
Connection Health Monitoring
Active Directory On-Prem Microsoft Entra ID
Cloud Access & Entra Governance
Microsoft Entra ID Jira Snowflake
Identity Lifecycle & Health Monitoring
Snowflake Jira Microsoft Entra ID Google Looker Datadog Delinea Exchange Online Active Directory On-Prem
Employee Offboarding — Full Lifecycle
Jira Microsoft Entra ID ServiceNow Snowflake Exchange Online Datadog Google Looker Delinea
Retail Workforce Training Provisioning
Snowflake Microsoft Entra ID
Employee Onboarding — Full Lifecycle
Snowflake Jira Active Directory On-Prem ServiceNow Microsoft Entra ID

04Key Observations

✓  Strengths

Strengths

  • High-volume SOC automation at scale: The SentinelOne + Expel pipeline processes ~23,000 events per year on a 5-minute polling interval. This represents the highest-volume use case by a wide margin and eliminates what would otherwise be thousands of manual alert-triage decisions annually.
  • Deep, multi-system offboarding pipeline: Employee offboarding spans 8 systems including Delinea PAM for privileged account revocation, two Manhattan supply chain platforms, and core enterprise tools (Celigo, Matillion, DataDog, Looker). The combination of automated HR triggers (Workday via Snowflake, Ranger API) and a manual web-form pathway for ad-hoc cases ensures complete coverage across all departure types.
  • Data-first IAM architecture: Snowflake serves as the authoritative data layer for user metadata sync, termination detection, and high-value target tracking — making the IAM pipeline data-driven rather than solely event-driven.
  • Operational resilience built in: Daily connection health checks and IAM health check playbooks indicate a mature approach to automation monitoring and failure detection rather than reactive debugging.
  • Full employee onboarding now in production: The previously dev-only joiner
△  Gaps & Growth Opportunities

gap has closed. A new production pipeline provisions accounts for both Oxford and Tommy Bahama brands, syncs Ranger contractor and Workday new-hire identities (1,986 executions), and drives Jira-tracked, OU-mapped Active Directory/Entra ID provisioning — delivering the symmetric onboarding/offboarding coverage previously missing.

Gaps / Opportunities

  • Onboarding pipeline has duplicate/near-duplicate utilities: Four zero-execution backfill playbooks (Backfill, Backfills, BackfillNewHire, BackfillNewHIres) perform overlapping Snowflake reconciliation logic. Consolidating these would reduce clutter as the new onboarding pipeline matures.
  • Vulnerability management is inactive: Rapid7 is integrated and a playbook exists in the production workspace, but it has 0 executions. The integration is deployed but no active automation is driving it.
  • No GRC or compliance automation: There is no coverage for compliance monitoring, DLP, audit reporting, RBAC access review/certification, or regulatory controls. Given the depth of IAM investment, automated access certification campaigns are a natural next step.
  • Cloud security scope is narrow: Entra credential monitoring and mobile access policy enforcement cover a small slice of cloud governance. No CSPM, cloud asset inventory, or broader configuration audit automation is present.
  • 5 sandbox/test playbooks with 0 executions exist across three separate test workspaces (New Workflow, New Workflow 1, Sub Workflow, Parent Workflow, Workflow Version History Test) — these can be cleaned up to reduce workspace clutter.

Integration Ecosystem

Domain Integrations
EDR / MDR SentinelOne, Expel
Identity & Directory Microsoft Entra ID, Active Directory (WinRM/ADOP), Exchange Online, Delinea (PAM)
ITSM ServiceNow, Jira
Data / HR Snowflake, Workday (via Snowflake), Ranger API
Business Applications Celigo, Matillion, DataDog, Looker, Manhattan Active Omni, Manhattan Active Warehouse Management
Scripting / Compute Python, PowerShell, WinRM
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 2 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 New Agent alex.doliner@blinkops.com 0 0 0
2 New Agent Global 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
alex.doliner@blinkops.com0
Global0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Sandbox 00
2 workflow-metrics-DEV 00

Webforms

Forms
7
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 IAM Joiner TB Legacy 00
2 asd 00
3 Manual Leaver 00
4 IAM Joiner TB Legacy 00
5 Manual Leaver 00
D Full Use Case Analysis 9 use cases | 30,102 executions (12m)

Business KPIs

Metric Count Playbook
Security threat events detected and triaged 11,541 SentinelOne Threats
IOC investigations automatically processed 11,540 Expel IOC
Employee and contractor identity records synced (Ranger & Workday) 1,986 Sync
Application access requests processed 961 ServiceNOW Application Request
Temporary warehouse staff accounts provisioned 321 Temporary Warehouse Staff Joiner
Employee offboardings completed (full lifecycle) 129 IAM Leaver
Temporary warehouse staff accounts deprovisioned 41 Temporary Warehouse Staff Leaver
Retail training access records synced 41 Lilly Pulitzer Retail Training
Ranger contractor onboarding accounts provisioned 33 001 IAM Joiner Ranger
Full employee onboardings completed (Oxford & Tommy Bahama) 18 IAM Joiner
Manual ad-hoc leaver flows executed 17 IAM-AD-HOC
Workday-triggered automated offboarding runs 10 IAM Leaver Workday
Ranger-triggered contractor deprovisioning runs 10 IAM Leaver Ranger
In the last 12 months, Blink automated: - 23,081 security events detected and triaged across EDR and IOC pipelines — without analyst triage - 1,986 employee and contractor identity records synchronized from Ranger and Workday to drive onboarding automation - 961 application access requests processed via ServiceNow without manual IT involvement - 321 temporary workforce accounts provisioned automatically from HR system data - 156 employee and contractor offboarding events orchestrated end-to-end across 8+ business systems - 59 full employee onboardings completed across Oxford and Tommy Bahama brands, end-to-end with Jira-tracked fulfillment - 41 retail training access records synced on schedule

Use Case Summary

# Use Case Category Playbooks Executions (12mo)
1 SOC Threat Detection & IOC Processing SOC 4 23,121
2 Employee Offboarding — Full Lifecycle IAM 28 1,434
3 Temporary Workforce Lifecycle (Joiner & Leaver) IAM 3 366
4 Identity Lifecycle & Health Monitoring IAM 9 241
5 Cloud Access & Entra Governance Cloud Security 2 9
6 IT Service Request Automation Other 1 961
7 Connection Health Monitoring Other 1 41
8 Retail Workforce Training Provisioning Other 1 41
9 Employee Onboarding — Full Lifecycle IAM 15 3,115

Use Cases

1. SOC Threat Detection & IOC Processing

Description: Fully automated threat detection and IOC investigation pipeline running at a 5-minute polling cadence across SentinelOne EDR and Expel MDR. Each threat event and IOC is automatically fetched, evaluated, and routed without analyst involvement in the initial triage layer. A daily health check validates that both integrations are operating correctly.

Business problem: Alert volume exceeds human capacity to triage manually. A continuous polling automation layer ensures no event is missed and response begins immediately — at a volume that would be operationally impossible to handle manually.

Integrations: SentinelOne, Expel, PowerShell

Playbook Executions (12mo) Automation Type Category Subcategories
Expel IOC 11,540 Scheduled (every 5 min) SOC Alert enrichment / IOC lookup, Case mgmt & SOAR
SentinelOne Threats 11,541 Scheduled (every 5 min) SOC EDR containment & response, Alert enrichment / IOC lookup
IOC Health Check 40 Scheduled (daily) SOC Alert enrichment / IOC lookup, SIEM & log pipeline monitoring
Expel IOC 0 On demand (subflow) SOC Alert enrichment / IOC lookup

2. Employee Offboarding — Full Lifecycle

Description: End-to-end employee and contractor offboarding spanning identity deprovisioning in Microsoft Entra ID and Active Directory, plus access revocation across 7 business applications (Celigo, Matillion, DataDog, Looker, Manhattan Active Omni, Manhattan Active Warehouse Management, Delinea PAM). Triggered by automated HR feeds from Workday (via Snowflake) and Ranger API on daily schedules, plus a manual web-form pathway for ad-hoc cases. All offboarding actions are tracked with Jira comments for audit. A full dev workspace mirrors the production stack for continuous iteration.

Business problem: Manual offboarding across 8+ systems takes hours per leaver and creates identity sprawl and access risk. Automation ensures access is revoked consistently and immediately from every system — with Jira ticketing as the audit trail.

Integrations: Microsoft Entra ID, Active Directory (WinRM), Snowflake, Ranger API, ServiceNow, Jira, Celigo, Matillion, DataDog, Looker, Manhattan Active Omni, Manhattan Active Warehouse Management, Delinea, Python, PowerShell

Production Workspace

Playbook Executions (12mo) Automation Type Category Subcategories
IAM Leaver 129 On demand IAM Employee offboarding, Identity lifecycle automation
IAM-AD-HOC 17 Event (web form) IAM Employee offboarding, Identity lifecycle automation
IAM Leaver Workday 10 Scheduled (daily) IAM Employee offboarding, Identity sync & directory mgmt
IAM Leaver Ranger 10 Scheduled (daily) IAM Employee offboarding, Identity sync & directory mgmt
IAM Leaver Apps Subflow 112 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Manhattan Active Omni 144 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Manhattan Active Warehouse Management 201 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Celigo 112 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Matillion 110 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
DataDog 112 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Looker 110 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Delinea 113 On demand (subflow) IAM Employee offboarding, Privileged account mgmt
Rapid7 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
datadog 197 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
ranger 44 On demand (subflow) IAM Employee offboarding, Identity sync & directory mgmt

Development Workspace

Playbook Executions (12mo) Automation Type Category Subcategories
IAM Leaver 2 On demand IAM Employee offboarding, Identity lifecycle automation
IAM-AD-HOC 11 Event (web form) IAM Employee offboarding, Identity lifecycle automation
IAM Leaver Workday 0 On demand IAM Employee offboarding, Identity sync & directory mgmt
IAM Leaver Ranger 0 On demand IAM Employee offboarding, Identity sync & directory mgmt
IAM Leaver Apps Subflow 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Manhattan Active Omni 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Manhattan Active Warehouse 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Celigo 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Matillion 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
DataDog 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Looker 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt
Delinea 0 On demand (subflow) IAM Employee offboarding, Privileged account mgmt
ranger 0 On demand (subflow) IAM Employee offboarding, Access review & group mgmt

3. Temporary Workforce Lifecycle (Joiner & Leaver)

Description: Automated lifecycle management for temporary warehouse staff, provisioning accounts every 3 hours via the Ranger workforce API and deprovisioning on a daily schedule. A full-employee joiner flow (covering Entra ID account creation with Python normalization and OU mapping) exists in the development workspace with early executions.

Business problem: Temporary workforce turnover is high and constant. Manual account management at this volume creates orphaned accounts and access risk; automation eliminates both and ensures shift-ready access at all times.

Integrations: Ranger API, Microsoft Entra ID, Active Directory (WinRM), Python, PowerShell

Playbook Executions (12mo) Automation Type Category Subcategories
Temporary Warehouse Staff Joiner 321 Scheduled (every 3 hrs) IAM Employee onboarding, JIT & temporary access
Temporary Warehouse Staff Leaver 41 Scheduled (daily) IAM Employee offboarding, JIT & temporary access
IAM Joiner 4 On demand IAM Employee onboarding, Identity lifecycle automation

4. Identity Lifecycle & Health Monitoring

Description: Supporting playbooks that maintain data integrity and operational health across the IAM pipeline. Covers daily user metadata sync from Snowflake, directory hygiene checks (litigation hold status, disabled-account cleanup), weekly tracking of high-value target employees and their direct reports, self-service account unlock, and scheduled health checks that validate termination processing is functioning correctly end-to-end.

Business problem: IAM automation is only reliable if its underlying data is current and its execution is verified. These playbooks provide the observability and data hygiene layer that makes the broader offboarding pipeline trustworthy.

Integrations: Snowflake, Microsoft Entra ID, Exchange Online, PowerShell, Blink Tables

Playbook Executions (12mo) Automation Type Category Subcategories
User Metadata Sync 41 Scheduled (daily) IAM Identity sync & directory mgmt
IAM Health Check - OLD 34 On demand IAM Identity lifecycle automation
Directory Hygiene Cleaner 114 On demand IAM Identity sync & directory mgmt
Directory Hygiene 37 Scheduled (daily) IAM Identity sync & directory mgmt
High Value Targets 6 Scheduled (weekly) IAM Access review & group mgmt, Identity sync & directory mgmt
IAM Termination Health Check 6 Scheduled (weekly) IAM Employee offboarding, Identity lifecycle automation
IAM-HealthCheck-PROD 1 Scheduled (daily) IAM Identity lifecycle automation
Unlock Account 2 On demand IAM Password & credential lifecycle, Identity lifecycle automation
IAM-HealthCheck-DEV 0 On demand IAM Identity lifecycle automation

5. Cloud Access & Entra Governance

Description: Two targeted governance automations for Microsoft Entra ID: a credential expiry monitor that checks enterprise application certificate and secret expiry on a rolling schedule (preventing service outages from lapsed credentials), and a weekly policy enforcement run that reviews non-exempt mobile access for warehouse workers.

Business problem: Expired app credentials cause production outages; unchecked mobile access creates compliance gaps. Both require regular detection that is impractical to run manually at scale.

Integrations: Microsoft Entra ID, Snowflake

Playbook Executions (12mo) Automation Type Category Subcategories
Non Exempt Mobile Access 6 Scheduled (weekly) Cloud Security Cloud access & SaaS policy mgmt
Entra Enterprise Apps 3 Scheduled (every 12 days) Cloud Security Config audit & remediation, Cloud access & SaaS policy mgmt

6. IT Service Request Automation

Description: Hourly processing of application access requests submitted through ServiceNow. Polls for open records, iterates over them, and processes each request — eliminating manual IT queue management for a high-volume, recurring request type.

Business problem: Application access requests accumulate in the ServiceNow queue and require constant manual review. Hourly automation processes them without IT intervention, reducing fulfillment time from hours to minutes.

Integrations: ServiceNow

Playbook Executions (12mo) Automation Type Category Subcategories
ServiceNOW Application Request 961 Scheduled (hourly) Other IT helpdesk & ticket routing, SaaS / IT administration

7. Connection Health Monitoring

Description: Daily validation that all critical integration endpoints — Ranger API, Active Directory (OXM), and Microsoft Entra ID — are reachable and returning expected responses. Provides an early-warning signal for integration failures before they cause silent automation breakdowns downstream.

Business problem: Broken connections cause automation failures that are invisible until an offboarding or provisioning event fails mid-execution. A daily health check surfaces issues proactively.

Integrations: Ranger API, Active Directory (WinRM/ADOP), Microsoft Entra ID

Playbook Executions (12mo) Automation Type Category Subcategories
Global Connections Health Check 41 Scheduled (daily) Other IT/OT & network infra monitoring

8. Retail Workforce Training Provisioning

Description: Daily overnight sync of retail employee training data from Snowflake, automating access provisioning for a retail brand subsidiary. Runs at 00:45 UTC to ensure records are current at the start of each business day.

Business problem: Retail training access for a subsidiary brand requires daily reconciliation between HR data (Snowflake) and access systems, a task that is repetitive and operationally low-value when performed manually.

Integrations: Snowflake

Playbook Executions (12mo) Automation Type Category Subcategories
Lilly Pulitzer Retail Training 41 Scheduled (daily) Other SaaS / IT administration

9. Employee Onboarding — Full Lifecycle

Description: End-to-end joiner automation now live in production, spanning Ranger contractor sourcing (hourly polling plus on-prem/cloud account creation and password generation), Workday/Snowflake new-hire intake, and a dual-brand (Oxford / Tommy Bahama) full-employee joiner with Active Directory/Entra ID provisioning, OU mapping, and Jira-tracked fulfillment. Data reconciliation utilities (Employee Lookup, Backfill variants) support historical and ad-hoc hire record correction, and a web-form intake pathway exists in development for manual ad-hoc joiner requests.

Business problem: Onboarding previously lacked a production pathway for full employees and Ranger-sourced contractors, creating delays and inconsistent day-one access across two brands and multiple hiring sources (Workday, Ranger). This pipeline automates account creation, password generation, OU placement, and Jira-tracked fulfillment consistently across both brands and sourcing systems.

Integrations: Microsoft Entra ID, Active Directory (WinRM), Snowflake, Ranger API, Jira, Blink Tables, Python, PowerShell

Production Workspace

Playbook Executions (12mo) Automation Type Category Subcategories
Sync 1,986 On demand (subflow) IAM Employee onboarding, Identity sync & directory mgmt
000 IAM Joiner Ranger 963 Scheduled (hourly) IAM Employee onboarding, Identity sync & directory mgmt
Ranger 40 Scheduled (daily) IAM Employee onboarding, Identity sync & directory mgmt
001 IAM Joiner Ranger 33 On demand (subflow) IAM Employee onboarding, Password & credential lifecycle
IAM Joiner 18 On demand IAM Employee onboarding, Identity lifecycle automation
Tommy Bahama Onboarding 24 On demand IAM Employee onboarding, Identity lifecycle automation
IAM Joiner Legacy TB 17 On demand (subflow) IAM Employee onboarding, Identity lifecycle automation
Employee Lookup 5 On demand (subflow) IAM Employee onboarding, Identity sync & directory mgmt
IAM Joiner Workday 0 On demand IAM Employee onboarding, Identity sync & directory mgmt
Backfill 0 On demand IAM Employee onboarding, Identity sync & directory mgmt
Backfills 0 On demand IAM Employee onboarding, Identity sync & directory mgmt
BackfillNewHire 0 On demand IAM Employee onboarding, Identity sync & directory mgmt
BackfillNewHIres 0 On demand IAM Employee onboarding, Identity sync & directory mgmt

Development Workspace

Playbook Executions (12mo) Automation Type Category Subcategories
Ad Hoc Joiner Legacy 29 Event (web form) IAM Employee onboarding, Identity lifecycle automation
Ad Hoc Joiner 0 Event (web form) IAM Employee onboarding, Identity lifecycle automation

Key Observations

Strengths

  • High-volume SOC automation at scale: The SentinelOne + Expel pipeline processes ~23,000 events per year on a 5-minute polling interval. This represents the highest-volume use case by a wide margin and eliminates what would otherwise be thousands of manual alert-triage decisions annually.
  • Deep, multi-system offboarding pipeline: Employee offboarding spans 8 systems including Delinea PAM for privileged account revocation, two Manhattan supply chain platforms, and core enterprise tools (Celigo, Matillion, DataDog, Looker). The combination of automated HR triggers (Workday via Snowflake, Ranger API) and a manual web-form pathway for ad-hoc cases ensures complete coverage across all departure types.
  • Data-first IAM architecture: Snowflake serves as the authoritative data layer for user metadata sync, termination detection, and high-value target tracking — making the IAM pipeline data-driven rather than solely event-driven.
  • Operational resilience built in: Daily connection health checks and IAM health check playbooks indicate a mature approach to automation monitoring and failure detection rather than reactive debugging.
  • Full employee onboarding now in production: The previously dev-only joiner gap has closed. A new production pipeline provisions accounts for both Oxford and Tommy Bahama brands, syncs Ranger contractor and Workday new-hire identities (1,986 executions), and drives Jira-tracked, OU-mapped Active Directory/Entra ID provisioning — delivering the symmetric onboarding/offboarding coverage previously missing.

Gaps / Opportunities

  • Onboarding pipeline has duplicate/near-duplicate utilities: Four zero-execution backfill playbooks (Backfill, Backfills, BackfillNewHire, BackfillNewHIres) perform overlapping Snowflake reconciliation logic. Consolidating these would reduce clutter as the new onboarding pipeline matures.
  • Vulnerability management is inactive: Rapid7 is integrated and a playbook exists in the production workspace, but it has 0 executions. The integration is deployed but no active automation is driving it.
  • No GRC or compliance automation: There is no coverage for compliance monitoring, DLP, audit reporting, RBAC access review/certification, or regulatory controls. Given the depth of IAM investment, automated access certification campaigns are a natural next step.
  • Cloud security scope is narrow: Entra credential monitoring and mobile access policy enforcement cover a small slice of cloud governance. No CSPM, cloud asset inventory, or broader configuration audit automation is present.
  • 5 sandbox/test playbooks with 0 executions exist across three separate test workspaces (New Workflow, New Workflow 1, Sub Workflow, Parent Workflow, Workflow Version History Test) — these can be cleaned up to reduce workspace clutter.

Integration Ecosystem

Domain Integrations
EDR / MDR SentinelOne, Expel
Identity & Directory Microsoft Entra ID, Active Directory (WinRM/ADOP), Exchange Online, Delinea (PAM)
ITSM ServiceNow, Jira
Data / HR Snowflake, Workday (via Snowflake), Ranger API
Business Applications Celigo, Matillion, DataDog, Looker, Manhattan Active Omni, Manhattan Active Warehouse Management
Scripting / Compute Python, PowerShell, WinRM
E New Integrations (detail) 10 added in last 30d

New Integrations Added - Last 30 Days

10 new connections
TenantIntegrationConnection NameAdded
oxford snowflake snowflake 2026-08-19
oxford winrm active_directory_hk 2026-08-17
oxford winrm active_directory_stide 2026-08-17
oxford atlassian-organizations unscoped_atlassian_org_admin 2026-08-17
oxford winrm active_directory_oxford_dmz 2026-08-17
oxford winrm active_directory_shirtings 2026-08-17
oxford winrm active_directory_oxford_corporate 2026-08-17
oxford winrm active_directory_oxford_root 2026-08-17
oxford winrm active_directory_retail_tbahama 2026-08-17
oxford winrm active_directory_lillypulitzer 2026-08-17