Blink Security Automation — Confidential

rockwell-c-i-training — Customer Success Report

Generated 2026-08-30 | rockwell-c-i-training-value-report.md
2026-08-30Report Date
167Total Playbooks
26Unique Workflows (12m)
234Actions Automated (12m)
$60Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

167
Total playbooks built
all non-deleted workflows
99
Active playbooks
currently enabled
26
Unique workflows executed (12m)
distinct workflows that ran
234
Actions automated (12m)
completed action steps
1.3h
Hours saved (12m)
@ 20s per action
$60
Money saved (12m)
@ $100K avg salary
2
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 11,552 customer weather alerts monitored and notifications automatically delivered - 1 security alert processed through the full end-to-end automated SOC pipeline - 1 customer onboarding request submitted via the Drive Monitoring Customer Onboarding Form

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — Alert Triage & Response Pipeline
  • 1Security alerts processed through automated triage pipeline
0.0%
15
15 active
Alert Enrichment & IOC Lookup0 executions
0.0%
14
14 active
On-Demand Investigation Tools0 executions
0.0%
13
13 active
EDR Containment & Remote Response0 executions
0.0%
3
3 active
Case Management Utilities0 executions
0.0%
5
5 active
IT/OT Network Infrastructure Automation0 executions
0.0%
4
4 active
VM Disk Capacity Management0 executions
0.0%
1
1 active
Scheduled Alerting & Notifications
  • 11,552Customer weather alerts monitored & notifications delivered
100.0%
1
1 active
AI-Augmented Workflow Automation
  • 1Customer onboarding requests submitted
0.0%
9
8 active
Training & Platform Familiarization1 executions
0.0%
15
14 active
Employee Offboarding Intake0 executions
0.0%
2
2 active
Total11,515 executions100%
82
80 active

Use Case Growth Over Time

108 unique playbooks  |  11 operational use cases  |  11,515 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Slack
Agentic SOC — Alert Triage & Response Pipeline
Microsoft Outlook Email
On-Demand Investigation Tools
Google Workspace GitHub Microsoft Entra ID URLScan Okta Slack CrowdStrike VirusTotal
EDR Containment & Remote Response
CrowdStrike
IT/OT Network Infrastructure Automation
SSH Email Sumo Logic
VM Disk Capacity Management
VMware vSphere Microsoft Teams
Training & Platform Familiarization
Web Form
AI-Augmented Workflow Automation
OpenAI Microsoft Teams Email Web Form SSH
Scheduled Alerting & Notifications
Microsoft Teams

04Key Observations

✓  Strengths

Strengths

1. Production-ready SOC automation stack. The main SOC workspace (076024e1) contains a sophisticated agentic SOC pipeline — event-driven alert ingestion, observable extraction and deduplication, multi-source enrichment, type-specific response subflows, and case lifecycle management. This is a complete blueprint for enterprise SOC automation at scale.

2. Exceptional enrichment coverage. The enrichment library spans 9 distinct integrations and every major observable type an enterprise SOC analyst would encounter: IPs (VirusTotal, AbuseIPDB), hashes (VirusTotal, CrowdStrike), URLs (VirusTotal, URLScan), usernames/emails (Okta, Entra ID, Google Workspace, GitHub, Slack), domains (WHOIS). Few environments achieve this breadth.

3. Active production automation. The Customer Weather Alert Notification workflow executed 11,552 times over the past 12 months — demonstrating consistent operational automation delivery on a non-security use case, and confirming the environment can sustain production-grade scheduled workloads.

4. IT/OT automation investment. The Cisco SmartNet Coverage workflow (marked POC COMPLETE) and the Cisco Switch Health Check (POC Draft) demonstrate active exploration of OT/network infrastructure automation — a high-value area given Rockwell's industrial automation domain. The Ansible-based health check in particular shows ambition to automate complex multi-step network operations.

5. AI integration actively explored. Multiple workspaces contain LLM-powered workflows using Azure OpenAI. The RA-LLM Request pattern is cleanly abstracted as a reusable subflow, showing architectural maturity in how AI is being incorporated.

6. Structured enablement program. Eight distinct training workspaces, each containing exercises and hands-on scenarios, indicate a formal and repeating Blink onboarding program — a strong signal of organizational adoption depth.

###

△  Gaps & Growth Opportunities

Gaps

1. SOC pipeline not yet receiving live alert volume. Despite a complete and validated SOC automation stack, only 1 alert was processed through Process Alert in the last 12 months. All enrichment subflows show 0 executions, indicating the pipeline has been built and demonstrated but is not yet connected to a live alert source (e.g., CrowdStrike, Proofpoint).

2. EDR containment not activated. The CrowdStrike RTR and host quarantine workflows exist but have never executed. Containment actions remain manual, which is the highest-impact gap in a mature SOC program.

3. IT/OT workflows in POC state. The Cisco SmartNet and Switch Health Check automations are validated but deployed only in training workspaces. Production promotion — connecting to live Cisco infrastructure — would immediately deliver operational value.

4. AI workflows not yet in production. All LLM-powered workflows have 0 executions. The Azure OpenAI integration is configured and the workflow architecture is solid; the gap is connecting to live ticket or alert feeds.

Integration Ecosystem

Integration Use Cases
CrowdStrike EDR enrichment, endpoint containment, RTR
VirusTotal Hash, IP, URL threat intelligence
Microsoft Entra ID Identity enrichment, risky user detection
Okta Identity enrichment, user activity audit
Google Workspace Identity enrichment
AbuseIPDB IP reputation
URLScan URL analysis, screenshot capture
GitHub User enrichment
Slack User enrichment
Microsoft Outlook Email retrieval, phishing response
Microsoft Teams Human-in-the-loop approvals, notifications
VMware vSphere VM disk management
Sumo Logic Log insight ingestion
N-Able N-Central Device service monitoring
Azure OpenAI AI-augmented ticket triage and response
Cisco API SmartNet coverage validation
SSH Switch command execution
Ansible Network health automation
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink SOC - Training Lab 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
SOC - Training Lab0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Training Test 00

Webforms

Forms
14
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Test Webform 00
2 Test Webform 00
3 Test Automation for this Web Form 00
4 Request Support 00
5 Training Example 00
D Full Use Case Analysis 11 use cases | 11,515 executions (12m)

Business KPIs

Metric Count Playbook
Customer weather alerts monitored & notifications delivered 11,552 Customer Weather Alert Notification
Security alerts processed through automated triage pipeline 1 Process Alert
Customer onboarding requests submitted 1 Drive Monitoring Customer Onboarding Form
In the last 12 months, Blink automated: - 11,552 customer weather alerts monitored and notifications automatically delivered - 1 security alert processed through the full end-to-end automated SOC pipeline - 1 customer onboarding request submitted via the Drive Monitoring Customer Onboarding Form

Use Case Summary

# Use Case Category Subcategories Playbooks
1 Agentic SOC — Alert Triage & Response Pipeline SOC Agentic SOC, Case mgmt & SOAR, Phishing detection & response, EDR containment & response 15
2 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 14
3 On-Demand Investigation Tools SOC Alert enrichment / IOC lookup, Identity threat response 13
4 EDR Containment & Remote Response SOC EDR containment & response 3
5 Case Management Utilities SOC Case mgmt & SOAR 5
6 IT/OT Network Infrastructure Automation Other IT/OT & network infra monitoring 6
7 VM Disk Capacity Management Other DevOps & release automation 1
8 Scheduled Alerting & Notifications Other IT helpdesk & ticket routing 1
9 AI-Augmented Workflow Automation Other IT helpdesk & ticket routing, SaaS / IT administration 10
10 Training & Platform Familiarization Other SaaS / IT administration 17
11 Employee Offboarding Intake IAM Employee offboarding 2

Total: 87 playbook instances across 9 workspaces (several Cisco POC workflows are duplicated across training workspaces)

Use Cases

1. Agentic SOC — Alert Triage & Response Pipeline

Description: A full end-to-end automated SOC pipeline that ingests incoming alerts on a 1-minute polling interval, extracts and deduplicates observables, enriches indicators, routes cases to type-specific response subflows (phishing, malware), and manages case lifecycle. Built entirely on Blink's native case management.

Business problem solved: Eliminates manual alert triage and first-responder investigation. Analysts work pre-enriched, deduplicated cases rather than raw alerts — reducing mean time to respond and analyst fatigue across high-volume environments.

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR, Phishing detection & response, EDR containment & response

Playbook Type Executions
Process Alert Event (polling) 1
Subflow - Response - Main Router Subflow 0
Response Subflow - Phishing Subflow 0
Response Subflow - Malware Subflow 0
Subflow - Enrich Observables - Main Router Subflow 0
Subflow - Missing Alert Template Notification Subflow 0
Subflow - Update Enrichment Data Subflow 0
Utility - Close Stale Cases On-demand 0
Recovery - Handle Unprocessed Alerts On-demand 0
Recovery - Enrich Non-Enriched Observables On-demand 0
Error Handling - Send Error Notification Email Subflow 0
Table Action - Validate Observables Extraction Template On-demand 0
Simulate Crowdstrike Alert On-demand 0
Simulate Multiple Alerts from Different Sources On-demand 0
USE WITH CARE - Reset Case Management Environment On-demand 0

Integrations: CrowdStrike, Microsoft Outlook, Blink Case Management, Email (core)

2. Alert Enrichment & IOC Lookup

Description: A comprehensive library of enrichment subflows automatically invoked by the SOC pipeline for every observable extracted from an incoming alert. Covers all major IOC types — IPs, hashes, URLs, usernames, email addresses, and domain names — across the full security toolstack.

Business problem solved: Replaces manual analyst lookups across 8+ security tools. Every indicator is enriched before an analyst touches a case, providing context at the moment it is needed.

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Playbook IOC Type Integration Executions
Enrich - Agent ID - Crowdstrike Agent / Device CrowdStrike 0
Enrich - URL - URLScan URL URLScan 0
Enrich - Hash - VT Hash VirusTotal 0
Enrich - IP - IPDB IP AbuseIPDB 0
Enrich - Username or Email - Okta Username / Email Okta 0
Enrich - IP - VT IP VirusTotal 0
Enrich - URL - VT URL VirusTotal 0
Enrich - Hash - Crowdstrike Hash CrowdStrike 0
Enrich - IP or Domain - Whois IP / Domain WHOIS 0
Enrich - Username or Email - Google Workspace Username / Email Google Workspace 0
Enrich - Username or Email - Microsoft Entra ID Username / Email Microsoft Entra ID 0
Enrich - Username - Github Username GitHub 0
Enrich - Email Address - Slack Email Slack 0
Utility - Update Enrichment — Blink Case Management 0

Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack

3. On-Demand Investigation Tools

Description: A library of standalone analyst-facing investigation workflows invokable on-demand for ad-hoc lookups — user identities, threat intelligence, DNS/WHOIS, URL screenshots, and product end-of-life dates. Designed for analyst investigations independent of the automated alert pipeline.

Business problem solved: Gives SOC analysts single-click access to multi-source enrichment without requiring direct tool access, stored credentials, or manual API calls.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Identity threat response

Playbook Integration Executions
Get User Information Using Google Workspace Google Workspace 0
Enrich IP or Domain Using Whois WHOIS 0
Get User Information Using Github GitHub 0
Get User Information Using Microsoft Entra ID Microsoft Entra ID 0
Get User Information Using Okta Okta 0
Okta Search for User Activity Okta 0
Get Hash Info Using Crowdstrike CrowdStrike 0
Get Hash Info Using VirusTotal VirusTotal 0
Get User Information on Email Address Using Slack Slack 0
Get End of Life Date for a Product HTTP API 0
Run Dig Command Bash / DNS 0
Secure URL Screenshot Capture Internal 0
Analyze URL with URLScan URLScan 0

Integrations: Google Workspace, GitHub, Microsoft Entra ID, Okta, CrowdStrike, VirusTotal, Slack, URLScan, HTTP APIs, Bash/DNS

4. EDR Containment & Remote Response

Description: CrowdStrike-based endpoint containment and Real-Time Response (RTR) workflows enabling isolation of compromised hosts and execution of remote commands — on a single endpoint or across a batch — directly from Blink.

Business problem solved: Reduces time-to-containment on endpoint threats. Analysts quarantine devices or run remediation commands without switching tools or logging into CrowdStrike directly.

Category: SOC | Subcategories: EDR containment & response

Playbook Capability Executions
Manage Endpoint Quarantine Status in Crowdstrike Isolate / lift isolation 0
CrowdStrike RTR to a Batch of Hosts Remote command execution (batch) 0
CrowdStrike RTR to a Single Host Remote command execution (single) 0

Integrations: CrowdStrike

5. Case Management Utilities

Description: Utility workflows for managing the observable relationship graph within Blink's case management system — listing, creating, updating, and deleting observable-to-alert links, and finding similar open cases based on shared indicators.

Business problem solved: Maintains case data integrity and surfaces related investigations automatically, reducing analyst correlation effort and duplicate case creation.

Category: SOC | Subcategories: Case mgmt & SOAR

Playbook Executions
Utility - List Observable Alert Relations 0
Utility - Set Or Update Observable Relation 0
Utility - Delete Observable Relation 0
Utility - List Alert Observable Relations 0
Utility - Find Similar Cases Based on Observables 0

Integrations: Blink Case Management

6. IT/OT Network Infrastructure Automation

Description: POC and working automations targeting Rockwell's OT/network infrastructure stack. Covers Cisco switch SmartNet coverage validation (marked POC COMPLETE), switch health checks via Ansible, SSH-based switch command execution, and Sumo Logic insight processing. These automations are deployed across multiple training workspaces, indicating active iteration by multiple engineering teams.

Business problem solved: Automates manual network operations tasks — warranty/support coverage checks, switch health monitoring, and SIEM log review — reducing manual effort for network engineers managing industrial OT environments.

Category: Other | Subcategories: IT/OT & network infra monitoring

Playbook Status Integration Executions
_Cisco_Switch_SmartNet_Coverage (POC COMPLETE) POC Complete Cisco API, Bash 0
_Cisco Switch Health Check - Ansible (POC Draft) POC Draft Ansible, SSH 0
Sumo Logic Collectors (Working) Working Sumo Logic 0
Training Canvas Overview Training SSH 0
Web Form — Cisco Switch Test Training Web Form 0
New Workflow 1 — N-Able Device Monitoring Draft N-Able N-Central 0

*Note: Cisco SmartNet Coverage and Cisco Switch Health Check each appear in 5 training workspaces; Sumo Logic Collectors appears in 2. Links point to the primary workspace instance.*

Integrations: Cisco API, Ansible, SSH, Sumo Logic, N-Able N-Central, Bash

7. VM Disk Capacity Management

Description: An approval-gated workflow that checks current VMware vSphere disk capacity, presents findings to an approver via Microsoft Teams, and expands disk size only after explicit change approval. Human-in-the-loop by design.

Business problem solved: Automates disk expansion requests with a governed approval process, removing manual back-and-forth between requestors, infrastructure engineers, and change management.

Category: Other | Subcategories: DevOps & release automation

Playbook Integration Executions
Expand VM Disk Capacity VMware vSphere, Microsoft Teams 0

*Note: Also deployed in workspaces 978e9c6d and d4059f53.*

Integrations: VMware vSphere, Microsoft Teams

8. Scheduled Alerting & Notifications

Description: A scheduled automation running every 5 minutes that polls a weather alert API and conditionally delivers customer notifications when active alerts are detected. The only automation in the environment with significant production execution volume.

Business problem solved: Ensures timely weather alert notifications without manual monitoring — relevant to Rockwell's field operations and customer-facing service delivery in environments where weather conditions affect industrial operations.

Category: Other | Subcategories: IT helpdesk & ticket routing

Playbook Schedule Executions
Customer Weather Alert Notification Every 5 minutes 11,552

Integrations: HTTP API (weather service), Blink default API

9. AI-Augmented Workflow Automation

Description: A set of LLM-powered workflows integrating with an internal Azure OpenAI endpoint for intelligent request handling, ticket triage, and automated response generation. Includes a web-form-driven email simulation pipeline that classifies inbound tickets via OpenAI and routes responses through Microsoft Teams, as well as a drive intake process and server pre-check automation.

Business problem solved: Augments human decision-making with AI-generated analysis and routing, reducing time spent on routine classification tasks. The LLM request framework (RA-LLM Request) provides a reusable AI invocation pattern for downstream automations.

Category: Other | Subcategories: IT helpdesk & ticket routing, SaaS / IT administration

Playbook Integration Executions
RA-LLM Request Azure OpenAI, Blink Tables 0
RA-LLM Request (Training Development) Azure OpenAI, Blink Tables 0
LLM Training Request Blink Automation (subflow) 0
New Ticket Workflow Azure OpenAI, Microsoft Teams 0
Drive Intake Web form Email (core), Web Form 0
New Workflow — Drive Intake (On-demand) Web Form (interactive) 0
Pre check Internal 0
ELABS request Web Form 0
Multi-step web form Web Form 0
Drive Monitoring Customer Onboarding Form Web Form (interactive) 1

Integrations: Azure OpenAI, Microsoft Teams, Blink Tables, Web Forms, Email

10. Training & Platform Familiarization

Description: A collection of "hello world" style workflows, web form exercises, subflow training, and hands-on training scenarios spread across multiple isolated training workspaces. Each workspace represents a distinct training cohort or session for Rockwell's teams learning Blink's core capabilities.

Business problem solved: Provides safe, isolated environments for teams to learn automation logic, web forms, subflows, and integrations without impacting production systems.

Category: Other | Subcategories: SaaS / IT administration

Playbook Workspace Executions
Getting Started - Hello World f7d2d507 0
New Workflow — Expel Webhook f7d2d507 0
Training Workflow 1 d4059f53 0
Webform Training d4059f53 0
Training Workflow 0053b4f0 0
Web Form Training 0053b4f0 0
Sub flow Training 978e9c6d 0
Web form training - MSS 978e9c6d 0
Webform Training 1 7f254867 0
Hands On Training Workflow - Form 760b3675 0
amit_training_1 7f254867 0
UserDataCollect 7f254867 0
New Workflow 3 7f254867 0
Automation Form 7f254867 0
TestWF 7f254867 0
Web Form — File Upload 7f254867 0
Hello World 7f254867 1

Integrations: Various (training exercises across all major Blink capabilities)

11. Employee Offboarding Intake

Description: A public-facing web form allowing HR/IT to initiate employee offboarding by submitting the company name and employee email, paired with a supporting subflow that reformats usernames for downstream identity system lookups.

Business problem solved: Provides a self-service entry point for kicking off employee offboarding, standardizing the request format before it reaches identity/directory systems and reducing manual ticket creation.

Category: IAM | Subcategories: Employee offboarding

Playbook Type Executions
Webform Event (webform) 0
Subflow - Reformat User Name Subflow 0

Integrations: Blink Web Form (internal)

Key Observations

Strengths

1. Production-ready SOC automation stack. The main SOC workspace (076024e1) contains a sophisticated agentic SOC pipeline — event-driven alert ingestion, observable extraction and deduplication, multi-source enrichment, type-specific response subflows, and case lifecycle management. This is a complete blueprint for enterprise SOC automation at scale.

2. Exceptional enrichment coverage. The enrichment library spans 9 distinct integrations and every major observable type an enterprise SOC analyst would encounter: IPs (VirusTotal, AbuseIPDB), hashes (VirusTotal, CrowdStrike), URLs (VirusTotal, URLScan), usernames/emails (Okta, Entra ID, Google Workspace, GitHub, Slack), domains (WHOIS). Few environments achieve this breadth.

3. Active production automation. The Customer Weather Alert Notification workflow executed 11,552 times over the past 12 months — demonstrating consistent operational automation delivery on a non-security use case, and confirming the environment can sustain production-grade scheduled workloads.

4. IT/OT automation investment. The Cisco SmartNet Coverage workflow (marked POC COMPLETE) and the Cisco Switch Health Check (POC Draft) demonstrate active exploration of OT/network infrastructure automation — a high-value area given Rockwell's industrial automation domain. The Ansible-based health check in particular shows ambition to automate complex multi-step network operations.

5. AI integration actively explored. Multiple workspaces contain LLM-powered workflows using Azure OpenAI. The RA-LLM Request pattern is cleanly abstracted as a reusable subflow, showing architectural maturity in how AI is being incorporated.

6. Structured enablement program. Eight distinct training workspaces, each containing exercises and hands-on scenarios, indicate a formal and repeating Blink onboarding program — a strong signal of organizational adoption depth.

Gaps

1. SOC pipeline not yet receiving live alert volume. Despite a complete and validated SOC automation stack, only 1 alert was processed through Process Alert in the last 12 months. All enrichment subflows show 0 executions, indicating the pipeline has been built and demonstrated but is not yet connected to a live alert source (e.g., CrowdStrike, Proofpoint).

2. EDR containment not activated. The CrowdStrike RTR and host quarantine workflows exist but have never executed. Containment actions remain manual, which is the highest-impact gap in a mature SOC program.

3. IT/OT workflows in POC state. The Cisco SmartNet and Switch Health Check automations are validated but deployed only in training workspaces. Production promotion — connecting to live Cisco infrastructure — would immediately deliver operational value.

4. AI workflows not yet in production. All LLM-powered workflows have 0 executions. The Azure OpenAI integration is configured and the workflow architecture is solid; the gap is connecting to live ticket or alert feeds.

Integration Ecosystem

Integration Use Cases
CrowdStrike EDR enrichment, endpoint containment, RTR
VirusTotal Hash, IP, URL threat intelligence
Microsoft Entra ID Identity enrichment, risky user detection
Okta Identity enrichment, user activity audit
Google Workspace Identity enrichment
AbuseIPDB IP reputation
URLScan URL analysis, screenshot capture
GitHub User enrichment
Slack User enrichment
Microsoft Outlook Email retrieval, phishing response
Microsoft Teams Human-in-the-loop approvals, notifications
VMware vSphere VM disk management
Sumo Logic Log insight ingestion
N-Able N-Central Device service monitoring
Azure OpenAI AI-augmented ticket triage and response
Cisco API SmartNet coverage validation
SSH Switch command execution
Ansible Network health automation
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.