01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — Alert Triage & Response Pipeline |
| 0.0% | 15 15 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 14 14 active |
| On-Demand Investigation Tools | 0 executions | 0.0% | 13 13 active |
| EDR Containment & Remote Response | 0 executions | 0.0% | 3 3 active |
| Case Management Utilities | 0 executions | 0.0% | 5 5 active |
| IT/OT Network Infrastructure Automation | 0 executions | 0.0% | 4 4 active |
| VM Disk Capacity Management | 0 executions | 0.0% | 1 1 active |
| Scheduled Alerting & Notifications |
| 100.0% | 1 1 active |
| AI-Augmented Workflow Automation |
| 0.0% | 9 8 active |
| Training & Platform Familiarization | 1 executions | 0.0% | 15 14 active |
| Employee Offboarding Intake | 0 executions | 0.0% | 2 2 active |
| Total | 11,515 executions | 100% | 82 80 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Production-ready SOC automation stack. The main SOC workspace (076024e1) contains a sophisticated agentic SOC pipeline — event-driven alert ingestion, observable extraction and deduplication, multi-source enrichment, type-specific response subflows, and case lifecycle management. This is a complete blueprint for enterprise SOC automation at scale.
2. Exceptional enrichment coverage. The enrichment library spans 9 distinct integrations and every major observable type an enterprise SOC analyst would encounter: IPs (VirusTotal, AbuseIPDB), hashes (VirusTotal, CrowdStrike), URLs (VirusTotal, URLScan), usernames/emails (Okta, Entra ID, Google Workspace, GitHub, Slack), domains (WHOIS). Few environments achieve this breadth.
3. Active production automation. The Customer Weather Alert Notification workflow executed 11,552 times over the past 12 months — demonstrating consistent operational automation delivery on a non-security use case, and confirming the environment can sustain production-grade scheduled workloads.
4. IT/OT automation investment. The Cisco SmartNet Coverage workflow (marked POC COMPLETE) and the Cisco Switch Health Check (POC Draft) demonstrate active exploration of OT/network infrastructure automation — a high-value area given Rockwell's industrial automation domain. The Ansible-based health check in particular shows ambition to automate complex multi-step network operations.
5. AI integration actively explored. Multiple workspaces contain LLM-powered workflows using Azure OpenAI. The RA-LLM Request pattern is cleanly abstracted as a reusable subflow, showing architectural maturity in how AI is being incorporated.
6. Structured enablement program. Eight distinct training workspaces, each containing exercises and hands-on scenarios, indicate a formal and repeating Blink onboarding program — a strong signal of organizational adoption depth.
###
Gaps
1. SOC pipeline not yet receiving live alert volume. Despite a complete and validated SOC automation stack, only 1 alert was processed through Process Alert in the last 12 months. All enrichment subflows show 0 executions, indicating the pipeline has been built and demonstrated but is not yet connected to a live alert source (e.g., CrowdStrike, Proofpoint).
2. EDR containment not activated. The CrowdStrike RTR and host quarantine workflows exist but have never executed. Containment actions remain manual, which is the highest-impact gap in a mature SOC program.
3. IT/OT workflows in POC state. The Cisco SmartNet and Switch Health Check automations are validated but deployed only in training workspaces. Production promotion — connecting to live Cisco infrastructure — would immediately deliver operational value.
4. AI workflows not yet in production. All LLM-powered workflows have 0 executions. The Azure OpenAI integration is configured and the workflow architecture is solid; the gap is connecting to live ticket or alert feeds.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| CrowdStrike | EDR enrichment, endpoint containment, RTR |
| VirusTotal | Hash, IP, URL threat intelligence |
| Microsoft Entra ID | Identity enrichment, risky user detection |
| Okta | Identity enrichment, user activity audit |
| Google Workspace | Identity enrichment |
| AbuseIPDB | IP reputation |
| URLScan | URL analysis, screenshot capture |
| GitHub | User enrichment |
| Slack | User enrichment |
| Microsoft Outlook | Email retrieval, phishing response |
| Microsoft Teams | Human-in-the-loop approvals, notifications |
| VMware vSphere | VM disk management |
| Sumo Logic | Log insight ingestion |
| N-Able N-Central | Device service monitoring |
| Azure OpenAI | AI-augmented ticket triage and response |
| Cisco API | SmartNet coverage validation |
| SSH | Switch command execution |
| Ansible | Network health automation |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | SOC - Training Lab | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| SOC - Training Lab | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Training Test | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Test Webform | 0 | 0 |
| 2 | Test Webform | 0 | 0 |
| 3 | Test Automation for this Web Form | 0 | 0 |
| 4 | Request Support | 0 | 0 |
| 5 | Training Example | 0 | 0 |
D Full Use Case Analysis 11 use cases | 11,515 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Customer weather alerts monitored & notifications delivered | 11,552 | Customer Weather Alert Notification |
| Security alerts processed through automated triage pipeline | 1 | Process Alert |
| Customer onboarding requests submitted | 1 | Drive Monitoring Customer Onboarding Form |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks |
|---|---|---|---|---|
| 1 | Agentic SOC — Alert Triage & Response Pipeline | SOC | Agentic SOC, Case mgmt & SOAR, Phishing detection & response, EDR containment & response | 15 |
| 2 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 14 |
| 3 | On-Demand Investigation Tools | SOC | Alert enrichment / IOC lookup, Identity threat response | 13 |
| 4 | EDR Containment & Remote Response | SOC | EDR containment & response | 3 |
| 5 | Case Management Utilities | SOC | Case mgmt & SOAR | 5 |
| 6 | IT/OT Network Infrastructure Automation | Other | IT/OT & network infra monitoring | 6 |
| 7 | VM Disk Capacity Management | Other | DevOps & release automation | 1 |
| 8 | Scheduled Alerting & Notifications | Other | IT helpdesk & ticket routing | 1 |
| 9 | AI-Augmented Workflow Automation | Other | IT helpdesk & ticket routing, SaaS / IT administration | 10 |
| 10 | Training & Platform Familiarization | Other | SaaS / IT administration | 17 |
| 11 | Employee Offboarding Intake | IAM | Employee offboarding | 2 |
Total: 87 playbook instances across 9 workspaces (several Cisco POC workflows are duplicated across training workspaces)
Use Cases
1. Agentic SOC — Alert Triage & Response Pipeline
Description: A full end-to-end automated SOC pipeline that ingests incoming alerts on a 1-minute polling interval, extracts and deduplicates observables, enriches indicators, routes cases to type-specific response subflows (phishing, malware), and manages case lifecycle. Built entirely on Blink's native case management.
Business problem solved: Eliminates manual alert triage and first-responder investigation. Analysts work pre-enriched, deduplicated cases rather than raw alerts — reducing mean time to respond and analyst fatigue across high-volume environments.
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR, Phishing detection & response, EDR containment & response
| Playbook | Type | Executions |
|---|---|---|
| Process Alert | Event (polling) | 1 |
| Subflow - Response - Main Router | Subflow | 0 |
| Response Subflow - Phishing | Subflow | 0 |
| Response Subflow - Malware | Subflow | 0 |
| Subflow - Enrich Observables - Main Router | Subflow | 0 |
| Subflow - Missing Alert Template Notification | Subflow | 0 |
| Subflow - Update Enrichment Data | Subflow | 0 |
| Utility - Close Stale Cases | On-demand | 0 |
| Recovery - Handle Unprocessed Alerts | On-demand | 0 |
| Recovery - Enrich Non-Enriched Observables | On-demand | 0 |
| Error Handling - Send Error Notification Email | Subflow | 0 |
| Table Action - Validate Observables Extraction Template | On-demand | 0 |
| Simulate Crowdstrike Alert | On-demand | 0 |
| Simulate Multiple Alerts from Different Sources | On-demand | 0 |
| USE WITH CARE - Reset Case Management Environment | On-demand | 0 |
Integrations: CrowdStrike, Microsoft Outlook, Blink Case Management, Email (core)
2. Alert Enrichment & IOC Lookup
Description: A comprehensive library of enrichment subflows automatically invoked by the SOC pipeline for every observable extracted from an incoming alert. Covers all major IOC types — IPs, hashes, URLs, usernames, email addresses, and domain names — across the full security toolstack.
Business problem solved: Replaces manual analyst lookups across 8+ security tools. Every indicator is enriched before an analyst touches a case, providing context at the moment it is needed.
Category: SOC | Subcategories: Alert enrichment / IOC lookup
| Playbook | IOC Type | Integration | Executions |
|---|---|---|---|
| Enrich - Agent ID - Crowdstrike | Agent / Device | CrowdStrike | 0 |
| Enrich - URL - URLScan | URL | URLScan | 0 |
| Enrich - Hash - VT | Hash | VirusTotal | 0 |
| Enrich - IP - IPDB | IP | AbuseIPDB | 0 |
| Enrich - Username or Email - Okta | Username / Email | Okta | 0 |
| Enrich - IP - VT | IP | VirusTotal | 0 |
| Enrich - URL - VT | URL | VirusTotal | 0 |
| Enrich - Hash - Crowdstrike | Hash | CrowdStrike | 0 |
| Enrich - IP or Domain - Whois | IP / Domain | WHOIS | 0 |
| Enrich - Username or Email - Google Workspace | Username / Email | Google Workspace | 0 |
| Enrich - Username or Email - Microsoft Entra ID | Username / Email | Microsoft Entra ID | 0 |
| Enrich - Username - Github | Username | GitHub | 0 |
| Enrich - Email Address - Slack | Slack | 0 | |
| Utility - Update Enrichment | — | Blink Case Management | 0 |
Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack
3. On-Demand Investigation Tools
Description: A library of standalone analyst-facing investigation workflows invokable on-demand for ad-hoc lookups — user identities, threat intelligence, DNS/WHOIS, URL screenshots, and product end-of-life dates. Designed for analyst investigations independent of the automated alert pipeline.
Business problem solved: Gives SOC analysts single-click access to multi-source enrichment without requiring direct tool access, stored credentials, or manual API calls.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Identity threat response
| Playbook | Integration | Executions |
|---|---|---|
| Get User Information Using Google Workspace | Google Workspace | 0 |
| Enrich IP or Domain Using Whois | WHOIS | 0 |
| Get User Information Using Github | GitHub | 0 |
| Get User Information Using Microsoft Entra ID | Microsoft Entra ID | 0 |
| Get User Information Using Okta | Okta | 0 |
| Okta Search for User Activity | Okta | 0 |
| Get Hash Info Using Crowdstrike | CrowdStrike | 0 |
| Get Hash Info Using VirusTotal | VirusTotal | 0 |
| Get User Information on Email Address Using Slack | Slack | 0 |
| Get End of Life Date for a Product | HTTP API | 0 |
| Run Dig Command | Bash / DNS | 0 |
| Secure URL Screenshot Capture | Internal | 0 |
| Analyze URL with URLScan | URLScan | 0 |
Integrations: Google Workspace, GitHub, Microsoft Entra ID, Okta, CrowdStrike, VirusTotal, Slack, URLScan, HTTP APIs, Bash/DNS
4. EDR Containment & Remote Response
Description: CrowdStrike-based endpoint containment and Real-Time Response (RTR) workflows enabling isolation of compromised hosts and execution of remote commands — on a single endpoint or across a batch — directly from Blink.
Business problem solved: Reduces time-to-containment on endpoint threats. Analysts quarantine devices or run remediation commands without switching tools or logging into CrowdStrike directly.
Category: SOC | Subcategories: EDR containment & response
| Playbook | Capability | Executions |
|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | Isolate / lift isolation | 0 |
| CrowdStrike RTR to a Batch of Hosts | Remote command execution (batch) | 0 |
| CrowdStrike RTR to a Single Host | Remote command execution (single) | 0 |
Integrations: CrowdStrike
5. Case Management Utilities
Description: Utility workflows for managing the observable relationship graph within Blink's case management system — listing, creating, updating, and deleting observable-to-alert links, and finding similar open cases based on shared indicators.
Business problem solved: Maintains case data integrity and surfaces related investigations automatically, reducing analyst correlation effort and duplicate case creation.
Category: SOC | Subcategories: Case mgmt & SOAR
Integrations: Blink Case Management
6. IT/OT Network Infrastructure Automation
Description: POC and working automations targeting Rockwell's OT/network infrastructure stack. Covers Cisco switch SmartNet coverage validation (marked POC COMPLETE), switch health checks via Ansible, SSH-based switch command execution, and Sumo Logic insight processing. These automations are deployed across multiple training workspaces, indicating active iteration by multiple engineering teams.
Business problem solved: Automates manual network operations tasks — warranty/support coverage checks, switch health monitoring, and SIEM log review — reducing manual effort for network engineers managing industrial OT environments.
Category: Other | Subcategories: IT/OT & network infra monitoring
| Playbook | Status | Integration | Executions |
|---|---|---|---|
| _Cisco_Switch_SmartNet_Coverage (POC COMPLETE) | POC Complete | Cisco API, Bash | 0 |
| _Cisco Switch Health Check - Ansible (POC Draft) | POC Draft | Ansible, SSH | 0 |
| Sumo Logic Collectors (Working) | Working | Sumo Logic | 0 |
| Training Canvas Overview | Training | SSH | 0 |
| Web Form — Cisco Switch Test | Training | Web Form | 0 |
| New Workflow 1 — N-Able Device Monitoring | Draft | N-Able N-Central | 0 |
*Note: Cisco SmartNet Coverage and Cisco Switch Health Check each appear in 5 training workspaces; Sumo Logic Collectors appears in 2. Links point to the primary workspace instance.*
Integrations: Cisco API, Ansible, SSH, Sumo Logic, N-Able N-Central, Bash
7. VM Disk Capacity Management
Description: An approval-gated workflow that checks current VMware vSphere disk capacity, presents findings to an approver via Microsoft Teams, and expands disk size only after explicit change approval. Human-in-the-loop by design.
Business problem solved: Automates disk expansion requests with a governed approval process, removing manual back-and-forth between requestors, infrastructure engineers, and change management.
Category: Other | Subcategories: DevOps & release automation
| Playbook | Integration | Executions |
|---|---|---|
| Expand VM Disk Capacity | VMware vSphere, Microsoft Teams | 0 |
*Note: Also deployed in workspaces 978e9c6d and d4059f53.*
Integrations: VMware vSphere, Microsoft Teams
8. Scheduled Alerting & Notifications
Description: A scheduled automation running every 5 minutes that polls a weather alert API and conditionally delivers customer notifications when active alerts are detected. The only automation in the environment with significant production execution volume.
Business problem solved: Ensures timely weather alert notifications without manual monitoring — relevant to Rockwell's field operations and customer-facing service delivery in environments where weather conditions affect industrial operations.
Category: Other | Subcategories: IT helpdesk & ticket routing
| Playbook | Schedule | Executions |
|---|---|---|
| Customer Weather Alert Notification | Every 5 minutes | 11,552 |
Integrations: HTTP API (weather service), Blink default API
9. AI-Augmented Workflow Automation
Description: A set of LLM-powered workflows integrating with an internal Azure OpenAI endpoint for intelligent request handling, ticket triage, and automated response generation. Includes a web-form-driven email simulation pipeline that classifies inbound tickets via OpenAI and routes responses through Microsoft Teams, as well as a drive intake process and server pre-check automation.
Business problem solved: Augments human decision-making with AI-generated analysis and routing, reducing time spent on routine classification tasks. The LLM request framework (RA-LLM Request) provides a reusable AI invocation pattern for downstream automations.
Category: Other | Subcategories: IT helpdesk & ticket routing, SaaS / IT administration
| Playbook | Integration | Executions |
|---|---|---|
| RA-LLM Request | Azure OpenAI, Blink Tables | 0 |
| RA-LLM Request (Training Development) | Azure OpenAI, Blink Tables | 0 |
| LLM Training Request | Blink Automation (subflow) | 0 |
| New Ticket Workflow | Azure OpenAI, Microsoft Teams | 0 |
| Drive Intake Web form | Email (core), Web Form | 0 |
| New Workflow — Drive Intake (On-demand) | Web Form (interactive) | 0 |
| Pre check | Internal | 0 |
| ELABS request | Web Form | 0 |
| Multi-step web form | Web Form | 0 |
| Drive Monitoring Customer Onboarding Form | Web Form (interactive) | 1 |
Integrations: Azure OpenAI, Microsoft Teams, Blink Tables, Web Forms, Email
10. Training & Platform Familiarization
Description: A collection of "hello world" style workflows, web form exercises, subflow training, and hands-on training scenarios spread across multiple isolated training workspaces. Each workspace represents a distinct training cohort or session for Rockwell's teams learning Blink's core capabilities.
Business problem solved: Provides safe, isolated environments for teams to learn automation logic, web forms, subflows, and integrations without impacting production systems.
Category: Other | Subcategories: SaaS / IT administration
| Playbook | Workspace | Executions |
|---|---|---|
| Getting Started - Hello World | f7d2d507 | 0 |
| New Workflow — Expel Webhook | f7d2d507 | 0 |
| Training Workflow 1 | d4059f53 | 0 |
| Webform Training | d4059f53 | 0 |
| Training Workflow | 0053b4f0 | 0 |
| Web Form Training | 0053b4f0 | 0 |
| Sub flow Training | 978e9c6d | 0 |
| Web form training - MSS | 978e9c6d | 0 |
| Webform Training 1 | 7f254867 | 0 |
| Hands On Training Workflow - Form | 760b3675 | 0 |
| amit_training_1 | 7f254867 | 0 |
| UserDataCollect | 7f254867 | 0 |
| New Workflow 3 | 7f254867 | 0 |
| Automation Form | 7f254867 | 0 |
| TestWF | 7f254867 | 0 |
| Web Form — File Upload | 7f254867 | 0 |
| Hello World | 7f254867 | 1 |
Integrations: Various (training exercises across all major Blink capabilities)
11. Employee Offboarding Intake
Description: A public-facing web form allowing HR/IT to initiate employee offboarding by submitting the company name and employee email, paired with a supporting subflow that reformats usernames for downstream identity system lookups.
Business problem solved: Provides a self-service entry point for kicking off employee offboarding, standardizing the request format before it reaches identity/directory systems and reducing manual ticket creation.
Category: IAM | Subcategories: Employee offboarding
| Playbook | Type | Executions |
|---|---|---|
| Webform | Event (webform) | 0 |
| Subflow - Reformat User Name | Subflow | 0 |
Integrations: Blink Web Form (internal)
Key Observations
Strengths
1. Production-ready SOC automation stack. The main SOC workspace (076024e1) contains a sophisticated agentic SOC pipeline — event-driven alert ingestion, observable extraction and deduplication, multi-source enrichment, type-specific response subflows, and case lifecycle management. This is a complete blueprint for enterprise SOC automation at scale.
2. Exceptional enrichment coverage. The enrichment library spans 9 distinct integrations and every major observable type an enterprise SOC analyst would encounter: IPs (VirusTotal, AbuseIPDB), hashes (VirusTotal, CrowdStrike), URLs (VirusTotal, URLScan), usernames/emails (Okta, Entra ID, Google Workspace, GitHub, Slack), domains (WHOIS). Few environments achieve this breadth.
3. Active production automation. The Customer Weather Alert Notification workflow executed 11,552 times over the past 12 months — demonstrating consistent operational automation delivery on a non-security use case, and confirming the environment can sustain production-grade scheduled workloads.
4. IT/OT automation investment. The Cisco SmartNet Coverage workflow (marked POC COMPLETE) and the Cisco Switch Health Check (POC Draft) demonstrate active exploration of OT/network infrastructure automation — a high-value area given Rockwell's industrial automation domain. The Ansible-based health check in particular shows ambition to automate complex multi-step network operations.
5. AI integration actively explored. Multiple workspaces contain LLM-powered workflows using Azure OpenAI. The RA-LLM Request pattern is cleanly abstracted as a reusable subflow, showing architectural maturity in how AI is being incorporated.
6. Structured enablement program. Eight distinct training workspaces, each containing exercises and hands-on scenarios, indicate a formal and repeating Blink onboarding program — a strong signal of organizational adoption depth.
Gaps
1. SOC pipeline not yet receiving live alert volume. Despite a complete and validated SOC automation stack, only 1 alert was processed through Process Alert in the last 12 months. All enrichment subflows show 0 executions, indicating the pipeline has been built and demonstrated but is not yet connected to a live alert source (e.g., CrowdStrike, Proofpoint).
2. EDR containment not activated. The CrowdStrike RTR and host quarantine workflows exist but have never executed. Containment actions remain manual, which is the highest-impact gap in a mature SOC program.
3. IT/OT workflows in POC state. The Cisco SmartNet and Switch Health Check automations are validated but deployed only in training workspaces. Production promotion — connecting to live Cisco infrastructure — would immediately deliver operational value.
4. AI workflows not yet in production. All LLM-powered workflows have 0 executions. The Azure OpenAI integration is configured and the workflow architecture is solid; the gap is connecting to live ticket or alert feeds.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| CrowdStrike | EDR enrichment, endpoint containment, RTR |
| VirusTotal | Hash, IP, URL threat intelligence |
| Microsoft Entra ID | Identity enrichment, risky user detection |
| Okta | Identity enrichment, user activity audit |
| Google Workspace | Identity enrichment |
| AbuseIPDB | IP reputation |
| URLScan | URL analysis, screenshot capture |
| GitHub | User enrichment |
| Slack | User enrichment |
| Microsoft Outlook | Email retrieval, phishing response |
| Microsoft Teams | Human-in-the-loop approvals, notifications |
| VMware vSphere | VM disk management |
| Sumo Logic | Log insight ingestion |
| N-Able N-Central | Device service monitoring |
| Azure OpenAI | AI-augmented ticket triage and response |
| Cisco API | SmartNet coverage validation |
| SSH | Switch command execution |
| Ansible | Network health automation |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.