Blink Security Automation — Confidential

rockwell_c-i_management — Customer Success Report

Generated 2026-08-30 | rockwell_c-i_management-value-report.md
2026-08-30Report Date
800Total Playbooks
251Unique Workflows (12m)
1,948,448Actions Automated (12m)
$501,144Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

800
Total playbooks built
all non-deleted workflows
392
Active playbooks
currently enabled
251
Unique workflows executed (12m)
distinct workflows that ran
1,948,448
Actions automated (12m)
completed action steps
10,824.7h
Hours saved (12m)
@ 20s per action
$501,144
Money saved (12m)
@ $100K avg salary
40
New active workflows (last 30d)
recently created & enabled
2
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
2
Active AI agents
of 11 total
16
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 57,762 security alerts auto-processed and case-correlated without analyst involvement - 11,552 case data synchronizations pushed to downstream SIEM and ticketing systems - 3,031 N-Central script executions orchestrated end-to-end - 1,794 OT/IT alarms auto-processed end-to-end via ServiceNow - 1,782 critical CPU/Memory alarms automatically triaged - 978 OT/IT alerts automatically resolved in Claroty CTD - 495 DevOps work item change notifications automatically routed to Microsoft Teams - 237 workflow naming-governance checks run automatically, flagging non-compliant automations - 179 server alerts received, deduplicated, and stored for review - 152 OT device health incidents automatically created in ServiceNow - 105 stale OT security alerts archived automatically on schedule - 61 remote access proxy OVA configurations generated on demand - 52 Omni Bot AI expertise queries answered end-to-end - 44 OT remote access AD group synchronizations completed without manual action - 20 OT license, certificate, and health/version records compiled into a customer time-savings dashboard - 20 remote access proxy build pipeline status emails sent automatically - 18 ServiceNow incidents automatically resolved without analyst action

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOAR & Security Case Management
  • 57,762Security alerts auto-processed and case-correlated
  • 11,552Case data synchronizations pushed to downstream systems
40.0%
20
20 active
Alert Enrichment & IOC Lookup0 executions
0.0%
27
27 active
Phishing & Malware Response0 executions
0.0%
6
6 active
OT Asset Monitoring & SIEM Incident Management
  • 105Stale OT security alerts automatically archived
  • 52Omni Bot AI expertise queries answered end-to-end
0.2%
22
19 active
OT CVE & Vulnerability Extraction0 executions
0.0%
0
0 active
ITSM Automation — ServiceNow & Oracle
  • 18ServiceNow incidents automatically resolved
0.0%
1
1 active
Cisco Network Device SmartNet & Firmware Management6 executions
0.0%
5
5 active
MSRA / Cyolo OT Remote Access Management25 executions
0.0%
10
10 active
N-Central / N-able Managed Services Platform
  • 1,782Critical CPU/Memory alarms auto-triaged
  • 179Server alerts received and auto-processed
  • 61Remote access proxy configurations generated on demand
11.5%
46
44 active
Azure Storage Artifact Repository9 executions
0.0%
9
9 active
DevOps & Teams Notification Automation535 executions
0.3%
9
8 active
Network Infrastructure Auditing & Remediation0 executions
0.0%
9
9 active
VM Infrastructure Management1 executions
0.0%
9
9 active
GRC & Automation Intake0 executions
0.0%
3
3 active
Automation Governance & Naming Compliance
  • 237Workflow naming-governance checks run automatically
0.1%
1
1 active
Total89,992 executions100%
177
171 active

Use Case Growth Over Time

523 unique playbooks  |  14 operational use cases  |  172,700 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Slack Extraction Utilities String Utilities
Phishing & Malware Response
Microsoft Outlook CrowdStrike ServiceNow Slack
SOAR & Security Case Management
Email
MSRA / Cyolo OT Remote Access Management
Keeper Secrets Manager Microsoft Teams String Utilities Agents Microsoft SQL Server Web Form
Cisco Network Device SmartNet & Firmware Management
SSH Email Web Form
Network Infrastructure Auditing & Remediation
Ansible Email SSH Forescout
Azure Storage Artifact Repository
Git GitHub SSH Azure Storage Web Form
VM Infrastructure Management
AWS VMware vSphere Microsoft Teams SSH SharePoint
N-Central / N-able Managed Services Platform
Gmail Keeper Secrets Manager N-able N-Central Web Form Email N-able Cove ServiceNow SSH Azure DevOps
OT Asset Monitoring & SIEM Incident Management
SSH Sumo Logic SharePoint Claroty CTD Web Form Microsoft Teams Email N-able N-Central
DevOps & Teams Notification Automation
Microsoft Teams Azure DevOps
GRC & Automation Intake
Email Smartsheet
ITSM Automation — ServiceNow & Oracle
ServiceNow
Automation Governance & Naming Compliance
Microsoft Teams

04Key Observations

✓  Strengths

Strengths

1. Scale of SOAR automation is exceptional.

The core SOAR platform processed 57,762 alerts and 11,552 case syncs in 12 months — together representing ~69K automated security operations events handled without analyst queuing. This is the largest concentration of value in the tenant and indicates a fully operational, high-volume case management platform.

2. Deep OT/IT integration is a differentiator.

The integration of Claroty CTD, XDome, Sumo Logic, ServiceNow, and Oracle into a single automated pipeline is technically complex and rarely seen at this depth. With 978 Claroty alerts auto-resolved and 152 SNOW health incidents auto-created, the C&I team has automated the most time-consuming parts of OT incident management across a multi-site estate.

3. Multi-team platform adoption.

The 27 distinct workspaces reflect genuine multi-team adoption — SOC, OT/C&I, infrastructure, DevOps, and managed services teams all have their own automation footprint. The Infra DevOps WorkItem Update and AET DevOps WorkItem Update flows (495 executions combined) demonstrate that value extends beyond security into engineering operations.

4. Mature credential and access management automation.

The combination of Keeper Secrets Manager integration, Cyolo MSRA group synchronization, and N-Central site standardization workflows represents a sophisticated, end-to-end automated credential lifecycle for managed service environments — a capability that typically requires significant manual operational overhead.

5. LLM integration is in active production.

The RA-LLM Request Model Agnostic workflow ran 23 times, indicating live AI-assisted operations (DevOps comment summarization). This positions the team ahead of the curve on AI-augmented operations.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. CVE pipeline has zero executions despite complete build-out.

The CTD CVE ETL pipeline (9 workflows across 3 workspaces) has never run in production. Given the OT vulnerability posture implications, activating this pipeline would immediately extend the value story into quantifiable vulnerability management.

2. SOC enrichment library is built but idle.

27 enrichment workflows in the main SOAR workspace have zero executions. These are designed as subflows called by Process Alert, but if the observable enrichment pipeline is not routing correctly, a significant capability investment is going unutilized.

3. Cisco SmartNet & firmware automation under-scheduled.

The PROD firmware and coverage workflows run only 6 times per year (weekly on two workflows). Given the breadth of the multi-SN coverage check tooling (16 workflows across 4 workspaces), there is an opportunity to expand scheduled execution and integrate results into a reporting dashboard.

4. Network auditing workflows not yet in production.

Network Configuration Audit, Remediation, Network Alert Triage, and Forescout dashboard workflows have no executions. These represent substantial capability investment that could deliver value if activated with the right device inventory inputs.

5. Staging pipeline visibility.

The SOC Development workspace (0605b8ff) runs several workflows in parallel with production (b3bdd488, 20e0b237), suggesting a multi-stage promotion pipeline. Clearer workspace naming conventions and execution metrics per stage would make promotion progress easier to track.

Integration Ecosystem

Domain Integrations
OT/ICS Claroty CTD, XDome, Cyolo (MSRA), Cisco API (SmartNet), FortiGate (POC)
SIEM / Logging Sumo Logic
ITSM ServiceNow, Oracle ITSM
Endpoint / EDR CrowdStrike (RTR, isolation, hash lookup)
Identity Okta, Microsoft Entra ID, Active Directory, Google Workspace, GitHub, Slack
Threat Intel VirusTotal, URLScan, AbuseIPDB, Whois
Cloud Azure Storage (AzCopy), Azure DevOps, VMware vSphere, AWS S3
Managed Services N-able N-Central, N-able Cove, Keeper Secrets Manager
Collaboration Microsoft Teams, Microsoft Outlook, SharePoint, Smartsheet
AI / LLM Azure OpenAI (model-agnostic wrapper supporting Claude and OpenAI)
Scripting PowerShell, Python, Ansible, WinRM, SSH, Bash
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
2
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Shared_Workspace 1 0 0 N/A
Case_Management_Playground 1 0 0 N/A
B AI Agents 2 active | 16 tasks (12m)

AI Agents

Active Agents
2
of 11 total
Tasks Executed (12m)
16
0 in last 30d
Data Usage (12m)
702,790
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Teresa RA-Cyolo-Integration-Prod 11 0 106,147
2 BlinkOps Workflow Troubleshooting Agent Shared_Workspace 5 0 596,643
3 Agent Blink Shared_Workspace 0 0 0
4 Agent Blink Case_Management_Playground 0 0 0
5 Agent Mason Shared_Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
RA-Cyolo-Integration-Prod11
Shared_Workspace5
Case_Management_Playground0
Anthony.Rice@rockwellautomation.com0
Tarani.Debnath@rockwellautomation.com0
C Self-Service & Webforms 0 app runs | 175 form submissions

Self-Service Applications

Apps
18
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Intake Form Dashboard2 00
2 Runner-Status 00
3 Toms Example 00
4 Network Device Compliance Dashboard 00
5 Corey SW 00

Webforms

Forms
28
active webforms
Total Submissions
175
all time
Completed
170
fully submitted
Submissions (30d)
112
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Start 147147
2 MSRA Tenant onboarding process 2722
3 Select Site name 11
4 Cisco Multi-SN Contract Coverage Check 00
5 Cisco Multi-SN Contract Coverage Check 00
D Full Use Case Analysis 14 use cases | 172,700 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-processed and case-correlated 57,762 Process Alert
Case data synchronizations pushed to downstream systems 11,552 Sync Case Details
N-Central script executions orchestrated end-to-end 3,031 N-Central Script Execution Wrapper / N-Central Script Execution Wrapper (fa8601a4)
OT/IT alarms auto-processed end-to-end via ServiceNow 1,794 1.0 Alarm Intake with SNOW / 2.0 - Alarm Processing with SNOW
Critical CPU/Memory alarms auto-triaged 1,782 CPU/Memory - Critical
Claroty OT alerts automatically resolved 978 SubFlow Claroty CTD Resolve Alert
DevOps work item change notifications routed to Teams 495 Infra DevOps WorkItem Update / AET DevOps WorkItem Update
Workflow naming-governance checks run automatically 237 regex trigger
Server alerts received and auto-processed 179 Server Alert
OT device health incidents auto-created in ServiceNow 152 Create SNOW Health Incident
Stale OT security alerts automatically archived 105 Claroty CTD Archive Old Alerts v2
Remote access proxy configurations generated on demand 61 Ra proxy web form
Omni Bot AI expertise queries answered end-to-end 52 EM_LLM_API
OT remote access group synchronizations completed 44 KraftMSRAGroupSyncAutomatic
Automated server availability checks run 40 Monitor Server Alert Event
Security incidents escalated to ServiceNow 22 Create SNOW Security Case
Claroty CTD license, certificate, and health/version records compiled into customer time-savings dashboard 20 PROD_Unilever_License_CTD_BlinkTable / PROD_Unilever_Cert_BlinkTable / PROD_Unilever_CTD_Health_Version_BlinkTable
Remote access proxy build pipeline status emails sent automatically 20 Ra proxy web hook
ServiceNow incidents automatically resolved 18 Resolve SNOW Incidents
In the last 12 months, Blink automated: - 57,762 security alerts auto-processed and case-correlated without analyst involvement - 11,552 case data synchronizations pushed to downstream SIEM and ticketing systems - 3,031 N-Central script executions orchestrated end-to-end - 1,794 OT/IT alarms auto-processed end-to-end via ServiceNow - 1,782 critical CPU/Memory alarms automatically triaged - 978 OT/IT alerts automatically resolved in Claroty CTD - 495 DevOps work item change notifications automatically routed to Microsoft Teams - 237 workflow naming-governance checks run automatically, flagging non-compliant automations - 179 server alerts received, deduplicated, and stored for review - 152 OT device health incidents automatically created in ServiceNow - 105 stale OT security alerts archived automatically on schedule - 61 remote access proxy OVA configurations generated on demand - 52 Omni Bot AI expertise queries answered end-to-end - 44 OT remote access AD group synchronizations completed without manual action - 20 OT license, certificate, and health/version records compiled into a customer time-savings dashboard - 20 remote access proxy build pipeline status emails sent automatically - 18 ServiceNow incidents automatically resolved without analyst action

Use Case Summary

# Use Case Category Subcategory Playbooks
1 SOAR & Security Case Management SOC Case mgmt & SOAR 20
2 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 27
3 Phishing & Malware Response SOC Phishing detection & response, EDR containment & response 6
4 OT Asset Monitoring & SIEM Incident Management Other / SOC IT/OT & network infra monitoring, SIEM & log pipeline monitoring 95
5 OT CVE & Vulnerability Extraction Vulnerability Mgmt Vuln scanning ingest & report 10
6 ITSM Automation — ServiceNow & Oracle Other IT helpdesk & ticket routing 14
7 Cisco Network Device SmartNet & Firmware Other IT/OT & network infra monitoring 20
8 MSRA / Cyolo OT Remote Access Management IAM / GRC Access review & group mgmt, Privileged account mgmt, Security metrics & reporting 15
9 N-Central / N-able Managed Services Platform Other / IAM IT/OT & network infra monitoring, Endpoint hygiene & MDM ops, Password & credential lifecycle 51
10 Azure Storage Artifact Repository Cloud Security Cloud asset coverage & inventory, Cloud provisioning & IaC automation 13
11 DevOps & Teams Notification Automation Other DevOps & release automation 10
12 Network Infrastructure Auditing & Remediation Other IT/OT & network infra monitoring 10
13 VM Infrastructure Management Other / IAM IT/OT & network infra monitoring, DevOps & release automation 9
14 GRC & Automation Intake GRC Security metrics & reporting 4
15 Automation Governance & Naming Compliance GRC DevSecOps compliance 1

Use Cases

1. SOAR & Security Case Management

Description: A fully custom security case management and SOAR platform built on Blink's native case management module. Ingests alerts from all security tools every minute, extracts and deduplicates observables, correlates related alerts into cases, and routes each alert to the appropriate automated response playbook. The platform also provides analyst-facing utilities for case hygiene and observable lifecycle management.

Business problem solved: Replaces manual alert triage and ticket creation with an always-on ingestion engine that processes every alert, finds similar historical cases, and triggers response automation — eliminating the alert queue backlog and reducing mean time to respond.

Integrations: Blink Case Management, Microsoft Outlook, CrowdStrike, Okta, Active Directory / Entra ID, Google Workspace, GitHub, Slack, VirusTotal, URLScan, AbuseIPDB

Category: SOC | Subcategory: Case mgmt & SOAR

Playbook Executions (12 mo) Role
Process Alert 57,762 Top-level alert ingestion, deduplication, case creation, routing
Sync Case Details 11,552 Polls case updates and pushes to downstream systems
Subflow - Response - Main Router 0 Routes to phishing/malware/identity response branches
Recovery - Handle Unprocessed Alerts 0 Finds and reprocesses alerts missed during downtime
Recovery - Enrich Non-Enriched Observables 0 Retroactively enriches observables missing context
Utility - Find Similar Cases Based on Observables 0 Similarity scoring across open cases
Utility - Close Stale Cases 0 Closes cases inactive for >1 month
Utility - Delete Observable Relation 0 Removes observable–alert relation
Utility - Set Or Update Observable Relation 0 Adds/updates observable–alert relation
Utility - List Observable Alert Relations 0 Lists alert relations for an observable
Utility - List Alert Observable Relations 0 Lists observable relations for an alert
Utility - Update Enrichment 0 Triggers enrichment router subflow
Table Action - Validate Observables Extraction Template 0 Validates extraction templates against known alert vendors
Subflow - Update Enrichment Data 0 Updates observable enrichment record in CM tables
Subflow - Missing Alert Template Notification 0 Notifies when no extraction template found for an alert type
Error Handling - Send Error Notification Email 0 Emails admin on workflow error
On Error, Email Admin 0 Error event trigger; emails admin
Simulate Crowdstrike Alert 0 Test: injects CrowdStrike alert payload
Simulate Multiple Alerts from Different Sources 0 Test: injects ProofPoint/CrowdStrike/Okta alerts
USE WITH CARE - Reset Case Management Environment 0 Admin: destroys all CM data for reset

2. Alert Enrichment & IOC Lookup

Description: A comprehensive enrichment library attached to the SOAR platform. When the case management engine creates an observable (IP, hash, URL, username, domain), it routes it through a central enrichment router that dispatches to the appropriate vendor integration. Standalone callable versions of each enrichment are also available for analyst self-service.

Business problem solved: Provides instant context on every indicator — reputation, user identity, endpoint state — without requiring analysts to manually pivot across tools. Enrichment data flows directly into the case record for analyst review.

Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois (bash), DNS dig

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Playbook Executions (12 mo) Role
Subflow - Enrich Observables - Main Router 0 Routes enrichment requests by observable type
Enrich - Agent ID - Crowdstrike 0 Device lookup by CrowdStrike agent ID
Enrich - Hash - VT 0 File hash reputation via VirusTotal
Enrich - Hash - Crowdstrike 0 Hash search across CrowdStrike endpoints
Enrich - IP - VT 0 IP reputation via VirusTotal
Enrich - IP - IPDB 0 IP reputation via AbuseIPDB
Enrich - IP or Domain - Whois 0 Whois lookup
Enrich - URL - VT 0 URL scan via VirusTotal
Enrich - URL - URLScan 0 URL analysis via URLScan
Enrich - Username or Email - Okta 0 User details from Okta
Enrich - Username or Email - Microsoft Entra ID 0 User details + risky user status from Entra ID
Enrich - Username or Email - Google Workspace 0 User info from Google Workspace
Enrich - Username - Github 0 User info from GitHub
Enrich - Email Address - Slack 0 Slack user lookup by email
Get Hash Info Using VirusTotal 0 Standalone hash lookup — VirusTotal
Get Hash Info Using Crowdstrike 0 Standalone hash lookup — CrowdStrike
Okta Search for User Activity 0 Okta log search by user/IP/time
Get User Information Using Okta 0 Standalone user lookup — Okta
Get User Information Using Microsoft Entra ID 0 Standalone user lookup — Entra ID
Get User Information Using Google Workspace 0 Standalone user lookup — Google Workspace
Get User Information Using Github 0 Standalone user lookup — GitHub
Get User Information on Email Address Using Slack 0 Standalone user lookup — Slack
Enrich IP or Domain Using Whois 0 Standalone Whois lookup
Run Dig Command 0 DNS dig query
Analyze URL with URLScan 0 Standalone URL analysis — URLScan
Secure URL Screenshot Capture 0 Captures screenshot of suspicious URL
Get End of Life Date for a Product 0 Retrieves EOL/EOS date for product version

3. Phishing & Malware Response

Description: Automated response playbooks that execute when the SOAR router classifies an alert as phishing or malware. The phishing branch retrieves the original email from Outlook and inspects headers to distinguish simulated phishing tests (KnowBe4) from real incidents before escalating. The malware branch checks CrowdStrike remediation status and responds accordingly. EDR containment capabilities (endpoint isolation, RTR scripting) are available for immediate host response.

Business problem solved: Replaces manual analyst triage on high-volume phishing and malware alerts with structured, automated response logic — ensuring consistent handling, reducing false-positive escalations, and enabling immediate EDR containment when needed.

Integrations: Microsoft Outlook, CrowdStrike (RTR, isolation), Slack, ServiceNow

Category: SOC | Subcategory: Phishing detection & response, EDR containment & response

Playbook Executions (12 mo) Role
Response Subflow - Phishing 0 Retrieves email, checks KnowBe4 headers, routes real vs sim
Response Subflow - Malware 0 Checks CrowdStrike remediation status, branches response
Manage Endpoint Quarantine Status in Crowdstrike 0 Isolates or lifts isolation on a CrowdStrike endpoint
CrowdStrike RTR to a Batch of Hosts 0 Runs RTR command across a batch of hosts
CrowdStrike RTR to a Single Host 0 Runs RTR command on a single host
Isolate or Unisolate Device on CrowdStrike 0 Isolates/unisolates device, creates SNOW ticket, notifies via Slack

4. OT Asset Monitoring & SIEM Incident Management

Description: The core operational technology (OT) security monitoring pipeline for Rockwell's C&I managed service. Claroty CTD sensors monitor industrial environments across multiple customer sites and generate security alerts. Blink continuously resolves, archives, and reports on these alerts, feeds asset inventory and metrics into Sumo Logic as the central SIEM, and triggers ServiceNow / Oracle ITSM ticket creation for incidents that require field response. XDome provides additional OT device inventory that is also fed to Sumo Logic.

Business problem solved: Bridges OT security platforms (Claroty CTD, XDome) with IT SIEM and ticketing systems (Sumo Logic, ServiceNow, Oracle) at scale across dozens of customer sites — replacing per-site manual intervention with automated data pipelines, alert lifecycle management, and incident creation.

Integrations: Claroty CTD, XDome, Sumo Logic, ServiceNow, Oracle ITSM, Microsoft Teams, SharePoint

Category: Other / SOC | Subcategory: IT/OT & network infra monitoring, SIEM & log pipeline monitoring

Playbook Executions (12 mo) Role
SubFlow Claroty CTD Resolve Alert (prod) 918 Resolves/closes a Claroty CTD alert with comment
SubFlow Claroty CTD Resolve Alert (20e0b) 60 Resolves Claroty CTD alert — second production workspace
Claroty CTD Archive Old Alerts v2 31 Nightly: archives stale Claroty CTD alerts
Claroty CTD Archive Old Alerts (SOC Development) 40 SOC dev variant
Claroty CTD Archive Old Alerts v2 (SOC Development) 34 SOC dev variant v2
SubFlow - Send Claroty Data To Sumo Webhook (20e0b) 18 Forwards Claroty telemetry batch to Sumo Logic
SubFlow - Send Claroty Data To Sumo Webhook (prod) 4 Prod variant
Sumo Logic - Insight Closure (20e0b) 4 Webhook: closes Sumo Logic insight; triggers Claroty/XDome closure
Subflow - Claroty - Close Alert Related To Sumo Insight (prod) 3 Closes Claroty alert linked to a resolved Sumo insight
Subflow - Claroty - Close Alert Related To Sumo Insight (20e0b) 3 20e0b variant
Claroty CTD - Get Alert Count (20e0b) 2 Monthly: counts active Claroty alerts
Sumo Logic SIEM Enrichment Automation (20e0b) 2 Webhook: enriches Sumo Logic insights on creation/update
Subflow - XDome - Close Alert Related To Sumo Insight (20e0b) 2 Closes XDome alert linked to a resolved Sumo insight
Claroty CTD Get Site Version Workflow (20e0b) 6 Weekly: checks Claroty CTD version per site
Claroty CTD Get Site Version Workflow (SOC Dev) 6 SOC dev variant
Claroty_CTD_Execute_Site_Metrics_Assets (20e0b) 1 Monthly: per-site asset metrics to Sumo
Claroty_CTD_Execute_Site_Metrics_Assets (SOC Dev) 1 SOC dev variant
Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol 1 Monthly: unsecured protocol metrics per site
Claroty CTD - Get Alert Count (SOC Dev) 1 SOC dev variant
Sumo Logic - Insight Closure (prod) 1 Prod variant
Kraft Monthly Sumo Report 1 Monthly: Sumo Logic insights report → SharePoint
XDome Get Devices and Send to Sumo (20e0b) 1 Gets XDome devices, forwards to Sumo Logic
XDome Get Devices Related to Alerts and Send to Sumo (20e0b) 1 Correlates XDome devices with active alerts → Sumo
XDome Execution Scheduler 1 Monthly: triggers XDome data collection pipeline
Sumo Logic SIEM Enrichment Automation (prod) 0 Prod webhook listener (standby)
Sumo Logic SIEM Enrichment Automation (SOC Dev) 0 SOC dev variant
XDome Get Devices and Send to Sumo (prod) 0 Prod variant
XDome Get Devices Related to Alerts and Send to Sumo (prod) 0 Prod variant
SubFlow Claroty CTD Resolve Alert (SOC Dev) 0 SOC dev variant
Subflow - XDome - Close Alert Related To Sumo Insight (prod) 0 Prod variant
Subflow - Claroty - Close Alert Related To Sumo Insight (SOC Dev) 0 SOC dev variant
Subflow - XDome - Close Alert Related To Sumo Insight (SOC Dev) 0 SOC dev variant
Claroty_CTD_Get_Assets_With_Insights (prod) 0 Gets Claroty assets with associated Sumo insights
Claroty_CTD_Get_Assets_With_Insights_Reworked (20e0b) 0 Reworked variant
Claroty_Get Asset Unsecured Protocol From Baseline v3 (prod) 0 Gets assets using unsecured protocols vs baseline
Claroty_Get Asset Unsecured Protocol From Baseline v3 (20e0b) 0 20e0b variant
Subflow - Claroty List Assets - Wrapper (prod) 0 Paginated asset list from Claroty CTD
Subflow - Claroty List Baselines - Wrapper (prod) 0 Paginated baseline list from Claroty CTD
Subflow - Claroty List Unsecured Protocols - Wrapper (prod) 0 Paginated unsecured protocol list from Claroty CTD
SubFlow Get Claroty Data (prod) 0 Fetches raw Claroty CTD data block
SubFlow - Send Claroty Data Iteratively To Sumo Webhook (prod) 0 Iterative batch sender to Sumo
SubFlow Send Claroty Asset Data Iteratively To Sumo (prod) 0 Asset-specific batch sender
SubFlow - Loop Through Array And Send Claroty Data To Sumo Webhook 0 Array loop for Sumo forwarding
Sumo Logic Create Oracle Ticket (prod) 1 Webhook: creates Oracle ITSM ticket from Sumo insight
Sumo Logic Create Oracle Ticket (20e0b) 1 20e0b variant
Global-LLM-Workflow (C&I Development) 0 LLM proxy for C&I dev enrichment tasks
Global-LLM-Workflow (b3bdd488) 0 Reusable LLM proxy subflow (Environment/Message/Model/SystemPrompt inputs) via Run RA LLM Workflow
EM_LLM_API 52 On-demand: routes expertise/query input through Global-LLM-Workflow, returns Omni Bot answer
EM_LLM_API_NCENTRALDRAFT 0 Draft variant of Omni Bot query endpoint with conditional routing (N-Central-focused)
Global-LLM-Workflow (C&I Development) (1ab99233) 0 LLM proxy for C&I dev enrichment tasks
Large String LLM Summary (C&I Development) (1ab99233) 0 Chunked large-text summarization via Azure Foundry
Global-LLM-Workflow (C&I Development) (5644713c) 0 LLM proxy for C&I dev enrichment tasks
Global-LLM-Workflow (5644713c) 1 Reusable LLM proxy subflow (Environment/Message/Model/SystemPrompt inputs) via Run RA LLM Workflow
Large String LLM Summary (C&I Development) (5644713c) 0 Chunked large-text summarization via Azure Foundry
Global-LLM-Workflow (C&I Development) (22daa2e4) 0 LLM proxy for C&I dev enrichment tasks
Large String LLM Summary (C&I Development) (22daa2e4) 0 Chunked large-text summarization via Azure Foundry
Global-LLM-Workflow (C&I Development) (3b45f6fa) 0 LLM proxy for C&I dev enrichment tasks
Large String LLM Summary (C&I Development) (3b45f6fa) 0 Chunked large-text summarization via Azure Foundry
Global-LLM-Workflow (C&I Development) (009efb6c) 0 LLM proxy for C&I dev enrichment tasks
Large String LLM Summary (C&I Development) (009efb6c) 0 Chunked large-text summarization via Azure Foundry
Get Claroty KRI Data and Send To Sharepoint 1 Monthly: extracts Claroty KRI metrics, sends to SharePoint
SubFlow - Claroty CTD get entitiy baseline 6 Retrieves source baseline for a Claroty CTD alert
SubFlow - Claroty CTD get entitiy baseline (20e0b) 1 20e0b variant
Create Monthly PowerPoint (prod) 0 Generates monthly OT reporting PowerPoint (in development)
Create Monthly PowerPoint (20e0b) 0 20e0b variant: generates monthly OT reporting PowerPoint (in development)
Web Form Test 0 Test scaffold for interactive web form (no production logic)
SubFlow - Claroty CTD get events 0 Retrieves events for a Claroty CTD alert
SubFlow - Claroty CTD get events (20e0b) 2 20e0b variant
Get KPI Data and Send To Sharepoint v2 (prod) 0 Monthly: extracts KPI metrics, sends to SharePoint
Get KPI Data and Send To Sharepoint v2 (20e0b) 0 Monthly (cron): extracts KPI metrics, sends to SharePoint — 20e0b variant
Populate Last Month KPI Data (prod) 0 Populates prior-month KPI data for SharePoint reporting
Populate Last Month KPI Data (20e0b) 0 20e0b variant
Populate Last Last Month KPI (prod) 0 Populates two-months-prior KPI data for SharePoint reporting
Populate Last Last Month KPI (20e0b) 0 20e0b variant
Get KRI Summary v2 (prod) 0 Monthly (cron): compiles KRI summary metrics
Get KRI Summary v2 (20e0b) 0 20e0b variant
Populate Previous Month KRI Summary v2 (prod) 0 Populates prior-month KRI summary data
Populate Previous Month KRI Summary v2 (20e0b) 0 20e0b variant
Populate Previous Previous Month KRI Summary v2 (prod) 0 Populates two-months-prior KRI summary data
Populate Previous Previous Month KRI Summary v2 (20e0b) 0 20e0b variant
Global-LLM-Workflow (C&I Development) (20e0b) 0 LLM proxy for C&I dev enrichment tasks
Large String LLM Summary (C&I Development) (20e0b) 0 Chunked large-text summarization via Azure Foundry
Workflow Orchestrator 12 Webhook: Sumo Logic-triggered orchestrator with try/catch error handling
Workflow Orchestrator (20e0b) 8 20e0b variant
SubFlow Sumo Logic - New Asset workflow 7 Handles new-asset events from Sumo Logic insights
SubFlow Sumo Logic - New Asset workflow (20e0b) 2 20e0b variant
SubFlow Sumo Logic - Failed Login workflow 0 Handles failed-login events from Sumo Logic insights
SubFlow Sumo Logic - Failed Login workflow (20e0b) 3 20e0b variant
New Workflow 3 0 Test scaffold: web form file upload, prints only (no production logic)
SubFlow - Send Error Message Via Teams Reporting (20e0b) 2 Sends workflow error notifications via Microsoft Teams
SubFlow - Send Error Message Via Teams Reporting (prod) 0 Prod variant
HA Test 40 Daily: high-availability health check loop
PROD_Unilever_License_CTD_BlinkTable 5 Weekly: compiles Claroty CTD license data per site into time-savings table, emails report
PROD_Unilever_Cert_BlinkTable 10 On-demand: compiles Claroty CTD certificate data into time-savings dashboard
PROD_Unilever_CTD_Health_Version_BlinkTable 5 Weekly: checks Claroty CTD health/version across global regions, logs to time-savings table

5. OT CVE & Vulnerability Extraction

Description: Automated ETL pipeline that extracts CVE and vulnerability data from Claroty CTD deployments across all customer sites on a scheduled basis, then ships the structured data to Sumo Logic for centralized vulnerability tracking and reporting. A Claroty TDMS patch check notification flow is also in place for proactive patch awareness.

Business problem solved: Eliminates manual CVE export and aggregation from distributed OT environments. Vulnerability data flows automatically into the SIEM, enabling consistent vulnerability posture reporting across the entire managed services portfolio without per-site analyst effort.

Integrations: Claroty CTD, Sumo Logic

Category: Vulnerability Mgmt | Subcategory: Vuln scanning ingest & report

Playbook Executions (12 mo) Role
CTD_CVE_ETL_Scheduler (prod) 0 Scheduled: triggers per-site CVE extraction
CTD_CVE_ETL_Scheduler (20e0b) 0 20e0b variant
CTD_CVE_ETL_Scheduler (SOC Dev) 0 SOC dev variant
CTD_CVE_ETL_Site (prod) 0 Per-site CVE extraction subflow
CTD_CVE_ETL_Site (20e0b) 0 20e0b variant
CTD_CVE_ETL_Site (SOC Dev) 0 SOC dev variant
Claroty CTD CVE Extraction Send To Sumo (prod) 0 Extracts CVEs and ships to Sumo Logic
Claroty CTD CVE Extraction Send To Sumo (20e0b) 0 20e0b variant
Claroty CTD CVE Extraction Send To Sumo (SOC Dev) 0 SOC dev variant
_Claroty_TDMS_Patch_Check_Notification (POC) 0 POC: checks TDMS patch status and notifies

6. ITSM Automation — ServiceNow & Oracle

Description: Webhook-driven workflows that automatically create and close incidents in ServiceNow and Oracle ITSM based on events from Sumo Logic and Claroty. Health incidents (device/service outages) and security cases are created without manual ticketing, and incident closure is synchronized back when the Sumo Logic insight is resolved.

Business problem solved: Removes manual ticket creation for OT health and security events across managed customer sites. Ensures that every Sumo Logic insight that requires field response immediately generates a tracked ITSM record.

Integrations: ServiceNow, Oracle ITSM, Sumo Logic (webhook)

Category: Other | Subcategory: IT helpdesk & ticket routing

Playbook Executions (12 mo) Role
Create SNOW Health Incident (prod) 123 Webhook: creates SNOW health incident
Create SNOW Health Incident (20e0b) 29 20e0b variant
Create SNOW Security Case (prod) 12 Webhook: creates SNOW security incident
Create SNOW Security Case (20e0b) 10 20e0b variant
Oracle Get Incident and Close (20e0b) 2 Gets Oracle ITSM incident and closes on Sumo resolution
SNOW Get Case and Close (prod) 0 Gets SNOW case and closes based on Sumo insight
Oracle Get Incident and Close (prod) 0 Prod variant
Create SNOW Security Case (SOC Dev) 0 SOC dev variant
Resolve SNOW Incidents 18 Lists open SNOW incidents and resolves each in a loop
ServiceNow QA AI-Powered Ticket Assistance (58a6e767) 0 Web form: AI-generates a case summary or response draft for a given SNOW case number
ServiceNow QA AI-Powered Ticket Assistance (b3bdd488) 0 Web form variant: AI-generates a case summary or response draft for a given SNOW case number
ServiceNow QA AI-Powered Ticket Assistance (5644713c) 1 Single-step web form variant (dev SNOW connection)
Kill Blink Execution by SNOW ID (5644713c) 0 On-demand: terminates a running Blink execution tied to a SNOW ticket ID
Kill Blink Execution by SNOW ID (fa8601a4) 0 fa8601a4 variant

7. Cisco Network Device SmartNet & Firmware Management

Description: A suite of automation workflows that check Cisco device SmartNet contract coverage and recommended firmware versions across the managed device estate. Devices are queried via SSH; the Cisco API is called to verify contract status and retrieve recommended software versions. Results are stored in Blink tables and surfaced via web forms and email. Cisco switch health checks via Ansible are also in development.

Business problem solved: Removes manual tracking of Cisco device contract expiration and firmware currency across a large, distributed device estate. Ensures proactive identification of out-of-support devices and devices running non-recommended firmware before they create audit or reliability risk.

Integrations: Cisco API (SmartNet), SSH, PowerShell, Ansible, email, web forms

Category: Other | Subcategory: IT/OT & network infra monitoring

Playbook Executions (12 mo) Role
PROD_Cisco SN Suggested Software Version Check 6 Weekly: gets Cisco PIDs, fetches recommended firmware
PROD_Cisco_switch_recm_firmware Table Update 6 Weekly: updates recommended firmware table
PROD_UPDATETABLE_RAAUTOSTORAGE 6 Weekly: inventories Azure Storage blobs into local table
Switch_SSH_API_Contract_Checker 0 SSH to switch + Cisco API: checks SmartNet coverage, emails results
Switch_SSH_API_Contract_Checker (REV05JUN2025) 0 Latest revision
_Cisco_Switch_SmartNet_Coverage (POC) 0 POC: switch SmartNet coverage via SSH + Cisco API
_Cisco_Firewall_SmartNet_Coverage (POC) 0 POC: firewall SmartNet coverage
_Cisco_SN_Coverage_Checker (CI_WebFormPOC) 0 Web form POC for Cisco SN coverage check
Cisco_SN_Web_Form 0 Interactive web form for Cisco SN lookup
_Cisco Multi-SN Contract Coverage Check (d877f) 0 Multi-SN coverage check subflow
_Cisco Multi-SN Contract Coverage Check (58a6e) 0 Variant workspace
_Cisco Multi-SN Contract Coverage Check (5921c) 0 Variant workspace
_Cisco Multi-SN Contract Coverage Check (5ed87) 0 Variant workspace
_Cisco Multi-SN Contract Coverage Check _ Webform Trigger (58a6e) 0 Web form entry point, emails results
_Cisco Multi-SN Contract Coverage Check _ Webform Trigger (5921c) 0 Variant workspace
_Cisco Multi-SN Contract Coverage Check _ Webform Trigger (5ed87) 0 Variant workspace
PROD_Using SN, GET PID, Using PID, GET SOFTWARE, UPDATE TABLE (d877f) 0 On-demand: SN → PID → recommended software → table
PROD_Using SN, GET PID, Using PID, GET SOFTWARE, UPDATE TABLE (58a6e) 0 58a6e variant
_Cisco Switch Health Check - Ansible (POC Draft) 0 Ansible-based Cisco switch health check (draft)
Switch_SSH_API_Contract_Checker COPY FOR BLINKOPS 0 Working copy

8. MSRA / Cyolo OT Remote Access Management

Description: Manages the Managed Service Remote Access (MSRA) platform built on Cyolo for OT environments. Automatically synchronizes Active Directory groups with Cyolo local groups across all customer sites on a daily schedule, generates monthly access reports written to an MSSQL database, and provides health checks, software version queries, and upgrade automation for the Cyolo infrastructure.

Business problem solved: Eliminates manual AD group management for OT remote access permissions across a multi-site environment, and provides automated monthly reporting on remote access activity without requiring analyst intervention.

Integrations: Cyolo, Active Directory, PowerShell, MSSQL, Blink tables

Category: IAM / GRC | Subcategory: Access review & group mgmt, Privileged account mgmt, Security metrics & reporting

Playbook Executions (12 mo) Role
KraftMSRAGroupSyncAutomatic (prod) 44 Daily: syncs OT AD groups with Cyolo across sites
MSRA Reports SQL Insert 14 Inserts MSRA report row into MSSQL
MSRAHealthCheck 5 Health check across all MSRA tenants via PowerShell
MSRA Reports Generate (prod) 1 Monthly: generates MSRA reports, writes to MSSQL
KraftMSRAGroupSyncAutomatic (on-demand) 0 On-demand sync variant
MSRA Reports Generate (on-demand) 0 On-demand variant
MSRA Reports SQL Insert (on-demand) 0 On-demand variant
CyoloLicenceGet 0 Gets Cyolo license info from table records
CyoloSoftwareUpgrade 0 Upgrades Cyolo software across multi-tenant deployment
Cyolo MSRA get software version self Service trigger 0 Self-service: gets Cyolo software version
_BlinkStandarizationWindowsServiceAccount 0 Creates Windows service account via WinRM
CYOLO Application Import - WebForm Production 5 Web form: imports Cyolo credential/parameter CSVs, provisions via PowerShell
Simple Group Creation 2 Web form: imports group/credential CSVs, creates groups via PowerShell
Dynamic Group Creation 2 Web form: imports group/credential CSVs, creates AD groups dynamically via PowerShell
1. MSRA - Tenant onboarding 1 Web form: onboards a new Cyolo MSRA tenant by URL

9. N-Central / N-able Managed Services Platform

Description: A comprehensive automation platform supporting Rockwell's N-able N-Central–based managed services operations. Covers server alert ingestion and deduplication, daily server availability monitoring, remote access proxy configuration generation (RA proxy OVA), N-Central device and OU synchronization, automated endpoint script execution via N-Central, credential lifecycle management via Keeper Secrets Manager, N-able Cove backup administration, and an end-to-end alarm intake/processing pipeline that raises N-Central threshold alarms (disk, connectivity, CPU/memory) as ServiceNow incidents.

Business problem solved: Automates the repetitive operational work of a multi-site managed services NOC — server alert processing, device inventory synchronization, endpoint script queuing, credential management, and alarm-to-incident ticketing — while maintaining auditability via MSSQL and Blink tables.

Integrations: N-able N-Central, N-able Cove, Keeper Secrets Manager, ServiceNow, PowerShell, MSSQL, SSH, Blink tables

Category: Other / IAM | Subcategory: IT/OT & network infra monitoring, Endpoint hygiene & MDM ops, Password & credential lifecycle

Playbook Executions (12 mo) Role
Server Alert 179 Webhook: receives server alert, deduplicates, stores CSV
Monitor Server Alert Event 40 Daily: checks all servers have checked in, flags missing
Ra proxy web form 61 Self-service web form: generates RA proxy OVA config
N-Central Script Execution 14 Event-triggered: queues and executes N-Central scripts
Download N-Central Script Output 11 Downloads and parses N-Central script execution output
Catch Keeper Credential Event 3 Webhook: routes Keeper credential create/update/delete events
N-CentralDeviceSync 0 Syncs all devices from N-Central (paginated)
N-CentralOUSyncAll 0 Syncs all N-Central Organization Units
N-CentralOUSyncSingle 0 Syncs a single N-Central OU chunk
N-CentralFilterSyncAll 0 Syncs all N-Central device filters
N-CentralFilterSyncSingle 0 Syncs single filter (create/update/delete)
_Execute-N-AbleSync 0 Loops monitoring platform records and triggers sync
N-Central Build SiteList Global Variable 0 Builds global variable with all N-Central sites JSON
n-CentralSiteSelectionOneTimeStandarization 0 Web form: selects site, creates Keeper folder structure, creates Windows service account
On-Demand Bulk Site Credential Sync 0 On-demand sync of site credentials to Keeper
On-Demand Keeper Credential Structure Build Out 0 Creates Keeper folder structure and syncs credentials
Connection Creation Method 0 Creates Blink connection from Keeper credential record
Connection Update Method 0 Updates Blink connection from updated Keeper credential
Connection Deletion Method 0 Deletes credential–connection mapping
keeperFoldersRecordNormalization 0 Normalizes Keeper folder/record data
Generate ssh key 7 Generates SSH key pair, stores public/private keys in Keeper Secrets Manager
Create N-Central Execution Record 0 Queues N-Central script execution record
Cleanup N-Central Script Executions 0 Cleans up stale execution records
CRUD Operation for user in N-able Cove 0 Create/read/update/delete user in N-able Cove
Create Delete operation for customer in N-able cove 0 CRUD for customer record in N-able Cove
CRUD operation for Site in N-able Cove 0 CRUD for site in N-able Cove
N-Central Script Execution Wrapper 50 Wraps N-Central script execution: queues, polls, returns raw output
Execution Error Handling 4 Error event handler: fetches failed workflow inputs, notifies
Disk - Critical 0 N-Central disk critical threshold alert handler
Connect - Critical 0 N-Central connectivity critical threshold alert handler
Disk - Warning 0 N-Central disk warning threshold alert handler
Connect - Warning 0 N-Central connectivity warning threshold alert handler
CPU/Memory - Warning 0 N-Central CPU/memory warning threshold alert handler
CPU/Memory - Critical 1,782 N-Central CPU/memory critical threshold handler: identifies top offending process, notifies
1.0 Alarm Intake with SNOW 1,791 On-demand: receives alarm payload, creates ServiceNow incident
2.0 - Alarm Processing with SNOW 1,794 Polls new ServiceNow incident records, processes alarm
Execution Error Handling with SNOW Payload 53 Error event handler: fetches failed execution payload, updates SNOW incident
Execution Error Handling (fa8601a4) 20 Error event handler: fetches failed workflow inputs, notifies
N-Central Script Execution (fa8601a4) 2,987 Event-triggered: queues and executes N-Central scripts
Create N-Central Execution Record (fa8601a4) 2,981 Queues N-Central script execution record
N-Central Script Execution Wrapper (fa8601a4) 2,981 Wraps N-Central script execution: queues, polls, returns raw output
Download N-Central Script Output (fa8601a4) 2,879 Downloads and parses N-Central script execution output
Ra proxy web hook 20 Webhook: receives Azure DevOps pipeline result for RA proxy build, emails status
PROD_PepsiCo_NABLE_SiteList_BlinkTable copy 2 Builds PepsiCo regional site list from N-Central org units into Blink table
PROD_PepsiCo_NABLE_SiteList_BlinkTable (VERSION2) 0 Builds PepsiCo LATAM/NABQ regional site list from N-Central org units into Blink table
PROD_PepsiCo_NABLE_SiteList_BlinkTable (VERSION3) 1 Rebuilds PepsiCo site list, reading and writing back to the PepsiCo site table
PROD_PepsiCo_Get_Table 6 Retrieves records from the PepsiCo site table
New Workflow 7 0 On-demand utility: reads a source table's schema/records and prepares a table-creation payload for a target workspace
PepsiCo_Backup_CSV_Verification 0 Reconciles Azure-backed CSV site data against PepsiCo site table, skipping duplicates
Unilever_N-Central Get Memory Metrics 0 On-demand: runs N-Central script to collect device memory metrics, emails HTML report
BlinkGetWorkspaceTableRecords 7 Reusable utility: paginates through a Blink workspace table to return all records

10. Azure Storage Artifact Repository

Description: Manages a centralized Azure Storage artifact repository used to store and distribute firmware, software packages, and tooling artifacts across managed customer sites. Workflows automate the inventory of stored blobs, generate AzCopy upload/download scripts, manage artifact quarantine workflows, and refresh the local artifact table on demand.

Business problem solved: Provides a version-controlled, auditable artifact distribution mechanism for firmware and software across OT environments — replacing manual file transfers and ad-hoc tooling.

Integrations: Azure Storage, AzCopy, Python, PowerShell

Category: Cloud Security | Subcategory: Cloud asset coverage & inventory, Cloud provisioning & IaC automation

Playbook Executions (12 mo) Role
Azure Storage Upload - Create Upload Script 16 Generates AzCopy upload script with quarantine metadata
Azure Storage File Download - GetAZCopy & RunAZCopy 12 Downloads file from Azure Storage via AzCopy
Azure Storage - Refresh Table OnDemand 9 On-demand refresh of artifact inventory table
PROD_UPDATETABLE_RAAUTOSTORAGE 6 Weekly: lists blobs, updates artifact inventory table
Azure Storage Delete - Delete File 1 Deletes a file from Azure Storage by path
PROD_RAAUTOSTORAGE_UploadToQuarantine 0 Generates upload-to-quarantine script
PROD_RAAUTOSTORAGE Upload to Quarantine (d877f) 0 d877f workspace variant
PROD_Azure_Storage_GetAZCopy_+_GetAZCopyCommand_BLOB (58a6e) 0 Generates AzCopy BLOB download command
PROD_Azure_Storage_GetAZCopy_+_GetAZCopyCommand_BLOB (d877f) 0 d877f variant
Azure_MetaData_Update (DRAFT WEBFORM) 0 Draft: web form to update artifact metadata
Clone ADO and Push to GitHub 0 Clones Azure DevOps repo and pushes to GitHub
NULL_Azure_Storage_RunTransferCommand_FILE 0 POC: AzCopy file transfer via SSH to Windows host
NULL_Azure_Storage_Transfer_File (POC) 0 POC: table-driven file transfer to Azure Storage

11. DevOps & Teams Notification Automation

Description: Bridges Azure DevOps work item activity with Microsoft Teams channels for two internal engineering teams (Infrastructure and AET). Any work item update in Azure DevOps triggers an instant Teams notification to the appropriate channel. An LLM-powered workflow summarizes recent DevOps comments via Azure OpenAI and posts digests to Teams, and a Smartsheet-connected intake workflow routes new automation project requests into the backlog.

Business problem solved: Eliminates the need for engineers to monitor ADO manually for work item changes, reduces context-switching, and ensures teams stay informed of project state in real time. LLM-based comment summarization reduces the overhead of parsing long DevOps threads.

Integrations: Azure DevOps, Microsoft Teams, Azure OpenAI / LLM, Smartsheet

Category: Other | Subcategory: DevOps & release automation

Playbook Executions (12 mo) Role
Infra DevOps WorkItem Update 285 Teams webhook: forwards ADO work item updates to Infra channel
AET DevOps WorkItem Update 210 Teams webhook: forwards ADO work item updates to AET channel
RA-LLM Request Model Agnostic 23 Model-agnostic LLM wrapper (Claude/OpenAI); used for summarization
Summarize DevOps Comments 0 Gets ADO comments, LLM-summarizes, posts to Teams
Add new Feature to current PI 0 Adds new ADO feature to current Program Increment
Sync All Records From DevOps 0 Loops all ADO work items and syncs to Blink table
Sync a Single DevOps Work Item To Blink Table 0 Syncs one ADO work item to table
Smartsheet Project Intake 0 Gets Smartsheet row, routes to intake workflow
RA-LLM Request OpenAI 0 Model-specific LLM wrapper for Azure OpenAI
TeamsTesting 0 Test scaffold: exercises Microsoft Teams user lookup and direct-reports API calls

12. Network Infrastructure Auditing & Remediation

Description: Workflows for auditing and remediating network device configurations across the managed estate. Python-based configuration audits pull device configs and flag deviations; Ansible-based remediation applies fixes. Forescout integration provides asset inventory with a self-service HTML dashboard. Network connectivity testing tools support rapid diagnostics.

Business problem solved: Provides automated network configuration compliance checking and remediation across distributed environments, replacing manual config reviews with consistent, repeatable tooling.

Integrations: Python, Ansible, Forescout, NetBox (simulated), SSH, bash

Category: Other | Subcategory: IT/OT & network infra monitoring

Playbook Executions (12 mo) Role
Network Configuration Audit 0 Audits network device configs via Python/NetBox
Network Configuration Audit Table Test 0 Table-driven test version of audit
Network Configuration Remediation 0 Remediates device config issues via Ansible
On-Demand: Update Network Device Global Variable 0 Updates network device global variable from table
Network Alert Triage 0 Triages network alerts via SSH and Python tools
Probe Forescout and Build Asset Summary Dashboard 0 Queries Forescout, builds HTML asset summary dashboard
Network Connectivity Test To Host 0 Tests DNS, ping, SSH/HTTP/HTTPS/traceroute to target host
Run Ansible Playbook To Query Cisco Switch 0 Runs Ansible playbook to query Cisco switch
Run Ansible Playbook 0 Generic Ansible playbook runner
Update FortiGate Firmware (POC) 0 POC: installs firmware on FortiGate via API

13. VM Infrastructure Management

Description: VMware vSphere management automation covering VM disk expansion, reboots, user provisioning, and OS deployment. Disk expansion requests require Teams-based approval before execution, with state saved to S3. Ubuntu VM deployment includes full post-deployment Ansible configuration (k3s, squid proxy). User add/remove flows for VMs round out the IAM lifecycle.

Business problem solved: Provides self-service and automated VM lifecycle operations for engineering teams, reducing dependency on infrastructure admins for routine changes while enforcing approval gates on impactful operations like disk expansion.

Integrations: VMware vSphere (PowerCLI), AWS S3, Microsoft Teams, Ansible

Category: Other / IAM | Subcategory: IT/OT & network infra monitoring, DevOps & release automation, Employee onboarding/offboarding

Playbook Executions (12 mo) Role
Expand VM Disk Capacity 0 Expands VM disk via PowerCLI; Teams approval required
VM reboot request 0 Reboots named VM via PowerCLI
Add User to VM via PowerCLI 0 Adds user account to VM if not already present
Remove User from VM via PowerCLI 0 Removes user from VM, notifies via Teams
Deploy Ubuntu 22 - Install k3s and squid container 0 Deploys Ubuntu 22 VM and configures via Ansible
PowerCLI Custom Actions 0 Creates new VM from template via PowerCLI
SiteContactsCompateAndUpdate 0 Syncs SharePoint customer list with Blink table
SOCSiteContactsCompareAndUpdate 0 SOC-specific SharePoint contact sync
VMWare License Automation 1 Monthly: checks and reports VMware vSphere license status

14. GRC & Automation Intake

Description: Provides a structured intake process for new automation requests from the C&I security team, routing requests from public web forms and Smartsheet into a scored backlog. Automation Request Form submissions are stored, acknowledged via email, and tracked for prioritization. Monthly MSRA and Sumo Logic reports contribute to a consistent security metrics posture.

Business problem solved: Standardizes how automation ideas are captured and evaluated — replacing ad-hoc Slack/email requests with a formalized intake process tied to a backlog, ensuring alignment with engineering capacity.

Integrations: Web form, Smartsheet, email, Blink tables

Category: GRC | Subcategory: Security metrics & reporting

Playbook Executions (12 mo) Role
Automation Request Form Workflow 6 Public web form intake: stores request, sends email acknowledgment
Smartsheet Project Intake 0 Gets Smartsheet row, routes through Unified Intake Workflow
Unified Intake Workflow 0 Stores intake request scoring data to table
MSRA Reports Generate (prod) 1 Monthly MSRA access report — see UC8

15. Automation Governance & Naming Compliance

Description: A scheduled self-audit of the Blink automation tenant itself. Every four hours, the workflow lists all playbooks via the Blink API, validates each name against the team's naming convention, and posts a Teams alert when non-compliant workflow names are found.

Business problem solved: Keeps the growing automation footprint auditable and consistent as new workflows are built across 27 workspaces, catching naming standard violations automatically instead of relying on manual review during promotion or audit.

Integrations: Blink API (self-referential), Microsoft Teams

Category: GRC | Subcategory: DevSecOps compliance

Playbook Executions (12 mo) Role
regex trigger 237 Every 4 hours: lists playbooks, validates naming, alerts Teams on violations

Key Observations

Strengths

1. Scale of SOAR automation is exceptional.

The core SOAR platform processed 57,762 alerts and 11,552 case syncs in 12 months — together representing ~69K automated security operations events handled without analyst queuing. This is the largest concentration of value in the tenant and indicates a fully operational, high-volume case management platform.

2. Deep OT/IT integration is a differentiator.

The integration of Claroty CTD, XDome, Sumo Logic, ServiceNow, and Oracle into a single automated pipeline is technically complex and rarely seen at this depth. With 978 Claroty alerts auto-resolved and 152 SNOW health incidents auto-created, the C&I team has automated the most time-consuming parts of OT incident management across a multi-site estate.

3. Multi-team platform adoption.

The 27 distinct workspaces reflect genuine multi-team adoption — SOC, OT/C&I, infrastructure, DevOps, and managed services teams all have their own automation footprint. The Infra DevOps WorkItem Update and AET DevOps WorkItem Update flows (495 executions combined) demonstrate that value extends beyond security into engineering operations.

4. Mature credential and access management automation.

The combination of Keeper Secrets Manager integration, Cyolo MSRA group synchronization, and N-Central site standardization workflows represents a sophisticated, end-to-end automated credential lifecycle for managed service environments — a capability that typically requires significant manual operational overhead.

5. LLM integration is in active production.

The RA-LLM Request Model Agnostic workflow ran 23 times, indicating live AI-assisted operations (DevOps comment summarization). This positions the team ahead of the curve on AI-augmented operations.

Gaps & Opportunities

1. CVE pipeline has zero executions despite complete build-out.

The CTD CVE ETL pipeline (9 workflows across 3 workspaces) has never run in production. Given the OT vulnerability posture implications, activating this pipeline would immediately extend the value story into quantifiable vulnerability management.

2. SOC enrichment library is built but idle.

27 enrichment workflows in the main SOAR workspace have zero executions. These are designed as subflows called by Process Alert, but if the observable enrichment pipeline is not routing correctly, a significant capability investment is going unutilized.

3. Cisco SmartNet & firmware automation under-scheduled.

The PROD firmware and coverage workflows run only 6 times per year (weekly on two workflows). Given the breadth of the multi-SN coverage check tooling (16 workflows across 4 workspaces), there is an opportunity to expand scheduled execution and integrate results into a reporting dashboard.

4. Network auditing workflows not yet in production.

Network Configuration Audit, Remediation, Network Alert Triage, and Forescout dashboard workflows have no executions. These represent substantial capability investment that could deliver value if activated with the right device inventory inputs.

5. Staging pipeline visibility.

The SOC Development workspace (0605b8ff) runs several workflows in parallel with production (b3bdd488, 20e0b237), suggesting a multi-stage promotion pipeline. Clearer workspace naming conventions and execution metrics per stage would make promotion progress easier to track.

Integration Ecosystem

Domain Integrations
OT/ICS Claroty CTD, XDome, Cyolo (MSRA), Cisco API (SmartNet), FortiGate (POC)
SIEM / Logging Sumo Logic
ITSM ServiceNow, Oracle ITSM
Endpoint / EDR CrowdStrike (RTR, isolation, hash lookup)
Identity Okta, Microsoft Entra ID, Active Directory, Google Workspace, GitHub, Slack
Threat Intel VirusTotal, URLScan, AbuseIPDB, Whois
Cloud Azure Storage (AzCopy), Azure DevOps, VMware vSphere, AWS S3
Managed Services N-able N-Central, N-able Cove, Keeper Secrets Manager
Collaboration Microsoft Teams, Microsoft Outlook, SharePoint, Smartsheet
AI / LLM Azure OpenAI (model-agnostic wrapper supporting Claude and OpenAI)
Scripting PowerShell, Python, Ansible, WinRM, SSH, Bash
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
rockwell_c-i_management power-bi ml_powerbi 2026-08-18