01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SOAR & Security Case Management |
| 40.0% | 20 20 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 27 27 active |
| Phishing & Malware Response | 0 executions | 0.0% | 6 6 active |
| OT Asset Monitoring & SIEM Incident Management |
| 0.2% | 22 19 active |
| OT CVE & Vulnerability Extraction | 0 executions | 0.0% | 0 0 active |
| ITSM Automation — ServiceNow & Oracle |
| 0.0% | 1 1 active |
| Cisco Network Device SmartNet & Firmware Management | 6 executions | 0.0% | 5 5 active |
| MSRA / Cyolo OT Remote Access Management | 25 executions | 0.0% | 10 10 active |
| N-Central / N-able Managed Services Platform |
| 11.5% | 46 44 active |
| Azure Storage Artifact Repository | 9 executions | 0.0% | 9 9 active |
| DevOps & Teams Notification Automation | 535 executions | 0.3% | 9 8 active |
| Network Infrastructure Auditing & Remediation | 0 executions | 0.0% | 9 9 active |
| VM Infrastructure Management | 1 executions | 0.0% | 9 9 active |
| GRC & Automation Intake | 0 executions | 0.0% | 3 3 active |
| Automation Governance & Naming Compliance |
| 0.1% | 1 1 active |
| Total | 89,992 executions | 100% | 177 171 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Scale of SOAR automation is exceptional.
The core SOAR platform processed 57,762 alerts and 11,552 case syncs in 12 months — together representing ~69K automated security operations events handled without analyst queuing. This is the largest concentration of value in the tenant and indicates a fully operational, high-volume case management platform.
2. Deep OT/IT integration is a differentiator.
The integration of Claroty CTD, XDome, Sumo Logic, ServiceNow, and Oracle into a single automated pipeline is technically complex and rarely seen at this depth. With 978 Claroty alerts auto-resolved and 152 SNOW health incidents auto-created, the C&I team has automated the most time-consuming parts of OT incident management across a multi-site estate.
3. Multi-team platform adoption.
The 27 distinct workspaces reflect genuine multi-team adoption — SOC, OT/C&I, infrastructure, DevOps, and managed services teams all have their own automation footprint. The Infra DevOps WorkItem Update and AET DevOps WorkItem Update flows (495 executions combined) demonstrate that value extends beyond security into engineering operations.
4. Mature credential and access management automation.
The combination of Keeper Secrets Manager integration, Cyolo MSRA group synchronization, and N-Central site standardization workflows represents a sophisticated, end-to-end automated credential lifecycle for managed service environments — a capability that typically requires significant manual operational overhead.
5. LLM integration is in active production.
The RA-LLM Request Model Agnostic workflow ran 23 times, indicating live AI-assisted operations (DevOps comment summarization). This positions the team ahead of the curve on AI-augmented operations.
###
Gaps & Opportunities
1. CVE pipeline has zero executions despite complete build-out.
The CTD CVE ETL pipeline (9 workflows across 3 workspaces) has never run in production. Given the OT vulnerability posture implications, activating this pipeline would immediately extend the value story into quantifiable vulnerability management.
2. SOC enrichment library is built but idle.
27 enrichment workflows in the main SOAR workspace have zero executions. These are designed as subflows called by Process Alert, but if the observable enrichment pipeline is not routing correctly, a significant capability investment is going unutilized.
3. Cisco SmartNet & firmware automation under-scheduled.
The PROD firmware and coverage workflows run only 6 times per year (weekly on two workflows). Given the breadth of the multi-SN coverage check tooling (16 workflows across 4 workspaces), there is an opportunity to expand scheduled execution and integrate results into a reporting dashboard.
4. Network auditing workflows not yet in production.
Network Configuration Audit, Remediation, Network Alert Triage, and Forescout dashboard workflows have no executions. These represent substantial capability investment that could deliver value if activated with the right device inventory inputs.
5. Staging pipeline visibility.
The SOC Development workspace (0605b8ff) runs several workflows in parallel with production (b3bdd488, 20e0b237), suggesting a multi-stage promotion pipeline. Clearer workspace naming conventions and execution metrics per stage would make promotion progress easier to track.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| OT/ICS | Claroty CTD, XDome, Cyolo (MSRA), Cisco API (SmartNet), FortiGate (POC) |
| SIEM / Logging | Sumo Logic |
| ITSM | ServiceNow, Oracle ITSM |
| Endpoint / EDR | CrowdStrike (RTR, isolation, hash lookup) |
| Identity | Okta, Microsoft Entra ID, Active Directory, Google Workspace, GitHub, Slack |
| Threat Intel | VirusTotal, URLScan, AbuseIPDB, Whois |
| Cloud | Azure Storage (AzCopy), Azure DevOps, VMware vSphere, AWS S3 |
| Managed Services | N-able N-Central, N-able Cove, Keeper Secrets Manager |
| Collaboration | Microsoft Teams, Microsoft Outlook, SharePoint, Smartsheet |
| AI / LLM | Azure OpenAI (model-agnostic wrapper supporting Claude and OpenAI) |
| Scripting | PowerShell, Python, Ansible, WinRM, SSH, Bash |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Shared_Workspace | 1 | 0 | 0 | N/A |
| Case_Management_Playground | 1 | 0 | 0 | N/A |
B AI Agents 2 active | 16 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Teresa | RA-Cyolo-Integration-Prod | 11 | 0 | 106,147 |
| 2 | BlinkOps Workflow Troubleshooting Agent | Shared_Workspace | 5 | 0 | 596,643 |
| 3 | Agent Blink | Shared_Workspace | 0 | 0 | 0 |
| 4 | Agent Blink | Case_Management_Playground | 0 | 0 | 0 |
| 5 | Agent Mason | Shared_Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| RA-Cyolo-Integration-Prod | 11 |
| Shared_Workspace | 5 |
| Case_Management_Playground | 0 |
| Anthony.Rice@rockwellautomation.com | 0 |
| Tarani.Debnath@rockwellautomation.com | 0 |
C Self-Service & Webforms 0 app runs | 175 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Intake Form Dashboard2 | 0 | 0 |
| 2 | Runner-Status | 0 | 0 |
| 3 | Toms Example | 0 | 0 |
| 4 | Network Device Compliance Dashboard | 0 | 0 |
| 5 | Corey SW | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Start | 147 | 147 |
| 2 | MSRA Tenant onboarding process | 27 | 22 |
| 3 | Select Site name | 1 | 1 |
| 4 | Cisco Multi-SN Contract Coverage Check | 0 | 0 |
| 5 | Cisco Multi-SN Contract Coverage Check | 0 | 0 |
D Full Use Case Analysis 14 use cases | 172,700 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-processed and case-correlated | 57,762 | Process Alert |
| Case data synchronizations pushed to downstream systems | 11,552 | Sync Case Details |
| N-Central script executions orchestrated end-to-end | 3,031 | N-Central Script Execution Wrapper / N-Central Script Execution Wrapper (fa8601a4) |
| OT/IT alarms auto-processed end-to-end via ServiceNow | 1,794 | 1.0 Alarm Intake with SNOW / 2.0 - Alarm Processing with SNOW |
| Critical CPU/Memory alarms auto-triaged | 1,782 | CPU/Memory - Critical |
| Claroty OT alerts automatically resolved | 978 | SubFlow Claroty CTD Resolve Alert |
| DevOps work item change notifications routed to Teams | 495 | Infra DevOps WorkItem Update / AET DevOps WorkItem Update |
| Workflow naming-governance checks run automatically | 237 | regex trigger |
| Server alerts received and auto-processed | 179 | Server Alert |
| OT device health incidents auto-created in ServiceNow | 152 | Create SNOW Health Incident |
| Stale OT security alerts automatically archived | 105 | Claroty CTD Archive Old Alerts v2 |
| Remote access proxy configurations generated on demand | 61 | Ra proxy web form |
| Omni Bot AI expertise queries answered end-to-end | 52 | EM_LLM_API |
| OT remote access group synchronizations completed | 44 | KraftMSRAGroupSyncAutomatic |
| Automated server availability checks run | 40 | Monitor Server Alert Event |
| Security incidents escalated to ServiceNow | 22 | Create SNOW Security Case |
| Claroty CTD license, certificate, and health/version records compiled into customer time-savings dashboard | 20 | PROD_Unilever_License_CTD_BlinkTable / PROD_Unilever_Cert_BlinkTable / PROD_Unilever_CTD_Health_Version_BlinkTable |
| Remote access proxy build pipeline status emails sent automatically | 20 | Ra proxy web hook |
| ServiceNow incidents automatically resolved | 18 | Resolve SNOW Incidents |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks |
|---|---|---|---|---|
| 1 | SOAR & Security Case Management | SOC | Case mgmt & SOAR | 20 |
| 2 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 27 |
| 3 | Phishing & Malware Response | SOC | Phishing detection & response, EDR containment & response | 6 |
| 4 | OT Asset Monitoring & SIEM Incident Management | Other / SOC | IT/OT & network infra monitoring, SIEM & log pipeline monitoring | 95 |
| 5 | OT CVE & Vulnerability Extraction | Vulnerability Mgmt | Vuln scanning ingest & report | 10 |
| 6 | ITSM Automation — ServiceNow & Oracle | Other | IT helpdesk & ticket routing | 14 |
| 7 | Cisco Network Device SmartNet & Firmware | Other | IT/OT & network infra monitoring | 20 |
| 8 | MSRA / Cyolo OT Remote Access Management | IAM / GRC | Access review & group mgmt, Privileged account mgmt, Security metrics & reporting | 15 |
| 9 | N-Central / N-able Managed Services Platform | Other / IAM | IT/OT & network infra monitoring, Endpoint hygiene & MDM ops, Password & credential lifecycle | 51 |
| 10 | Azure Storage Artifact Repository | Cloud Security | Cloud asset coverage & inventory, Cloud provisioning & IaC automation | 13 |
| 11 | DevOps & Teams Notification Automation | Other | DevOps & release automation | 10 |
| 12 | Network Infrastructure Auditing & Remediation | Other | IT/OT & network infra monitoring | 10 |
| 13 | VM Infrastructure Management | Other / IAM | IT/OT & network infra monitoring, DevOps & release automation | 9 |
| 14 | GRC & Automation Intake | GRC | Security metrics & reporting | 4 |
| 15 | Automation Governance & Naming Compliance | GRC | DevSecOps compliance | 1 |
Use Cases
1. SOAR & Security Case Management
Description: A fully custom security case management and SOAR platform built on Blink's native case management module. Ingests alerts from all security tools every minute, extracts and deduplicates observables, correlates related alerts into cases, and routes each alert to the appropriate automated response playbook. The platform also provides analyst-facing utilities for case hygiene and observable lifecycle management.
Business problem solved: Replaces manual alert triage and ticket creation with an always-on ingestion engine that processes every alert, finds similar historical cases, and triggers response automation — eliminating the alert queue backlog and reducing mean time to respond.
Integrations: Blink Case Management, Microsoft Outlook, CrowdStrike, Okta, Active Directory / Entra ID, Google Workspace, GitHub, Slack, VirusTotal, URLScan, AbuseIPDB
Category: SOC | Subcategory: Case mgmt & SOAR
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Process Alert | 57,762 | Top-level alert ingestion, deduplication, case creation, routing |
| Sync Case Details | 11,552 | Polls case updates and pushes to downstream systems |
| Subflow - Response - Main Router | 0 | Routes to phishing/malware/identity response branches |
| Recovery - Handle Unprocessed Alerts | 0 | Finds and reprocesses alerts missed during downtime |
| Recovery - Enrich Non-Enriched Observables | 0 | Retroactively enriches observables missing context |
| Utility - Find Similar Cases Based on Observables | 0 | Similarity scoring across open cases |
| Utility - Close Stale Cases | 0 | Closes cases inactive for >1 month |
| Utility - Delete Observable Relation | 0 | Removes observable–alert relation |
| Utility - Set Or Update Observable Relation | 0 | Adds/updates observable–alert relation |
| Utility - List Observable Alert Relations | 0 | Lists alert relations for an observable |
| Utility - List Alert Observable Relations | 0 | Lists observable relations for an alert |
| Utility - Update Enrichment | 0 | Triggers enrichment router subflow |
| Table Action - Validate Observables Extraction Template | 0 | Validates extraction templates against known alert vendors |
| Subflow - Update Enrichment Data | 0 | Updates observable enrichment record in CM tables |
| Subflow - Missing Alert Template Notification | 0 | Notifies when no extraction template found for an alert type |
| Error Handling - Send Error Notification Email | 0 | Emails admin on workflow error |
| On Error, Email Admin | 0 | Error event trigger; emails admin |
| Simulate Crowdstrike Alert | 0 | Test: injects CrowdStrike alert payload |
| Simulate Multiple Alerts from Different Sources | 0 | Test: injects ProofPoint/CrowdStrike/Okta alerts |
| USE WITH CARE - Reset Case Management Environment | 0 | Admin: destroys all CM data for reset |
2. Alert Enrichment & IOC Lookup
Description: A comprehensive enrichment library attached to the SOAR platform. When the case management engine creates an observable (IP, hash, URL, username, domain), it routes it through a central enrichment router that dispatches to the appropriate vendor integration. Standalone callable versions of each enrichment are also available for analyst self-service.
Business problem solved: Provides instant context on every indicator — reputation, user identity, endpoint state — without requiring analysts to manually pivot across tools. Enrichment data flows directly into the case record for analyst review.
Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois (bash), DNS dig
Category: SOC | Subcategory: Alert enrichment / IOC lookup
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Subflow - Enrich Observables - Main Router | 0 | Routes enrichment requests by observable type |
| Enrich - Agent ID - Crowdstrike | 0 | Device lookup by CrowdStrike agent ID |
| Enrich - Hash - VT | 0 | File hash reputation via VirusTotal |
| Enrich - Hash - Crowdstrike | 0 | Hash search across CrowdStrike endpoints |
| Enrich - IP - VT | 0 | IP reputation via VirusTotal |
| Enrich - IP - IPDB | 0 | IP reputation via AbuseIPDB |
| Enrich - IP or Domain - Whois | 0 | Whois lookup |
| Enrich - URL - VT | 0 | URL scan via VirusTotal |
| Enrich - URL - URLScan | 0 | URL analysis via URLScan |
| Enrich - Username or Email - Okta | 0 | User details from Okta |
| Enrich - Username or Email - Microsoft Entra ID | 0 | User details + risky user status from Entra ID |
| Enrich - Username or Email - Google Workspace | 0 | User info from Google Workspace |
| Enrich - Username - Github | 0 | User info from GitHub |
| Enrich - Email Address - Slack | 0 | Slack user lookup by email |
| Get Hash Info Using VirusTotal | 0 | Standalone hash lookup — VirusTotal |
| Get Hash Info Using Crowdstrike | 0 | Standalone hash lookup — CrowdStrike |
| Okta Search for User Activity | 0 | Okta log search by user/IP/time |
| Get User Information Using Okta | 0 | Standalone user lookup — Okta |
| Get User Information Using Microsoft Entra ID | 0 | Standalone user lookup — Entra ID |
| Get User Information Using Google Workspace | 0 | Standalone user lookup — Google Workspace |
| Get User Information Using Github | 0 | Standalone user lookup — GitHub |
| Get User Information on Email Address Using Slack | 0 | Standalone user lookup — Slack |
| Enrich IP or Domain Using Whois | 0 | Standalone Whois lookup |
| Run Dig Command | 0 | DNS dig query |
| Analyze URL with URLScan | 0 | Standalone URL analysis — URLScan |
| Secure URL Screenshot Capture | 0 | Captures screenshot of suspicious URL |
| Get End of Life Date for a Product | 0 | Retrieves EOL/EOS date for product version |
3. Phishing & Malware Response
Description: Automated response playbooks that execute when the SOAR router classifies an alert as phishing or malware. The phishing branch retrieves the original email from Outlook and inspects headers to distinguish simulated phishing tests (KnowBe4) from real incidents before escalating. The malware branch checks CrowdStrike remediation status and responds accordingly. EDR containment capabilities (endpoint isolation, RTR scripting) are available for immediate host response.
Business problem solved: Replaces manual analyst triage on high-volume phishing and malware alerts with structured, automated response logic — ensuring consistent handling, reducing false-positive escalations, and enabling immediate EDR containment when needed.
Integrations: Microsoft Outlook, CrowdStrike (RTR, isolation), Slack, ServiceNow
Category: SOC | Subcategory: Phishing detection & response, EDR containment & response
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Response Subflow - Phishing | 0 | Retrieves email, checks KnowBe4 headers, routes real vs sim |
| Response Subflow - Malware | 0 | Checks CrowdStrike remediation status, branches response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Isolates or lifts isolation on a CrowdStrike endpoint |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs RTR command across a batch of hosts |
| CrowdStrike RTR to a Single Host | 0 | Runs RTR command on a single host |
| Isolate or Unisolate Device on CrowdStrike | 0 | Isolates/unisolates device, creates SNOW ticket, notifies via Slack |
4. OT Asset Monitoring & SIEM Incident Management
Description: The core operational technology (OT) security monitoring pipeline for Rockwell's C&I managed service. Claroty CTD sensors monitor industrial environments across multiple customer sites and generate security alerts. Blink continuously resolves, archives, and reports on these alerts, feeds asset inventory and metrics into Sumo Logic as the central SIEM, and triggers ServiceNow / Oracle ITSM ticket creation for incidents that require field response. XDome provides additional OT device inventory that is also fed to Sumo Logic.
Business problem solved: Bridges OT security platforms (Claroty CTD, XDome) with IT SIEM and ticketing systems (Sumo Logic, ServiceNow, Oracle) at scale across dozens of customer sites — replacing per-site manual intervention with automated data pipelines, alert lifecycle management, and incident creation.
Integrations: Claroty CTD, XDome, Sumo Logic, ServiceNow, Oracle ITSM, Microsoft Teams, SharePoint
Category: Other / SOC | Subcategory: IT/OT & network infra monitoring, SIEM & log pipeline monitoring
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| SubFlow Claroty CTD Resolve Alert (prod) | 918 | Resolves/closes a Claroty CTD alert with comment |
| SubFlow Claroty CTD Resolve Alert (20e0b) | 60 | Resolves Claroty CTD alert — second production workspace |
| Claroty CTD Archive Old Alerts v2 | 31 | Nightly: archives stale Claroty CTD alerts |
| Claroty CTD Archive Old Alerts (SOC Development) | 40 | SOC dev variant |
| Claroty CTD Archive Old Alerts v2 (SOC Development) | 34 | SOC dev variant v2 |
| SubFlow - Send Claroty Data To Sumo Webhook (20e0b) | 18 | Forwards Claroty telemetry batch to Sumo Logic |
| SubFlow - Send Claroty Data To Sumo Webhook (prod) | 4 | Prod variant |
| Sumo Logic - Insight Closure (20e0b) | 4 | Webhook: closes Sumo Logic insight; triggers Claroty/XDome closure |
| Subflow - Claroty - Close Alert Related To Sumo Insight (prod) | 3 | Closes Claroty alert linked to a resolved Sumo insight |
| Subflow - Claroty - Close Alert Related To Sumo Insight (20e0b) | 3 | 20e0b variant |
| Claroty CTD - Get Alert Count (20e0b) | 2 | Monthly: counts active Claroty alerts |
| Sumo Logic SIEM Enrichment Automation (20e0b) | 2 | Webhook: enriches Sumo Logic insights on creation/update |
| Subflow - XDome - Close Alert Related To Sumo Insight (20e0b) | 2 | Closes XDome alert linked to a resolved Sumo insight |
| Claroty CTD Get Site Version Workflow (20e0b) | 6 | Weekly: checks Claroty CTD version per site |
| Claroty CTD Get Site Version Workflow (SOC Dev) | 6 | SOC dev variant |
| Claroty_CTD_Execute_Site_Metrics_Assets (20e0b) | 1 | Monthly: per-site asset metrics to Sumo |
| Claroty_CTD_Execute_Site_Metrics_Assets (SOC Dev) | 1 | SOC dev variant |
| Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol | 1 | Monthly: unsecured protocol metrics per site |
| Claroty CTD - Get Alert Count (SOC Dev) | 1 | SOC dev variant |
| Sumo Logic - Insight Closure (prod) | 1 | Prod variant |
| Kraft Monthly Sumo Report | 1 | Monthly: Sumo Logic insights report → SharePoint |
| XDome Get Devices and Send to Sumo (20e0b) | 1 | Gets XDome devices, forwards to Sumo Logic |
| XDome Get Devices Related to Alerts and Send to Sumo (20e0b) | 1 | Correlates XDome devices with active alerts → Sumo |
| XDome Execution Scheduler | 1 | Monthly: triggers XDome data collection pipeline |
| Sumo Logic SIEM Enrichment Automation (prod) | 0 | Prod webhook listener (standby) |
| Sumo Logic SIEM Enrichment Automation (SOC Dev) | 0 | SOC dev variant |
| XDome Get Devices and Send to Sumo (prod) | 0 | Prod variant |
| XDome Get Devices Related to Alerts and Send to Sumo (prod) | 0 | Prod variant |
| SubFlow Claroty CTD Resolve Alert (SOC Dev) | 0 | SOC dev variant |
| Subflow - XDome - Close Alert Related To Sumo Insight (prod) | 0 | Prod variant |
| Subflow - Claroty - Close Alert Related To Sumo Insight (SOC Dev) | 0 | SOC dev variant |
| Subflow - XDome - Close Alert Related To Sumo Insight (SOC Dev) | 0 | SOC dev variant |
| Claroty_CTD_Get_Assets_With_Insights (prod) | 0 | Gets Claroty assets with associated Sumo insights |
| Claroty_CTD_Get_Assets_With_Insights_Reworked (20e0b) | 0 | Reworked variant |
| Claroty_Get Asset Unsecured Protocol From Baseline v3 (prod) | 0 | Gets assets using unsecured protocols vs baseline |
| Claroty_Get Asset Unsecured Protocol From Baseline v3 (20e0b) | 0 | 20e0b variant |
| Subflow - Claroty List Assets - Wrapper (prod) | 0 | Paginated asset list from Claroty CTD |
| Subflow - Claroty List Baselines - Wrapper (prod) | 0 | Paginated baseline list from Claroty CTD |
| Subflow - Claroty List Unsecured Protocols - Wrapper (prod) | 0 | Paginated unsecured protocol list from Claroty CTD |
| SubFlow Get Claroty Data (prod) | 0 | Fetches raw Claroty CTD data block |
| SubFlow - Send Claroty Data Iteratively To Sumo Webhook (prod) | 0 | Iterative batch sender to Sumo |
| SubFlow Send Claroty Asset Data Iteratively To Sumo (prod) | 0 | Asset-specific batch sender |
| SubFlow - Loop Through Array And Send Claroty Data To Sumo Webhook | 0 | Array loop for Sumo forwarding |
| Sumo Logic Create Oracle Ticket (prod) | 1 | Webhook: creates Oracle ITSM ticket from Sumo insight |
| Sumo Logic Create Oracle Ticket (20e0b) | 1 | 20e0b variant |
| Global-LLM-Workflow (C&I Development) | 0 | LLM proxy for C&I dev enrichment tasks |
| Global-LLM-Workflow (b3bdd488) | 0 | Reusable LLM proxy subflow (Environment/Message/Model/SystemPrompt inputs) via Run RA LLM Workflow |
| EM_LLM_API | 52 | On-demand: routes expertise/query input through Global-LLM-Workflow, returns Omni Bot answer |
| EM_LLM_API_NCENTRALDRAFT | 0 | Draft variant of Omni Bot query endpoint with conditional routing (N-Central-focused) |
| Global-LLM-Workflow (C&I Development) (1ab99233) | 0 | LLM proxy for C&I dev enrichment tasks |
| Large String LLM Summary (C&I Development) (1ab99233) | 0 | Chunked large-text summarization via Azure Foundry |
| Global-LLM-Workflow (C&I Development) (5644713c) | 0 | LLM proxy for C&I dev enrichment tasks |
| Global-LLM-Workflow (5644713c) | 1 | Reusable LLM proxy subflow (Environment/Message/Model/SystemPrompt inputs) via Run RA LLM Workflow |
| Large String LLM Summary (C&I Development) (5644713c) | 0 | Chunked large-text summarization via Azure Foundry |
| Global-LLM-Workflow (C&I Development) (22daa2e4) | 0 | LLM proxy for C&I dev enrichment tasks |
| Large String LLM Summary (C&I Development) (22daa2e4) | 0 | Chunked large-text summarization via Azure Foundry |
| Global-LLM-Workflow (C&I Development) (3b45f6fa) | 0 | LLM proxy for C&I dev enrichment tasks |
| Large String LLM Summary (C&I Development) (3b45f6fa) | 0 | Chunked large-text summarization via Azure Foundry |
| Global-LLM-Workflow (C&I Development) (009efb6c) | 0 | LLM proxy for C&I dev enrichment tasks |
| Large String LLM Summary (C&I Development) (009efb6c) | 0 | Chunked large-text summarization via Azure Foundry |
| Get Claroty KRI Data and Send To Sharepoint | 1 | Monthly: extracts Claroty KRI metrics, sends to SharePoint |
| SubFlow - Claroty CTD get entitiy baseline | 6 | Retrieves source baseline for a Claroty CTD alert |
| SubFlow - Claroty CTD get entitiy baseline (20e0b) | 1 | 20e0b variant |
| Create Monthly PowerPoint (prod) | 0 | Generates monthly OT reporting PowerPoint (in development) |
| Create Monthly PowerPoint (20e0b) | 0 | 20e0b variant: generates monthly OT reporting PowerPoint (in development) |
| Web Form Test | 0 | Test scaffold for interactive web form (no production logic) |
| SubFlow - Claroty CTD get events | 0 | Retrieves events for a Claroty CTD alert |
| SubFlow - Claroty CTD get events (20e0b) | 2 | 20e0b variant |
| Get KPI Data and Send To Sharepoint v2 (prod) | 0 | Monthly: extracts KPI metrics, sends to SharePoint |
| Get KPI Data and Send To Sharepoint v2 (20e0b) | 0 | Monthly (cron): extracts KPI metrics, sends to SharePoint — 20e0b variant |
| Populate Last Month KPI Data (prod) | 0 | Populates prior-month KPI data for SharePoint reporting |
| Populate Last Month KPI Data (20e0b) | 0 | 20e0b variant |
| Populate Last Last Month KPI (prod) | 0 | Populates two-months-prior KPI data for SharePoint reporting |
| Populate Last Last Month KPI (20e0b) | 0 | 20e0b variant |
| Get KRI Summary v2 (prod) | 0 | Monthly (cron): compiles KRI summary metrics |
| Get KRI Summary v2 (20e0b) | 0 | 20e0b variant |
| Populate Previous Month KRI Summary v2 (prod) | 0 | Populates prior-month KRI summary data |
| Populate Previous Month KRI Summary v2 (20e0b) | 0 | 20e0b variant |
| Populate Previous Previous Month KRI Summary v2 (prod) | 0 | Populates two-months-prior KRI summary data |
| Populate Previous Previous Month KRI Summary v2 (20e0b) | 0 | 20e0b variant |
| Global-LLM-Workflow (C&I Development) (20e0b) | 0 | LLM proxy for C&I dev enrichment tasks |
| Large String LLM Summary (C&I Development) (20e0b) | 0 | Chunked large-text summarization via Azure Foundry |
| Workflow Orchestrator | 12 | Webhook: Sumo Logic-triggered orchestrator with try/catch error handling |
| Workflow Orchestrator (20e0b) | 8 | 20e0b variant |
| SubFlow Sumo Logic - New Asset workflow | 7 | Handles new-asset events from Sumo Logic insights |
| SubFlow Sumo Logic - New Asset workflow (20e0b) | 2 | 20e0b variant |
| SubFlow Sumo Logic - Failed Login workflow | 0 | Handles failed-login events from Sumo Logic insights |
| SubFlow Sumo Logic - Failed Login workflow (20e0b) | 3 | 20e0b variant |
| New Workflow 3 | 0 | Test scaffold: web form file upload, prints only (no production logic) |
| SubFlow - Send Error Message Via Teams Reporting (20e0b) | 2 | Sends workflow error notifications via Microsoft Teams |
| SubFlow - Send Error Message Via Teams Reporting (prod) | 0 | Prod variant |
| HA Test | 40 | Daily: high-availability health check loop |
| PROD_Unilever_License_CTD_BlinkTable | 5 | Weekly: compiles Claroty CTD license data per site into time-savings table, emails report |
| PROD_Unilever_Cert_BlinkTable | 10 | On-demand: compiles Claroty CTD certificate data into time-savings dashboard |
| PROD_Unilever_CTD_Health_Version_BlinkTable | 5 | Weekly: checks Claroty CTD health/version across global regions, logs to time-savings table |
5. OT CVE & Vulnerability Extraction
Description: Automated ETL pipeline that extracts CVE and vulnerability data from Claroty CTD deployments across all customer sites on a scheduled basis, then ships the structured data to Sumo Logic for centralized vulnerability tracking and reporting. A Claroty TDMS patch check notification flow is also in place for proactive patch awareness.
Business problem solved: Eliminates manual CVE export and aggregation from distributed OT environments. Vulnerability data flows automatically into the SIEM, enabling consistent vulnerability posture reporting across the entire managed services portfolio without per-site analyst effort.
Integrations: Claroty CTD, Sumo Logic
Category: Vulnerability Mgmt | Subcategory: Vuln scanning ingest & report
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| CTD_CVE_ETL_Scheduler (prod) | 0 | Scheduled: triggers per-site CVE extraction |
| CTD_CVE_ETL_Scheduler (20e0b) | 0 | 20e0b variant |
| CTD_CVE_ETL_Scheduler (SOC Dev) | 0 | SOC dev variant |
| CTD_CVE_ETL_Site (prod) | 0 | Per-site CVE extraction subflow |
| CTD_CVE_ETL_Site (20e0b) | 0 | 20e0b variant |
| CTD_CVE_ETL_Site (SOC Dev) | 0 | SOC dev variant |
| Claroty CTD CVE Extraction Send To Sumo (prod) | 0 | Extracts CVEs and ships to Sumo Logic |
| Claroty CTD CVE Extraction Send To Sumo (20e0b) | 0 | 20e0b variant |
| Claroty CTD CVE Extraction Send To Sumo (SOC Dev) | 0 | SOC dev variant |
| _Claroty_TDMS_Patch_Check_Notification (POC) | 0 | POC: checks TDMS patch status and notifies |
6. ITSM Automation — ServiceNow & Oracle
Description: Webhook-driven workflows that automatically create and close incidents in ServiceNow and Oracle ITSM based on events from Sumo Logic and Claroty. Health incidents (device/service outages) and security cases are created without manual ticketing, and incident closure is synchronized back when the Sumo Logic insight is resolved.
Business problem solved: Removes manual ticket creation for OT health and security events across managed customer sites. Ensures that every Sumo Logic insight that requires field response immediately generates a tracked ITSM record.
Integrations: ServiceNow, Oracle ITSM, Sumo Logic (webhook)
Category: Other | Subcategory: IT helpdesk & ticket routing
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Create SNOW Health Incident (prod) | 123 | Webhook: creates SNOW health incident |
| Create SNOW Health Incident (20e0b) | 29 | 20e0b variant |
| Create SNOW Security Case (prod) | 12 | Webhook: creates SNOW security incident |
| Create SNOW Security Case (20e0b) | 10 | 20e0b variant |
| Oracle Get Incident and Close (20e0b) | 2 | Gets Oracle ITSM incident and closes on Sumo resolution |
| SNOW Get Case and Close (prod) | 0 | Gets SNOW case and closes based on Sumo insight |
| Oracle Get Incident and Close (prod) | 0 | Prod variant |
| Create SNOW Security Case (SOC Dev) | 0 | SOC dev variant |
| Resolve SNOW Incidents | 18 | Lists open SNOW incidents and resolves each in a loop |
| ServiceNow QA AI-Powered Ticket Assistance (58a6e767) | 0 | Web form: AI-generates a case summary or response draft for a given SNOW case number |
| ServiceNow QA AI-Powered Ticket Assistance (b3bdd488) | 0 | Web form variant: AI-generates a case summary or response draft for a given SNOW case number |
| ServiceNow QA AI-Powered Ticket Assistance (5644713c) | 1 | Single-step web form variant (dev SNOW connection) |
| Kill Blink Execution by SNOW ID (5644713c) | 0 | On-demand: terminates a running Blink execution tied to a SNOW ticket ID |
| Kill Blink Execution by SNOW ID (fa8601a4) | 0 | fa8601a4 variant |
7. Cisco Network Device SmartNet & Firmware Management
Description: A suite of automation workflows that check Cisco device SmartNet contract coverage and recommended firmware versions across the managed device estate. Devices are queried via SSH; the Cisco API is called to verify contract status and retrieve recommended software versions. Results are stored in Blink tables and surfaced via web forms and email. Cisco switch health checks via Ansible are also in development.
Business problem solved: Removes manual tracking of Cisco device contract expiration and firmware currency across a large, distributed device estate. Ensures proactive identification of out-of-support devices and devices running non-recommended firmware before they create audit or reliability risk.
Integrations: Cisco API (SmartNet), SSH, PowerShell, Ansible, email, web forms
Category: Other | Subcategory: IT/OT & network infra monitoring
8. MSRA / Cyolo OT Remote Access Management
Description: Manages the Managed Service Remote Access (MSRA) platform built on Cyolo for OT environments. Automatically synchronizes Active Directory groups with Cyolo local groups across all customer sites on a daily schedule, generates monthly access reports written to an MSSQL database, and provides health checks, software version queries, and upgrade automation for the Cyolo infrastructure.
Business problem solved: Eliminates manual AD group management for OT remote access permissions across a multi-site environment, and provides automated monthly reporting on remote access activity without requiring analyst intervention.
Integrations: Cyolo, Active Directory, PowerShell, MSSQL, Blink tables
Category: IAM / GRC | Subcategory: Access review & group mgmt, Privileged account mgmt, Security metrics & reporting
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| KraftMSRAGroupSyncAutomatic (prod) | 44 | Daily: syncs OT AD groups with Cyolo across sites |
| MSRA Reports SQL Insert | 14 | Inserts MSRA report row into MSSQL |
| MSRAHealthCheck | 5 | Health check across all MSRA tenants via PowerShell |
| MSRA Reports Generate (prod) | 1 | Monthly: generates MSRA reports, writes to MSSQL |
| KraftMSRAGroupSyncAutomatic (on-demand) | 0 | On-demand sync variant |
| MSRA Reports Generate (on-demand) | 0 | On-demand variant |
| MSRA Reports SQL Insert (on-demand) | 0 | On-demand variant |
| CyoloLicenceGet | 0 | Gets Cyolo license info from table records |
| CyoloSoftwareUpgrade | 0 | Upgrades Cyolo software across multi-tenant deployment |
| Cyolo MSRA get software version self Service trigger | 0 | Self-service: gets Cyolo software version |
| _BlinkStandarizationWindowsServiceAccount | 0 | Creates Windows service account via WinRM |
| CYOLO Application Import - WebForm Production | 5 | Web form: imports Cyolo credential/parameter CSVs, provisions via PowerShell |
| Simple Group Creation | 2 | Web form: imports group/credential CSVs, creates groups via PowerShell |
| Dynamic Group Creation | 2 | Web form: imports group/credential CSVs, creates AD groups dynamically via PowerShell |
| 1. MSRA - Tenant onboarding | 1 | Web form: onboards a new Cyolo MSRA tenant by URL |
9. N-Central / N-able Managed Services Platform
Description: A comprehensive automation platform supporting Rockwell's N-able N-Central–based managed services operations. Covers server alert ingestion and deduplication, daily server availability monitoring, remote access proxy configuration generation (RA proxy OVA), N-Central device and OU synchronization, automated endpoint script execution via N-Central, credential lifecycle management via Keeper Secrets Manager, N-able Cove backup administration, and an end-to-end alarm intake/processing pipeline that raises N-Central threshold alarms (disk, connectivity, CPU/memory) as ServiceNow incidents.
Business problem solved: Automates the repetitive operational work of a multi-site managed services NOC — server alert processing, device inventory synchronization, endpoint script queuing, credential management, and alarm-to-incident ticketing — while maintaining auditability via MSSQL and Blink tables.
Integrations: N-able N-Central, N-able Cove, Keeper Secrets Manager, ServiceNow, PowerShell, MSSQL, SSH, Blink tables
Category: Other / IAM | Subcategory: IT/OT & network infra monitoring, Endpoint hygiene & MDM ops, Password & credential lifecycle
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Server Alert | 179 | Webhook: receives server alert, deduplicates, stores CSV |
| Monitor Server Alert Event | 40 | Daily: checks all servers have checked in, flags missing |
| Ra proxy web form | 61 | Self-service web form: generates RA proxy OVA config |
| N-Central Script Execution | 14 | Event-triggered: queues and executes N-Central scripts |
| Download N-Central Script Output | 11 | Downloads and parses N-Central script execution output |
| Catch Keeper Credential Event | 3 | Webhook: routes Keeper credential create/update/delete events |
| N-CentralDeviceSync | 0 | Syncs all devices from N-Central (paginated) |
| N-CentralOUSyncAll | 0 | Syncs all N-Central Organization Units |
| N-CentralOUSyncSingle | 0 | Syncs a single N-Central OU chunk |
| N-CentralFilterSyncAll | 0 | Syncs all N-Central device filters |
| N-CentralFilterSyncSingle | 0 | Syncs single filter (create/update/delete) |
| _Execute-N-AbleSync | 0 | Loops monitoring platform records and triggers sync |
| N-Central Build SiteList Global Variable | 0 | Builds global variable with all N-Central sites JSON |
| n-CentralSiteSelectionOneTimeStandarization | 0 | Web form: selects site, creates Keeper folder structure, creates Windows service account |
| On-Demand Bulk Site Credential Sync | 0 | On-demand sync of site credentials to Keeper |
| On-Demand Keeper Credential Structure Build Out | 0 | Creates Keeper folder structure and syncs credentials |
| Connection Creation Method | 0 | Creates Blink connection from Keeper credential record |
| Connection Update Method | 0 | Updates Blink connection from updated Keeper credential |
| Connection Deletion Method | 0 | Deletes credential–connection mapping |
| keeperFoldersRecordNormalization | 0 | Normalizes Keeper folder/record data |
| Generate ssh key | 7 | Generates SSH key pair, stores public/private keys in Keeper Secrets Manager |
| Create N-Central Execution Record | 0 | Queues N-Central script execution record |
| Cleanup N-Central Script Executions | 0 | Cleans up stale execution records |
| CRUD Operation for user in N-able Cove | 0 | Create/read/update/delete user in N-able Cove |
| Create Delete operation for customer in N-able cove | 0 | CRUD for customer record in N-able Cove |
| CRUD operation for Site in N-able Cove | 0 | CRUD for site in N-able Cove |
| N-Central Script Execution Wrapper | 50 | Wraps N-Central script execution: queues, polls, returns raw output |
| Execution Error Handling | 4 | Error event handler: fetches failed workflow inputs, notifies |
| Disk - Critical | 0 | N-Central disk critical threshold alert handler |
| Connect - Critical | 0 | N-Central connectivity critical threshold alert handler |
| Disk - Warning | 0 | N-Central disk warning threshold alert handler |
| Connect - Warning | 0 | N-Central connectivity warning threshold alert handler |
| CPU/Memory - Warning | 0 | N-Central CPU/memory warning threshold alert handler |
| CPU/Memory - Critical | 1,782 | N-Central CPU/memory critical threshold handler: identifies top offending process, notifies |
| 1.0 Alarm Intake with SNOW | 1,791 | On-demand: receives alarm payload, creates ServiceNow incident |
| 2.0 - Alarm Processing with SNOW | 1,794 | Polls new ServiceNow incident records, processes alarm |
| Execution Error Handling with SNOW Payload | 53 | Error event handler: fetches failed execution payload, updates SNOW incident |
| Execution Error Handling (fa8601a4) | 20 | Error event handler: fetches failed workflow inputs, notifies |
| N-Central Script Execution (fa8601a4) | 2,987 | Event-triggered: queues and executes N-Central scripts |
| Create N-Central Execution Record (fa8601a4) | 2,981 | Queues N-Central script execution record |
| N-Central Script Execution Wrapper (fa8601a4) | 2,981 | Wraps N-Central script execution: queues, polls, returns raw output |
| Download N-Central Script Output (fa8601a4) | 2,879 | Downloads and parses N-Central script execution output |
| Ra proxy web hook | 20 | Webhook: receives Azure DevOps pipeline result for RA proxy build, emails status |
| PROD_PepsiCo_NABLE_SiteList_BlinkTable copy | 2 | Builds PepsiCo regional site list from N-Central org units into Blink table |
| PROD_PepsiCo_NABLE_SiteList_BlinkTable (VERSION2) | 0 | Builds PepsiCo LATAM/NABQ regional site list from N-Central org units into Blink table |
| PROD_PepsiCo_NABLE_SiteList_BlinkTable (VERSION3) | 1 | Rebuilds PepsiCo site list, reading and writing back to the PepsiCo site table |
| PROD_PepsiCo_Get_Table | 6 | Retrieves records from the PepsiCo site table |
| New Workflow 7 | 0 | On-demand utility: reads a source table's schema/records and prepares a table-creation payload for a target workspace |
| PepsiCo_Backup_CSV_Verification | 0 | Reconciles Azure-backed CSV site data against PepsiCo site table, skipping duplicates |
| Unilever_N-Central Get Memory Metrics | 0 | On-demand: runs N-Central script to collect device memory metrics, emails HTML report |
| BlinkGetWorkspaceTableRecords | 7 | Reusable utility: paginates through a Blink workspace table to return all records |
10. Azure Storage Artifact Repository
Description: Manages a centralized Azure Storage artifact repository used to store and distribute firmware, software packages, and tooling artifacts across managed customer sites. Workflows automate the inventory of stored blobs, generate AzCopy upload/download scripts, manage artifact quarantine workflows, and refresh the local artifact table on demand.
Business problem solved: Provides a version-controlled, auditable artifact distribution mechanism for firmware and software across OT environments — replacing manual file transfers and ad-hoc tooling.
Integrations: Azure Storage, AzCopy, Python, PowerShell
Category: Cloud Security | Subcategory: Cloud asset coverage & inventory, Cloud provisioning & IaC automation
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Azure Storage Upload - Create Upload Script | 16 | Generates AzCopy upload script with quarantine metadata |
| Azure Storage File Download - GetAZCopy & RunAZCopy | 12 | Downloads file from Azure Storage via AzCopy |
| Azure Storage - Refresh Table OnDemand | 9 | On-demand refresh of artifact inventory table |
| PROD_UPDATETABLE_RAAUTOSTORAGE | 6 | Weekly: lists blobs, updates artifact inventory table |
| Azure Storage Delete - Delete File | 1 | Deletes a file from Azure Storage by path |
| PROD_RAAUTOSTORAGE_UploadToQuarantine | 0 | Generates upload-to-quarantine script |
| PROD_RAAUTOSTORAGE Upload to Quarantine (d877f) | 0 | d877f workspace variant |
| PROD_Azure_Storage_GetAZCopy_+_GetAZCopyCommand_BLOB (58a6e) | 0 | Generates AzCopy BLOB download command |
| PROD_Azure_Storage_GetAZCopy_+_GetAZCopyCommand_BLOB (d877f) | 0 | d877f variant |
| Azure_MetaData_Update (DRAFT WEBFORM) | 0 | Draft: web form to update artifact metadata |
| Clone ADO and Push to GitHub | 0 | Clones Azure DevOps repo and pushes to GitHub |
| NULL_Azure_Storage_RunTransferCommand_FILE | 0 | POC: AzCopy file transfer via SSH to Windows host |
| NULL_Azure_Storage_Transfer_File (POC) | 0 | POC: table-driven file transfer to Azure Storage |
11. DevOps & Teams Notification Automation
Description: Bridges Azure DevOps work item activity with Microsoft Teams channels for two internal engineering teams (Infrastructure and AET). Any work item update in Azure DevOps triggers an instant Teams notification to the appropriate channel. An LLM-powered workflow summarizes recent DevOps comments via Azure OpenAI and posts digests to Teams, and a Smartsheet-connected intake workflow routes new automation project requests into the backlog.
Business problem solved: Eliminates the need for engineers to monitor ADO manually for work item changes, reduces context-switching, and ensures teams stay informed of project state in real time. LLM-based comment summarization reduces the overhead of parsing long DevOps threads.
Integrations: Azure DevOps, Microsoft Teams, Azure OpenAI / LLM, Smartsheet
Category: Other | Subcategory: DevOps & release automation
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Infra DevOps WorkItem Update | 285 | Teams webhook: forwards ADO work item updates to Infra channel |
| AET DevOps WorkItem Update | 210 | Teams webhook: forwards ADO work item updates to AET channel |
| RA-LLM Request Model Agnostic | 23 | Model-agnostic LLM wrapper (Claude/OpenAI); used for summarization |
| Summarize DevOps Comments | 0 | Gets ADO comments, LLM-summarizes, posts to Teams |
| Add new Feature to current PI | 0 | Adds new ADO feature to current Program Increment |
| Sync All Records From DevOps | 0 | Loops all ADO work items and syncs to Blink table |
| Sync a Single DevOps Work Item To Blink Table | 0 | Syncs one ADO work item to table |
| Smartsheet Project Intake | 0 | Gets Smartsheet row, routes to intake workflow |
| RA-LLM Request OpenAI | 0 | Model-specific LLM wrapper for Azure OpenAI |
| TeamsTesting | 0 | Test scaffold: exercises Microsoft Teams user lookup and direct-reports API calls |
12. Network Infrastructure Auditing & Remediation
Description: Workflows for auditing and remediating network device configurations across the managed estate. Python-based configuration audits pull device configs and flag deviations; Ansible-based remediation applies fixes. Forescout integration provides asset inventory with a self-service HTML dashboard. Network connectivity testing tools support rapid diagnostics.
Business problem solved: Provides automated network configuration compliance checking and remediation across distributed environments, replacing manual config reviews with consistent, repeatable tooling.
Integrations: Python, Ansible, Forescout, NetBox (simulated), SSH, bash
Category: Other | Subcategory: IT/OT & network infra monitoring
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Network Configuration Audit | 0 | Audits network device configs via Python/NetBox |
| Network Configuration Audit Table Test | 0 | Table-driven test version of audit |
| Network Configuration Remediation | 0 | Remediates device config issues via Ansible |
| On-Demand: Update Network Device Global Variable | 0 | Updates network device global variable from table |
| Network Alert Triage | 0 | Triages network alerts via SSH and Python tools |
| Probe Forescout and Build Asset Summary Dashboard | 0 | Queries Forescout, builds HTML asset summary dashboard |
| Network Connectivity Test To Host | 0 | Tests DNS, ping, SSH/HTTP/HTTPS/traceroute to target host |
| Run Ansible Playbook To Query Cisco Switch | 0 | Runs Ansible playbook to query Cisco switch |
| Run Ansible Playbook | 0 | Generic Ansible playbook runner |
| Update FortiGate Firmware (POC) | 0 | POC: installs firmware on FortiGate via API |
13. VM Infrastructure Management
Description: VMware vSphere management automation covering VM disk expansion, reboots, user provisioning, and OS deployment. Disk expansion requests require Teams-based approval before execution, with state saved to S3. Ubuntu VM deployment includes full post-deployment Ansible configuration (k3s, squid proxy). User add/remove flows for VMs round out the IAM lifecycle.
Business problem solved: Provides self-service and automated VM lifecycle operations for engineering teams, reducing dependency on infrastructure admins for routine changes while enforcing approval gates on impactful operations like disk expansion.
Integrations: VMware vSphere (PowerCLI), AWS S3, Microsoft Teams, Ansible
Category: Other / IAM | Subcategory: IT/OT & network infra monitoring, DevOps & release automation, Employee onboarding/offboarding
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Expand VM Disk Capacity | 0 | Expands VM disk via PowerCLI; Teams approval required |
| VM reboot request | 0 | Reboots named VM via PowerCLI |
| Add User to VM via PowerCLI | 0 | Adds user account to VM if not already present |
| Remove User from VM via PowerCLI | 0 | Removes user from VM, notifies via Teams |
| Deploy Ubuntu 22 - Install k3s and squid container | 0 | Deploys Ubuntu 22 VM and configures via Ansible |
| PowerCLI Custom Actions | 0 | Creates new VM from template via PowerCLI |
| SiteContactsCompateAndUpdate | 0 | Syncs SharePoint customer list with Blink table |
| SOCSiteContactsCompareAndUpdate | 0 | SOC-specific SharePoint contact sync |
| VMWare License Automation | 1 | Monthly: checks and reports VMware vSphere license status |
14. GRC & Automation Intake
Description: Provides a structured intake process for new automation requests from the C&I security team, routing requests from public web forms and Smartsheet into a scored backlog. Automation Request Form submissions are stored, acknowledged via email, and tracked for prioritization. Monthly MSRA and Sumo Logic reports contribute to a consistent security metrics posture.
Business problem solved: Standardizes how automation ideas are captured and evaluated — replacing ad-hoc Slack/email requests with a formalized intake process tied to a backlog, ensuring alignment with engineering capacity.
Integrations: Web form, Smartsheet, email, Blink tables
Category: GRC | Subcategory: Security metrics & reporting
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| Automation Request Form Workflow | 6 | Public web form intake: stores request, sends email acknowledgment |
| Smartsheet Project Intake | 0 | Gets Smartsheet row, routes through Unified Intake Workflow |
| Unified Intake Workflow | 0 | Stores intake request scoring data to table |
| MSRA Reports Generate (prod) | 1 | Monthly MSRA access report — see UC8 |
15. Automation Governance & Naming Compliance
Description: A scheduled self-audit of the Blink automation tenant itself. Every four hours, the workflow lists all playbooks via the Blink API, validates each name against the team's naming convention, and posts a Teams alert when non-compliant workflow names are found.
Business problem solved: Keeps the growing automation footprint auditable and consistent as new workflows are built across 27 workspaces, catching naming standard violations automatically instead of relying on manual review during promotion or audit.
Integrations: Blink API (self-referential), Microsoft Teams
Category: GRC | Subcategory: DevSecOps compliance
| Playbook | Executions (12 mo) | Role |
|---|---|---|
| regex trigger | 237 | Every 4 hours: lists playbooks, validates naming, alerts Teams on violations |
Key Observations
Strengths
1. Scale of SOAR automation is exceptional.
The core SOAR platform processed 57,762 alerts and 11,552 case syncs in 12 months — together representing ~69K automated security operations events handled without analyst queuing. This is the largest concentration of value in the tenant and indicates a fully operational, high-volume case management platform.
2. Deep OT/IT integration is a differentiator.
The integration of Claroty CTD, XDome, Sumo Logic, ServiceNow, and Oracle into a single automated pipeline is technically complex and rarely seen at this depth. With 978 Claroty alerts auto-resolved and 152 SNOW health incidents auto-created, the C&I team has automated the most time-consuming parts of OT incident management across a multi-site estate.
3. Multi-team platform adoption.
The 27 distinct workspaces reflect genuine multi-team adoption — SOC, OT/C&I, infrastructure, DevOps, and managed services teams all have their own automation footprint. The Infra DevOps WorkItem Update and AET DevOps WorkItem Update flows (495 executions combined) demonstrate that value extends beyond security into engineering operations.
4. Mature credential and access management automation.
The combination of Keeper Secrets Manager integration, Cyolo MSRA group synchronization, and N-Central site standardization workflows represents a sophisticated, end-to-end automated credential lifecycle for managed service environments — a capability that typically requires significant manual operational overhead.
5. LLM integration is in active production.
The RA-LLM Request Model Agnostic workflow ran 23 times, indicating live AI-assisted operations (DevOps comment summarization). This positions the team ahead of the curve on AI-augmented operations.
Gaps & Opportunities
1. CVE pipeline has zero executions despite complete build-out.
The CTD CVE ETL pipeline (9 workflows across 3 workspaces) has never run in production. Given the OT vulnerability posture implications, activating this pipeline would immediately extend the value story into quantifiable vulnerability management.
2. SOC enrichment library is built but idle.
27 enrichment workflows in the main SOAR workspace have zero executions. These are designed as subflows called by Process Alert, but if the observable enrichment pipeline is not routing correctly, a significant capability investment is going unutilized.
3. Cisco SmartNet & firmware automation under-scheduled.
The PROD firmware and coverage workflows run only 6 times per year (weekly on two workflows). Given the breadth of the multi-SN coverage check tooling (16 workflows across 4 workspaces), there is an opportunity to expand scheduled execution and integrate results into a reporting dashboard.
4. Network auditing workflows not yet in production.
Network Configuration Audit, Remediation, Network Alert Triage, and Forescout dashboard workflows have no executions. These represent substantial capability investment that could deliver value if activated with the right device inventory inputs.
5. Staging pipeline visibility.
The SOC Development workspace (0605b8ff) runs several workflows in parallel with production (b3bdd488, 20e0b237), suggesting a multi-stage promotion pipeline. Clearer workspace naming conventions and execution metrics per stage would make promotion progress easier to track.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| OT/ICS | Claroty CTD, XDome, Cyolo (MSRA), Cisco API (SmartNet), FortiGate (POC) |
| SIEM / Logging | Sumo Logic |
| ITSM | ServiceNow, Oracle ITSM |
| Endpoint / EDR | CrowdStrike (RTR, isolation, hash lookup) |
| Identity | Okta, Microsoft Entra ID, Active Directory, Google Workspace, GitHub, Slack |
| Threat Intel | VirusTotal, URLScan, AbuseIPDB, Whois |
| Cloud | Azure Storage (AzCopy), Azure DevOps, VMware vSphere, AWS S3 |
| Managed Services | N-able N-Central, N-able Cove, Keeper Secrets Manager |
| Collaboration | Microsoft Teams, Microsoft Outlook, SharePoint, Smartsheet |
| AI / LLM | Azure OpenAI (model-agnostic wrapper supporting Claude and OpenAI) |
| Scripting | PowerShell, Python, Ansible, WinRM, SSH, Bash |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| rockwell_c-i_management | power-bi | ml_powerbi | 2026-08-18 |