01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Security Alert Enrichment & EDR Response |
| 55.2% | 27 27 active |
| Phishing & Suspicious Email Triage |
| 0.6% | 7 6 active |
| CSIRT Incident Operations & Shift Handoff |
| 3.9% | 16 15 active |
| Atlassian Access Revocation |
| 3.3% | 2 1 active |
| Password & Credential Resets |
| 0.1% | 3 3 active |
| Third-Party Vendor Risk Management |
| 11.3% | 4 3 active |
| Known-Exploited Vulnerability (KEV) Remediation Routing |
| 0.2% | 1 1 active |
| Network Configuration Compliance & Remediation |
| 2.8% | 42 41 active |
| Network Device OS/Firmware Upgrade Orchestration | 997 executions | 4.2% | 19 18 active |
| Network Device Inventory & Discovery |
| 8.5% | 26 26 active |
| Zero-Touch Switch Provisioning | 60 executions | 0.3% | 36 35 active |
| Palo Alto Firewall Rule & Object Governance | 94 executions | 0.4% | 15 15 active |
| IT Helpdesk Ticket Routing & Compliance Reporting | 18 executions | 0.1% | 10 5 active |
| Endpoint / Device Compliance & MDM Tracking | 0 executions | 0.0% | 4 4 active |
| Platform Notification & Messaging Utilities | 1,313 executions | 5.6% | 18 18 active |
| Sandbox, Testing & Getting-Started Workflows | 0 executions | 0.0% | 20 17 active |
| Total | 22,658 executions | 100% | 250 235 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- SOC alert enrichment remains the deepest and highest-volume use case. Security Alert Enrichment & EDR Response alone accounts for 37 playbooks and nearly 17,500 executions in the trailing 12 months — spanning Sentinel and CrowdStrike enrichment, entity/user lookups, browser-history retrieval, and containment actions — and grew further versus the prior reporting period, reinforcing it as the most mature and heavily-relied-upon automation surface in the tenant.
- Cross-domain coverage. Rockwell has extended Blink well beyond the SOC into IAM (Atlassian token revocation, password resets), GRC (third-party risk sync, major-incident reporting), Vulnerability Management (KEV routing), and — most heavily — network/IT operations (configuration compliance, OS upgrades, inventory, firewall governance, zero-touch provisioning).
- Network operations is the largest category by playbook count. Across Network Configuration Compliance, OS/Firmware Upgrades, Network Inventory, Zero-Touch Provisioning, and Palo Alto Governance, Rockwell has built 179 playbooks (56% of the tenant) automating global network engineering workflows across AMER/APAC/EMEA regions — indicating Blink has become core infrastructure for the network engineering team, not just security.
- Real business-action volume is substantial and growing. Even after excluding infrastructure/subflow noise, the KPI table above reflects over 9,100 discrete, describable business actions completed by automation in 12 months — vendor risk syncs, alert enrichments, token revocations, incident reports, ticket lifecycle actions, and compliance audits — up from ~8,100 at the prior measurement.
Gaps & Opportunities
- Heavy reliance on internal subflows inflates raw execution counts without a matching top-level business narrative. Playbooks like "Subflow - Get Entities" (7,946 executions) and several "Retrieve User Info"/"Get Host Browser History" subflows are called by multiple parent automations across workspaces; consolidating shared subflow logic (rather than duplicating it per workspace) would simplify maintenance and make the automation inventory easier to reason about.
- The OS/firmware upgrade pipeline appears to be mid-transition. The historical "os-upgrade: execution" playbook now shows zero runs in the trailing window (down from 79), while a newer device-name variable-sync step ("os-upgrade: update device names in variable," 1,516 runs) and the C9300 supported-firmware/global-variable playbooks (1,585 runs each) carry most of the volume — worth confirming whether live upgrade executions have genuinely paused or simply moved to a playbook not yet reflected as a distinct "upgrade completed" action.
- Vendor-risk alerting coverage narrowed. The "Compromised TPV Alerts V2" playbook present in the prior period is no longer in the active workflow set, leaving Third-Party Vendor Risk Management focused solely on the OneTrust sync rather than also surfacing compromised-vendor alerts — a natural candidate to rebuild if that alerting need still exists.
- Significant dev/test/duplicate sprawl. Of the 23 workspaces, at least two (
04203f4a...and several ZTP-related workspaces) appear to be dev/test mirrors of production network automations, and the Sandbox use case (23 playbooks) plus the bulk of the 61-playbook Zero-Touch Provisioning use case show 0 executions — suggesting ZTP and several admin-tool switch-provisioning subflows are still mid-build rather than live in production. - Endpoint/Device Compliance (Intune, CrowdStrike table fill) has zero executions, indicating this use case has been built but not yet activated or scheduled — a natural next-phase rollout candidate.
- GRC and Vulnerability Management are thin relative to SOC and Network Ops. Only 1 playbook covers KEV-based vulnerability remediation routing and 4 cover vendor risk management; given the size of the network/security footprint already automated, there is room to expand structured vulnerability and compliance-reporting automation.
- Some playbooks straddle categories informally (e.g., CAB_Report and ISCDD Pipeline sit under IT Helpdesk operationally but serve a GRC/change-reporting function) — as the taxonomy matures, formally splitting these into their own GRC reporting use case would sharpen KPI attribution.
Integration Ecosystem
Rockwell's Blink footprint integrates with: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID/Active Directory, Microsoft Graph/Teams/Outlook/Excel/OneDrive, ServiceNow, Jira/Atlassian, VirusTotal, Proofpoint TAP, OneTrust, PagerDuty, Zendesk, VulnCheck, Armis Centrix, ForeScout, Cisco (IOS/C9300 switches, Meraki, ISE), Palo Alto Networks/Panorama, NetBox, EfficientIP, SolarWinds, Azure DevOps, Grafana, Microsoft Intune, and SharePoint. This breadth — spanning SIEM/EDR, identity, ITSM, GRC, and network infrastructure vendors — reflects Blink's role as a central automation fabric connecting Rockwell's security and network engineering tool stacks rather than a point solution for a single team.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | CS AI Agent | Skills Integrations Workspace | 0 | 0 | 0 |
| 2 | John - Test delete | Incident Response: Main Dashboard | 0 | 0 | 0 |
| 3 | Kevin Delete | Incident Response: Main Dashboard | 0 | 0 | 0 |
| 4 | New Agent | tom@blinkops.com | 0 | 0 | 0 |
| 5 | New Agent | john.fung@rockwellautomation.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Skills Integrations Workspace | 0 |
| Incident Response: Main Dashboard | 0 |
| tom@blinkops.com | 0 |
| john.fung@rockwellautomation.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | mgolczyk | 0 | 0 |
| 2 | Executions | 0 | 0 |
| 3 | Incident Response Dashboard | 0 | 0 |
| 4 | Meraki | 0 | 0 |
| 5 | Test Dash | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Audit Site Squid File | 0 | 0 |
| 2 | Test | 0 | 0 |
| 3 | HEADER | 0 | 0 |
| 4 | Firewall REquest | 0 | 0 |
| 5 | Network Configuration Compliance Audit | 0 | 0 |
D Full Use Case Analysis 16 use cases | 23,505 executions (12m)
Business KPIs
| Metric | Count | Playbook(s) |
|---|---|---|
| Third-party vendor risk records synchronized from OneTrust | 2,845 | Subflow: TPV via OneTrust Table Update, TPV via OneTrust Table Update |
| Security alerts enriched with entity & user context for the SOC | 2,269 | Sentinel Automated Entity Enrichment |
| Endpoint browser history retrievals for active security investigations | 2,268 | Sentinel Automated Retrieve Browser History on RA-CS Alert, Sentinel Automated Retrieve Browser History on CS Alert |
| Unauthorized Atlassian API tokens detected & revoked | 894 | Revoke Atlassian API |
| Major incident reports generated & distributed to leadership | 240 | Major-Incident-Report-timed |
| Phishing / suspicious email alerts triaged | 149 | Triage an incident table update, Triage an internal phishing table update, On Proofpoint TAP Malicious Email Click, AI Phishing Analysis, Triage Internal Phishing Email, Phishing Alert and Enrichment |
| CSIRT shift-handoff briefings updated for the on-call team | 120 | Shift Handoff Update Automation |
| CSIRT executive email summaries generated & distributed | 85 | Summarize CSIRT Email every 8 Hrs, Summarize and Send CSIRT Email On VP Address |
| Scheduled network configuration compliance audits completed (WAN/LAN/Wireless/Meraki) | 65 | Scheduled: WAN Configuration Compliance Audit - AMER Region (+7 regional/platform variants) |
| ServiceNow change tickets closed automatically | 45 | Subflow: Close ServiceNow Change Task, Subflow: Close ServiceNow Standard Change Ticket |
| New network devices with a primary IP flagged for security review (ForeScout) | 40 | Daily notification for new Switch or Router with primary IP - ForeScout |
| Known-exploited vulnerabilities (KEV) identified & routed for remediation | 40 | VulnCheck KEV to Teams/Jira |
| ServiceNow standard change tickets created automatically | 23 | Subflow: Create ServiceNow Standard Change Ticket (+1 regional variant) |
| Non-compliant network device configurations auto-remediated | 17 | LAN Configuration Remediation - Apply |
| User password resets executed via Entra ID | 12 | Single User Password Reset via Entra ID, Bulk Password Reset via Entra ID |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks |
|---|---|---|---|---|
| 1 | Security Alert Enrichment & EDR Response | SOC | Agentic SOC, Alert enrichment / IOC lookup, EDR containment & response, Identity threat response, Threat intel ingest & curation, Case mgmt & SOAR | 37 |
| 2 | Phishing & Suspicious Email Triage | SOC | Phishing detection & response, Case mgmt & SOAR | 6 |
| 3 | CSIRT Incident Operations & Shift Handoff | SOC / GRC | Case mgmt & SOAR, Security metrics & reporting | 16 |
| 4 | Atlassian Access Revocation | IAM | Privileged account mgmt, JIT & temporary access | 2 |
| 5 | Password & Credential Resets | IAM | Password & credential lifecycle | 4 |
| 6 | Third-Party Vendor Risk Management | GRC | Vendor risk & TPRM | 4 |
| 7 | Known-Exploited Vulnerability (KEV) Remediation Routing | Vulnerability Mgmt | CVE lookup & remediation | 1 |
| 8 | Network Configuration Compliance & Remediation | Other | IT/OT & network infra monitoring, DevOps & release automation | 52 |
| 9 | Network Device OS/Firmware Upgrade Orchestration | Other | DevOps & release automation, IT/OT & network infra monitoring | 22 |
| 10 | Network Device Inventory & Discovery | Other | IT/OT & network infra monitoring | 29 |
| 11 | Zero-Touch Switch Provisioning | Other | DevOps & release automation, IT/OT & network infra monitoring | 61 |
| 12 | Palo Alto Firewall Rule & Object Governance | Other | IT/OT & network infra monitoring | 15 |
| 13 | IT Helpdesk Ticket Routing & Compliance Reporting | Other / GRC | IT helpdesk & ticket routing, Security metrics & reporting | 14 |
| 14 | Endpoint / Device Compliance & MDM Tracking | Other | Endpoint hygiene & MDM ops | 4 |
| 15 | Platform Notification & Messaging Utilities | Other | SaaS / IT administration | 29 |
| 16 | Sandbox, Testing & Getting-Started Workflows | Other | SaaS / IT administration | 23 |
Use Cases
1. Security Alert Enrichment & EDR Response
Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup, EDR containment & response, Identity threat response, Threat intel ingest & curation, Case mgmt & SOAR | Playbooks: 37 | Executions (12mo): 17499
Description: Automatically enriches Microsoft Sentinel and CrowdStrike security alerts with entity, user, and host context, and pulls supporting endpoint evidence (browser history, host isolation) for the SOC.
Business Problem: Analysts previously had to manually pivot across Sentinel, CrowdStrike, Active Directory, and ServiceNow to gather context on every alert before they could triage it, adding minutes of manual lookup to every case and slowing mean-time-to-triage during high-volume alert periods.
Integrations: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID / Active Directory, Microsoft Graph, ServiceNow, VirusTotal, Armis Centrix, ForeScout
View all 37 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Subflow - Get Entities | 7946 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Sentinel Automated Entity Enrichment | 2269 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Sentinel Automated Retrieve Browser History on RA-CS Alert | 2263 | SOC | EDR containment & response |
| Retrieve User Info Subflow | 2158 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Get Host Browser History Subflow | 1420 | SOC | EDR containment & response |
| Exclude Mac Linux Subflow | 1371 | SOC | EDR containment & response |
| Subflow - Get Entities | 27 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Get Browser History via Crowdstrike Self-Service | 21 | SOC | EDR containment & response |
| Sentinel Automated: Fake Credential Access Alert | 7 | SOC | Identity threat response, Alert enrichment / IOC lookup |
| Sentinel Automated Zscaler Deception Alert | 6 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Sentinel Automated Retrieve Browser History on CS Alert | 5 | SOC | EDR containment & response |
| Connect to Host - Crowdstrike | 3 | SOC | EDR containment & response |
| Threat Hunt Case Creation | 2 | SOC | Threat intel ingest & curation, Case mgmt & SOAR |
| Sentinel Automated - Remote Logon to DC Alert | 1 | SOC | Identity threat response, Alert enrichment / IOC lookup |
| Enrich IP By IPInfo | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Get Entities | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Retrieve User Info Via Entra ID | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Isolate or Lift Isolation on Device Via Crowdstrike | 0 | SOC | EDR containment & response |
| Bulk Retrieve User Info via Entra ID | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Run Action on Host Subflow | 0 | SOC | EDR containment & response |
| Search IOC with VirusTotal Subflow | 0 | SOC | Alert enrichment / IOC lookup |
| Forensic Analysis on Device via Host Name | 0 | SOC | EDR containment & response |
| Run Action Until Complete - Crowdstrike | 0 | SOC | EDR containment & response |
| Retrieve User Info Subflow | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Search IOC with VirusTotal Subflow | 0 | SOC | Alert enrichment / IOC lookup |
| Sentinel Trigger | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Sentinel Trigger copy | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Connect to Host - Crowdstrike | 0 | SOC | EDR containment & response |
| Run Action on Host Subflow | 0 | SOC | EDR containment & response |
| Run Action Until Complete - Crowdstrike | 0 | SOC | EDR containment & response |
| Exclude Mac Linux Subflow | 0 | SOC | EDR containment & response |
| Get Host Browser History Subflow DEV | 0 | SOC | EDR containment & response |
| Sentinel Trigger copy copy | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Subflow - Get Entities | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Crowdstrike Fill Table - Subflow | 0 | SOC | Agentic SOC |
| Crowdstrike Fill Table | 0 | SOC | Agentic SOC |
| Subflow - Get Entities copy | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
2. Phishing & Suspicious Email Triage
Category: SOC | Subcategories: Phishing detection & response, Case mgmt & SOAR | Playbooks: 6 | Executions (12mo): 149
Description: Triages reported and detected phishing/malicious email events (including Proofpoint TAP malicious-click alerts and internally reported emails), using AI-assisted analysis to accelerate disposition.
Business Problem: High volumes of user-reported and vendor-flagged phishing emails compete with other SOC priorities; without automation each report requires manual review of headers, links, and sender reputation before the SOC can close it out or escalate.
Integrations: Microsoft Sentinel, Proofpoint TAP, Azure Log Analytics
View all 6 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Triage an incident table update | 40 | SOC | Phishing detection & response, Case mgmt & SOAR |
| Triage an internal phishing table update | 40 | SOC | Phishing detection & response, Case mgmt & SOAR |
| On Proofpoint TAP Malicious Email Click | 33 | SOC | Phishing detection & response, Case mgmt & SOAR |
| AI Phishing Analysis | 29 | SOC | Phishing detection & response, Case mgmt & SOAR |
| Triage Internal Phishing Email | 5 | SOC | Phishing detection & response, Case mgmt & SOAR |
| Phishing Alert and Enrichment | 2 | SOC | Phishing detection & response, Case mgmt & SOAR |
3. CSIRT Incident Operations & Shift Handoff
Category: SOC / GRC | Subcategories: Case mgmt & SOAR, Security metrics & reporting | Playbooks: 16 | Executions (12mo): 918
Description: Keeps the CSIRT running around the clock: compiles periodic incident email summaries, maintains the shift-handoff record for the on-call team, and generates/distributes major-incident reports to leadership via SharePoint.
Business Problem: Incident responders previously spent time manually compiling shift-handoff notes and status summaries between rotations, and major incidents required manual report writing and distribution, both of which delayed leadership visibility during active incidents.
Integrations: Microsoft Teams, Outlook, Excel, OneDrive, Microsoft Graph, PagerDuty, ServiceNow, SharePoint
View all 16 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Major-Incident-Report-timed | 240 | GRC | Security metrics & reporting |
| Subflow: ServiceNow to SharePoint list | 228 | GRC | Security metrics & reporting |
| SharepointListTimedUpdate | 228 | GRC | Security metrics & reporting |
| Shift Handoff Update Automation | 120 | SOC | Case mgmt & SOAR |
| Summarize CSIRT Email every 8 Hrs | 80 | SOC | Case mgmt & SOAR |
| OneTrust Inbox Incident copy | 9 | SOC | Case mgmt & SOAR |
| Pager Duty Shift Roster Automation | 5 | SOC | Case mgmt & SOAR |
| Summarize and Send CSIRT Email On VP Address | 5 | SOC | Case mgmt & SOAR |
| OneTrust Inbox Incident | 2 | SOC | Case mgmt & SOAR |
| Update Shift-Handoff URL | 1 | SOC | Case mgmt & SOAR |
| Who Is on Pager Duty Today | 0 | SOC | Case mgmt & SOAR |
| One Trust Create An Incident | 0 | SOC | Case mgmt & SOAR |
| OneTrust Update Incident | 0 | SOC | Case mgmt & SOAR |
| Major Incident Report | 0 | GRC | Security metrics & reporting |
| Onetrust Sync | 0 | SOC | Case mgmt & SOAR |
| Summarize Email Agent | 0 | SOC | Case mgmt & SOAR |
4. Atlassian Access Revocation
Category: IAM | Subcategories: Privileged account mgmt, JIT & temporary access | Playbooks: 2 | Executions (12mo): 894
Description: Detects and automatically revokes unauthorized or stale Atlassian (Jira) API tokens flagged by Sentinel, closing a common cloud-credential exposure path.
Business Problem: Unauthorized or forgotten API tokens are a persistent identity risk that is easy to miss in manual reviews; without automation, revocation depended on someone noticing and acting on a Sentinel alert before the token could be misused.
Integrations: Jira / Atlassian Admin API, Microsoft Entra ID / Active Directory, Microsoft Sentinel
View all 2 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Revoke Atlassian API | 894 | IAM | Privileged account mgmt, JIT & temporary access |
| Atlassian API Removal Automation | 0 | IAM | Privileged account mgmt, JIT & temporary access |
5. Password & Credential Resets
Category: IAM | Subcategories: Password & credential lifecycle | Playbooks: 4 | Executions (12mo): 25
Description: Executes single-user and bulk password resets in Entra ID on demand, and includes a newer SOP-triggered flow that watches for dark-web credential-exposure email alerts (currently triage/logging only, ahead of full reset automation).
Business Problem: Password reset requests are high-frequency, time-sensitive, and low-complexity, but manual handling still consumes helpdesk/IAM staff time and creates delay for locked-out users.
Integrations: Microsoft Entra ID (Azure AD), Microsoft Graph
View all 4 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Darkweb password reset on email based on SOP | 13 | IAM | Password & credential lifecycle |
| Single User Password Reset via Entra ID | 11 | IAM | Password & credential lifecycle |
| Bulk Password Reset via Entra ID | 1 | IAM | Password & credential lifecycle |
| Single User Password Reset via Entra ID | 0 | IAM | Password & credential lifecycle |
6. Third-Party Vendor Risk Management
Category: GRC | Subcategories: Vendor risk & TPRM | Playbooks: 4 | Executions (12mo): 2846
Description: Synchronizes third-party vendor risk data from OneTrust into Blink tables, keeping the vendor risk register current without manual data entry.
Business Problem: Vendor risk records in OneTrust needed to be manually pulled and reconciled against internal tracking before GRC could assess exposure across the vendor population.
Integrations: OneTrust
View all 4 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Subflow: TPV via OneTrust Table Update | 2805 | GRC | Vendor risk & TPRM |
| TPV via OneTrust Table Update | 40 | GRC | Vendor risk & TPRM |
| TPR Automated Reassessment | 1 | GRC | Vendor risk & TPRM |
| Export GRC OneTrust Docs to Sharepoint | 0 | GRC | Vendor risk & TPRM |
7. Known-Exploited Vulnerability (KEV) Remediation Routing
Category: Vulnerability Mgmt | Subcategories: CVE lookup & remediation | Playbooks: 1 | Executions (12mo): 40
Description: Checks new CVEs against the VulnCheck Known Exploited Vulnerabilities catalog and automatically routes matches to Teams/Jira for remediation tracking.
Business Problem: Identifying which newly disclosed CVEs are already being actively exploited in the wild (and therefore need urgent patching) requires cross-referencing external threat intel feeds — a manual step that delays prioritization if not automated.
Integrations: VulnCheck, Jira, Microsoft Teams
View all 1 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| VulnCheck KEV to Teams/Jira | 40 | Vulnerability Mgmt | CVE lookup & remediation |
8. Network Configuration Compliance & Remediation
Category: Other | Subcategories: IT/OT & network infra monitoring, DevOps & release automation | Playbooks: 52 | Executions (12mo): 580
Description: Runs scheduled configuration-compliance audits across WAN, LAN, Wireless, and Meraki estates, and — where drift is found — pushes remediation and opens/closes the associated ServiceNow change tickets.
Business Problem: Network engineers previously had to manually audit device configurations against baseline standards region by region and hand-track the ServiceNow change process for every remediation, which did not scale across a large global network estate.
Integrations: Cisco (switches/routers), Cisco Meraki, ServiceNow, Azure DevOps, Blink Tables
View all 52 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Subflow: Network Configuration Compliance Audit | 96 | Other | IT/OT & network infra monitoring |
| Subflow: Get Device Facts | 96 | Other | IT/OT & network infra monitoring |
| Subflow: Test Unreachable Devices | 61 | Other | IT/OT & network infra monitoring |
| Subflow: LAN Configuration Remediation Workflow | 40 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Close ServiceNow Change Task | 30 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Table Button: Configuration Compliance Audit Workflow | 22 | Other | IT/OT & network infra monitoring |
| DEV: LAN Configuration Remediation Workflow | 21 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| LAN Configuration Remediation - Prep | 18 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| LAN Configuration Remediation - Apply | 17 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Get ServiceNow Change Ticket Status | 17 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Create ServiceNow Standard Change Ticket | 17 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Close ServiceNow Standard Change Ticket | 15 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Scheduled: WAN Configuration Compliance Audit - AMER Region | 9 | Other | IT/OT & network infra monitoring |
| Scheduled: WAN Configuration Compliance Audit - APAC Region | 9 | Other | IT/OT & network infra monitoring |
| Scheduled: WAN Configuration Compliance Audit - EMEA Region | 9 | Other | IT/OT & network infra monitoring |
| Scheduled: LAN Configuration Compliance Audit - AMER Region | 9 | Other | IT/OT & network infra monitoring |
| @DEV - LAN Configuration Remediation - Apply | 9 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Populate Compliance Time Series Table | 8 | Other | IT/OT & network infra monitoring |
| Scheduled: LAN Configuration Compliance Audit - APAC Region | 8 | Other | IT/OT & network infra monitoring |
| Scheduled: LAN Configuration Compliance Audit - EMEA Region | 8 | Other | IT/OT & network infra monitoring |
| Scheduled: Wireless Configuration Compliance Audit - Global | 7 | Other | IT/OT & network infra monitoring |
| Subflow: Get Device Facts | 7 | Other | IT/OT & network infra monitoring |
| Subflow: Network Configuration Compliance Audit | 7 | Other | IT/OT & network infra monitoring |
| Subflow: Get Meraki Facts | 6 | Other | IT/OT & network infra monitoring |
| Subflow: Meraki Configuration Compliance Audit | 6 | Other | IT/OT & network infra monitoring |
| Scheduled: Meraki Configuration Compliance Audit - Global | 6 | Other | IT/OT & network infra monitoring |
| @DEV - LAN Configuration Remediation - Prep | 6 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| @DEV - LAN Configuration Remediation - Dry Run | 6 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Create ServiceNow Standard Change Ticket | 6 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| LAN Configuration Remediation - Dry Run | 4 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Audit ra-allowed-sites.conf | 0 | Other | IT/OT & network infra monitoring |
| Audit ra-allowed-sites.conf (MAIN) | 0 | Other | IT/OT & network infra monitoring |
| Audit ra-allowed-sites.conf (MAIN) | 0 | Other | IT/OT & network infra monitoring |
| Main Router | 0 | Other | IT/OT & network infra monitoring |
| Main Router | 0 | Other | IT/OT & network infra monitoring |
| Workspace Router | 0 | Other | IT/OT & network infra monitoring |
| Workspace Router (MAIN) | 0 | Other | IT/OT & network infra monitoring |
| Workspace Router (MAIN) | 0 | Other | IT/OT & network infra monitoring |
| Web Form | 0 | Other | IT/OT & network infra monitoring |
| Subflow: Get Device Facts - DEPRECATED | 0 | Other | IT/OT & network infra monitoring |
| Subflow: Test Unreachable Devices | 0 | Other | IT/OT & network infra monitoring |
| Subflow: Get Device Facts - FEATURE | 0 | Other | IT/OT & network infra monitoring |
| @PROD - TEST - LAN Configuration Remediation - Dry Run | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| @PROD - TEST - LAN Configuration Remediation - Prep | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| FEATURE - Subflow: Network Configuration Compliance Audit | 0 | Other | IT/OT & network infra monitoring |
| FEATURE - Subflow: Get Meraki Facts | 0 | Other | IT/OT & network infra monitoring |
| FEATURE - Meraki Configuration Compliance Audit | 0 | Other | IT/OT & network infra monitoring |
| @PROD - TEST - LAN Configuration Remediation - Apply | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Network Engineering Changes Bulk Table Insert | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Get ServiceNow Change Ticket Status | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Close ServiceNow Standard Change Ticket | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
| Subflow: Close ServiceNow Change Task | 0 | Other | IT/OT & network infra monitoring, DevOps & release automation |
9. Network Device OS/Firmware Upgrade Orchestration
Category: Other | Subcategories: DevOps & release automation, IT/OT & network infra monitoring | Playbooks: 22 | Executions (12mo): 5115
Description: Orchestrates staged OS/firmware upgrades (including Cisco C9300 switches and SAP RHEL servers), tracking supported-firmware variables, device-name/sync status, and per-device execution/validation.
Business Problem: Coordinating firmware upgrades across large fleets of switches and servers manually is error-prone and hard to track at scale; a missed validation step can leave devices on unsupported or vulnerable firmware.
Integrations: Cisco IOS/C9300 switches, Blink Tables
View all 22 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| C9300: Supported Firmwares Variable | 1585 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| C9300: SWITCH GLOBAL VARIABLE | 1585 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: update device names in variable | 1516 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| RUNNING WORKFLOW VALIDATION | 134 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| V1.0.2: SINGLE EXECUTION | 133 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| V1.0.2: DEVICE SYNC | 133 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| V1.0.2: BULK SELECTION | 29 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: subflow-device Sync + Row operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: execution | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| SAP RHEL Upgrade Part 2 | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| SAP RHEL Upgrade Part 1 | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| On-Demand: Update Sites Global Variable | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| On-Demand: Update Network Switch Regional Variable | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Upgrade IOS Subflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Populate NetBox OS Standards from Table | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| On-Demand: Update Network Switch Platform Variables | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| RHEL | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| RHEL 2 | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: subflow-device Sync + Row operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: execution | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: subflow-device Sync + Row operation copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| os-upgrade: execution copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
10. Network Device Inventory & Discovery
Category: Other | Subcategories: IT/OT & network infra monitoring | Playbooks: 29 | Executions (12mo): 1989
Description: Keeps network device inventory, end-of-life/end-of-support (EOX) status, and SD-WAN estate data current by continuously collecting and populating tracking tables from ForeScout, NetBox, and SD-WAN sources.
Business Problem: Without continuous discovery, network inventory and EOX records drift out of date, making it hard for engineering and procurement teams to plan refresh cycles or spot unmanaged/unauthorized devices on the network.
Integrations: ForeScout, NetBox, Cisco Meraki, Grafana, SharePoint
View all 29 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| SD-WAN Data Collection | 1920 | Other | IT/OT & network infra monitoring |
| Daily notification for new Switch or Router with primary IP - ForeScout | 40 | Other | IT/OT & network infra monitoring |
| Grafana + Blink | 10 | Other | IT/OT & network infra monitoring |
| Populate Network Device EOX Time Series Table | 6 | Other | IT/OT & network infra monitoring |
| Populate Managed Network Estate Time Series Table | 6 | Other | IT/OT & network infra monitoring |
| Populate Network Device Inventory Table | 5 | Other | IT/OT & network infra monitoring |
| NetBox - Populate Cisco EOX Fields into Device Types | 1 | Other | IT/OT & network infra monitoring |
| Cisco Interface Update Configuration Push | 1 | Other | IT/OT & network infra monitoring |
| Active switch or router with primary ip alert | 0 | Other | IT/OT & network infra monitoring |
| Active switch or router with primary ip alert (Marcin.Golczyk@rockwellautomation.com) | 0 | Other | IT/OT & network infra monitoring |
| Daily notification for new Switch or Router with primary IP | 0 | Other | IT/OT & network infra monitoring |
| SD-WAN Status Sync | 0 | Other | IT/OT & network infra monitoring |
| EOL Trend | 0 | Other | IT/OT & network infra monitoring |
| Network Device Triage | 0 | Other | IT/OT & network infra monitoring |
| Populate Device Inventory Min Table | 0 | Other | IT/OT & network infra monitoring |
| Router Triage (Deep Dive) | 0 | Other | IT/OT & network infra monitoring |
| Populate Refresh Tracking Table from SharePoint | 0 | Other | IT/OT & network infra monitoring |
| Cisco EOX NetBox | 0 | Other | IT/OT & network infra monitoring |
| Carrier Maintenance | 0 | Other | IT/OT & network infra monitoring |
| Get Organization Devices with Cisco Meraki and Send Results via Email | 0 | Other | IT/OT & network infra monitoring |
| Network Device Triage copy | 0 | Other | IT/OT & network infra monitoring |
| Grafana + Blink | 0 | Other | IT/OT & network infra monitoring |
| Remove Decommissioned Devices from Tables | 0 | Other | IT/OT & network infra monitoring |
| Add/Update Device Record | 0 | Other | IT/OT & network infra monitoring |
| Subflow: syslog message | 0 | Other | IT/OT & network infra monitoring |
| Subflow: syslog message | 0 | Other | IT/OT & network infra monitoring |
| Subflow: syslog message copy | 0 | Other | IT/OT & network infra monitoring |
| Netbox Racks Utilization | 0 | Other | IT/OT & network infra monitoring |
| Network Devices Discovery for Interface Automation (via CDP/LLDP) | 0 | Other | IT/OT & network infra monitoring |
11. Zero-Touch Switch Provisioning
Category: Other | Subcategories: DevOps & release automation, IT/OT & network infra monitoring | Playbooks: 61 | Executions (12mo): 41
Description: Automates end-to-end zero-touch provisioning (ZTP) of new switches — NetBox registration, ISE/EfficientIP/IPAM configuration, VLAN/uplink setup, IOS upgrade, and final configuration push — largely still in dev/build-out.
Business Problem: Manually staging a new switch requires touching half a dozen systems (NetBox, ISE, IPAM, syslog, IOS) in the right order; ZTP is designed to collapse that into a single automated pipeline, though most of this use case is currently in development/testing workspaces rather than production.
Integrations: NetBox, Cisco ISE, EfficientIP IPAM, SolarWinds
View all 61 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Switch Provisioning - Post-ZTP | 26 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Post-ZTP worflow | 15 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| NetboxtoBlinkops Email.(mmettu) | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| device-deletion-from-netbox | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Update Device Upgrade Exection Log | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| All Device Record | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Device Update | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Phase 1: Single Switch | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Phase 2: Single Switch | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Load All Device | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - final switch configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - ISE configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - uplink VLAN interface configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - HTTP/S iptables configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - state table interaction | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - Netbox configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - input uplink switch | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Register switch in ISE copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - Cleanup workflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - EfficientIP configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| DEPRECATED Subflow: Switch Provisioning - IOS upgrade | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - IOS upgrade | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - HTTP/S iptables configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - state table interaction | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - uplink VLAN interface configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - ISE configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - EfficientIP configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - Netbox configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - Cleanup workflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - final switch configuration | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - IOS upgrade | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Post-ZTP worflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - input uplink switch | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - IOS upgrade copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| TEST new ZTP approach | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - Netbox configuration copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Pre-ZTP | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - Netbox Client | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - ISE Client | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - Netbox client - Damian changesNetbox Client copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - EfficientIP Client | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - HTTP/S server operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - VLAN uplink operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - state table interaction copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Subflow: Switch Provisioning - state table interaction copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Post-ZTP | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN - Switch Provisioning - Cleanup workflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - final config application | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| FOR TESTING BLINKOPS FIX -ADMIN Tool: Switch Provisioning - Netbox Client copy | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Pre-ZTP FOR TESTING | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Pre-ZTP - uv test | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - VLAN uplink operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Pre-ZTP | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - Netbox Client | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| Switch Provisioning - Post-ZTP | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - ISE Client | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - final config application | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN Tool: Switch Provisioning - HTTP/S server operation | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
| ADMIN - Switch Provisioning - Cleanup workflow | 0 | Other | DevOps & release automation, IT/OT & network infra monitoring |
12. Palo Alto Firewall Rule & Object Governance
Category: Other | Subcategories: IT/OT & network infra monitoring | Playbooks: 15 | Executions (12mo): 92
Description: Audits and cleans up Palo Alto Panorama/firewall rule bases and objects — identifying stale, unused, or duplicate rules and objects, and reporting on Global Protect usage and interface configuration.
Business Problem: Firewall rule bases accumulate unused and duplicate rules/objects over time, which increases both attack surface and administrative overhead when nobody is systematically auditing them.
Integrations: Palo Alto Networks (Panorama / Firewalls)
View all 15 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| paloalto-table-weekly-updates | 40 | Other | IT/OT & network infra monitoring |
| PaloAlto Firewalls Interface Information. | 40 | Other | IT/OT & network infra monitoring |
| Palo Alto Firewall Unused Rule/Object Count Tables and Graph | 6 | Other | IT/OT & network infra monitoring |
| Palo Alto Global Protect Users Reporting | 6 | Other | IT/OT & network infra monitoring |
| Paloalto Disable/Delete Rules and Objects. | 0 | Other | IT/OT & network infra monitoring |
| paloalto unused/stalerules and unused/duplicate objects-audit | 0 | Other | IT/OT & network infra monitoring |
| Palo Alto Firewall Rule/Object Cleanup-Audit | 0 | Other | IT/OT & network infra monitoring |
| paloalto disable/delete rules and objects. | 0 | Other | IT/OT & network infra monitoring |
| paloalto stale/unused rules for specific device groups. | 0 | Other | IT/OT & network infra monitoring |
| PaloAlto Stale/Unused Rules for Specific Device Groups. | 0 | Other | IT/OT & network infra monitoring |
| PaloAlto Route Configuration | 0 | Other | IT/OT & network infra monitoring |
| PaloAlto DNS Route Configuration | 0 | Other | IT/OT & network infra monitoring |
| Palo Alto Firewall Unused/Duplicate Object Cleanup-PROD-Audit | 0 | Other | IT/OT & network infra monitoring |
| Palo Alto Current data | 0 | Other | IT/OT & network infra monitoring |
| Panorama Duplicate Objects Consolidation | 0 | Other | IT/OT & network infra monitoring |
13. IT Helpdesk Ticket Routing & Compliance Reporting
Category: Other / GRC | Subcategories: IT helpdesk & ticket routing, Security metrics & reporting | Playbooks: 14 | Executions (12mo): 54
Description: Routes and summarizes helpdesk/service-desk activity (Zendesk, Jira intake, AI-assisted triage) and produces recurring compliance/procurement reporting (CAB change reports, ISCDD pipeline, Cyber RDO procurement).
Business Problem: Ticket intake and recurring governance reports (change advisory board packets, procurement/compliance pipelines) were manually compiled on a schedule, consuming analyst time on work that follows a repeatable template.
Integrations: Jira, Zendesk, Microsoft Excel/OneDrive/Graph, SharePoint
View all 14 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Zendesk Report | 6 | Other | IT helpdesk & ticket routing |
| Zendesk Report | 6 | Other | IT helpdesk & ticket routing |
| Jira Intake | 6 | Other | IT helpdesk & ticket routing |
| Jira Intake | 6 | Other | IT helpdesk & ticket routing |
| Cyber RDO Procurement | 6 | GRC | Security metrics & reporting |
| ISCDD Pipeline | 6 | GRC | Security metrics & reporting |
| ISCDD Pipeline | 6 | GRC | Security metrics & reporting |
| CAB_Report | 6 | Other | DevOps & release automation, IT helpdesk & ticket routing |
| CAB_Report | 6 | Other | DevOps & release automation, IT helpdesk & ticket routing |
| Service Desk AI Assisted Triage | 0 | Other | IT helpdesk & ticket routing |
| On SIEM Logging Form Request Create a Jira Ticket and Inform the SIEM Team | 0 | Other | IT helpdesk & ticket routing |
| Jira storypack from epic | 0 | Other | IT helpdesk & ticket routing |
| BlinkOps Request Form To Jira | 0 | Other | IT helpdesk & ticket routing |
| ADX AI Assisted Triage | 0 | Other | IT helpdesk & ticket routing |
14. Endpoint / Device Compliance & MDM Tracking
Category: Other | Subcategories: Endpoint hygiene & MDM ops | Playbooks: 4 | Executions (12mo): 0
Description: Populates device compliance and Intune/CrowdStrike-sourced endpoint tables to track MDM and endpoint hygiene status; currently built but not yet driving executions in production.
Business Problem: Endpoint compliance status (MDM enrollment, CrowdStrike coverage) needs to be centrally tracked to spot gaps, but this use case is still in a pre-production/build phase for Rockwell.
Integrations: Microsoft Intune (Graph API), CrowdStrike
View all 4 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Device Compliance - Generate Run Results Entry | 0 | Other | Endpoint hygiene & MDM ops |
| Device Compliance - Main | 0 | Other | Endpoint hygiene & MDM ops |
| Intune by Graph API Fill Table | 0 | Other | Endpoint hygiene & MDM ops |
| Intune by Graph API Fill Table - Subflow | 0 | Other | Endpoint hygiene & MDM ops |
15. Platform Notification & Messaging Utilities
Category: Other | Subcategories: SaaS / IT administration | Playbooks: 29 | Executions (12mo): 2452
Description: Shared notification and messaging plumbing (Teams webhooks/direct messages, email/SMTP delivery workarounds, service-account chat channels, execution-tracking utilities) that other use cases call to deliver their outputs.
Business Problem: Reliable, consistent delivery of automation output (alerts, reports, approvals) to Teams and email needed a standardized, reusable mechanism rather than each automation implementing its own notification logic.
Integrations: Microsoft Teams, SMTP/Email, Jira
View all 29 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| NOTIFICATION: TEAMS WEBHOOK | 2070 | Other | SaaS / IT administration |
| NOTIFICATION: EMAIL WEBHOOK | 143 | Other | SaaS / IT administration |
| NOTIFICATION: TEAMS DIRECT | 133 | Other | SaaS / IT administration |
| Microsoft Graph Mail Service | 41 | Other | SaaS / IT administration |
| SMTP Email Workaround | 37 | Other | SaaS / IT administration |
| Python SMTP Email Workaround | 10 | Other | SaaS / IT administration |
| 1:1 SVC-BlinkOps Chat | 9 | Other | SaaS / IT administration |
| Python SMTP Email Workaround | 6 | Other | SaaS / IT administration |
| Execution Recorder | 2 | Other | SaaS / IT administration |
| Python SMTP Email Workaround | 1 | Other | SaaS / IT administration |
| Request Access for JIRA API | 0 | Other | SaaS / IT administration |
| Ubuntu - Add user with password and Sudo | 0 | Other | SaaS / IT administration |
| Get Approval | 0 | Other | SaaS / IT administration |
| Nutanix Get VMs | 0 | Other | SaaS / IT administration |
| Group SVC-BlinkOps Chat | 0 | Other | SaaS / IT administration |
| SMTP Email Workaround | 0 | Other | SaaS / IT administration |
| Fill out this form | 0 | Other | SaaS / IT administration |
| 1:1 SVC-BlinkOps Chat | 0 | Other | SaaS / IT administration |
| SMTP Email Workaround | 0 | Other | SaaS / IT administration |
| Teams Approval Request Notification | 0 | Other | SaaS / IT administration |
| 1:1 SVC-BlinkOps Chat | 0 | Other | SaaS / IT administration |
| SMTP Email Workaround | 0 | Other | SaaS / IT administration |
| SMTP Email Workaround | 0 | Other | SaaS / IT administration |
| 1:1 SVC-BlinkOps Chat | 0 | Other | SaaS / IT administration |
| Import Blink Automations from a Git Repository | 0 | Other | SaaS / IT administration |
| Import Blink Automations from a Git Repository | 0 | Other | SaaS / IT administration |
| Microsoft Graph Mail Service | 0 | Other | SaaS / IT administration |
| NOTIFICATION: EMAIL | 0 | Other | SaaS / IT administration |
| Execution Recorder: Updator | 0 | Other | SaaS / IT administration |
16. Sandbox, Testing & Getting-Started Workflows
Category: Other | Subcategories: SaaS / IT administration | Playbooks: 23 | Executions (12mo): 0
Description: Onboarding templates ("Getting Started - Hello World"), scratch/test workflows, and workspace-router utilities used by builders while developing or evaluating new automations; not part of steady-state production operations.
Business Problem: N/A — these are platform onboarding and development artifacts rather than automations that solve a standing business problem.
Integrations: n/a (test/sandbox connectors: Bash, PowerShell, Nutanix, NetBox, ServiceNow test endpoints)
View all 23 playbooks
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Getting Started - Hello World | 0 | Other | SaaS / IT administration |
| Getting Started - Hello World | 0 | Other | SaaS / IT administration |
| Test Bash | 0 | Other | SaaS / IT administration |
| Powershell Test | 0 | Other | SaaS / IT administration |
| Test Len OF rows | 0 | Other | SaaS / IT administration |
| Subflow - Example | 0 | Other | SaaS / IT administration |
| Simple Flow | 0 | Other | SaaS / IT administration |
| Getting Started - Hello World | 0 | Other | SaaS / IT administration |
| Kevin For .txt | 0 | Other | SaaS / IT administration |
| New Workflow | 0 | Other | SaaS / IT administration |
| New Workflow (Marcin.Golczyk@rockwellautomation.com) | 0 | Other | SaaS / IT administration |
| ipam_prefix_changed | 0 | Other | SaaS / IT administration |
| ipam_prefix_changed (Marcin.Golczyk@rockwellautomation.com) | 0 | Other | SaaS / IT administration |
| Create Table | 0 | Other | SaaS / IT administration |
| Create Table from Schema | 0 | Other | SaaS / IT administration |
| On-Demand: Create a Table From Schema | 0 | Other | SaaS / IT administration |
| New Workflow | 0 | Other | SaaS / IT administration |
| Python Hello World | 0 | Other | SaaS / IT administration |
| Python Hello World 3 | 0 | Other | SaaS / IT administration |
| Python Hello World Second2 | 0 | Other | SaaS / IT administration |
| On Demand: Create Dashboard from Schema | 0 | Other | SaaS / IT administration |
| test_serviceNow_sc_task_fetch | 0 | Other | SaaS / IT administration |
| Fail This | 0 | Other | SaaS / IT administration |
Key Observations
Strengths
- SOC alert enrichment remains the deepest and highest-volume use case. Security Alert Enrichment & EDR Response alone accounts for 37 playbooks and nearly 17,500 executions in the trailing 12 months — spanning Sentinel and CrowdStrike enrichment, entity/user lookups, browser-history retrieval, and containment actions — and grew further versus the prior reporting period, reinforcing it as the most mature and heavily-relied-upon automation surface in the tenant.
- Cross-domain coverage. Rockwell has extended Blink well beyond the SOC into IAM (Atlassian token revocation, password resets), GRC (third-party risk sync, major-incident reporting), Vulnerability Management (KEV routing), and — most heavily — network/IT operations (configuration compliance, OS upgrades, inventory, firewall governance, zero-touch provisioning).
- Network operations is the largest category by playbook count. Across Network Configuration Compliance, OS/Firmware Upgrades, Network Inventory, Zero-Touch Provisioning, and Palo Alto Governance, Rockwell has built 179 playbooks (56% of the tenant) automating global network engineering workflows across AMER/APAC/EMEA regions — indicating Blink has become core infrastructure for the network engineering team, not just security.
- Real business-action volume is substantial and growing. Even after excluding infrastructure/subflow noise, the KPI table above reflects over 9,100 discrete, describable business actions completed by automation in 12 months — vendor risk syncs, alert enrichments, token revocations, incident reports, ticket lifecycle actions, and compliance audits — up from ~8,100 at the prior measurement.
Gaps & Opportunities
- Heavy reliance on internal subflows inflates raw execution counts without a matching top-level business narrative. Playbooks like "Subflow - Get Entities" (7,946 executions) and several "Retrieve User Info"/"Get Host Browser History" subflows are called by multiple parent automations across workspaces; consolidating shared subflow logic (rather than duplicating it per workspace) would simplify maintenance and make the automation inventory easier to reason about.
- The OS/firmware upgrade pipeline appears to be mid-transition. The historical "os-upgrade: execution" playbook now shows zero runs in the trailing window (down from 79), while a newer device-name variable-sync step ("os-upgrade: update device names in variable," 1,516 runs) and the C9300 supported-firmware/global-variable playbooks (1,585 runs each) carry most of the volume — worth confirming whether live upgrade executions have genuinely paused or simply moved to a playbook not yet reflected as a distinct "upgrade completed" action.
- Vendor-risk alerting coverage narrowed. The "Compromised TPV Alerts V2" playbook present in the prior period is no longer in the active workflow set, leaving Third-Party Vendor Risk Management focused solely on the OneTrust sync rather than also surfacing compromised-vendor alerts — a natural candidate to rebuild if that alerting need still exists.
- Significant dev/test/duplicate sprawl. Of the 23 workspaces, at least two (
04203f4a...and several ZTP-related workspaces) appear to be dev/test mirrors of production network automations, and the Sandbox use case (23 playbooks) plus the bulk of the 61-playbook Zero-Touch Provisioning use case show 0 executions — suggesting ZTP and several admin-tool switch-provisioning subflows are still mid-build rather than live in production. - Endpoint/Device Compliance (Intune, CrowdStrike table fill) has zero executions, indicating this use case has been built but not yet activated or scheduled — a natural next-phase rollout candidate.
- GRC and Vulnerability Management are thin relative to SOC and Network Ops. Only 1 playbook covers KEV-based vulnerability remediation routing and 4 cover vendor risk management; given the size of the network/security footprint already automated, there is room to expand structured vulnerability and compliance-reporting automation.
- Some playbooks straddle categories informally (e.g., CAB_Report and ISCDD Pipeline sit under IT Helpdesk operationally but serve a GRC/change-reporting function) — as the taxonomy matures, formally splitting these into their own GRC reporting use case would sharpen KPI attribution.
Integration Ecosystem
Rockwell's Blink footprint integrates with: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID/Active Directory, Microsoft Graph/Teams/Outlook/Excel/OneDrive, ServiceNow, Jira/Atlassian, VirusTotal, Proofpoint TAP, OneTrust, PagerDuty, Zendesk, VulnCheck, Armis Centrix, ForeScout, Cisco (IOS/C9300 switches, Meraki, ISE), Palo Alto Networks/Panorama, NetBox, EfficientIP, SolarWinds, Azure DevOps, Grafana, Microsoft Intune, and SharePoint. This breadth — spanning SIEM/EDR, identity, ITSM, GRC, and network infrastructure vendors — reflects Blink's role as a central automation fabric connecting Rockwell's security and network engineering tool stacks rather than a point solution for a single team.
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Rockwell | censys | blinkops_censys | 2026-08-25 |