Blink Security Automation — Confidential

Rockwell — Customer Success Report

Generated 2026-08-31 | rockwell-value-report.md
2026-08-31Report Date
770Total Playbooks
327Unique Workflows (12m)
16,521,600Actions Automated (12m)
$4,249,383Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

770
Total playbooks built
all non-deleted workflows
304
Active playbooks
currently enabled
327
Unique workflows executed (12m)
distinct workflows that ran
16,521,600
Actions automated (12m)
completed action steps
91,786.7h
Hours saved (12m)
@ 20s per action
$4,249,383
Money saved (12m)
@ $100K avg salary
13
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 5 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 2,845 third-party vendor risk records synchronized with OneTrust - 2,269 security alerts enriched with entity & user context for the SOC - 2,268 endpoint browser history retrievals for active security investigations - 894 unauthorized Atlassian API tokens detected & revoked - 240 major incident reports generated & distributed to leadership - 149 phishing and suspicious email alerts triaged - 120 CSIRT shift-handoff briefings updated for the on-call team - 85 CSIRT executive email summaries generated & distributed - 65 scheduled network configuration compliance audits completed - 45 ServiceNow change tickets closed automatically - 40 new network devices with a primary IP flagged for security review - 40 known-exploited (KEV) vulnerabilities identified & routed for remediation - 23 ServiceNow standard change tickets created automatically - 17 non-compliant network configurations auto-remediated - 12 user password resets executed via Entra ID

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Security Alert Enrichment & EDR Response
  • 2,269Security alerts enriched with entity & user context for the SOC
  • 2,268Endpoint browser history retrievals for active security investigations
55.2%
27
27 active
Phishing & Suspicious Email Triage
  • 149Phishing / suspicious email alerts triaged
0.6%
7
6 active
CSIRT Incident Operations & Shift Handoff
  • 240Major incident reports generated & distributed to leadership
  • 120CSIRT shift-handoff briefings updated for the on-call team
  • 85CSIRT executive email summaries generated & distributed
3.9%
16
15 active
Atlassian Access Revocation
  • 894Unauthorized Atlassian API tokens detected & revoked
3.3%
2
1 active
Password & Credential Resets
  • 12User password resets executed via Entra ID
0.1%
3
3 active
Third-Party Vendor Risk Management
  • 2,845Third-party vendor risk records synchronized from OneTrust
11.3%
4
3 active
Known-Exploited Vulnerability (KEV) Remediation Routing
  • 40Known-exploited vulnerabilities (KEV) identified & routed for remediation
0.2%
1
1 active
Network Configuration Compliance & Remediation
  • 45ServiceNow change tickets closed automatically
  • 17Non-compliant network device configurations auto-remediated
2.8%
42
41 active
Network Device OS/Firmware Upgrade Orchestration997 executions
4.2%
19
18 active
Network Device Inventory & Discovery
  • 40New network devices with a primary IP flagged for security review (ForeScout)
8.5%
26
26 active
Zero-Touch Switch Provisioning60 executions
0.3%
36
35 active
Palo Alto Firewall Rule & Object Governance94 executions
0.4%
15
15 active
IT Helpdesk Ticket Routing & Compliance Reporting18 executions
0.1%
10
5 active
Endpoint / Device Compliance & MDM Tracking0 executions
0.0%
4
4 active
Platform Notification & Messaging Utilities1,313 executions
5.6%
18
18 active
Sandbox, Testing & Getting-Started Workflows0 executions
0.0%
20
17 active
Total22,658 executions100%
250
235 active

Use Case Growth Over Time

530 unique playbooks  |  16 operational use cases  |  23,505 total executions (12m)  |  2024-02 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Security Alert Enrichment & EDR Response
IPinfo Microsoft Sentinel Email CrowdStrike Microsoft Entra ID Microsoft Teams Azure Storage Microsoft Graph ServiceNow VirusTotal Forescout Armis Centrix
Phishing & Suspicious Email Triage
Microsoft Sentinel Azure Log Analytics VirusTotal Email Proofpoint Recorded Future Azure Microsoft Teams
Atlassian Access Revocation
Microsoft Sentinel Microsoft Entra ID Email Jira
Platform Notification & Messaging Utilities
Email SSH Nutanix Hypervisor Microsoft Teams Git Slack
Password & Credential Resets
Microsoft Entra ID
Sandbox, Testing & Getting-Started Workflows
Gmail VirusTotal Microsoft Teams ServiceNow CrowdStrike Terraform Email AWS Wiz Palo Alto Firewall Azure Microsoft Outlook SharePoint ThreatQuotient Dashboards
Network Configuration Compliance & Remediation
SSH Web Form Azure DevOps Microsoft Teams Email Git
CSIRT Incident Operations & Shift Handoff
PagerDuty Microsoft Teams Microsoft Outlook OneTrust Git Microsoft Graph OneDrive Microsoft Excel
Network Device Inventory & Discovery
Email Git Microsoft Graph Cisco Meraki Microsoft Teams
Zero-Touch Switch Provisioning
Email SolarWinds Information Service Git Microsoft Teams NetBox
Palo Alto Firewall Rule & Object Governance
Email
Third-Party Vendor Risk Management
Bitsight
IT Helpdesk Ticket Routing & Compliance Reporting
Jira OneDrive Microsoft Graph Microsoft Excel
Network Device OS/Firmware Upgrade Orchestration
Azure Email
Known-Exploited Vulnerability (KEV) Remediation Routing
CrowdStrike Wiz Jira Microsoft Teams
Endpoint / Device Compliance & MDM Tracking
Microsoft Graph

04Key Observations

✓  Strengths

Strengths

  • SOC alert enrichment remains the deepest and highest-volume use case. Security Alert Enrichment & EDR Response alone accounts for 37 playbooks and nearly 17,500 executions in the trailing 12 months — spanning Sentinel and CrowdStrike enrichment, entity/user lookups, browser-history retrieval, and containment actions — and grew further versus the prior reporting period, reinforcing it as the most mature and heavily-relied-upon automation surface in the tenant.
  • Cross-domain coverage. Rockwell has extended Blink well beyond the SOC into IAM (Atlassian token revocation, password resets), GRC (third-party risk sync, major-incident reporting), Vulnerability Management (KEV routing), and — most heavily — network/IT operations (configuration compliance, OS upgrades, inventory, firewall governance, zero-touch provisioning).
  • Network operations is the largest category by playbook count. Across Network Configuration Compliance, OS/Firmware Upgrades, Network Inventory, Zero-Touch Provisioning, and Palo Alto Governance, Rockwell has built 179 playbooks (56% of the tenant) automating global network engineering workflows across AMER/APAC/EMEA regions — indicating Blink has become core infrastructure for the network engineering team, not just security.
  • Real business-action volume is substantial and growing. Even after excluding infrastructure/subflow noise, the KPI table above reflects over 9,100 discrete, describable business actions completed by automation in 12 months — vendor risk syncs, alert enrichments, token revocations, incident reports, ticket lifecycle actions, and compliance audits — up from ~8,100 at the prior measurement.

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Heavy reliance on internal subflows inflates raw execution counts without a matching top-level business narrative. Playbooks like "Subflow - Get Entities" (7,946 executions) and several "Retrieve User Info"/"Get Host Browser History" subflows are called by multiple parent automations across workspaces; consolidating shared subflow logic (rather than duplicating it per workspace) would simplify maintenance and make the automation inventory easier to reason about.
  • The OS/firmware upgrade pipeline appears to be mid-transition. The historical "os-upgrade: execution" playbook now shows zero runs in the trailing window (down from 79), while a newer device-name variable-sync step ("os-upgrade: update device names in variable," 1,516 runs) and the C9300 supported-firmware/global-variable playbooks (1,585 runs each) carry most of the volume — worth confirming whether live upgrade executions have genuinely paused or simply moved to a playbook not yet reflected as a distinct "upgrade completed" action.
  • Vendor-risk alerting coverage narrowed. The "Compromised TPV Alerts V2" playbook present in the prior period is no longer in the active workflow set, leaving Third-Party Vendor Risk Management focused solely on the OneTrust sync rather than also surfacing compromised-vendor alerts — a natural candidate to rebuild if that alerting need still exists.
  • Significant dev/test/duplicate sprawl. Of the 23 workspaces, at least two (04203f4a... and several ZTP-related workspaces) appear to be dev/test mirrors of production network automations, and the Sandbox use case (23 playbooks) plus the bulk of the 61-playbook Zero-Touch Provisioning use case show 0 executions — suggesting ZTP and several admin-tool switch-provisioning subflows are still mid-build rather than live in production.
  • Endpoint/Device Compliance (Intune, CrowdStrike table fill) has zero executions, indicating this use case has been built but not yet activated or scheduled — a natural next-phase rollout candidate.
  • GRC and Vulnerability Management are thin relative to SOC and Network Ops. Only 1 playbook covers KEV-based vulnerability remediation routing and 4 cover vendor risk management; given the size of the network/security footprint already automated, there is room to expand structured vulnerability and compliance-reporting automation.
  • Some playbooks straddle categories informally (e.g., CAB_Report and ISCDD Pipeline sit under IT Helpdesk operationally but serve a GRC/change-reporting function) — as the taxonomy matures, formally splitting these into their own GRC reporting use case would sharpen KPI attribution.

Integration Ecosystem

Rockwell's Blink footprint integrates with: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID/Active Directory, Microsoft Graph/Teams/Outlook/Excel/OneDrive, ServiceNow, Jira/Atlassian, VirusTotal, Proofpoint TAP, OneTrust, PagerDuty, Zendesk, VulnCheck, Armis Centrix, ForeScout, Cisco (IOS/C9300 switches, Meraki, ISE), Palo Alto Networks/Panorama, NetBox, EfficientIP, SolarWinds, Azure DevOps, Grafana, Microsoft Intune, and SharePoint. This breadth — spanning SIEM/EDR, identity, ITSM, GRC, and network infrastructure vendors — reflects Blink's role as a central automation fabric connecting Rockwell's security and network engineering tool stacks rather than a point solution for a single team.

Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 5 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 CS AI Agent Skills Integrations Workspace 0 0 0
2 John - Test delete Incident Response: Main Dashboard 0 0 0
3 Kevin Delete Incident Response: Main Dashboard 0 0 0
4 New Agent tom@blinkops.com 0 0 0
5 New Agent john.fung@rockwellautomation.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Skills Integrations Workspace0
Incident Response: Main Dashboard0
tom@blinkops.com0
john.fung@rockwellautomation.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
26
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 mgolczyk 00
2 Executions 00
3 Incident Response Dashboard 00
4 Meraki 00
5 Test Dash 00

Webforms

Forms
12
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Audit Site Squid File 00
2 Test 00
3 HEADER 00
4 Firewall REquest 00
5 Network Configuration Compliance Audit 00
D Full Use Case Analysis 16 use cases | 23,505 executions (12m)

Business KPIs

Metric Count Playbook(s)
Third-party vendor risk records synchronized from OneTrust 2,845 Subflow: TPV via OneTrust Table Update, TPV via OneTrust Table Update
Security alerts enriched with entity & user context for the SOC 2,269 Sentinel Automated Entity Enrichment
Endpoint browser history retrievals for active security investigations 2,268 Sentinel Automated Retrieve Browser History on RA-CS Alert, Sentinel Automated Retrieve Browser History on CS Alert
Unauthorized Atlassian API tokens detected & revoked 894 Revoke Atlassian API
Major incident reports generated & distributed to leadership 240 Major-Incident-Report-timed
Phishing / suspicious email alerts triaged 149 Triage an incident table update, Triage an internal phishing table update, On Proofpoint TAP Malicious Email Click, AI Phishing Analysis, Triage Internal Phishing Email, Phishing Alert and Enrichment
CSIRT shift-handoff briefings updated for the on-call team 120 Shift Handoff Update Automation
CSIRT executive email summaries generated & distributed 85 Summarize CSIRT Email every 8 Hrs, Summarize and Send CSIRT Email On VP Address
Scheduled network configuration compliance audits completed (WAN/LAN/Wireless/Meraki) 65 Scheduled: WAN Configuration Compliance Audit - AMER Region (+7 regional/platform variants)
ServiceNow change tickets closed automatically 45 Subflow: Close ServiceNow Change Task, Subflow: Close ServiceNow Standard Change Ticket
New network devices with a primary IP flagged for security review (ForeScout) 40 Daily notification for new Switch or Router with primary IP - ForeScout
Known-exploited vulnerabilities (KEV) identified & routed for remediation 40 VulnCheck KEV to Teams/Jira
ServiceNow standard change tickets created automatically 23 Subflow: Create ServiceNow Standard Change Ticket (+1 regional variant)
Non-compliant network device configurations auto-remediated 17 LAN Configuration Remediation - Apply
User password resets executed via Entra ID 12 Single User Password Reset via Entra ID, Bulk Password Reset via Entra ID
In the last 12 months, Blink automated: - 2,845 third-party vendor risk records synchronized with OneTrust - 2,269 security alerts enriched with entity & user context for the SOC - 2,268 endpoint browser history retrievals for active security investigations - 894 unauthorized Atlassian API tokens detected & revoked - 240 major incident reports generated & distributed to leadership - 149 phishing and suspicious email alerts triaged - 120 CSIRT shift-handoff briefings updated for the on-call team - 85 CSIRT executive email summaries generated & distributed - 65 scheduled network configuration compliance audits completed - 45 ServiceNow change tickets closed automatically - 40 new network devices with a primary IP flagged for security review - 40 known-exploited (KEV) vulnerabilities identified & routed for remediation - 23 ServiceNow standard change tickets created automatically - 17 non-compliant network configurations auto-remediated - 12 user password resets executed via Entra ID

Use Case Summary

# Use Case Category Subcategories Playbooks
1 Security Alert Enrichment & EDR Response SOC Agentic SOC, Alert enrichment / IOC lookup, EDR containment & response, Identity threat response, Threat intel ingest & curation, Case mgmt & SOAR 37
2 Phishing & Suspicious Email Triage SOC Phishing detection & response, Case mgmt & SOAR 6
3 CSIRT Incident Operations & Shift Handoff SOC / GRC Case mgmt & SOAR, Security metrics & reporting 16
4 Atlassian Access Revocation IAM Privileged account mgmt, JIT & temporary access 2
5 Password & Credential Resets IAM Password & credential lifecycle 4
6 Third-Party Vendor Risk Management GRC Vendor risk & TPRM 4
7 Known-Exploited Vulnerability (KEV) Remediation Routing Vulnerability Mgmt CVE lookup & remediation 1
8 Network Configuration Compliance & Remediation Other IT/OT & network infra monitoring, DevOps & release automation 52
9 Network Device OS/Firmware Upgrade Orchestration Other DevOps & release automation, IT/OT & network infra monitoring 22
10 Network Device Inventory & Discovery Other IT/OT & network infra monitoring 29
11 Zero-Touch Switch Provisioning Other DevOps & release automation, IT/OT & network infra monitoring 61
12 Palo Alto Firewall Rule & Object Governance Other IT/OT & network infra monitoring 15
13 IT Helpdesk Ticket Routing & Compliance Reporting Other / GRC IT helpdesk & ticket routing, Security metrics & reporting 14
14 Endpoint / Device Compliance & MDM Tracking Other Endpoint hygiene & MDM ops 4
15 Platform Notification & Messaging Utilities Other SaaS / IT administration 29
16 Sandbox, Testing & Getting-Started Workflows Other SaaS / IT administration 23

Use Cases

1. Security Alert Enrichment & EDR Response

Category: SOC  |  Subcategories: Agentic SOC, Alert enrichment / IOC lookup, EDR containment & response, Identity threat response, Threat intel ingest & curation, Case mgmt & SOAR  |  Playbooks: 37  |  Executions (12mo): 17499

Description: Automatically enriches Microsoft Sentinel and CrowdStrike security alerts with entity, user, and host context, and pulls supporting endpoint evidence (browser history, host isolation) for the SOC.

Business Problem: Analysts previously had to manually pivot across Sentinel, CrowdStrike, Active Directory, and ServiceNow to gather context on every alert before they could triage it, adding minutes of manual lookup to every case and slowing mean-time-to-triage during high-volume alert periods.

Integrations: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID / Active Directory, Microsoft Graph, ServiceNow, VirusTotal, Armis Centrix, ForeScout

View all 37 playbooks

Playbook Executions Category Subcategory
Subflow - Get Entities 7946 SOC Agentic SOC, Alert enrichment / IOC lookup
Sentinel Automated Entity Enrichment 2269 SOC Agentic SOC, Alert enrichment / IOC lookup
Sentinel Automated Retrieve Browser History on RA-CS Alert 2263 SOC EDR containment & response
Retrieve User Info Subflow 2158 SOC Agentic SOC, Alert enrichment / IOC lookup
Get Host Browser History Subflow 1420 SOC EDR containment & response
Exclude Mac Linux Subflow 1371 SOC EDR containment & response
Subflow - Get Entities 27 SOC Agentic SOC, Alert enrichment / IOC lookup
Get Browser History via Crowdstrike Self-Service 21 SOC EDR containment & response
Sentinel Automated: Fake Credential Access Alert 7 SOC Identity threat response, Alert enrichment / IOC lookup
Sentinel Automated Zscaler Deception Alert 6 SOC Agentic SOC, Alert enrichment / IOC lookup
Sentinel Automated Retrieve Browser History on CS Alert 5 SOC EDR containment & response
Connect to Host - Crowdstrike 3 SOC EDR containment & response
Threat Hunt Case Creation 2 SOC Threat intel ingest & curation, Case mgmt & SOAR
Sentinel Automated - Remote Logon to DC Alert 1 SOC Identity threat response, Alert enrichment / IOC lookup
Enrich IP By IPInfo 0 SOC Alert enrichment / IOC lookup
Subflow - Get Entities 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Retrieve User Info Via Entra ID 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Isolate or Lift Isolation on Device Via Crowdstrike 0 SOC EDR containment & response
Bulk Retrieve User Info via Entra ID 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Run Action on Host Subflow 0 SOC EDR containment & response
Search IOC with VirusTotal Subflow 0 SOC Alert enrichment / IOC lookup
Forensic Analysis on Device via Host Name 0 SOC EDR containment & response
Run Action Until Complete - Crowdstrike 0 SOC EDR containment & response
Retrieve User Info Subflow 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Search IOC with VirusTotal Subflow 0 SOC Alert enrichment / IOC lookup
Sentinel Trigger 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Sentinel Trigger copy 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Connect to Host - Crowdstrike 0 SOC EDR containment & response
Run Action on Host Subflow 0 SOC EDR containment & response
Run Action Until Complete - Crowdstrike 0 SOC EDR containment & response
Exclude Mac Linux Subflow 0 SOC EDR containment & response
Get Host Browser History Subflow DEV 0 SOC EDR containment & response
Sentinel Trigger copy copy 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Subflow - Get Entities 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Crowdstrike Fill Table - Subflow 0 SOC Agentic SOC
Crowdstrike Fill Table 0 SOC Agentic SOC
Subflow - Get Entities copy 0 SOC Agentic SOC, Alert enrichment / IOC lookup

2. Phishing & Suspicious Email Triage

Category: SOC  |  Subcategories: Phishing detection & response, Case mgmt & SOAR  |  Playbooks: 6  |  Executions (12mo): 149

Description: Triages reported and detected phishing/malicious email events (including Proofpoint TAP malicious-click alerts and internally reported emails), using AI-assisted analysis to accelerate disposition.

Business Problem: High volumes of user-reported and vendor-flagged phishing emails compete with other SOC priorities; without automation each report requires manual review of headers, links, and sender reputation before the SOC can close it out or escalate.

Integrations: Microsoft Sentinel, Proofpoint TAP, Azure Log Analytics

View all 6 playbooks

Playbook Executions Category Subcategory
Triage an incident table update 40 SOC Phishing detection & response, Case mgmt & SOAR
Triage an internal phishing table update 40 SOC Phishing detection & response, Case mgmt & SOAR
On Proofpoint TAP Malicious Email Click 33 SOC Phishing detection & response, Case mgmt & SOAR
AI Phishing Analysis 29 SOC Phishing detection & response, Case mgmt & SOAR
Triage Internal Phishing Email 5 SOC Phishing detection & response, Case mgmt & SOAR
Phishing Alert and Enrichment 2 SOC Phishing detection & response, Case mgmt & SOAR

3. CSIRT Incident Operations & Shift Handoff

Category: SOC / GRC  |  Subcategories: Case mgmt & SOAR, Security metrics & reporting  |  Playbooks: 16  |  Executions (12mo): 918

Description: Keeps the CSIRT running around the clock: compiles periodic incident email summaries, maintains the shift-handoff record for the on-call team, and generates/distributes major-incident reports to leadership via SharePoint.

Business Problem: Incident responders previously spent time manually compiling shift-handoff notes and status summaries between rotations, and major incidents required manual report writing and distribution, both of which delayed leadership visibility during active incidents.

Integrations: Microsoft Teams, Outlook, Excel, OneDrive, Microsoft Graph, PagerDuty, ServiceNow, SharePoint

View all 16 playbooks

Playbook Executions Category Subcategory
Major-Incident-Report-timed 240 GRC Security metrics & reporting
Subflow: ServiceNow to SharePoint list 228 GRC Security metrics & reporting
SharepointListTimedUpdate 228 GRC Security metrics & reporting
Shift Handoff Update Automation 120 SOC Case mgmt & SOAR
Summarize CSIRT Email every 8 Hrs 80 SOC Case mgmt & SOAR
OneTrust Inbox Incident copy 9 SOC Case mgmt & SOAR
Pager Duty Shift Roster Automation 5 SOC Case mgmt & SOAR
Summarize and Send CSIRT Email On VP Address 5 SOC Case mgmt & SOAR
OneTrust Inbox Incident 2 SOC Case mgmt & SOAR
Update Shift-Handoff URL 1 SOC Case mgmt & SOAR
Who Is on Pager Duty Today 0 SOC Case mgmt & SOAR
One Trust Create An Incident 0 SOC Case mgmt & SOAR
OneTrust Update Incident 0 SOC Case mgmt & SOAR
Major Incident Report 0 GRC Security metrics & reporting
Onetrust Sync 0 SOC Case mgmt & SOAR
Summarize Email Agent 0 SOC Case mgmt & SOAR

4. Atlassian Access Revocation

Category: IAM  |  Subcategories: Privileged account mgmt, JIT & temporary access  |  Playbooks: 2  |  Executions (12mo): 894

Description: Detects and automatically revokes unauthorized or stale Atlassian (Jira) API tokens flagged by Sentinel, closing a common cloud-credential exposure path.

Business Problem: Unauthorized or forgotten API tokens are a persistent identity risk that is easy to miss in manual reviews; without automation, revocation depended on someone noticing and acting on a Sentinel alert before the token could be misused.

Integrations: Jira / Atlassian Admin API, Microsoft Entra ID / Active Directory, Microsoft Sentinel

View all 2 playbooks

Playbook Executions Category Subcategory
Revoke Atlassian API 894 IAM Privileged account mgmt, JIT & temporary access
Atlassian API Removal Automation 0 IAM Privileged account mgmt, JIT & temporary access

5. Password & Credential Resets

Category: IAM  |  Subcategories: Password & credential lifecycle  |  Playbooks: 4  |  Executions (12mo): 25

Description: Executes single-user and bulk password resets in Entra ID on demand, and includes a newer SOP-triggered flow that watches for dark-web credential-exposure email alerts (currently triage/logging only, ahead of full reset automation).

Business Problem: Password reset requests are high-frequency, time-sensitive, and low-complexity, but manual handling still consumes helpdesk/IAM staff time and creates delay for locked-out users.

Integrations: Microsoft Entra ID (Azure AD), Microsoft Graph

View all 4 playbooks

Playbook Executions Category Subcategory
Darkweb password reset on email based on SOP 13 IAM Password & credential lifecycle
Single User Password Reset via Entra ID 11 IAM Password & credential lifecycle
Bulk Password Reset via Entra ID 1 IAM Password & credential lifecycle
Single User Password Reset via Entra ID 0 IAM Password & credential lifecycle

6. Third-Party Vendor Risk Management

Category: GRC  |  Subcategories: Vendor risk & TPRM  |  Playbooks: 4  |  Executions (12mo): 2846

Description: Synchronizes third-party vendor risk data from OneTrust into Blink tables, keeping the vendor risk register current without manual data entry.

Business Problem: Vendor risk records in OneTrust needed to be manually pulled and reconciled against internal tracking before GRC could assess exposure across the vendor population.

Integrations: OneTrust

View all 4 playbooks

Playbook Executions Category Subcategory
Subflow: TPV via OneTrust Table Update 2805 GRC Vendor risk & TPRM
TPV via OneTrust Table Update 40 GRC Vendor risk & TPRM
TPR Automated Reassessment 1 GRC Vendor risk & TPRM
Export GRC OneTrust Docs to Sharepoint 0 GRC Vendor risk & TPRM

7. Known-Exploited Vulnerability (KEV) Remediation Routing

Category: Vulnerability Mgmt  |  Subcategories: CVE lookup & remediation  |  Playbooks: 1  |  Executions (12mo): 40

Description: Checks new CVEs against the VulnCheck Known Exploited Vulnerabilities catalog and automatically routes matches to Teams/Jira for remediation tracking.

Business Problem: Identifying which newly disclosed CVEs are already being actively exploited in the wild (and therefore need urgent patching) requires cross-referencing external threat intel feeds — a manual step that delays prioritization if not automated.

Integrations: VulnCheck, Jira, Microsoft Teams

View all 1 playbooks

Playbook Executions Category Subcategory
VulnCheck KEV to Teams/Jira 40 Vulnerability Mgmt CVE lookup & remediation

8. Network Configuration Compliance & Remediation

Category: Other  |  Subcategories: IT/OT & network infra monitoring, DevOps & release automation  |  Playbooks: 52  |  Executions (12mo): 580

Description: Runs scheduled configuration-compliance audits across WAN, LAN, Wireless, and Meraki estates, and — where drift is found — pushes remediation and opens/closes the associated ServiceNow change tickets.

Business Problem: Network engineers previously had to manually audit device configurations against baseline standards region by region and hand-track the ServiceNow change process for every remediation, which did not scale across a large global network estate.

Integrations: Cisco (switches/routers), Cisco Meraki, ServiceNow, Azure DevOps, Blink Tables

View all 52 playbooks

Playbook Executions Category Subcategory
Subflow: Network Configuration Compliance Audit 96 Other IT/OT & network infra monitoring
Subflow: Get Device Facts 96 Other IT/OT & network infra monitoring
Subflow: Test Unreachable Devices 61 Other IT/OT & network infra monitoring
Subflow: LAN Configuration Remediation Workflow 40 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Close ServiceNow Change Task 30 Other IT/OT & network infra monitoring, DevOps & release automation
Table Button: Configuration Compliance Audit Workflow 22 Other IT/OT & network infra monitoring
DEV: LAN Configuration Remediation Workflow 21 Other IT/OT & network infra monitoring, DevOps & release automation
LAN Configuration Remediation - Prep 18 Other IT/OT & network infra monitoring, DevOps & release automation
LAN Configuration Remediation - Apply 17 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Get ServiceNow Change Ticket Status 17 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Create ServiceNow Standard Change Ticket 17 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Close ServiceNow Standard Change Ticket 15 Other IT/OT & network infra monitoring, DevOps & release automation
Scheduled: WAN Configuration Compliance Audit - AMER Region 9 Other IT/OT & network infra monitoring
Scheduled: WAN Configuration Compliance Audit - APAC Region 9 Other IT/OT & network infra monitoring
Scheduled: WAN Configuration Compliance Audit - EMEA Region 9 Other IT/OT & network infra monitoring
Scheduled: LAN Configuration Compliance Audit - AMER Region 9 Other IT/OT & network infra monitoring
@DEV - LAN Configuration Remediation - Apply 9 Other IT/OT & network infra monitoring, DevOps & release automation
Populate Compliance Time Series Table 8 Other IT/OT & network infra monitoring
Scheduled: LAN Configuration Compliance Audit - APAC Region 8 Other IT/OT & network infra monitoring
Scheduled: LAN Configuration Compliance Audit - EMEA Region 8 Other IT/OT & network infra monitoring
Scheduled: Wireless Configuration Compliance Audit - Global 7 Other IT/OT & network infra monitoring
Subflow: Get Device Facts 7 Other IT/OT & network infra monitoring
Subflow: Network Configuration Compliance Audit 7 Other IT/OT & network infra monitoring
Subflow: Get Meraki Facts 6 Other IT/OT & network infra monitoring
Subflow: Meraki Configuration Compliance Audit 6 Other IT/OT & network infra monitoring
Scheduled: Meraki Configuration Compliance Audit - Global 6 Other IT/OT & network infra monitoring
@DEV - LAN Configuration Remediation - Prep 6 Other IT/OT & network infra monitoring, DevOps & release automation
@DEV - LAN Configuration Remediation - Dry Run 6 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Create ServiceNow Standard Change Ticket 6 Other IT/OT & network infra monitoring, DevOps & release automation
LAN Configuration Remediation - Dry Run 4 Other IT/OT & network infra monitoring, DevOps & release automation
Audit ra-allowed-sites.conf 0 Other IT/OT & network infra monitoring
Audit ra-allowed-sites.conf (MAIN) 0 Other IT/OT & network infra monitoring
Audit ra-allowed-sites.conf (MAIN) 0 Other IT/OT & network infra monitoring
Main Router 0 Other IT/OT & network infra monitoring
Main Router 0 Other IT/OT & network infra monitoring
Workspace Router 0 Other IT/OT & network infra monitoring
Workspace Router (MAIN) 0 Other IT/OT & network infra monitoring
Workspace Router (MAIN) 0 Other IT/OT & network infra monitoring
Web Form 0 Other IT/OT & network infra monitoring
Subflow: Get Device Facts - DEPRECATED 0 Other IT/OT & network infra monitoring
Subflow: Test Unreachable Devices 0 Other IT/OT & network infra monitoring
Subflow: Get Device Facts - FEATURE 0 Other IT/OT & network infra monitoring
@PROD - TEST - LAN Configuration Remediation - Dry Run 0 Other IT/OT & network infra monitoring, DevOps & release automation
@PROD - TEST - LAN Configuration Remediation - Prep 0 Other IT/OT & network infra monitoring, DevOps & release automation
FEATURE - Subflow: Network Configuration Compliance Audit 0 Other IT/OT & network infra monitoring
FEATURE - Subflow: Get Meraki Facts 0 Other IT/OT & network infra monitoring
FEATURE - Meraki Configuration Compliance Audit 0 Other IT/OT & network infra monitoring
@PROD - TEST - LAN Configuration Remediation - Apply 0 Other IT/OT & network infra monitoring, DevOps & release automation
Network Engineering Changes Bulk Table Insert 0 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Get ServiceNow Change Ticket Status 0 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Close ServiceNow Standard Change Ticket 0 Other IT/OT & network infra monitoring, DevOps & release automation
Subflow: Close ServiceNow Change Task 0 Other IT/OT & network infra monitoring, DevOps & release automation

9. Network Device OS/Firmware Upgrade Orchestration

Category: Other  |  Subcategories: DevOps & release automation, IT/OT & network infra monitoring  |  Playbooks: 22  |  Executions (12mo): 5115

Description: Orchestrates staged OS/firmware upgrades (including Cisco C9300 switches and SAP RHEL servers), tracking supported-firmware variables, device-name/sync status, and per-device execution/validation.

Business Problem: Coordinating firmware upgrades across large fleets of switches and servers manually is error-prone and hard to track at scale; a missed validation step can leave devices on unsupported or vulnerable firmware.

Integrations: Cisco IOS/C9300 switches, Blink Tables

View all 22 playbooks

Playbook Executions Category Subcategory
C9300: Supported Firmwares Variable 1585 Other DevOps & release automation, IT/OT & network infra monitoring
C9300: SWITCH GLOBAL VARIABLE 1585 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: update device names in variable 1516 Other DevOps & release automation, IT/OT & network infra monitoring
RUNNING WORKFLOW VALIDATION 134 Other DevOps & release automation, IT/OT & network infra monitoring
V1.0.2: SINGLE EXECUTION 133 Other DevOps & release automation, IT/OT & network infra monitoring
V1.0.2: DEVICE SYNC 133 Other DevOps & release automation, IT/OT & network infra monitoring
V1.0.2: BULK SELECTION 29 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: subflow-device Sync + Row operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: execution 0 Other DevOps & release automation, IT/OT & network infra monitoring
SAP RHEL Upgrade Part 2 0 Other DevOps & release automation, IT/OT & network infra monitoring
SAP RHEL Upgrade Part 1 0 Other DevOps & release automation, IT/OT & network infra monitoring
On-Demand: Update Sites Global Variable 0 Other DevOps & release automation, IT/OT & network infra monitoring
On-Demand: Update Network Switch Regional Variable 0 Other DevOps & release automation, IT/OT & network infra monitoring
Upgrade IOS Subflow 0 Other DevOps & release automation, IT/OT & network infra monitoring
Populate NetBox OS Standards from Table 0 Other DevOps & release automation, IT/OT & network infra monitoring
On-Demand: Update Network Switch Platform Variables 0 Other DevOps & release automation, IT/OT & network infra monitoring
RHEL 0 Other DevOps & release automation, IT/OT & network infra monitoring
RHEL 2 0 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: subflow-device Sync + Row operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: execution 0 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: subflow-device Sync + Row operation copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
os-upgrade: execution copy 0 Other DevOps & release automation, IT/OT & network infra monitoring

10. Network Device Inventory & Discovery

Category: Other  |  Subcategories: IT/OT & network infra monitoring  |  Playbooks: 29  |  Executions (12mo): 1989

Description: Keeps network device inventory, end-of-life/end-of-support (EOX) status, and SD-WAN estate data current by continuously collecting and populating tracking tables from ForeScout, NetBox, and SD-WAN sources.

Business Problem: Without continuous discovery, network inventory and EOX records drift out of date, making it hard for engineering and procurement teams to plan refresh cycles or spot unmanaged/unauthorized devices on the network.

Integrations: ForeScout, NetBox, Cisco Meraki, Grafana, SharePoint

View all 29 playbooks

Playbook Executions Category Subcategory
SD-WAN Data Collection 1920 Other IT/OT & network infra monitoring
Daily notification for new Switch or Router with primary IP - ForeScout 40 Other IT/OT & network infra monitoring
Grafana + Blink 10 Other IT/OT & network infra monitoring
Populate Network Device EOX Time Series Table 6 Other IT/OT & network infra monitoring
Populate Managed Network Estate Time Series Table 6 Other IT/OT & network infra monitoring
Populate Network Device Inventory Table 5 Other IT/OT & network infra monitoring
NetBox - Populate Cisco EOX Fields into Device Types 1 Other IT/OT & network infra monitoring
Cisco Interface Update Configuration Push 1 Other IT/OT & network infra monitoring
Active switch or router with primary ip alert 0 Other IT/OT & network infra monitoring
Active switch or router with primary ip alert (Marcin.Golczyk@rockwellautomation.com) 0 Other IT/OT & network infra monitoring
Daily notification for new Switch or Router with primary IP 0 Other IT/OT & network infra monitoring
SD-WAN Status Sync 0 Other IT/OT & network infra monitoring
EOL Trend 0 Other IT/OT & network infra monitoring
Network Device Triage 0 Other IT/OT & network infra monitoring
Populate Device Inventory Min Table 0 Other IT/OT & network infra monitoring
Router Triage (Deep Dive) 0 Other IT/OT & network infra monitoring
Populate Refresh Tracking Table from SharePoint 0 Other IT/OT & network infra monitoring
Cisco EOX NetBox 0 Other IT/OT & network infra monitoring
Carrier Maintenance 0 Other IT/OT & network infra monitoring
Get Organization Devices with Cisco Meraki and Send Results via Email 0 Other IT/OT & network infra monitoring
Network Device Triage copy 0 Other IT/OT & network infra monitoring
Grafana + Blink 0 Other IT/OT & network infra monitoring
Remove Decommissioned Devices from Tables 0 Other IT/OT & network infra monitoring
Add/Update Device Record 0 Other IT/OT & network infra monitoring
Subflow: syslog message 0 Other IT/OT & network infra monitoring
Subflow: syslog message 0 Other IT/OT & network infra monitoring
Subflow: syslog message copy 0 Other IT/OT & network infra monitoring
Netbox Racks Utilization 0 Other IT/OT & network infra monitoring
Network Devices Discovery for Interface Automation (via CDP/LLDP) 0 Other IT/OT & network infra monitoring

11. Zero-Touch Switch Provisioning

Category: Other  |  Subcategories: DevOps & release automation, IT/OT & network infra monitoring  |  Playbooks: 61  |  Executions (12mo): 41

Description: Automates end-to-end zero-touch provisioning (ZTP) of new switches — NetBox registration, ISE/EfficientIP/IPAM configuration, VLAN/uplink setup, IOS upgrade, and final configuration push — largely still in dev/build-out.

Business Problem: Manually staging a new switch requires touching half a dozen systems (NetBox, ISE, IPAM, syslog, IOS) in the right order; ZTP is designed to collapse that into a single automated pipeline, though most of this use case is currently in development/testing workspaces rather than production.

Integrations: NetBox, Cisco ISE, EfficientIP IPAM, SolarWinds

View all 61 playbooks

Playbook Executions Category Subcategory
Switch Provisioning - Post-ZTP 26 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Post-ZTP worflow 15 Other DevOps & release automation, IT/OT & network infra monitoring
NetboxtoBlinkops Email.(mmettu) 0 Other DevOps & release automation, IT/OT & network infra monitoring
device-deletion-from-netbox 0 Other DevOps & release automation, IT/OT & network infra monitoring
Update Device Upgrade Exection Log 0 Other DevOps & release automation, IT/OT & network infra monitoring
All Device Record 0 Other DevOps & release automation, IT/OT & network infra monitoring
Device Update 0 Other DevOps & release automation, IT/OT & network infra monitoring
Phase 1: Single Switch 0 Other DevOps & release automation, IT/OT & network infra monitoring
Phase 2: Single Switch 0 Other DevOps & release automation, IT/OT & network infra monitoring
Load All Device 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - final switch configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - ISE configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - uplink VLAN interface configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - HTTP/S iptables configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - state table interaction 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - Netbox configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - input uplink switch 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Register switch in ISE copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - Cleanup workflow 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - EfficientIP configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
DEPRECATED Subflow: Switch Provisioning - IOS upgrade 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - IOS upgrade 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - HTTP/S iptables configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - state table interaction 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - uplink VLAN interface configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - ISE configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - EfficientIP configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - Netbox configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - Cleanup workflow 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - final switch configuration 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - IOS upgrade 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Post-ZTP worflow 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - input uplink switch 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - IOS upgrade copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
TEST new ZTP approach 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - Netbox configuration copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Pre-ZTP 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - Netbox Client 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - ISE Client 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - Netbox client - Damian changesNetbox Client copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - EfficientIP Client 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - HTTP/S server operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - VLAN uplink operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - state table interaction copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
Subflow: Switch Provisioning - state table interaction copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Post-ZTP 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN - Switch Provisioning - Cleanup workflow 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - final config application 0 Other DevOps & release automation, IT/OT & network infra monitoring
FOR TESTING BLINKOPS FIX -ADMIN Tool: Switch Provisioning - Netbox Client copy 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Pre-ZTP FOR TESTING 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Pre-ZTP - uv test 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - VLAN uplink operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Pre-ZTP 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - Netbox Client 0 Other DevOps & release automation, IT/OT & network infra monitoring
Switch Provisioning - Post-ZTP 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - ISE Client 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - final config application 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN Tool: Switch Provisioning - HTTP/S server operation 0 Other DevOps & release automation, IT/OT & network infra monitoring
ADMIN - Switch Provisioning - Cleanup workflow 0 Other DevOps & release automation, IT/OT & network infra monitoring

12. Palo Alto Firewall Rule & Object Governance

Category: Other  |  Subcategories: IT/OT & network infra monitoring  |  Playbooks: 15  |  Executions (12mo): 92

Description: Audits and cleans up Palo Alto Panorama/firewall rule bases and objects — identifying stale, unused, or duplicate rules and objects, and reporting on Global Protect usage and interface configuration.

Business Problem: Firewall rule bases accumulate unused and duplicate rules/objects over time, which increases both attack surface and administrative overhead when nobody is systematically auditing them.

Integrations: Palo Alto Networks (Panorama / Firewalls)

View all 15 playbooks

Playbook Executions Category Subcategory
paloalto-table-weekly-updates 40 Other IT/OT & network infra monitoring
PaloAlto Firewalls Interface Information. 40 Other IT/OT & network infra monitoring
Palo Alto Firewall Unused Rule/Object Count Tables and Graph 6 Other IT/OT & network infra monitoring
Palo Alto Global Protect Users Reporting 6 Other IT/OT & network infra monitoring
Paloalto Disable/Delete Rules and Objects. 0 Other IT/OT & network infra monitoring
paloalto unused/stalerules and unused/duplicate objects-audit 0 Other IT/OT & network infra monitoring
Palo Alto Firewall Rule/Object Cleanup-Audit 0 Other IT/OT & network infra monitoring
paloalto disable/delete rules and objects. 0 Other IT/OT & network infra monitoring
paloalto stale/unused rules for specific device groups. 0 Other IT/OT & network infra monitoring
PaloAlto Stale/Unused Rules for Specific Device Groups. 0 Other IT/OT & network infra monitoring
PaloAlto Route Configuration 0 Other IT/OT & network infra monitoring
PaloAlto DNS Route Configuration 0 Other IT/OT & network infra monitoring
Palo Alto Firewall Unused/Duplicate Object Cleanup-PROD-Audit 0 Other IT/OT & network infra monitoring
Palo Alto Current data 0 Other IT/OT & network infra monitoring
Panorama Duplicate Objects Consolidation 0 Other IT/OT & network infra monitoring

13. IT Helpdesk Ticket Routing & Compliance Reporting

Category: Other / GRC  |  Subcategories: IT helpdesk & ticket routing, Security metrics & reporting  |  Playbooks: 14  |  Executions (12mo): 54

Description: Routes and summarizes helpdesk/service-desk activity (Zendesk, Jira intake, AI-assisted triage) and produces recurring compliance/procurement reporting (CAB change reports, ISCDD pipeline, Cyber RDO procurement).

Business Problem: Ticket intake and recurring governance reports (change advisory board packets, procurement/compliance pipelines) were manually compiled on a schedule, consuming analyst time on work that follows a repeatable template.

Integrations: Jira, Zendesk, Microsoft Excel/OneDrive/Graph, SharePoint

View all 14 playbooks

Playbook Executions Category Subcategory
Zendesk Report 6 Other IT helpdesk & ticket routing
Zendesk Report 6 Other IT helpdesk & ticket routing
Jira Intake 6 Other IT helpdesk & ticket routing
Jira Intake 6 Other IT helpdesk & ticket routing
Cyber RDO Procurement 6 GRC Security metrics & reporting
ISCDD Pipeline 6 GRC Security metrics & reporting
ISCDD Pipeline 6 GRC Security metrics & reporting
CAB_Report 6 Other DevOps & release automation, IT helpdesk & ticket routing
CAB_Report 6 Other DevOps & release automation, IT helpdesk & ticket routing
Service Desk AI Assisted Triage 0 Other IT helpdesk & ticket routing
On SIEM Logging Form Request Create a Jira Ticket and Inform the SIEM Team 0 Other IT helpdesk & ticket routing
Jira storypack from epic 0 Other IT helpdesk & ticket routing
BlinkOps Request Form To Jira 0 Other IT helpdesk & ticket routing
ADX AI Assisted Triage 0 Other IT helpdesk & ticket routing

14. Endpoint / Device Compliance & MDM Tracking

Category: Other  |  Subcategories: Endpoint hygiene & MDM ops  |  Playbooks: 4  |  Executions (12mo): 0

Description: Populates device compliance and Intune/CrowdStrike-sourced endpoint tables to track MDM and endpoint hygiene status; currently built but not yet driving executions in production.

Business Problem: Endpoint compliance status (MDM enrollment, CrowdStrike coverage) needs to be centrally tracked to spot gaps, but this use case is still in a pre-production/build phase for Rockwell.

Integrations: Microsoft Intune (Graph API), CrowdStrike

View all 4 playbooks

Playbook Executions Category Subcategory
Device Compliance - Generate Run Results Entry 0 Other Endpoint hygiene & MDM ops
Device Compliance - Main 0 Other Endpoint hygiene & MDM ops
Intune by Graph API Fill Table 0 Other Endpoint hygiene & MDM ops
Intune by Graph API Fill Table - Subflow 0 Other Endpoint hygiene & MDM ops

15. Platform Notification & Messaging Utilities

Category: Other  |  Subcategories: SaaS / IT administration  |  Playbooks: 29  |  Executions (12mo): 2452

Description: Shared notification and messaging plumbing (Teams webhooks/direct messages, email/SMTP delivery workarounds, service-account chat channels, execution-tracking utilities) that other use cases call to deliver their outputs.

Business Problem: Reliable, consistent delivery of automation output (alerts, reports, approvals) to Teams and email needed a standardized, reusable mechanism rather than each automation implementing its own notification logic.

Integrations: Microsoft Teams, SMTP/Email, Jira

View all 29 playbooks

Playbook Executions Category Subcategory
NOTIFICATION: TEAMS WEBHOOK 2070 Other SaaS / IT administration
NOTIFICATION: EMAIL WEBHOOK 143 Other SaaS / IT administration
NOTIFICATION: TEAMS DIRECT 133 Other SaaS / IT administration
Microsoft Graph Mail Service 41 Other SaaS / IT administration
SMTP Email Workaround 37 Other SaaS / IT administration
Python SMTP Email Workaround 10 Other SaaS / IT administration
1:1 SVC-BlinkOps Chat 9 Other SaaS / IT administration
Python SMTP Email Workaround 6 Other SaaS / IT administration
Execution Recorder 2 Other SaaS / IT administration
Python SMTP Email Workaround 1 Other SaaS / IT administration
Request Access for JIRA API 0 Other SaaS / IT administration
Ubuntu - Add user with password and Sudo 0 Other SaaS / IT administration
Get Approval 0 Other SaaS / IT administration
Nutanix Get VMs 0 Other SaaS / IT administration
Group SVC-BlinkOps Chat 0 Other SaaS / IT administration
SMTP Email Workaround 0 Other SaaS / IT administration
Fill out this form 0 Other SaaS / IT administration
1:1 SVC-BlinkOps Chat 0 Other SaaS / IT administration
SMTP Email Workaround 0 Other SaaS / IT administration
Teams Approval Request Notification 0 Other SaaS / IT administration
1:1 SVC-BlinkOps Chat 0 Other SaaS / IT administration
SMTP Email Workaround 0 Other SaaS / IT administration
SMTP Email Workaround 0 Other SaaS / IT administration
1:1 SVC-BlinkOps Chat 0 Other SaaS / IT administration
Import Blink Automations from a Git Repository 0 Other SaaS / IT administration
Import Blink Automations from a Git Repository 0 Other SaaS / IT administration
Microsoft Graph Mail Service 0 Other SaaS / IT administration
NOTIFICATION: EMAIL 0 Other SaaS / IT administration
Execution Recorder: Updator 0 Other SaaS / IT administration

16. Sandbox, Testing & Getting-Started Workflows

Category: Other  |  Subcategories: SaaS / IT administration  |  Playbooks: 23  |  Executions (12mo): 0

Description: Onboarding templates ("Getting Started - Hello World"), scratch/test workflows, and workspace-router utilities used by builders while developing or evaluating new automations; not part of steady-state production operations.

Business Problem: N/A — these are platform onboarding and development artifacts rather than automations that solve a standing business problem.

Integrations: n/a (test/sandbox connectors: Bash, PowerShell, Nutanix, NetBox, ServiceNow test endpoints)

View all 23 playbooks

Playbook Executions Category Subcategory
Getting Started - Hello World 0 Other SaaS / IT administration
Getting Started - Hello World 0 Other SaaS / IT administration
Test Bash 0 Other SaaS / IT administration
Powershell Test 0 Other SaaS / IT administration
Test Len OF rows 0 Other SaaS / IT administration
Subflow - Example 0 Other SaaS / IT administration
Simple Flow 0 Other SaaS / IT administration
Getting Started - Hello World 0 Other SaaS / IT administration
Kevin For .txt 0 Other SaaS / IT administration
New Workflow 0 Other SaaS / IT administration
New Workflow (Marcin.Golczyk@rockwellautomation.com) 0 Other SaaS / IT administration
ipam_prefix_changed 0 Other SaaS / IT administration
ipam_prefix_changed (Marcin.Golczyk@rockwellautomation.com) 0 Other SaaS / IT administration
Create Table 0 Other SaaS / IT administration
Create Table from Schema 0 Other SaaS / IT administration
On-Demand: Create a Table From Schema 0 Other SaaS / IT administration
New Workflow 0 Other SaaS / IT administration
Python Hello World 0 Other SaaS / IT administration
Python Hello World 3 0 Other SaaS / IT administration
Python Hello World Second2 0 Other SaaS / IT administration
On Demand: Create Dashboard from Schema 0 Other SaaS / IT administration
test_serviceNow_sc_task_fetch 0 Other SaaS / IT administration
Fail This 0 Other SaaS / IT administration

Key Observations

Strengths

  • SOC alert enrichment remains the deepest and highest-volume use case. Security Alert Enrichment & EDR Response alone accounts for 37 playbooks and nearly 17,500 executions in the trailing 12 months — spanning Sentinel and CrowdStrike enrichment, entity/user lookups, browser-history retrieval, and containment actions — and grew further versus the prior reporting period, reinforcing it as the most mature and heavily-relied-upon automation surface in the tenant.
  • Cross-domain coverage. Rockwell has extended Blink well beyond the SOC into IAM (Atlassian token revocation, password resets), GRC (third-party risk sync, major-incident reporting), Vulnerability Management (KEV routing), and — most heavily — network/IT operations (configuration compliance, OS upgrades, inventory, firewall governance, zero-touch provisioning).
  • Network operations is the largest category by playbook count. Across Network Configuration Compliance, OS/Firmware Upgrades, Network Inventory, Zero-Touch Provisioning, and Palo Alto Governance, Rockwell has built 179 playbooks (56% of the tenant) automating global network engineering workflows across AMER/APAC/EMEA regions — indicating Blink has become core infrastructure for the network engineering team, not just security.
  • Real business-action volume is substantial and growing. Even after excluding infrastructure/subflow noise, the KPI table above reflects over 9,100 discrete, describable business actions completed by automation in 12 months — vendor risk syncs, alert enrichments, token revocations, incident reports, ticket lifecycle actions, and compliance audits — up from ~8,100 at the prior measurement.

Gaps & Opportunities

  • Heavy reliance on internal subflows inflates raw execution counts without a matching top-level business narrative. Playbooks like "Subflow - Get Entities" (7,946 executions) and several "Retrieve User Info"/"Get Host Browser History" subflows are called by multiple parent automations across workspaces; consolidating shared subflow logic (rather than duplicating it per workspace) would simplify maintenance and make the automation inventory easier to reason about.
  • The OS/firmware upgrade pipeline appears to be mid-transition. The historical "os-upgrade: execution" playbook now shows zero runs in the trailing window (down from 79), while a newer device-name variable-sync step ("os-upgrade: update device names in variable," 1,516 runs) and the C9300 supported-firmware/global-variable playbooks (1,585 runs each) carry most of the volume — worth confirming whether live upgrade executions have genuinely paused or simply moved to a playbook not yet reflected as a distinct "upgrade completed" action.
  • Vendor-risk alerting coverage narrowed. The "Compromised TPV Alerts V2" playbook present in the prior period is no longer in the active workflow set, leaving Third-Party Vendor Risk Management focused solely on the OneTrust sync rather than also surfacing compromised-vendor alerts — a natural candidate to rebuild if that alerting need still exists.
  • Significant dev/test/duplicate sprawl. Of the 23 workspaces, at least two (04203f4a... and several ZTP-related workspaces) appear to be dev/test mirrors of production network automations, and the Sandbox use case (23 playbooks) plus the bulk of the 61-playbook Zero-Touch Provisioning use case show 0 executions — suggesting ZTP and several admin-tool switch-provisioning subflows are still mid-build rather than live in production.
  • Endpoint/Device Compliance (Intune, CrowdStrike table fill) has zero executions, indicating this use case has been built but not yet activated or scheduled — a natural next-phase rollout candidate.
  • GRC and Vulnerability Management are thin relative to SOC and Network Ops. Only 1 playbook covers KEV-based vulnerability remediation routing and 4 cover vendor risk management; given the size of the network/security footprint already automated, there is room to expand structured vulnerability and compliance-reporting automation.
  • Some playbooks straddle categories informally (e.g., CAB_Report and ISCDD Pipeline sit under IT Helpdesk operationally but serve a GRC/change-reporting function) — as the taxonomy matures, formally splitting these into their own GRC reporting use case would sharpen KPI attribution.

Integration Ecosystem

Rockwell's Blink footprint integrates with: Microsoft Sentinel, CrowdStrike, Microsoft Entra ID/Active Directory, Microsoft Graph/Teams/Outlook/Excel/OneDrive, ServiceNow, Jira/Atlassian, VirusTotal, Proofpoint TAP, OneTrust, PagerDuty, Zendesk, VulnCheck, Armis Centrix, ForeScout, Cisco (IOS/C9300 switches, Meraki, ISE), Palo Alto Networks/Panorama, NetBox, EfficientIP, SolarWinds, Azure DevOps, Grafana, Microsoft Intune, and SharePoint. This breadth — spanning SIEM/EDR, identity, ITSM, GRC, and network infrastructure vendors — reflects Blink's role as a central automation fabric connecting Rockwell's security and network engineering tool stacks rather than a point solution for a single team.

E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Rockwell censys blinkops_censys 2026-08-25