01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Identity & Credential Lifecycle |
| 60.0% | 4 4 active |
| Phishing & Suspicious Email Response |
| 16.0% | 1 1 active |
| Endpoint Threat Response |
| 8.0% | 3 3 active |
| System Health Monitoring | 4 executions | 16.0% | 1 1 active |
| Worklog & Operational Reporting | 0 executions | 0.0% | 1 1 active |
| Total | 25 executions | 100% | 10 10 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Identity-first posture: The most-executed automation by a wide margin is the Okta MFA deactivation response (21 runs), reflecting a mature focus on identity threat detection and response. The workflow combines SIEM alert ingestion (InsightIDR), Teams-based approval gates, and Okta remediation in a single end-to-end chain.
- Credential hygiene automation: Two complementary SPN secret expiry workflows run on a monthly schedule, ensuring that privileged service account credentials are tracked and communicated proactively — reducing the risk of expired credentials causing service disruptions or going unnoticed.
- Microsoft ecosystem depth: The integration stack spans Microsoft Defender XDR, Defender for Endpoints, Entra ID, Teams, and Outlook, demonstrating strong operational coverage within a Microsoft-centric environment.
- Analyst-in-the-loop design: Both the MFA reset and the suspicious email workflows use Teams-based approval steps before taking action, reflecting a responsible automation philosophy that preserves analyst control over high-risk decisions.
###
Gaps & Opportunities
- Low activation on built workflows: Several workflows — Password Expiration Notification, Scan Machine, Get Alert, and Tempo Worklogs — have zero executions in the last 12 months. These represent either deprecated automations or deployed-but-unused capabilities worth reviewing for activation or cleanup.
- Phishing response at low volume: The MS Defender Suspicious Email workflow has only 3 executions despite being event-triggered. Tuning the trigger condition or broadening alert coverage could increase detection fidelity and workflow utilization.
- No vulnerability management automation: The current automation footprint has no coverage for vulnerability scanning, CVE tracking, or patch lifecycle management — a common gap for organizations at this stage of automation maturity.
- Limited GRC / compliance coverage: No workflows address audit reporting, access reviews, or compliance automation. Given the credential and identity focus already in place, RBAC review and access certification workflows would be a natural next step.
- Consolidation opportunity:
Scan MachineandAnti-Virus Scanappear to be functionally equivalent on-demand AV scan workflows. Consolidating these would reduce maintenance overhead.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 5 use cases | 25 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| MFA deactivation threats investigated & remediated | 21 | LIVE Okta MFA Password Reset Automation |
| Suspicious URL click alerts enriched & escalated | 3 | MS Defender Suspicious Email |
| SPN secret expiry notification cycles executed | 1 | SPN Secret Expiry Notification |
| Expired SPN secret reports delivered to teams | 1 | Get Expired SPN Secrets |
| On-demand endpoint antivirus scans initiated | 1 | Anti-Virus Scan |
Use Case Summary
| Use Case | Category | Playbook Count | Active Playbooks |
|---|---|---|---|
| Identity & Credential Lifecycle | IAM | 4 | 3 |
| Phishing & Suspicious Email Response | SOC | 1 | 1 |
| Endpoint Threat Response | SOC | 3 | 1 |
| System Health Monitoring | Other | 1 | 1 |
| Worklog & Operational Reporting | Other | 1 | 0 |
Use Cases
1. Identity & Credential Lifecycle
Description: Automated monitoring and response for credential-related threats and expiry events. Covers both proactive notification of expiring SPN secrets and reactive response to identity anomalies such as MFA deactivation events detected via SIEM.
Business Problem Solved: Credential exposure from expired or compromised service principal secrets and user MFA tampering introduces significant identity risk. Manual tracking of these events at scale is error-prone and slow. These workflows ensure timely notification and analyst-gated remediation.
Integrations: Okta, Rapid7 InsightIDR, Microsoft Teams, Microsoft Outlook, Microsoft Entra ID (Active Directory), HTTP Tables
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| LIVE Okta MFA Password Reset Automation | 21 | IAM | Identity threat response, Password & credential lifecycle |
| SPN Secret Expiry Notification | 1 | IAM | Password & credential lifecycle, Privileged account mgmt |
| Get Expired SPN Secrets | 1 | IAM | Password & credential lifecycle, Privileged account mgmt |
| Password Expiration Notification Workflow | 0 | IAM | Password & credential lifecycle |
2. Phishing & Suspicious Email Response
Description: Event-driven response workflow triggered by Microsoft Defender XDR when a potentially malicious URL click is detected. Enriches the alert with incident details, runs a threat hunting query, pulls login context from Entra ID, and routes an approval decision to a Teams channel.
Business Problem Solved: Phishing via malicious URLs is one of the most common initial access vectors. Manual investigation requires correlating data across Defender, Active Directory, and email — this workflow automates the enrichment chain and surfaces a concise, human-readable summary for analyst decision-making.
Integrations: Microsoft Defender XDR, Microsoft Entra ID, Microsoft Teams
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| MS Defender Suspicious Email | 3 | SOC | Phishing detection & response, Alert enrichment / IOC lookup, Identity threat response |
3. Endpoint Threat Response
Description: On-demand and utility workflows for triggering antivirus scans and retrieving alert details from Microsoft Defender for Endpoints. Provides a standardized interface for initiating endpoint response actions.
Business Problem Solved: Inconsistent or delayed endpoint scanning during incidents increases dwell time. These workflows give analysts a repeatable, auditable path to trigger scans and retrieve alert context without direct access to the Defender portal.
Integrations: Microsoft Defender for Endpoints, Microsoft Defender XDR
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Anti-Virus Scan | 1 | SOC | EDR containment & response |
| Scan Machine | 0 | SOC | EDR containment & response |
| Get alert | 0 | SOC | Alert enrichment / IOC lookup |
4. System Health Monitoring
Description: Scheduled heartbeat workflow that runs every two weeks to verify core Okta connectivity and system availability by performing a user lookup.
Business Problem Solved: Integration outages can silently break automated security workflows. A periodic heartbeat confirms that critical identity integrations remain operational and alerts the team to connectivity failures before they affect real incidents.
Integrations: Okta
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Heartbeat | 3 | Other | IT/OT & network infra monitoring |
5. Worklog & Operational Reporting
Description: On-demand workflow for fetching Tempo worklogs by date range, project, and team — likely used for time tracking or operational reporting tied to a Jira/Tempo environment.
Business Problem Solved: Manual extraction and formatting of worklog data is time-consuming for team leads and project managers. This workflow standardizes the extraction process across date ranges and team boundaries.
Integrations: Tempo (Jira)
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Tempo GET Worklogs | 0 | Other | DevOps & release automation |
Key Observations
Strengths
- Identity-first posture: The most-executed automation by a wide margin is the Okta MFA deactivation response (21 runs), reflecting a mature focus on identity threat detection and response. The workflow combines SIEM alert ingestion (InsightIDR), Teams-based approval gates, and Okta remediation in a single end-to-end chain.
- Credential hygiene automation: Two complementary SPN secret expiry workflows run on a monthly schedule, ensuring that privileged service account credentials are tracked and communicated proactively — reducing the risk of expired credentials causing service disruptions or going unnoticed.
- Microsoft ecosystem depth: The integration stack spans Microsoft Defender XDR, Defender for Endpoints, Entra ID, Teams, and Outlook, demonstrating strong operational coverage within a Microsoft-centric environment.
- Analyst-in-the-loop design: Both the MFA reset and the suspicious email workflows use Teams-based approval steps before taking action, reflecting a responsible automation philosophy that preserves analyst control over high-risk decisions.
Gaps & Opportunities
- Low activation on built workflows: Several workflows — Password Expiration Notification, Scan Machine, Get Alert, and Tempo Worklogs — have zero executions in the last 12 months. These represent either deprecated automations or deployed-but-unused capabilities worth reviewing for activation or cleanup.
- Phishing response at low volume: The MS Defender Suspicious Email workflow has only 3 executions despite being event-triggered. Tuning the trigger condition or broadening alert coverage could increase detection fidelity and workflow utilization.
- No vulnerability management automation: The current automation footprint has no coverage for vulnerability scanning, CVE tracking, or patch lifecycle management — a common gap for organizations at this stage of automation maturity.
- Limited GRC / compliance coverage: No workflows address audit reporting, access reviews, or compliance automation. Given the credential and identity focus already in place, RBAC review and access certification workflows would be a natural next step.
- Consolidation opportunity:
Scan MachineandAnti-Virus Scanappear to be functionally equivalent on-demand AV scan workflows. Consolidating these would reduce maintenance overhead.
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.