Blink Security Automation — Confidential

rotaryclub — Customer Success Report

Generated 2026-08-31 | rotaryclub-value-report.md
2026-08-31Report Date
73Total Playbooks
15Unique Workflows (12m)
489,963Actions Automated (12m)
$126,019Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

73
Total playbooks built
all non-deleted workflows
11
Active playbooks
currently enabled
15
Unique workflows executed (12m)
distinct workflows that ran
489,963
Actions automated (12m)
completed action steps
2,722.0h
Hours saved (12m)
@ 20s per action
$126,019
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 21 MFA deactivation threats investigated & remediated with analyst-in-the-loop approval via Teams - 3 suspicious URL click alerts enriched with identity context and escalated for response - 2 SPN credential expiry reporting cycles executed without manual intervention - 1 on-demand endpoint antivirus scan initiated through a standardized workflow

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Identity & Credential Lifecycle
  • 21MFA deactivation threats investigated & remediated
  • 1SPN secret expiry notification cycles executed
  • 1Expired SPN secret reports delivered to teams
60.0%
4
4 active
Phishing & Suspicious Email Response
  • 3Suspicious URL click alerts enriched & escalated
16.0%
1
1 active
Endpoint Threat Response
  • 1On-demand endpoint antivirus scans initiated
8.0%
3
3 active
System Health Monitoring4 executions
16.0%
1
1 active
Worklog & Operational Reporting0 executions
0.0%
1
1 active
Total25 executions100%
10
10 active

Use Case Growth Over Time

46 unique playbooks  |  5 operational use cases  |  25 total executions (12m)  |  2025-04 to 2026-06
Toggle:
Toggle:

03Integration Ecosystem

Identity & Credential Lifecycle
Microsoft Graph Microsoft Outlook Rapid7 InsightIDR Microsoft Teams Okta Email Microsoft Entra ID
Worklog & Operational Reporting
Tempo
Phishing & Suspicious Email Response
Microsoft Defender XDR Microsoft Entra ID Microsoft Intune Microsoft Teams Email Microsoft Outlook Okta
Endpoint Threat Response
Microsoft Defender XDR Microsoft Defender For Endpoints
System Health Monitoring
Okta

04Key Observations

✓  Strengths

Strengths

  • Identity-first posture: The most-executed automation by a wide margin is the Okta MFA deactivation response (21 runs), reflecting a mature focus on identity threat detection and response. The workflow combines SIEM alert ingestion (InsightIDR), Teams-based approval gates, and Okta remediation in a single end-to-end chain.
  • Credential hygiene automation: Two complementary SPN secret expiry workflows run on a monthly schedule, ensuring that privileged service account credentials are tracked and communicated proactively — reducing the risk of expired credentials causing service disruptions or going unnoticed.
  • Microsoft ecosystem depth: The integration stack spans Microsoft Defender XDR, Defender for Endpoints, Entra ID, Teams, and Outlook, demonstrating strong operational coverage within a Microsoft-centric environment.
  • Analyst-in-the-loop design: Both the MFA reset and the suspicious email workflows use Teams-based approval steps before taking action, reflecting a responsible automation philosophy that preserves analyst control over high-risk decisions.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Low activation on built workflows: Several workflows — Password Expiration Notification, Scan Machine, Get Alert, and Tempo Worklogs — have zero executions in the last 12 months. These represent either deprecated automations or deployed-but-unused capabilities worth reviewing for activation or cleanup.
  • Phishing response at low volume: The MS Defender Suspicious Email workflow has only 3 executions despite being event-triggered. Tuning the trigger condition or broadening alert coverage could increase detection fidelity and workflow utilization.
  • No vulnerability management automation: The current automation footprint has no coverage for vulnerability scanning, CVE tracking, or patch lifecycle management — a common gap for organizations at this stage of automation maturity.
  • Limited GRC / compliance coverage: No workflows address audit reporting, access reviews, or compliance automation. Given the credential and identity focus already in place, RBAC review and access certification workflows would be a natural next step.
  • Consolidation opportunity: Scan Machine and Anti-Virus Scan appear to be functionally equivalent on-demand AV scan workflows. Consolidating these would reduce maintenance overhead.
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 5 use cases | 25 executions (12m)

Business KPIs

Metric Count Playbook
MFA deactivation threats investigated & remediated 21 LIVE Okta MFA Password Reset Automation
Suspicious URL click alerts enriched & escalated 3 MS Defender Suspicious Email
SPN secret expiry notification cycles executed 1 SPN Secret Expiry Notification
Expired SPN secret reports delivered to teams 1 Get Expired SPN Secrets
On-demand endpoint antivirus scans initiated 1 Anti-Virus Scan
In the last 12 months, Blink automated: - 21 MFA deactivation threats investigated & remediated with analyst-in-the-loop approval via Teams - 3 suspicious URL click alerts enriched with identity context and escalated for response - 2 SPN credential expiry reporting cycles executed without manual intervention - 1 on-demand endpoint antivirus scan initiated through a standardized workflow

Use Case Summary

Use Case Category Playbook Count Active Playbooks
Identity & Credential Lifecycle IAM 4 3
Phishing & Suspicious Email Response SOC 1 1
Endpoint Threat Response SOC 3 1
System Health Monitoring Other 1 1
Worklog & Operational Reporting Other 1 0

Use Cases

1. Identity & Credential Lifecycle

Description: Automated monitoring and response for credential-related threats and expiry events. Covers both proactive notification of expiring SPN secrets and reactive response to identity anomalies such as MFA deactivation events detected via SIEM.

Business Problem Solved: Credential exposure from expired or compromised service principal secrets and user MFA tampering introduces significant identity risk. Manual tracking of these events at scale is error-prone and slow. These workflows ensure timely notification and analyst-gated remediation.

Integrations: Okta, Rapid7 InsightIDR, Microsoft Teams, Microsoft Outlook, Microsoft Entra ID (Active Directory), HTTP Tables

Playbook Executions (12mo) Category Subcategory
LIVE Okta MFA Password Reset Automation 21 IAM Identity threat response, Password & credential lifecycle
SPN Secret Expiry Notification 1 IAM Password & credential lifecycle, Privileged account mgmt
Get Expired SPN Secrets 1 IAM Password & credential lifecycle, Privileged account mgmt
Password Expiration Notification Workflow 0 IAM Password & credential lifecycle

2. Phishing & Suspicious Email Response

Description: Event-driven response workflow triggered by Microsoft Defender XDR when a potentially malicious URL click is detected. Enriches the alert with incident details, runs a threat hunting query, pulls login context from Entra ID, and routes an approval decision to a Teams channel.

Business Problem Solved: Phishing via malicious URLs is one of the most common initial access vectors. Manual investigation requires correlating data across Defender, Active Directory, and email — this workflow automates the enrichment chain and surfaces a concise, human-readable summary for analyst decision-making.

Integrations: Microsoft Defender XDR, Microsoft Entra ID, Microsoft Teams

Playbook Executions (12mo) Category Subcategory
MS Defender Suspicious Email 3 SOC Phishing detection & response, Alert enrichment / IOC lookup, Identity threat response

3. Endpoint Threat Response

Description: On-demand and utility workflows for triggering antivirus scans and retrieving alert details from Microsoft Defender for Endpoints. Provides a standardized interface for initiating endpoint response actions.

Business Problem Solved: Inconsistent or delayed endpoint scanning during incidents increases dwell time. These workflows give analysts a repeatable, auditable path to trigger scans and retrieve alert context without direct access to the Defender portal.

Integrations: Microsoft Defender for Endpoints, Microsoft Defender XDR

Playbook Executions (12mo) Category Subcategory
Anti-Virus Scan 1 SOC EDR containment & response
Scan Machine 0 SOC EDR containment & response
Get alert 0 SOC Alert enrichment / IOC lookup

4. System Health Monitoring

Description: Scheduled heartbeat workflow that runs every two weeks to verify core Okta connectivity and system availability by performing a user lookup.

Business Problem Solved: Integration outages can silently break automated security workflows. A periodic heartbeat confirms that critical identity integrations remain operational and alerts the team to connectivity failures before they affect real incidents.

Integrations: Okta

Playbook Executions (12mo) Category Subcategory
Heartbeat 3 Other IT/OT & network infra monitoring

5. Worklog & Operational Reporting

Description: On-demand workflow for fetching Tempo worklogs by date range, project, and team — likely used for time tracking or operational reporting tied to a Jira/Tempo environment.

Business Problem Solved: Manual extraction and formatting of worklog data is time-consuming for team leads and project managers. This workflow standardizes the extraction process across date ranges and team boundaries.

Integrations: Tempo (Jira)

Playbook Executions (12mo) Category Subcategory
Tempo GET Worklogs 0 Other DevOps & release automation

Key Observations

Strengths

  • Identity-first posture: The most-executed automation by a wide margin is the Okta MFA deactivation response (21 runs), reflecting a mature focus on identity threat detection and response. The workflow combines SIEM alert ingestion (InsightIDR), Teams-based approval gates, and Okta remediation in a single end-to-end chain.
  • Credential hygiene automation: Two complementary SPN secret expiry workflows run on a monthly schedule, ensuring that privileged service account credentials are tracked and communicated proactively — reducing the risk of expired credentials causing service disruptions or going unnoticed.
  • Microsoft ecosystem depth: The integration stack spans Microsoft Defender XDR, Defender for Endpoints, Entra ID, Teams, and Outlook, demonstrating strong operational coverage within a Microsoft-centric environment.
  • Analyst-in-the-loop design: Both the MFA reset and the suspicious email workflows use Teams-based approval steps before taking action, reflecting a responsible automation philosophy that preserves analyst control over high-risk decisions.

Gaps & Opportunities

  • Low activation on built workflows: Several workflows — Password Expiration Notification, Scan Machine, Get Alert, and Tempo Worklogs — have zero executions in the last 12 months. These represent either deprecated automations or deployed-but-unused capabilities worth reviewing for activation or cleanup.
  • Phishing response at low volume: The MS Defender Suspicious Email workflow has only 3 executions despite being event-triggered. Tuning the trigger condition or broadening alert coverage could increase detection fidelity and workflow utilization.
  • No vulnerability management automation: The current automation footprint has no coverage for vulnerability scanning, CVE tracking, or patch lifecycle management — a common gap for organizations at this stage of automation maturity.
  • Limited GRC / compliance coverage: No workflows address audit reporting, access reviews, or compliance automation. Given the credential and identity focus already in place, RBAC review and access certification workflows would be a natural next step.
  • Consolidation opportunity: Scan Machine and Anti-Virus Scan appear to be functionally equivalent on-demand AV scan workflows. Consolidating these would reduce maintenance overhead.
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.