Blink Security Automation — Confidential

Security-Scorecard — Customer Success Report

Generated 2026-08-31 | security-scorecard-value-report.md
2026-08-31Report Date
158Total Playbooks
38Unique Workflows (12m)
9,942,794Actions Automated (12m)
$2,557,303Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

158
Total playbooks built
all non-deleted workflows
46
Active playbooks
currently enabled
38
Unique workflows executed (12m)
distinct workflows that ran
9,942,794
Actions automated (12m)
completed action steps
55,237.7h
Hours saved (12m)
@ 20s per action
$2,557,303
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 11,545 Slack messages screened in real time for security keywords — continuous threat signal coverage across internal communications - 3,554 IT and security case events handled through Jira automation — combining ticket triage, routing, and intelligent response logic - 962 phishing investigation monitoring cycles completed against active Expel investigations without analyst involvement - 78 employee accounts automatically deactivated the moment a compromise signal was received - 94 mobile device compliance events matched to users and resolved automatically via Kandji - 40 critical CVEs triaged and enriched with CISA KEV context every day - 369 security metrics records populated across SECINC and SECQ operations dashboards - 40 daily training compliance checks run to track KnowBe4 program health across the workforce

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Security Awareness & Training Automation
  • 40Daily phishing training compliance checks run
  • 40Daily phishing campaign performance reports generated
  • 40Training reminder batches dispatched to non-compliant users
1.0%
8
8 active
Phishing Detection & Response
  • 962Phishing investigation monitoring cycles completed
5.8%
2
2 active
Slack Security Monitoring0 executions
0.0%
0
0 active
Identity Threat Response & Kill Switch
  • 78User accounts automatically deactivated on compromise signal
0.0%
2
2 active
IT Case Management & SOAR
  • 1,790IT service desk tickets automatically triaged and processed
  • 1,764Security case events handled via intelligent Jira automation
19.2%
3
3 active
CVE Intelligence & Daily Triage
  • 40Critical CVEs triaged and enriched with CISA KEV intelligence
0.2%
1
1 active
Security Metrics & Executive Reporting
  • 205Security queue (SECQ) metric records populated
  • 164Security incident (SECINC) metric records populated
  • 84Security incident and queue metric batch jobs processed
3.4%
8
8 active
Identity & Directory Backup
  • 2Identity directory snapshots taken (Okta + Google)
0.0%
11
11 active
Network Access Control — Cloudflare Zero Trust0 executions
0.0%
3
3 active
Endpoint Compliance & Device Management
  • 94Mobile device compliance events auto-matched and resolved (Kandji)
  • 19Windows device compliance events processed (Intune)
0.2%
5
5 active
Total4,939 executions100%
43
43 active

Use Case Growth Over Time

122 unique playbooks  |  9 operational use cases  |  16,451 total executions (12m)  |  2025-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Identity & Directory Backup
Google Drive Google Sheets Okta Google Workspace Array Utilities BambooHR
Network Access Control — Cloudflare Zero Trust
Cloudflare
Security Awareness & Training Automation
BambooHR Slack KnowBe4
Endpoint Compliance & Device Management
Microsoft Intune Kandji CrowdStrike
Security Metrics & Executive Reporting
Jira Wiz Dashboards Email
Phishing Detection & Response
Expel Slack
Identity Threat Response & Kill Switch
CrowdStrike Okta Google Admin Console Slack
IT Case Management & SOAR
Jira Confluence Gemini Anthropic Node.js Slack
CVE Intelligence & Daily Triage
Gemini Slack

04Key Observations

✓  Strengths

Strengths

High-volume SOC automation is operational and running at scale. The combination of Slack keyword monitoring (11,545 events), Jira case automation (3,554 events), phishing response (962 cycles), and the KillSwitch (78 deactivations) demonstrates a mature, production-grade SOC automation layer. These are not pilot workflows — they are embedded in daily operations.

Security awareness program is fully automated. KnowBe4 training compliance, campaign metrics, phishing report volume, reminder dispatch, and scoreboard distribution all run on automated schedules. This eliminates recurring manual work and ensures the awareness program operates consistently regardless of analyst availability. New hire campaign creation is also automated via BambooHR integration.

Identity containment with real-world usage. The webhook-triggered KillSwitch fired 78 times in 12 months — roughly 6–7 times per month — deactivating Okta accounts and notifying the security team in real time. This indicates the account compromise detection and containment pipeline is live and being used to respond to real incidents.

Broad integration ecosystem. The library spans MDR (Expel), EDR (CrowdStrike), identity (Okta, Google Workspace, BambooHR), endpoint MDM (Kandji, Intune), ITSM (Jira), security awareness (KnowBe4), CSPM (Wiz), network security (Cloudflare Zero Trust), SIEM (Sumo Logic), and communications (Slack). This breadth reflects a sophisticated security stack being automated end-to-end.

Security metrics program is automated. SECINC and SECQ dashboards receive automated daily data ingestion, and Wiz issues and findings counts are pulled on a consistent schedule. The monthly executive dashboard export and delivery closes the loop at the leadership reporting layer.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Cloudflare Zero Trust blocklist workflows are dormant. All three on-demand playbooks for adding hostnames, URLs, and IPs to Zero Trust team lists show zero executions. These may not be connected to automated threat intel feeds or SOAR escalation paths. Wiring these to phishing or IOC enrichment workflows would enable automated network-layer blocking as part of incident response.

Identity Backup coverage is incomplete. Only user exports (Okta, Google) are running on schedule; group, app, and OU backups have never executed. A full directory snapshot — users, groups, apps, and OUs — is the meaningful unit for compliance and recovery. Activating the scheduled backup trigger for the group, app, and OU workflows would close this gap with minimal effort.

Email security monitoring is not active. Both email-based detection workflows (Google Workspace email monitor and Gmail bounce/delivery failure monitor) have zero executions. The Google Risky Login webhook (Sumo Logic) is also inactive. Activating these would extend phishing and account compromise detection into the email layer, complementing the existing Expel-based hourly monitoring.

Endpoint automation depth is limited. While Kandji (94) and Intune (19) webhook handlers are active, the on-demand inventory workflows (Kandji, Intune, CrowdStrike Devices) have never run. The full Kill Switch on-demand workflow — which orchestrates CrowdStrike isolation, Google session revocation, and OAuth token deletion alongside Okta deactivation — also has zero executions. Extending the KillSwitch webhook to invoke this full containment sequence would significantly increase containment completeness.

Intune handler is still in Test Mode. The Intune Catch Hook is labeled "(Test Mode)" and has run 19 times. Moving it to production and removing the test designation would indicate operational readiness.

CVE triage is a single workflow without downstream ticketing. The Daily Critical CVE Triage workflow ingests and enriches CVEs but appears to stop there. Adding automated Jira ticket creation for CISA KEV-matched CVEs would close the loop between vulnerability intelligence and remediation tracking.

Integration Ecosystem Summary

Category Integrations
MDR / SOAR Expel
EDR CrowdStrike
Identity & Directory Okta, Google Workspace, BambooHR
Endpoint MDM Microsoft Intune, Kandji
ITSM Jira
Security Awareness KnowBe4
Cloud Security / CSPM Wiz
Network / Zero Trust Cloudflare
SIEM Sumo Logic
Communications Slack
Productivity Google Sheets, Google Drive, Gmail, Email
Threat Intel NVD API, CISA KEV
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Time Spent Building 00
2 Security Team Dashboard 00
3 CISO Dashboard 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 9 use cases | 16,451 executions (12m)

Business KPIs

Metric Count Playbook
Slack messages screened in real time for security keywords 11,545 New Workflow (Slack Keyword Monitor)
IT service desk tickets automatically triaged and processed 1,790 Ticket Resolution Automation
Security case events handled via intelligent Jira automation 1,764 The Conversationalist
Phishing investigation monitoring cycles completed 962 Phishing Remediation v3
Security queue (SECQ) metric records populated 205 SECQ Metrics Table Populater
Security incident (SECINC) metric records populated 164 SECINC Metrics Table Populater
Mobile device compliance events auto-matched and resolved (Kandji) 94 Kandji Catch Hook
User accounts automatically deactivated on compromise signal 78 KillSwitch
Security incident and queue metric batch jobs processed 84 SECINC Metrics Tickets Batcher + SECQ Metrics Tickets Batcher
Critical CVEs triaged and enriched with CISA KEV intelligence 40 Daily Critical CVE Triage & Intel (ZDaaS)
Daily phishing training compliance checks run 40 KnowBe4 Training Compliance
Daily phishing campaign performance reports generated 40 KnowBe4 Phishing Campaign Metrics
Training reminder batches dispatched to non-compliant users 40 Send Reminders To Users That Haven't Completed Trainings
Phishing report volume metrics collected 40 KnowBe4 Number of Reported Phishing Emails
Cloud security issues and findings snapshots generated 40 Populate Issues and Findings Counts
Windows device compliance events processed (Intune) 19 Intune Catch Hook (Test Mode)
Weekly training completion scoreboards distributed 12 Send Weekly Scoreboard with Completion Rates (×2)
New hire phishing simulation campaigns auto-created 1 Create Campaign for New Users
Executive security dashboard PDFs exported and delivered 1 Export The Dashboard and Send it to Steve
Identity directory snapshots taken (Okta + Google) 2 Okta Users Backup + Google Users Backup
In the last 12 months, Blink automated: - 11,545 Slack messages screened in real time for security keywords — continuous threat signal coverage across internal communications - 3,554 IT and security case events handled through Jira automation — combining ticket triage, routing, and intelligent response logic - 962 phishing investigation monitoring cycles completed against active Expel investigations without analyst involvement - 78 employee accounts automatically deactivated the moment a compromise signal was received - 94 mobile device compliance events matched to users and resolved automatically via Kandji - 40 critical CVEs triaged and enriched with CISA KEV context every day - 369 security metrics records populated across SECINC and SECQ operations dashboards - 40 daily training compliance checks run to track KnowBe4 program health across the workforce

Use Case Summary

# Use Case Category Subcategory Total Playbooks Active
1 Security Awareness & Training Automation SOC Phishing sim & awareness 8 7
2 Phishing Detection & Response SOC Phishing detection & response 4 1
3 Slack Security Monitoring SOC SIEM & log pipeline monitoring 1 1
4 Identity Threat Response & Kill Switch SOC Identity threat response 2 1
5 IT Case Management & SOAR SOC Case mgmt & SOAR 3 2
6 CVE Intelligence & Daily Triage Vulnerability Mgmt CVE lookup & remediation 1 1
7 Security Metrics & Executive Reporting GRC Security metrics & reporting 8 6
8 Identity & Directory Backup IAM Identity sync & directory mgmt 11 2
9 Network Access Control — Cloudflare Zero Trust Cloud Security Cloud access & SaaS policy mgmt 3 0
10 Endpoint Compliance & Device Management Other Endpoint hygiene & MDM ops 5 2
Total 46 23

Use Cases

1. Security Awareness & Training Automation

Category: SOC

Subcategory: Phishing sim & awareness

Description: End-to-end automation of the KnowBe4 security awareness program — from enrolling new hires in phishing simulations to tracking training completion, sending reminders, and distributing weekly scoreboards. Metrics collection runs daily to feed operational reporting.

Business Problem Solved: Security awareness programs require continuous administration: creating campaigns for new joiners, monitoring who hasn't completed trainings, and surfacing participation data to leadership. Without automation, these tasks demand recurring manual effort and often lapse.

Integrations: KnowBe4, BambooHR, Slack

Playbook Executions (12 mo) Trigger Status
Create Campaign for New Users 1 Scheduled (monthly) Active
KnowBe4 Phishing Campaign Metrics 40 Scheduled (daily) Active
KnowBe4 Training Compliance 40 Scheduled (daily) Active
KnowBe4 Number of Reported Phishing Emails 40 Scheduled (daily) Active
Send Reminders To Users That Haven't Completed Trainings 40 Scheduled (daily) Active
Send Weekly Scoreboard with Completion Rates 6 Scheduled (weekly, Monday AM) Active
Send Weekly Scoreboard with Completion Rates (afternoon) 6 Scheduled (weekly, Monday PM) Active
On Demand Scoreboard with Completion Rates 0 On-Demand Inactive

2. Phishing Detection & Response

Category: SOC

Subcategory: Phishing detection & response

Description: Automated phishing detection using Expel MDR integrations, Google Workspace email monitoring, and Gmail delivery failure triage. The core Phishing Remediation v3 workflow polls Expel every hour for new phishing investigations and applies automated response logic.

Business Problem Solved: Phishing is the leading initial access vector. Automated, near-real-time investigation of phishing events removes the need for analysts to manually monitor MDR queues and enables consistent, sub-minute response initiation.

Integrations: Expel, Google Workspace, Gmail, Sumo Logic

Playbook Executions (12 mo) Trigger Status
Phishing Remediation v3 962 Scheduled (hourly) Active
Google Risky Login 0 Webhook (Sumo Logic) Inactive
New Workflow *(Gmail security monitor)* 0 Polling (Google Workspace email) Inactive
New Workflow 1 *(Gmail bounce & delivery failure monitor)* 0 Polling (Google Workspace email) Inactive

3. Slack Security Monitoring

Category: SOC

Subcategory: SIEM & log pipeline monitoring

Description: High-volume, real-time Slack message monitoring that screens every sent message for security-relevant keywords. With 11,545 executions in 12 months — roughly 950 per month — this workflow provides continuous visibility into internal communications for threat or policy signals.

Business Problem Solved: Insider threats, data loss, and social engineering often surface first in communication platforms. Automated keyword monitoring enables detection of sensitive terms, suspicious patterns, or policy violations in Slack without manual review.

Integrations: Slack

Playbook Executions (12 mo) Trigger Status
New Workflow *(Slack keyword security monitor)* 11,545 Polling (Slack OnNewMessageSent) Active

4. Identity Threat Response & Kill Switch

Category: SOC

Subcategory: Identity threat response

Description: Automated containment of compromised identities. The webhook-triggered KillSwitch deactivates an Okta user and notifies a private Slack channel the moment a compromise signal arrives. A second, broader Kill Switch is available on-demand and extends containment to CrowdStrike endpoint isolation, Google session revocation, and OAuth token deletion.

Business Problem Solved: Mean time to contain (MTTC) for identity compromises directly impacts blast radius. Manual deactivation across multiple systems (IdP, endpoint, SSO) can take 30–60 minutes. Automated containment collapses this to seconds and ensures no step is missed under pressure.

Integrations: Okta, CrowdStrike, Google Admin Console, Slack

Playbook Executions (12 mo) Trigger Status
KillSwitch 78 Webhook Active
Kill Switch 0 On-Demand Inactive

5. IT Case Management & SOAR

Category: SOC

Subcategory: Case mgmt & SOAR

Description: Automated handling of Jira-based IT and security tickets. Ticket Resolution Automation polls the IS Service Desk project and applies conditional routing logic to new issues. The Conversationalist responds to Jira webhook events — likely processing ticket updates, comments, or status changes — with intelligent automated responses. A Markdown-to-ADF utility supports Jira-formatted automated comments.

Business Problem Solved: Security and IT teams spend significant time triaging, routing, and acknowledging helpdesk tickets. Automation handles first-touch processing, routing, and conditional responses at scale, letting analysts focus on complex issues.

Integrations: Jira

Playbook Executions (12 mo) Trigger Status
Ticket Resolution Automation 1,790 Polling (Jira IS Service Desk) Active
The Conversationalist 1,764 Webhook (Jira) Active
Markdown to ADF 0 On-Demand (utility) Inactive

6. CVE Intelligence & Daily Triage

Category: Vulnerability Mgmt

Subcategory: CVE lookup & remediation

Description: Daily automated ingestion of critical CVEs from the NVD API, cross-referenced with the CISA Known Exploited Vulnerabilities (KEV) catalog, to surface the most urgent vulnerabilities requiring attention. Runs every day at 2 PM Pacific.

Business Problem Solved: Security teams face an unmanageable volume of CVE publications. Automated daily triage that prioritizes critical CVEs against authoritative exploitability data (CISA KEV) enables faster, risk-ranked remediation without manual NVD browsing.

Integrations: NVD API, CISA KEV (HTTP), core.bash

Playbook Executions (12 mo) Trigger Status
Daily Critical CVE Triage & Intel (ZDaaS) 40 Scheduled (daily) Active

7. Security Metrics & Executive Reporting

Category: GRC

Subcategory: Security metrics & reporting

Description: Automated population and maintenance of security operations dashboards tracking incident metrics (SECINC), security queue metrics (SECQ), cloud vulnerability and issue counts (Wiz), and a monthly executive security dashboard delivered via email. Supporting workflows batch-process Jira tickets and keep hours columns up to date.

Business Problem Solved: Security metrics programs require continuous data collection from multiple systems (Jira, Wiz) and manual aggregation into dashboards. Automating this removes reporting lag, eliminates manual errors, and ensures leadership always has current data without analyst overhead.

Integrations: Jira, Wiz, HTTP Tables, Blink Dashboard, Email (core.emailV2)

Playbook Executions (12 mo) Trigger Status
SECQ Metrics Table Populater 205 On-Demand (sub-orchestrator) Active
SECINC Metrics Table Populater 164 On-Demand (sub-orchestrator) Active
SECINC Metrics Tickets Batcher 42 Scheduled (daily) Active
SECQ Metrics Tickets Batcher 42 Scheduled (daily) Active
Populate Issues and Findings Counts 40 Scheduled (daily) Active
Export The Dashboard and Send it to Steve 1 Scheduled (monthly) Active
Update Hours Columns 0 On-Demand Inactive
SECQ Update Hours Columns 0 On-Demand Inactive

8. Identity & Directory Backup

Category: IAM

Subcategory: Identity sync & directory mgmt

Description: Scheduled and on-demand backups of the full Okta identity directory (users, groups, apps) and Google Workspace directory (users, groups, organizational units) to Google Sheets. Monthly snapshots create an auditable historical record of the identity landscape. A BambooHR/Okta cross-reference utility supports reconciliation.

Business Problem Solved: Identity directories are critical assets — accidental deletions, policy drift, or insider changes can be catastrophic without a backup. Automated monthly exports provide a recoverable, auditable baseline for compliance and incident response.

Integrations: Okta, Google Workspace, Google Sheets, Google Drive, BambooHR

Playbook Executions (12 mo) Trigger Status
Okta Users Backup 1 Scheduled (monthly) Active
Google Users Backup 1 Scheduled (monthly) Active
Okta Groups Backup 0 On-Demand Inactive
Helper. Okta Groups Backup 0 On-Demand (sub-flow) Inactive
Okta Apps Backup 0 On-Demand Inactive
Helper. Okta Apps Backup 0 On-Demand (sub-flow) Inactive
Google Groups Backup 0 On-Demand Inactive
Helper. Google Groups Backup 0 On-Demand (sub-flow) Inactive
Google OUs Backup 0 On-Demand Inactive
Helper. Google OUs Backup 0 On-Demand (sub-flow) Inactive
Bamboo Workers 0 On-Demand Inactive

9. Network Access Control — Cloudflare Zero Trust

Category: Cloud Security

Subcategory: Cloud access & SaaS policy mgmt

Description: On-demand automation to update Cloudflare Zero Trust team lists with blocked hostnames, URLs, and IP addresses. Each workflow takes a single indicator as input and patches the relevant Zero Trust list — enabling rapid, automated blocklist management.

Business Problem Solved: Manually updating network access control lists in Cloudflare Zero Trust is slow and error-prone. These workflows enable automated or analyst-triggered IOC blocking, keeping network policies current without requiring Cloudflare console access.

Integrations: Cloudflare Zero Trust

Playbook Executions (12 mo) Trigger Status
Add Hostname to Cloudflare Zero Trust Team List 0 On-Demand Inactive
Add URL to Cloudflare Zero Trust Team List 0 On-Demand Inactive
Add IP to Cloudflare Zero Trust Team List 0 On-Demand Inactive

10. Endpoint Compliance & Device Management

Category: Other

Subcategory: Endpoint hygiene & MDM ops

Description: Automated endpoint compliance event processing across three MDM/EDR platforms. Kandji and Intune webhook handlers receive device events, match them to user records, and apply conditional logic. On-demand inventory workflows support ad-hoc device audits across Kandji, Intune, and CrowdStrike.

Business Problem Solved: Endpoint compliance gaps — unmanaged devices, policy violations, or new enrollments — need to be detected and actioned quickly. Automated event handlers close the loop between MDM/EDR signals and response actions without requiring analyst intervention.

Integrations: Microsoft Intune, Kandji, CrowdStrike

Playbook Executions (12 mo) Trigger Status
Kandji Catch Hook 94 Webhook Active
Intune Catch Hook (Test Mode) 19 Webhook Active
Kandji 0 On-Demand Inactive
Intune 0 On-Demand Inactive
Crowdstrike Devices 0 On-Demand Inactive

Key Observations

Strengths

High-volume SOC automation is operational and running at scale. The combination of Slack keyword monitoring (11,545 events), Jira case automation (3,554 events), phishing response (962 cycles), and the KillSwitch (78 deactivations) demonstrates a mature, production-grade SOC automation layer. These are not pilot workflows — they are embedded in daily operations.

Security awareness program is fully automated. KnowBe4 training compliance, campaign metrics, phishing report volume, reminder dispatch, and scoreboard distribution all run on automated schedules. This eliminates recurring manual work and ensures the awareness program operates consistently regardless of analyst availability. New hire campaign creation is also automated via BambooHR integration.

Identity containment with real-world usage. The webhook-triggered KillSwitch fired 78 times in 12 months — roughly 6–7 times per month — deactivating Okta accounts and notifying the security team in real time. This indicates the account compromise detection and containment pipeline is live and being used to respond to real incidents.

Broad integration ecosystem. The library spans MDR (Expel), EDR (CrowdStrike), identity (Okta, Google Workspace, BambooHR), endpoint MDM (Kandji, Intune), ITSM (Jira), security awareness (KnowBe4), CSPM (Wiz), network security (Cloudflare Zero Trust), SIEM (Sumo Logic), and communications (Slack). This breadth reflects a sophisticated security stack being automated end-to-end.

Security metrics program is automated. SECINC and SECQ dashboards receive automated daily data ingestion, and Wiz issues and findings counts are pulled on a consistent schedule. The monthly executive dashboard export and delivery closes the loop at the leadership reporting layer.

Gaps & Opportunities

Cloudflare Zero Trust blocklist workflows are dormant. All three on-demand playbooks for adding hostnames, URLs, and IPs to Zero Trust team lists show zero executions. These may not be connected to automated threat intel feeds or SOAR escalation paths. Wiring these to phishing or IOC enrichment workflows would enable automated network-layer blocking as part of incident response.

Identity Backup coverage is incomplete. Only user exports (Okta, Google) are running on schedule; group, app, and OU backups have never executed. A full directory snapshot — users, groups, apps, and OUs — is the meaningful unit for compliance and recovery. Activating the scheduled backup trigger for the group, app, and OU workflows would close this gap with minimal effort.

Email security monitoring is not active. Both email-based detection workflows (Google Workspace email monitor and Gmail bounce/delivery failure monitor) have zero executions. The Google Risky Login webhook (Sumo Logic) is also inactive. Activating these would extend phishing and account compromise detection into the email layer, complementing the existing Expel-based hourly monitoring.

Endpoint automation depth is limited. While Kandji (94) and Intune (19) webhook handlers are active, the on-demand inventory workflows (Kandji, Intune, CrowdStrike Devices) have never run. The full Kill Switch on-demand workflow — which orchestrates CrowdStrike isolation, Google session revocation, and OAuth token deletion alongside Okta deactivation — also has zero executions. Extending the KillSwitch webhook to invoke this full containment sequence would significantly increase containment completeness.

Intune handler is still in Test Mode. The Intune Catch Hook is labeled "(Test Mode)" and has run 19 times. Moving it to production and removing the test designation would indicate operational readiness.

CVE triage is a single workflow without downstream ticketing. The Daily Critical CVE Triage workflow ingests and enriches CVEs but appears to stop there. Adding automated Jira ticket creation for CISA KEV-matched CVEs would close the loop between vulnerability intelligence and remediation tracking.

Integration Ecosystem Summary

Category Integrations
MDR / SOAR Expel
EDR CrowdStrike
Identity & Directory Okta, Google Workspace, BambooHR
Endpoint MDM Microsoft Intune, Kandji
ITSM Jira
Security Awareness KnowBe4
Cloud Security / CSPM Wiz
Network / Zero Trust Cloudflare
SIEM Sumo Logic
Communications Slack
Productivity Google Sheets, Google Drive, Gmail, Email
Threat Intel NVD API, CISA KEV
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Security-Scorecard okta my_okta_connection 2026-08-20