01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Security Awareness & Training Automation |
| 1.0% | 8 8 active |
| Phishing Detection & Response |
| 5.8% | 2 2 active |
| Slack Security Monitoring | 0 executions | 0.0% | 0 0 active |
| Identity Threat Response & Kill Switch |
| 0.0% | 2 2 active |
| IT Case Management & SOAR |
| 19.2% | 3 3 active |
| CVE Intelligence & Daily Triage |
| 0.2% | 1 1 active |
| Security Metrics & Executive Reporting |
| 3.4% | 8 8 active |
| Identity & Directory Backup |
| 0.0% | 11 11 active |
| Network Access Control — Cloudflare Zero Trust | 0 executions | 0.0% | 3 3 active |
| Endpoint Compliance & Device Management |
| 0.2% | 5 5 active |
| Total | 4,939 executions | 100% | 43 43 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
High-volume SOC automation is operational and running at scale. The combination of Slack keyword monitoring (11,545 events), Jira case automation (3,554 events), phishing response (962 cycles), and the KillSwitch (78 deactivations) demonstrates a mature, production-grade SOC automation layer. These are not pilot workflows — they are embedded in daily operations.
Security awareness program is fully automated. KnowBe4 training compliance, campaign metrics, phishing report volume, reminder dispatch, and scoreboard distribution all run on automated schedules. This eliminates recurring manual work and ensures the awareness program operates consistently regardless of analyst availability. New hire campaign creation is also automated via BambooHR integration.
Identity containment with real-world usage. The webhook-triggered KillSwitch fired 78 times in 12 months — roughly 6–7 times per month — deactivating Okta accounts and notifying the security team in real time. This indicates the account compromise detection and containment pipeline is live and being used to respond to real incidents.
Broad integration ecosystem. The library spans MDR (Expel), EDR (CrowdStrike), identity (Okta, Google Workspace, BambooHR), endpoint MDM (Kandji, Intune), ITSM (Jira), security awareness (KnowBe4), CSPM (Wiz), network security (Cloudflare Zero Trust), SIEM (Sumo Logic), and communications (Slack). This breadth reflects a sophisticated security stack being automated end-to-end.
Security metrics program is automated. SECINC and SECQ dashboards receive automated daily data ingestion, and Wiz issues and findings counts are pulled on a consistent schedule. The monthly executive dashboard export and delivery closes the loop at the leadership reporting layer.
###
Gaps & Opportunities
Cloudflare Zero Trust blocklist workflows are dormant. All three on-demand playbooks for adding hostnames, URLs, and IPs to Zero Trust team lists show zero executions. These may not be connected to automated threat intel feeds or SOAR escalation paths. Wiring these to phishing or IOC enrichment workflows would enable automated network-layer blocking as part of incident response.
Identity Backup coverage is incomplete. Only user exports (Okta, Google) are running on schedule; group, app, and OU backups have never executed. A full directory snapshot — users, groups, apps, and OUs — is the meaningful unit for compliance and recovery. Activating the scheduled backup trigger for the group, app, and OU workflows would close this gap with minimal effort.
Email security monitoring is not active. Both email-based detection workflows (Google Workspace email monitor and Gmail bounce/delivery failure monitor) have zero executions. The Google Risky Login webhook (Sumo Logic) is also inactive. Activating these would extend phishing and account compromise detection into the email layer, complementing the existing Expel-based hourly monitoring.
Endpoint automation depth is limited. While Kandji (94) and Intune (19) webhook handlers are active, the on-demand inventory workflows (Kandji, Intune, CrowdStrike Devices) have never run. The full Kill Switch on-demand workflow — which orchestrates CrowdStrike isolation, Google session revocation, and OAuth token deletion alongside Okta deactivation — also has zero executions. Extending the KillSwitch webhook to invoke this full containment sequence would significantly increase containment completeness.
Intune handler is still in Test Mode. The Intune Catch Hook is labeled "(Test Mode)" and has run 19 times. Moving it to production and removing the test designation would indicate operational readiness.
CVE triage is a single workflow without downstream ticketing. The Daily Critical CVE Triage workflow ingests and enriches CVEs but appears to stop there. Adding automated Jira ticket creation for CISA KEV-matched CVEs would close the loop between vulnerability intelligence and remediation tracking.
Integration Ecosystem Summary
| Category | Integrations |
|---|---|
| MDR / SOAR | Expel |
| EDR | CrowdStrike |
| Identity & Directory | Okta, Google Workspace, BambooHR |
| Endpoint MDM | Microsoft Intune, Kandji |
| ITSM | Jira |
| Security Awareness | KnowBe4 |
| Cloud Security / CSPM | Wiz |
| Network / Zero Trust | Cloudflare |
| SIEM | Sumo Logic |
| Communications | Slack |
| Productivity | Google Sheets, Google Drive, Gmail, Email |
| Threat Intel | NVD API, CISA KEV |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Time Spent Building | 0 | 0 |
| 2 | Security Team Dashboard | 0 | 0 |
| 3 | CISO Dashboard | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 9 use cases | 16,451 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Slack messages screened in real time for security keywords | 11,545 | New Workflow (Slack Keyword Monitor) |
| IT service desk tickets automatically triaged and processed | 1,790 | Ticket Resolution Automation |
| Security case events handled via intelligent Jira automation | 1,764 | The Conversationalist |
| Phishing investigation monitoring cycles completed | 962 | Phishing Remediation v3 |
| Security queue (SECQ) metric records populated | 205 | SECQ Metrics Table Populater |
| Security incident (SECINC) metric records populated | 164 | SECINC Metrics Table Populater |
| Mobile device compliance events auto-matched and resolved (Kandji) | 94 | Kandji Catch Hook |
| User accounts automatically deactivated on compromise signal | 78 | KillSwitch |
| Security incident and queue metric batch jobs processed | 84 | SECINC Metrics Tickets Batcher + SECQ Metrics Tickets Batcher |
| Critical CVEs triaged and enriched with CISA KEV intelligence | 40 | Daily Critical CVE Triage & Intel (ZDaaS) |
| Daily phishing training compliance checks run | 40 | KnowBe4 Training Compliance |
| Daily phishing campaign performance reports generated | 40 | KnowBe4 Phishing Campaign Metrics |
| Training reminder batches dispatched to non-compliant users | 40 | Send Reminders To Users That Haven't Completed Trainings |
| Phishing report volume metrics collected | 40 | KnowBe4 Number of Reported Phishing Emails |
| Cloud security issues and findings snapshots generated | 40 | Populate Issues and Findings Counts |
| Windows device compliance events processed (Intune) | 19 | Intune Catch Hook (Test Mode) |
| Weekly training completion scoreboards distributed | 12 | Send Weekly Scoreboard with Completion Rates (×2) |
| New hire phishing simulation campaigns auto-created | 1 | Create Campaign for New Users |
| Executive security dashboard PDFs exported and delivered | 1 | Export The Dashboard and Send it to Steve |
| Identity directory snapshots taken (Okta + Google) | 2 | Okta Users Backup + Google Users Backup |
Use Case Summary
| # | Use Case | Category | Subcategory | Total Playbooks | Active |
|---|---|---|---|---|---|
| 1 | Security Awareness & Training Automation | SOC | Phishing sim & awareness | 8 | 7 |
| 2 | Phishing Detection & Response | SOC | Phishing detection & response | 4 | 1 |
| 3 | Slack Security Monitoring | SOC | SIEM & log pipeline monitoring | 1 | 1 |
| 4 | Identity Threat Response & Kill Switch | SOC | Identity threat response | 2 | 1 |
| 5 | IT Case Management & SOAR | SOC | Case mgmt & SOAR | 3 | 2 |
| 6 | CVE Intelligence & Daily Triage | Vulnerability Mgmt | CVE lookup & remediation | 1 | 1 |
| 7 | Security Metrics & Executive Reporting | GRC | Security metrics & reporting | 8 | 6 |
| 8 | Identity & Directory Backup | IAM | Identity sync & directory mgmt | 11 | 2 |
| 9 | Network Access Control — Cloudflare Zero Trust | Cloud Security | Cloud access & SaaS policy mgmt | 3 | 0 |
| 10 | Endpoint Compliance & Device Management | Other | Endpoint hygiene & MDM ops | 5 | 2 |
| Total | 46 | 23 |
Use Cases
1. Security Awareness & Training Automation
Category: SOC
Subcategory: Phishing sim & awareness
Description: End-to-end automation of the KnowBe4 security awareness program — from enrolling new hires in phishing simulations to tracking training completion, sending reminders, and distributing weekly scoreboards. Metrics collection runs daily to feed operational reporting.
Business Problem Solved: Security awareness programs require continuous administration: creating campaigns for new joiners, monitoring who hasn't completed trainings, and surfacing participation data to leadership. Without automation, these tasks demand recurring manual effort and often lapse.
Integrations: KnowBe4, BambooHR, Slack
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Create Campaign for New Users | 1 | Scheduled (monthly) | Active |
| KnowBe4 Phishing Campaign Metrics | 40 | Scheduled (daily) | Active |
| KnowBe4 Training Compliance | 40 | Scheduled (daily) | Active |
| KnowBe4 Number of Reported Phishing Emails | 40 | Scheduled (daily) | Active |
| Send Reminders To Users That Haven't Completed Trainings | 40 | Scheduled (daily) | Active |
| Send Weekly Scoreboard with Completion Rates | 6 | Scheduled (weekly, Monday AM) | Active |
| Send Weekly Scoreboard with Completion Rates (afternoon) | 6 | Scheduled (weekly, Monday PM) | Active |
| On Demand Scoreboard with Completion Rates | 0 | On-Demand | Inactive |
2. Phishing Detection & Response
Category: SOC
Subcategory: Phishing detection & response
Description: Automated phishing detection using Expel MDR integrations, Google Workspace email monitoring, and Gmail delivery failure triage. The core Phishing Remediation v3 workflow polls Expel every hour for new phishing investigations and applies automated response logic.
Business Problem Solved: Phishing is the leading initial access vector. Automated, near-real-time investigation of phishing events removes the need for analysts to manually monitor MDR queues and enables consistent, sub-minute response initiation.
Integrations: Expel, Google Workspace, Gmail, Sumo Logic
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Phishing Remediation v3 | 962 | Scheduled (hourly) | Active |
| Google Risky Login | 0 | Webhook (Sumo Logic) | Inactive |
| New Workflow *(Gmail security monitor)* | 0 | Polling (Google Workspace email) | Inactive |
| New Workflow 1 *(Gmail bounce & delivery failure monitor)* | 0 | Polling (Google Workspace email) | Inactive |
3. Slack Security Monitoring
Category: SOC
Subcategory: SIEM & log pipeline monitoring
Description: High-volume, real-time Slack message monitoring that screens every sent message for security-relevant keywords. With 11,545 executions in 12 months — roughly 950 per month — this workflow provides continuous visibility into internal communications for threat or policy signals.
Business Problem Solved: Insider threats, data loss, and social engineering often surface first in communication platforms. Automated keyword monitoring enables detection of sensitive terms, suspicious patterns, or policy violations in Slack without manual review.
Integrations: Slack
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| New Workflow *(Slack keyword security monitor)* | 11,545 | Polling (Slack OnNewMessageSent) | Active |
4. Identity Threat Response & Kill Switch
Category: SOC
Subcategory: Identity threat response
Description: Automated containment of compromised identities. The webhook-triggered KillSwitch deactivates an Okta user and notifies a private Slack channel the moment a compromise signal arrives. A second, broader Kill Switch is available on-demand and extends containment to CrowdStrike endpoint isolation, Google session revocation, and OAuth token deletion.
Business Problem Solved: Mean time to contain (MTTC) for identity compromises directly impacts blast radius. Manual deactivation across multiple systems (IdP, endpoint, SSO) can take 30–60 minutes. Automated containment collapses this to seconds and ensures no step is missed under pressure.
Integrations: Okta, CrowdStrike, Google Admin Console, Slack
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| KillSwitch | 78 | Webhook | Active |
| Kill Switch | 0 | On-Demand | Inactive |
5. IT Case Management & SOAR
Category: SOC
Subcategory: Case mgmt & SOAR
Description: Automated handling of Jira-based IT and security tickets. Ticket Resolution Automation polls the IS Service Desk project and applies conditional routing logic to new issues. The Conversationalist responds to Jira webhook events — likely processing ticket updates, comments, or status changes — with intelligent automated responses. A Markdown-to-ADF utility supports Jira-formatted automated comments.
Business Problem Solved: Security and IT teams spend significant time triaging, routing, and acknowledging helpdesk tickets. Automation handles first-touch processing, routing, and conditional responses at scale, letting analysts focus on complex issues.
Integrations: Jira
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Ticket Resolution Automation | 1,790 | Polling (Jira IS Service Desk) | Active |
| The Conversationalist | 1,764 | Webhook (Jira) | Active |
| Markdown to ADF | 0 | On-Demand (utility) | Inactive |
6. CVE Intelligence & Daily Triage
Category: Vulnerability Mgmt
Subcategory: CVE lookup & remediation
Description: Daily automated ingestion of critical CVEs from the NVD API, cross-referenced with the CISA Known Exploited Vulnerabilities (KEV) catalog, to surface the most urgent vulnerabilities requiring attention. Runs every day at 2 PM Pacific.
Business Problem Solved: Security teams face an unmanageable volume of CVE publications. Automated daily triage that prioritizes critical CVEs against authoritative exploitability data (CISA KEV) enables faster, risk-ranked remediation without manual NVD browsing.
Integrations: NVD API, CISA KEV (HTTP), core.bash
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Daily Critical CVE Triage & Intel (ZDaaS) | 40 | Scheduled (daily) | Active |
7. Security Metrics & Executive Reporting
Category: GRC
Subcategory: Security metrics & reporting
Description: Automated population and maintenance of security operations dashboards tracking incident metrics (SECINC), security queue metrics (SECQ), cloud vulnerability and issue counts (Wiz), and a monthly executive security dashboard delivered via email. Supporting workflows batch-process Jira tickets and keep hours columns up to date.
Business Problem Solved: Security metrics programs require continuous data collection from multiple systems (Jira, Wiz) and manual aggregation into dashboards. Automating this removes reporting lag, eliminates manual errors, and ensures leadership always has current data without analyst overhead.
Integrations: Jira, Wiz, HTTP Tables, Blink Dashboard, Email (core.emailV2)
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| SECQ Metrics Table Populater | 205 | On-Demand (sub-orchestrator) | Active |
| SECINC Metrics Table Populater | 164 | On-Demand (sub-orchestrator) | Active |
| SECINC Metrics Tickets Batcher | 42 | Scheduled (daily) | Active |
| SECQ Metrics Tickets Batcher | 42 | Scheduled (daily) | Active |
| Populate Issues and Findings Counts | 40 | Scheduled (daily) | Active |
| Export The Dashboard and Send it to Steve | 1 | Scheduled (monthly) | Active |
| Update Hours Columns | 0 | On-Demand | Inactive |
| SECQ Update Hours Columns | 0 | On-Demand | Inactive |
8. Identity & Directory Backup
Category: IAM
Subcategory: Identity sync & directory mgmt
Description: Scheduled and on-demand backups of the full Okta identity directory (users, groups, apps) and Google Workspace directory (users, groups, organizational units) to Google Sheets. Monthly snapshots create an auditable historical record of the identity landscape. A BambooHR/Okta cross-reference utility supports reconciliation.
Business Problem Solved: Identity directories are critical assets — accidental deletions, policy drift, or insider changes can be catastrophic without a backup. Automated monthly exports provide a recoverable, auditable baseline for compliance and incident response.
Integrations: Okta, Google Workspace, Google Sheets, Google Drive, BambooHR
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Okta Users Backup | 1 | Scheduled (monthly) | Active |
| Google Users Backup | 1 | Scheduled (monthly) | Active |
| Okta Groups Backup | 0 | On-Demand | Inactive |
| Helper. Okta Groups Backup | 0 | On-Demand (sub-flow) | Inactive |
| Okta Apps Backup | 0 | On-Demand | Inactive |
| Helper. Okta Apps Backup | 0 | On-Demand (sub-flow) | Inactive |
| Google Groups Backup | 0 | On-Demand | Inactive |
| Helper. Google Groups Backup | 0 | On-Demand (sub-flow) | Inactive |
| Google OUs Backup | 0 | On-Demand | Inactive |
| Helper. Google OUs Backup | 0 | On-Demand (sub-flow) | Inactive |
| Bamboo Workers | 0 | On-Demand | Inactive |
9. Network Access Control — Cloudflare Zero Trust
Category: Cloud Security
Subcategory: Cloud access & SaaS policy mgmt
Description: On-demand automation to update Cloudflare Zero Trust team lists with blocked hostnames, URLs, and IP addresses. Each workflow takes a single indicator as input and patches the relevant Zero Trust list — enabling rapid, automated blocklist management.
Business Problem Solved: Manually updating network access control lists in Cloudflare Zero Trust is slow and error-prone. These workflows enable automated or analyst-triggered IOC blocking, keeping network policies current without requiring Cloudflare console access.
Integrations: Cloudflare Zero Trust
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Add Hostname to Cloudflare Zero Trust Team List | 0 | On-Demand | Inactive |
| Add URL to Cloudflare Zero Trust Team List | 0 | On-Demand | Inactive |
| Add IP to Cloudflare Zero Trust Team List | 0 | On-Demand | Inactive |
10. Endpoint Compliance & Device Management
Category: Other
Subcategory: Endpoint hygiene & MDM ops
Description: Automated endpoint compliance event processing across three MDM/EDR platforms. Kandji and Intune webhook handlers receive device events, match them to user records, and apply conditional logic. On-demand inventory workflows support ad-hoc device audits across Kandji, Intune, and CrowdStrike.
Business Problem Solved: Endpoint compliance gaps — unmanaged devices, policy violations, or new enrollments — need to be detected and actioned quickly. Automated event handlers close the loop between MDM/EDR signals and response actions without requiring analyst intervention.
Integrations: Microsoft Intune, Kandji, CrowdStrike
| Playbook | Executions (12 mo) | Trigger | Status |
|---|---|---|---|
| Kandji Catch Hook | 94 | Webhook | Active |
| Intune Catch Hook (Test Mode) | 19 | Webhook | Active |
| Kandji | 0 | On-Demand | Inactive |
| Intune | 0 | On-Demand | Inactive |
| Crowdstrike Devices | 0 | On-Demand | Inactive |
Key Observations
Strengths
High-volume SOC automation is operational and running at scale. The combination of Slack keyword monitoring (11,545 events), Jira case automation (3,554 events), phishing response (962 cycles), and the KillSwitch (78 deactivations) demonstrates a mature, production-grade SOC automation layer. These are not pilot workflows — they are embedded in daily operations.
Security awareness program is fully automated. KnowBe4 training compliance, campaign metrics, phishing report volume, reminder dispatch, and scoreboard distribution all run on automated schedules. This eliminates recurring manual work and ensures the awareness program operates consistently regardless of analyst availability. New hire campaign creation is also automated via BambooHR integration.
Identity containment with real-world usage. The webhook-triggered KillSwitch fired 78 times in 12 months — roughly 6–7 times per month — deactivating Okta accounts and notifying the security team in real time. This indicates the account compromise detection and containment pipeline is live and being used to respond to real incidents.
Broad integration ecosystem. The library spans MDR (Expel), EDR (CrowdStrike), identity (Okta, Google Workspace, BambooHR), endpoint MDM (Kandji, Intune), ITSM (Jira), security awareness (KnowBe4), CSPM (Wiz), network security (Cloudflare Zero Trust), SIEM (Sumo Logic), and communications (Slack). This breadth reflects a sophisticated security stack being automated end-to-end.
Security metrics program is automated. SECINC and SECQ dashboards receive automated daily data ingestion, and Wiz issues and findings counts are pulled on a consistent schedule. The monthly executive dashboard export and delivery closes the loop at the leadership reporting layer.
Gaps & Opportunities
Cloudflare Zero Trust blocklist workflows are dormant. All three on-demand playbooks for adding hostnames, URLs, and IPs to Zero Trust team lists show zero executions. These may not be connected to automated threat intel feeds or SOAR escalation paths. Wiring these to phishing or IOC enrichment workflows would enable automated network-layer blocking as part of incident response.
Identity Backup coverage is incomplete. Only user exports (Okta, Google) are running on schedule; group, app, and OU backups have never executed. A full directory snapshot — users, groups, apps, and OUs — is the meaningful unit for compliance and recovery. Activating the scheduled backup trigger for the group, app, and OU workflows would close this gap with minimal effort.
Email security monitoring is not active. Both email-based detection workflows (Google Workspace email monitor and Gmail bounce/delivery failure monitor) have zero executions. The Google Risky Login webhook (Sumo Logic) is also inactive. Activating these would extend phishing and account compromise detection into the email layer, complementing the existing Expel-based hourly monitoring.
Endpoint automation depth is limited. While Kandji (94) and Intune (19) webhook handlers are active, the on-demand inventory workflows (Kandji, Intune, CrowdStrike Devices) have never run. The full Kill Switch on-demand workflow — which orchestrates CrowdStrike isolation, Google session revocation, and OAuth token deletion alongside Okta deactivation — also has zero executions. Extending the KillSwitch webhook to invoke this full containment sequence would significantly increase containment completeness.
Intune handler is still in Test Mode. The Intune Catch Hook is labeled "(Test Mode)" and has run 19 times. Moving it to production and removing the test designation would indicate operational readiness.
CVE triage is a single workflow without downstream ticketing. The Daily Critical CVE Triage workflow ingests and enriches CVEs but appears to stop there. Adding automated Jira ticket creation for CISA KEV-matched CVEs would close the loop between vulnerability intelligence and remediation tracking.
Integration Ecosystem Summary
| Category | Integrations |
|---|---|
| MDR / SOAR | Expel |
| EDR | CrowdStrike |
| Identity & Directory | Okta, Google Workspace, BambooHR |
| Endpoint MDM | Microsoft Intune, Kandji |
| ITSM | Jira |
| Security Awareness | KnowBe4 |
| Cloud Security / CSPM | Wiz |
| Network / Zero Trust | Cloudflare |
| SIEM | Sumo Logic |
| Communications | Slack |
| Productivity | Google Sheets, Google Drive, Gmail, Email |
| Threat Intel | NVD API, CISA KEV |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Security-Scorecard | okta | my_okta_connection | 2026-08-20 |