Blink Security Automation — Confidential

soteria — Customer Success Report

Generated 2026-08-31 | soteria-value-report.md
2026-08-31Report Date
218Total Playbooks
37Unique Workflows (12m)
152,781Actions Automated (12m)
$39,296Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

218
Total playbooks built
all non-deleted workflows
88
Active playbooks
currently enabled
37
Unique workflows executed (12m)
distinct workflows that ran
152,781
Actions automated (12m)
completed action steps
848.8h
Hours saved (12m)
@ 20s per action
$39,296
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
6
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 6 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 5,170 security alerts triaged and routed to stakeholders automatically - 120 database backup verifications completed without manual intervention - 50 MDR client touchpoint reports generated and delivered - 40 endpoint sensor health reports distributed - 21 client MDE connections verified across managed environments - 12 MFA compliance checks performed on user accounts - 10 compromised user accounts remediated or suspended across Microsoft Entra ID and Okta - 7 support tickets created via Slack-triggered automation - 6 client AWS environments provisioned for Panther MDR onboarding - 5 new employees provisioned end-to-end across 10+ SaaS systems

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOC Automation Platform1 executions
0.0%
14
14 active
Multi-Source Observable Enrichment0 executions
0.0%
21
21 active
On-Demand Threat Investigation
  • 1Ad-hoc threat investigations performed
0.0%
15
15 active
Security Alert Notification & Routing
  • 4,902Security alerts triaged & routed to stakeholders
  • 268High-priority security events escalated via targeted notifications
91.9%
4
4 active
EDR Containment & Response0 executions
0.0%
6
6 active
Identity Threat Response
  • 12MFA compliance checks performed on user accounts
  • 10Compromised user accounts remediated or suspended
0.3%
7
7 active
Employee Lifecycle Automation
  • 5New employees provisioned end-to-end
0.1%
2
2 active
MDR Operations & Client Reporting
  • 50MDR client touchpoint reports generated
  • 40Endpoint sensor health reports delivered
  • 21Client MDE connections verified across managed environments
6.2%
13
13 active
Client AWS Provisioning (Panther MDR)1 executions
0.0%
1
1 active
Platform Operations & DevOps
  • 40Workflow definitions automatically backed up
  • 23Microsoft platform change digests delivered
1.3%
2
2 active
IT Helpdesk Ticket Automation
  • 7Support tickets created via Slack-triggered automation
0.1%
1
1 active
Total5,953 executions100%
86
86 active

Use Case Growth Over Time

191 unique playbooks  |  11 operational use cases  |  5,953 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Multi-Source Observable Enrichment
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Slack
SOC Automation Platform
Microsoft Outlook Email Agents
On-Demand Threat Investigation
Google Workspace GitHub Microsoft Entra ID Okta Extraction Utilities String Utilities URLScan Slack VirusTotal CrowdStrike IP API
Employee Lifecycle Automation
1Password Microsoft Entra ID Google Workspace Google Admin Console Web Form Asana Slack Box Snipe-IT Email
EDR Containment & Response
CrowdStrike Microsoft Defender for Endpoint Slack SentinelOne
Platform Operations & DevOps
GitHub String Utilities Slack
Security Alert Notification & Routing
Panther Email
MDR Operations & Client Reporting
Slack GCP Google Drive LimaCharlie Email Microsoft Defender for Endpoint
Identity Threat Response
Slack Microsoft Entra ID Okta Microsoft Graph SentinelOne
Client AWS Provisioning (Panther MDR)
AWS Slack
IT Helpdesk Ticket Automation
Asana Slack

04Key Observations

✓  Strengths

Strengths

Full-stack SOAR platform built in-house. Soteria has assembled a production-grade case management and SOAR pipeline covering alert ingestion, observable extraction, multi-source enrichment, case deduplication, response routing, and recovery mechanisms. The modular subflow architecture — with separate enrichment, response, and error-handling layers — reflects mature automation design thinking.

MDR service delivery automated at scale. The MDR reporting suite is Soteria's most active area of execution. Monthly touchpoint presentations, daily sensor health reports, and three parallel backup verification automations run without manual intervention — a direct operational cost saving in service delivery. This reflects a compelling "Blink running a security operations business" story.

Breadth of enrichment coverage. The observable enrichment engine spans 10+ integrations across endpoint (CrowdStrike), threat intel (VirusTotal, AbuseIPDB, URLScan), identity (Okta, Entra ID, Google Workspace, GitHub), and network (Whois, Dig). This gives analysts multi-dimensional IOC context with a single automated trigger.

Alert notification at volume. The Panther-triggered alerting pipelines processed 5,170 notifications in 12 months, demonstrating that at least a portion of the automation stack is running in production at meaningful scale.

Richest employee onboarding in the stack. The User Onboarding Web Form orchestrates 10+ systems — Google Workspace, Entra ID, Asana, Box, 1Password, Slack, Atlassian, Harvest, Snipe-IT — in a single end-to-end workflow. This is operationally high-value and hard to replicate manually.

Agentic SOC capability deployed. The presence of "Activate Blackbeard" — a webhook-triggered workflow that invokes a Blink AI agent — signals that Soteria is actively piloting next-generation autonomous SOC capabilities.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Core SOAR platform dormant. The primary alert processing pipeline — Process Alert, all 14 Enrich-* workflows, and the Response Router subflow — has zero executions despite being fully built. This is the largest investment in the platform and is likely in a pre-production, showcase, or staging state. Activating this pipeline would be the highest-leverage action in the account.

EDR response capacity unused. Six CrowdStrike, MDE, and SentinelOne containment workflows exist with 0 executions. As Soteria's MDR clients face active endpoint threats, response automation remains manual. Connecting these to the SOAR pipeline (via the Response Subflow - Malware) would close the loop from detection to containment.

Offboarding gap is a security risk. User onboarding has 5 executions; offboarding has 0. The offboarding workflow handles credential rotation, OneDrive transfer, and access revocation across Entra ID and Google Workspace — all high-risk steps if missed. This gap warrants immediate attention.

No vulnerability management workflows. There are no vuln scanning, CVE lookup, or patch prioritization workflows in the environment. For an MDR provider, this is a notable absence.

Phishing response pipeline built but untested. The Response Subflow - Phishing integrates Microsoft Outlook and detects KnowBe4 simulation headers, but has 0 executions. If Soteria handles phishing cases for clients, this represents untapped automation capacity.

Multi-workspace sprawl (10 workspaces). Soteria operates across 10 distinct Blink workspaces — likely representing different teams, clients, or product lines. While organizationally sensible, this creates governance and visibility challenges. Standardizing shared enrichment and response subflows across workspaces would reduce duplication.

Integration Ecosystem

Soteria's automation stack spans 20+ integrations across five domains:

Domain Integrations
Security & detection CrowdStrike, Microsoft Defender for Endpoints, SentinelOne, Panther, LimaCharlie, VirusTotal, AbuseIPDB, URLScan, Shodan
Identity & IAM Microsoft Entra ID, Okta, Google Workspace, GitHub
Communication Slack, Microsoft Outlook, Blink Email
Cloud & infrastructure AWS Organizations, AWS IAM Identity Center, GCP / BigQuery
Productivity & ITSM Asana, Atlassian, Google Drive, Google Slides, Harvest, Snipe-IT, SharePoint, Box, 1Password
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
6
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management Playground 6 0 0 N/A
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 6 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink Case Management Playground 0 0 0
2 Blackbeard Pirate Shared_POV_Workspace 0 0 0
3 Blackbeard the Pirate Case Management Playground 0 0 0
4 New Agent ychoksey@soteria.io 0 0 0
5 New Agent Shared_POV_Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Case Management Playground0
Shared_POV_Workspace0
ychoksey@soteria.io0
DART Operations0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

No self-service usage data found for this customer.

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Panther AWS Account Creation 00
2 Panther AWS Account Creation 00
3 Soteria - Project Onboarding Workflow 00
4 User Onboarding 00
D Full Use Case Analysis 11 use cases | 5,953 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts triaged & routed to stakeholders 4,902 Email Alerting
High-priority security events escalated via targeted notifications 268 Soroban - Emails for Specific Alerts
MDR client touchpoint reports generated 50 MDR Monthly Touchpoints Automation
Database backup verifications completed 120 Firestore Backup Confirmation ×3 daily automations
Endpoint sensor health reports delivered 40 LC Sensor Report Email
Workflow definitions automatically backed up 40 Workflow Backup
Microsoft platform change digests delivered 23 DeltaPulse Workflow - Update Microsoft Changes
Client MDE connections verified across managed environments 21 MDE Connection Verifier
MFA compliance checks performed on user accounts 12 Entra - MFA Checker
Compromised user accounts remediated or suspended 10 Entra - Remediate User + Entra - Remediate User (With MFA) + Okta - Suspend User
Support tickets created via Slack-triggered automation 7 Ticket Test Workflow (Event)
Client AWS environments provisioned for Panther MDR 6 Panther - Create AWS Account ×2 workspaces
New employees provisioned end-to-end 5 User Onboarding - Web Form
Ad-hoc threat investigations performed 1 IP & Domain Info
In the last 12 months, Blink automated: - 5,170 security alerts triaged and routed to stakeholders automatically - 120 database backup verifications completed without manual intervention - 50 MDR client touchpoint reports generated and delivered - 40 endpoint sensor health reports distributed - 21 client MDE connections verified across managed environments - 12 MFA compliance checks performed on user accounts - 10 compromised user accounts remediated or suspended across Microsoft Entra ID and Okta - 7 support tickets created via Slack-triggered automation - 6 client AWS environments provisioned for Panther MDR onboarding - 5 new employees provisioned end-to-end across 10+ SaaS systems

Use Case Summary

Use Case Category Subcategories Playbooks Active Total Executions
SOC Automation Platform SOC Case mgmt & SOAR, Agentic SOC 14 0 0
Multi-Source Observable Enrichment SOC Alert enrichment / IOC lookup 21 0 0
On-Demand Threat Investigation SOC Alert enrichment / IOC lookup, Threat intel ingest & curation 15 1 1
Security Alert Notification & Routing SOC SIEM & log pipeline monitoring 4 2 5,170
EDR Containment & Response SOC EDR containment & response 6 0 0
Identity Threat Response SOC Identity threat response 7 4 22
Employee Lifecycle Automation IAM Employee onboarding, Employee offboarding 2 1 5
MDR Operations & Client Reporting GRC Security metrics & reporting 13 8 481
Client AWS Provisioning (Panther MDR) Cloud Security Cloud provisioning & IaC automation 2 2 6
Platform Operations & DevOps Other DevOps & release automation 2 2 63
IT Helpdesk Ticket Automation Other IT helpdesk & ticket routing 1 1 7
Total 87 21 5,755

Use Cases

1. SOC Automation Platform

Description: A full-stack SOAR platform built on Blink's native case management — ingesting alerts, extracting observables, deduplicating into cases, routing automated response playbooks, and handling recovery for unprocessed events.

Business problem: Manual alert triage forces analysts to context-switch across tools for every incoming event. This platform automates the full alert-to-case lifecycle, including error recovery and stale case closure, so analysts work cases rather than chase raw alerts.

Integrations: Blink Case Management, Microsoft Outlook, CrowdStrike, KnowBe4

Playbook Type Executions (12 mo)
Process Alert Event (polling) 0
Subflow - Response - Main Router Subflow 0
Response Subflow - Phishing Subflow 0
Response Subflow - Malware Subflow 0
Recovery - Handle Unprocessed Alerts On-demand 0
Recovery - Enrich Non-Enriched Observables On-demand 0
Utility - Close Stale Cases On-demand 0
Subflow - Missing Alert Template Notification Subflow 0
Table Action - Validate Observables Extraction Template On-demand 0
Error Handling - Send Error Notification Email Subflow 0
Activate Blackbeard Event (webhook) + Agentic 0
Simulate Crowdstrike Alert On-demand (testing) 0
Simulate Multiple Alerts from Different Sources On-demand (testing) 0
USE WITH CARE - Reset Case Management Environment On-demand (admin) 0

2. Multi-Source Observable Enrichment

Description: A modular enrichment pipeline that automatically enriches IOCs (IPs, URLs, hashes, domains, usernames, email addresses) across 10+ security and identity tools, updating observable records in case management with verdicts and metadata.

Business problem: Analysts spend significant time manually pivoting across tools to assess each IOC. This pipeline automates multi-source enrichment as part of the alert processing flow, delivering contextual verdicts before an analyst touches a case.

Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Bash (Whois), Blink Case Management

Playbook Type Executions (12 mo)
Subflow - Enrich Observables - Main Router Subflow 0
Enrich - Agent ID - Crowdstrike On-demand 0
Enrich - URL - URLScan On-demand 0
Enrich - Hash - VT On-demand 0
Enrich - IP - IPDB On-demand 0
Enrich - Username or Email - Okta On-demand 0
Enrich - IP - VT On-demand 0
Enrich - URL - VT On-demand 0
Enrich - Hash - Crowdstrike On-demand 0
Enrich - IP or Domain - Whois On-demand 0
Enrich - Username or Email - Google Workspace On-demand 0
Enrich - Username or Email - Microsoft Entra ID On-demand 0
Enrich - Username - Github On-demand 0
Enrich - Email Address - Slack On-demand 0
Subflow - Update Enrichment Data Subflow 0
Utility - Update Enrichment Utility 0
Utility - Set Or Update Observable Relation Utility 0
Utility - List Alert Observable Relations Utility 0
Utility - List Observable Alert Relations Utility 0
Utility - Find Similar Cases Based on Observables Utility 0
Utility - Delete Observable Relation Utility 0

3. On-Demand Threat Investigation

Description: A library of standalone enrichment and investigation utilities — reusable by analysts or callable from other workflows — covering user lookup, hash analysis, IP/domain reputation, DNS queries, URL scanning, and end-of-life data.

Business problem: Analysts need fast, repeatable enrichment primitives across a fragmented toolset. These on-demand workflows provide a consistent interface to query any tool without switching context.

Integrations: Google Workspace, GitHub, Microsoft Entra ID, VirusTotal, CrowdStrike, Okta, Slack, Bash (dig, whois), URLScan, Shodan, LimaCharlie

Playbook Type Executions (12 mo)
Get User Information Using Google Workspace On-demand 0
Enrich IP or Domain Using Whois On-demand 0
Get User Information Using Github On-demand 0
Get User Information Using Microsoft Entra ID On-demand 0
Get Hash Info Using VirusTotal On-demand 0
Get Hash Info Using Crowdstrike On-demand 0
Get User Information Using Okta On-demand 0
Get User Information on Email Address Using Slack On-demand 0
Run Dig Command On-demand 0
Okta Search for User Activity On-demand 0
Secure URL Screenshot Capture On-demand 0
Analyze URL with URLScan On-demand 0
Get End of Life Date for a Product On-demand 0
IP & Domain Info On-demand 1
Shodan Query On-demand 0

4. Security Alert Notification & Routing

Description: Event-driven workflows that receive Panther SIEM webhooks and route security alerts to stakeholders via email — with one general-purpose alerting engine and specialized variants for specific alert types and client environments.

Business problem: SIEM alert volume overwhelms analysts when delivered raw. These workflows act as a filtering and formatting layer, routing only actionable alerts to the right recipients with context.

Integrations: Panther, Blink Email

Playbook Type Executions (12 mo)
Email Alerting Event (webhook) 4,902
Soroban - Emails for Specific Alerts Event (webhook) 268
Send Emails for Alerts Event (webhook) 0
Veeva Alerting Event (webhook) 0

5. EDR Containment & Response

Description: Automated endpoint containment and remote command execution across CrowdStrike Falcon and Microsoft Defender for Endpoints — enabling device isolation, lift-of-isolation, and RTR commands with Slack-based human approval gates.

Business problem: Containing a compromised endpoint during an active incident requires rapid, coordinated action across EDR consoles. Manual steps introduce delay and inconsistency at the most time-critical moment.

Integrations: CrowdStrike, Microsoft Defender for Endpoints, SentinelOne, Slack

Playbook Type Executions (12 mo)
CrowdStrike RTR to a Single Host On-demand 0
CrowdStrike RTR to a Batch of Hosts On-demand 0
Manage Endpoint Quarantine Status in Crowdstrike On-demand 0
MDE - Isolate Device On-demand 0
MDE - Release from Isolation On-demand 0
S1 - Isolate Host On-demand 0

6. Identity Threat Response

Description: Analyst-driven identity remediation workflows with Slack approval loops — covering MFA enforcement checks, full user remediation (password reset, session revocation), and SharePoint file removal for Microsoft Entra ID and Okta environments.

Business problem: Responding to a compromised or risky user account requires coordinated, auditable actions across IAM platforms. Without automation, these responses are manual, slow, and inconsistently applied.

Integrations: Microsoft Entra ID, Okta, SentinelOne, Slack, SharePoint

Playbook Type Executions (12 mo)
Entra - MFA Checker On-demand 12
Entra - Remediate User On-demand 5
Entra - Remediate User (With MFA) On-demand 2
Okta - Remediate User On-demand 0
Okta - Suspend User On-demand 3
S1 - Remediate User On-demand 0
Sharepoint File Delete On-demand 0

7. Employee Lifecycle Automation

Description: End-to-end employee provisioning and deprovisioning — a web form-driven onboarding workflow that creates accounts, assigns equipment, and configures access across 10+ systems, and a corresponding offboarding workflow that revokes access, transfers data, and rotates credentials.

Business problem: Manual onboarding and offboarding across a complex SaaS stack is slow, error-prone, and creates security gaps — particularly around credential revocation and data transfer during offboarding.

Integrations: Google Workspace, Microsoft Entra ID, Asana, 1Password, Box, Slack, Atlassian, Harvest, Snipe-IT, Blink Web Forms, PowerShell

Playbook Type Executions (12 mo)
User Onboarding - Web Form Event (web form) 5
User Offboarding On-demand 0

8. MDR Operations & Client Reporting

Description: Automated service delivery infrastructure for Soteria's MDR practice — generating monthly client touchpoint presentations from Google Drive templates, verifying database backup success across three environments, delivering daily LimaCharlie sensor health reports, and maintaining escalation and org-list data.

Business problem: MDR service teams need to deliver consistent, data-driven client touchpoints and operational monitoring at scale without manual effort per client or per environment.

Integrations: Google Drive, Google Slides, GCP BigQuery, LimaCharlie, Slack, Blink Email, GitHub, Blink Tables

Playbook Type Executions (12 mo)
MDR Monthly Touchpoints Automation On-demand 50
MDR Touchpoint Search For Folder Subflow Subflow 200
MDR Touchpoint Search For Presentation Subflow Subflow 50
LC Sensor Report Email Scheduled (daily) 40
Inspect Firestore Database Backup Confirmation Automation Scheduled (daily) 40
DW Firestore Database Backup Confirmation Automation Scheduled (daily) 40
MDR Firestore Database Backup Confirmation Automation Scheduled (daily) 40
Escalation Count Subflow Subflow 0
A1 Actual Count Report Scheduled (monthly) 0
Update Org List Event (polling) 0
MDE Connection Verifier On-demand 21
Blink Tables - Get Customer Connection Info On-demand 0
MDR Monthly Touchpoints Automation Subflow Subflow 0

9. Client AWS Provisioning (Panther MDR)

Description: Web form-driven workflow that creates and configures new AWS accounts for Panther SIEM clients — handling account creation, OU placement, IAM Identity Center group assignment, and task tracking in Asana.

Business problem: Onboarding a new client to the Panther MDR platform requires orchestrating multiple AWS Organizations and IAM operations that are error-prone when performed manually across accounts.

Integrations: AWS Organizations, AWS IAM Identity Center, Asana

Playbook Type Executions (12 mo)
Panther - Create AWS Account Event (web form) 3
Panther - Create AWS Account Event (web form) 3

10. Platform Operations & DevOps

Description: Infrastructure automation for the Blink platform itself — daily workflow definition backups to GitHub, and a scheduled digest that monitors and delivers Microsoft product change updates.

Business problem: Workflow configurations need to be version-controlled for audit and recovery. Microsoft platform changes need to reach relevant teams proactively rather than being discovered reactively.

Integrations: GitHub, Blink API, HTTP (Microsoft)

Playbook Type Executions (12 mo)
Workflow Backup Scheduled (daily) 40
DeltaPulse Workflow - Update Microsoft Changes Scheduled (daily) 23

11. IT Helpdesk Ticket Automation

Description: A Slack slash-command-triggered workflow that creates a tracked task in Asana and confirms back to the requester in Slack.

Business problem: Ad-hoc requests submitted through chat are easy to lose track of. This workflow turns a Slack command into a tracked Asana ticket without the requester leaving Slack.

Integrations: Slack, Asana

Playbook Type Executions (12 mo)
Ticket Test Workflow (Event) Event (webhook) 7

Key Observations

Strengths

Full-stack SOAR platform built in-house. Soteria has assembled a production-grade case management and SOAR pipeline covering alert ingestion, observable extraction, multi-source enrichment, case deduplication, response routing, and recovery mechanisms. The modular subflow architecture — with separate enrichment, response, and error-handling layers — reflects mature automation design thinking.

MDR service delivery automated at scale. The MDR reporting suite is Soteria's most active area of execution. Monthly touchpoint presentations, daily sensor health reports, and three parallel backup verification automations run without manual intervention — a direct operational cost saving in service delivery. This reflects a compelling "Blink running a security operations business" story.

Breadth of enrichment coverage. The observable enrichment engine spans 10+ integrations across endpoint (CrowdStrike), threat intel (VirusTotal, AbuseIPDB, URLScan), identity (Okta, Entra ID, Google Workspace, GitHub), and network (Whois, Dig). This gives analysts multi-dimensional IOC context with a single automated trigger.

Alert notification at volume. The Panther-triggered alerting pipelines processed 5,170 notifications in 12 months, demonstrating that at least a portion of the automation stack is running in production at meaningful scale.

Richest employee onboarding in the stack. The User Onboarding Web Form orchestrates 10+ systems — Google Workspace, Entra ID, Asana, Box, 1Password, Slack, Atlassian, Harvest, Snipe-IT — in a single end-to-end workflow. This is operationally high-value and hard to replicate manually.

Agentic SOC capability deployed. The presence of "Activate Blackbeard" — a webhook-triggered workflow that invokes a Blink AI agent — signals that Soteria is actively piloting next-generation autonomous SOC capabilities.

Gaps & Opportunities

Core SOAR platform dormant. The primary alert processing pipeline — Process Alert, all 14 Enrich-* workflows, and the Response Router subflow — has zero executions despite being fully built. This is the largest investment in the platform and is likely in a pre-production, showcase, or staging state. Activating this pipeline would be the highest-leverage action in the account.

EDR response capacity unused. Six CrowdStrike, MDE, and SentinelOne containment workflows exist with 0 executions. As Soteria's MDR clients face active endpoint threats, response automation remains manual. Connecting these to the SOAR pipeline (via the Response Subflow - Malware) would close the loop from detection to containment.

Offboarding gap is a security risk. User onboarding has 5 executions; offboarding has 0. The offboarding workflow handles credential rotation, OneDrive transfer, and access revocation across Entra ID and Google Workspace — all high-risk steps if missed. This gap warrants immediate attention.

No vulnerability management workflows. There are no vuln scanning, CVE lookup, or patch prioritization workflows in the environment. For an MDR provider, this is a notable absence.

Phishing response pipeline built but untested. The Response Subflow - Phishing integrates Microsoft Outlook and detects KnowBe4 simulation headers, but has 0 executions. If Soteria handles phishing cases for clients, this represents untapped automation capacity.

Multi-workspace sprawl (10 workspaces). Soteria operates across 10 distinct Blink workspaces — likely representing different teams, clients, or product lines. While organizationally sensible, this creates governance and visibility challenges. Standardizing shared enrichment and response subflows across workspaces would reduce duplication.

Integration Ecosystem

Soteria's automation stack spans 20+ integrations across five domains:

Domain Integrations
Security & detection CrowdStrike, Microsoft Defender for Endpoints, SentinelOne, Panther, LimaCharlie, VirusTotal, AbuseIPDB, URLScan, Shodan
Identity & IAM Microsoft Entra ID, Okta, Google Workspace, GitHub
Communication Slack, Microsoft Outlook, Blink Email
Cloud & infrastructure AWS Organizations, AWS IAM Identity Center, GCP / BigQuery
Productivity & ITSM Asana, Atlassian, Google Drive, Google Slides, Harvest, Snipe-IT, SharePoint, Box, 1Password
E New Integrations (detail) 49 added in last 30d

New Integrations Added - Last 30 Days

49 new connections
TenantIntegrationConnection NameAdded
soteria microsoft-endpoints-defender zero_workspace_limited_mde 2026-08-07
soteria active-directory zero_workspace_limited_entra 2026-08-07
soteria microsoft-endpoints-defender zebedee_capital_mde 2026-08-07
soteria active-directory zebedee_capital_entra 2026-08-07
soteria microsoft-endpoints-defender shiprock_capital_mde 2026-08-07
soteria active-directory shiprock_capital_entra 2026-08-07
soteria microsoft-endpoints-defender reventus_power_limited_mde 2026-08-07
soteria active-directory reventus_power_limited_entra 2026-08-07
soteria microsoft-endpoints-defender sur_mfo_limited_mde 2026-08-07
soteria active-directory sur_mfo_limited_entra 2026-08-07
soteria microsoft-endpoints-defender pulse_clean_energy_mde 2026-08-07
soteria active-directory pulse_clean_energy_entra 2026-08-07
soteria microsoft-endpoints-defender portman_square_capital_mde 2026-08-07
soteria active-directory portman_square_capital_entra 2026-08-07
soteria microsoft-endpoints-defender polya_capital_management_mde 2026-08-07
soteria active-directory polya_capital_management_entra 2026-08-07
soteria microsoft-endpoints-defender plenisfer_investments_mde 2026-08-07
soteria active-directory plenisfer_investments_entra 2026-08-07
soteria microsoft-endpoints-defender palliser_capital_uk_mde 2026-08-07
soteria active-directory palliser_capital_uk_entra 2026-08-07
soteria microsoft-endpoints-defender noventa_capital_management_mde 2026-08-07
soteria active-directory noventa_capital_management_entra 2026-08-07
soteria microsoft-endpoints-defender macdoch_uk_mde 2026-08-06
soteria active-directory macdoch_uk_entra 2026-08-06
soteria microsoft-endpoints-defender leeside_capital_mde 2026-08-06
soteria active-directory leeside_capital_entra 2026-08-06
soteria microsoft-endpoints-defender kintbury_capital_mde 2026-08-06
soteria active-directory kintbury_capital_entra 2026-08-06
soteria microsoft-endpoints-defender hermitage_capital_mde 2026-08-06
soteria active-directory hermitage_capital_entra 2026-08-06
soteria active-directory alternit_one_uk_csp_entra 2026-08-06
soteria active-directory hengistbury_investment_partners_entra 2026-08-06
soteria microsoft-endpoints-defender hansa_capital_partners_mde 2026-08-06
soteria active-directory hansa_capital_partners_entra 2026-08-06
soteria microsoft-endpoints-defender eighteen48_mde 2026-08-06
soteria active-directory eighteen48_entra 2026-08-06
soteria microsoft-endpoints-defender crake_am_mde 2026-08-05
soteria active-directory crake_am_entra 2026-08-05
soteria microsoft-endpoints-defender clean_energy_transition_mde 2026-08-05
soteria active-directory clean_energy_transition_entra 2026-08-05
soteria active-directory carrhae_capital_entra 2026-08-05
soteria microsoft-endpoints-defender brickwood_asset_management_mde 2026-08-05
soteria active-directory brickwood_asset_management_entra 2026-08-05
soteria active-directory bezero_carbon_entra 2026-08-05
soteria microsoft-endpoints-defender bezero_carbon_mde 2026-08-05
soteria microsoft-endpoints-defender alinor_capital_management_mde 2026-08-05
soteria active-directory alinor_capital_management_entra 2026-08-05
soteria microsoft-endpoints-defender 8_strands_mde 2026-08-05
soteria active-directory 8_strands_entra 2026-08-05