01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1 — Agentic SOC: Sentinel Incident Investigation | 5,276 executions | 92.2% | 19 19 active |
| Use Case 2 — CVE Lifecycle Management & Reporting | 99 executions | 1.7% | 6 6 active |
| Use Case 3 — Identity Incident Response Runbook Library | 0 executions | 0.0% | 12 12 active |
| Use Case 4 — Agentic Employee Offboarding Investigation | 51 executions | 0.9% | 10 10 active |
| Use Case 5 — Cloud Security Posture & Azure Policy Compliance | 6 executions | 0.1% | 2 2 active |
| Use Case 6 — Okta CIAM Operations & Identity Monitoring | 71 executions | 1.2% | 4 4 active |
| Use Case 7 — Access Reviews & Privileged Access Governance | 4 executions | 0.1% | 26 26 active |
| Use Case 8 — Application Provisioning & Directory Sync | 0 executions | 0.0% | 8 8 active |
| Use Case 9 — Endpoint & Conditional Access Configuration Review | 18 executions | 0.3% | 23 23 active |
| Use Case 10 — Microsoft Sentinel SIEM Assessment Suite | 15 executions | 0.3% | 17 17 active |
| Use Case 11 — Security Reporting & Email Security Monitoring | 46 executions | 0.8% | 3 3 active |
| Use Case 12 — Third-Party Risk Management (TPRM) | 128 executions | 2.2% | 1 1 active |
| Total | 5,714 executions | 100% | 131 131 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.
Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.
CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.
Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.
Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.
High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.
###
Gaps & Opportunities
IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."
Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.
Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.
Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.
Integration Ecosystem
The tenant integrates 20+ distinct security and business systems through Blink:
| Domain | Integrations |
|---|---|
| SIEM / Detection | Microsoft Sentinel, Azure Log Analytics |
| Endpoint & EDR | Microsoft Defender for Endpoints |
| Identity | Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph |
| Cloud Security | Orca Security, Azure Policy (Management REST API), Microsoft Purview |
| Network Security | ZScaler ZIA |
| Email Security | ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP) |
| Threat Intel | VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI |
| ITSM / Ticketing | Jira, PagerDuty |
| DevOps | GitHub |
| SaaS / Apps | Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe |
| GRC / Vendor Risk | AuditBoard (Optro) |
| Azure Infrastructure | Azure Automation Account, Azure Monitor DCR, Azure ML |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 8 active | 2,572 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Cody Sentinel | Coterie SecOps/ITSS Workspace | 2,089 | 281 | 2,645,080,168 |
| 2 | Cody Orca Agent | Coterie SecOps/ITSS Workspace | 238 | 0 | 45,332,704 |
| 3 | Cody Offboarding Agent | Coterie SecOps/ITSS Workspace | 122 | 20 | 97,685,192 |
| 4 | Cody SCIM Agent | Coterie SecOps/ITSS Workspace | 88 | 0 | 1,918,905 |
| 5 | Cody Security Engineer I | Coterie SecOps/ITSS Workspace | 13 | 1 | 12,377,137 |
| Workspace | Tasks (12m) |
|---|---|
| Coterie SecOps/ITSS Workspace | 2,572 |
C Self-Service & Webforms 0 app runs | 21 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Okta CIAM Metrics | 0 | 0 |
| 2 | Cody Sentinel Incidents | 0 | 0 |
| 3 | Orca Repo Vulnerabilities | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | New Hire - Systems and Access Confirmation | 21 | 18 |
| 2 | New User Onboard Request | 0 | 0 |
D Full Use Case Analysis 12 use cases | 5,723 executions (12m)
Business KPIs
Metric Table
| Metric | Count | Playbook |
|---|---|---|
| Security incidents auto-enriched and investigated by AI | 303 | SecOps - Microsoft Sentinel Incident Enrichment |
| Third-party vendor risk sync cycles processed (Optro/AuditBoard TPRM) | 128 | TPRM - Optro |
| CVE SLA monitoring cycles completed (v1.0 + v2.0, combined) | 80 | SecurityOps - Orca CVE Query - 1.0 / 2.0 |
| Daily CIAM agent activation anomaly checks completed | 40 | SecurityOps - Okta Agent Activation Query |
| Email security hygiene audits of SendGrid bounce list | 40 | SecurityOps - Query SendGrid Bounce List |
| Conditional Access Policy Review modules executed (full pipeline pass, 1.3–1.16 combined) | 14 | SecurityOps - Conditional Access Policy Review 1.3–1.16 |
| Azure cloud policy remediation cycles executed | 6 | SecurityOps - Azure Policy Remediation Tasks |
| ZScaler user compliance comparisons generated | 6 | SecurityOps - ZScaler Usage Comparison |
| Trending CVE landscape analyses delivered | 6 | SecurityOps - Orca Trending CVE Query |
| CIAM security metrics collected and stored | 6 | SecurityOps - Okta CIAM Metrics |
| Employee offboarding security investigations completed | 3 | SecurityOps - User Offboarding Analysis |
| Okta CIAM administrative access reviews completed | 1 | Okta CIAM Admin Access Review |
Use Case Summary
| # | Use Case | Category | Playbooks | Active (exec > 0) |
|---|---|---|---|---|
| 1 | Agentic SOC — Sentinel Incident Investigation | SOC | 19 | 17 |
| 2 | CVE Lifecycle Management & Reporting | Vulnerability Mgmt | 6 | 4 |
| 3 | Identity Incident Response Runbook Library | SOC | 12 | 0 |
| 4 | Agentic Employee Offboarding Investigation | IAM | 10 | 10 |
| 5 | Cloud Security Posture & Azure Policy Compliance | Cloud Security | 2 | 1 |
| 6 | Okta CIAM Operations & Identity Monitoring | IAM | 4 | 3 |
| 7 | Access Reviews & Privileged Access Governance | GRC | 26 | 3 |
| 8 | Application Provisioning & Directory Sync | IAM | 8 | 0 |
| 9 | Endpoint & Conditional Access Configuration Review | Cloud Security | 24 | 14 |
| 10 | Microsoft Sentinel SIEM Assessment Suite | SOC | 17 | 0 |
| 11 | Security Reporting & Email Security Monitoring | GRC | 3 | 2 |
| 12 | Third-Party Risk Management (TPRM) | GRC | 1 | 1 |
| Total | 132 | 55 |
Use Cases
Use Case 1 — Agentic SOC: Sentinel Incident Investigation
Category: SOC
Subcategories: Agentic SOC · Alert enrichment / IOC lookup · Case mgmt & SOAR
Description: An AI-powered SOC analyst ("Cody") responds in real time to every Microsoft Sentinel alert via webhook. The agent autonomously gathers evidence from Log Analytics, enriches entity context using ProofPoint, Orca, Okta, VirusTotal, Purview, and Microsoft Graph, then writes findings directly back to the Sentinel incident. The 17 active agent tools in this use case were collectively invoked thousands of times in the past year, representing the deepest automation investment in the tenant.
Business problem solved: Eliminates analyst toil on Level 1 triage and enrichment for every Sentinel alert. Each incident arrives pre-investigated, allowing analysts to review conclusions rather than conduct evidence gathering from scratch.
Integrations: Microsoft Sentinel · Azure Log Analytics · Microsoft Graph / Entra ID · ProofPoint ITM · ProofPoint TAP · Orca Security · Okta Workforce · VirusTotal · MXToolBox · Microsoft Purview · Microsoft XDR Defender · NIST NVD · Traceable · PagerDuty
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecOps - Microsoft Sentinel Incident Enrichment | Event trigger (top-level) | 303 | Agentic SOC, Case mgmt & SOAR |
| Cody - Get Sentinel Incident | Agent tool | 304 | Agentic SOC |
| Cody - Search Log Analytics Workspace | Agent tool | 1,721 | Alert enrichment / IOC lookup |
| Cody - Comment on Sentinel Incident | Agent tool | 218 | Case mgmt & SOAR |
| Cody - Search VirusTotal | Agent tool | 255 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint Device Activity | Agent tool | 114 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint CASB Activity | Agent tool | 102 | Alert enrichment / IOC lookup |
| Cody - Get Information on Multiple Entra ID Users | Agent tool | 178 | Alert enrichment / IOC lookup |
| Cody - Search Purview Alerts | Agent tool | 97 | Alert enrichment / IOC lookup |
| Cody - Get Log Analytics Table Schema | Agent tool | 305 | Alert enrichment / IOC lookup |
| Cody - List Table Records | Agent tool | 200 | Alert enrichment / IOC lookup |
| Cody - Search Okta Workforce | Agent tool | 60 | Alert enrichment / IOC lookup |
| Cody - Search Microsoft Graph | Agent tool | 38 | Alert enrichment / IOC lookup |
| Cody - Search Orca Alerts | Agent tool | 22 | Alert enrichment / IOC lookup |
| Cody - Search MXToolBox | Agent tool | 18 | Alert enrichment / IOC lookup |
| Cody - Threat Hunting | Agent tool | 6 | Threat intel ingest & curation |
| Cody - Search NIST for CVE | Agent tool | 1 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint Blocked URLs | Agent tool | 0 | Alert enrichment / IOC lookup |
| Cody - Get Traceable Alerts | Agent tool | 0 | Alert enrichment / IOC lookup |
Use Case 2 — CVE Lifecycle Management & Reporting
Category: Vulnerability Mgmt
Subcategories: CVE lookup & remediation · Vuln scanning ingest & report · Vuln lifecycle prioritize & ticket
Description: Scheduled automations query Orca Security daily and weekly to identify cloud CVEs that are within SLA, approaching SLA, or overdue. Version 1.0 automatically creates Jira tickets for each affected team; version 2.0 converts findings to HTML and delivers email reports. A trending CVE workflow tracks longitudinal CVE posture by comparing weekly snapshots stored in Blink Tables.
Business problem solved: Eliminates manual CVE export-and-distribute workflows. Every cloud engineering team receives structured, SLA-bucketed CVE assignments without analyst intervention.
Integrations: Orca Security · Jira · Blink Tables · Blink Email · NIST NVD
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Orca CVE Query - 1.0 | Scheduled (daily, 6 AM ET) | 40 | CVE lookup & remediation, Vuln lifecycle prioritize & ticket |
| SecurityOps - Orca CVE Query - 2.0 | Scheduled (daily, 7 AM ET) | 40 | CVE lookup & remediation, Vuln scanning ingest & report |
| SecurityOps - Orca Trending CVE Query | Scheduled (weekly, Monday) | 6 | Vuln scanning ingest & report |
| Cody - Search Orca CVEs by Resource | Agent tool | 7 | CVE lookup & remediation |
| SecurityOps - Orca Trending CVE Query 1.1 | Scheduled (weekly, Friday) | 0 | Vuln scanning ingest & report |
| Cody - Search Orca CVEs by Name & Resource | Agent tool | 0 | CVE lookup & remediation |
Use Case 3 — Identity Incident Response Runbook Library
Category: SOC
Subcategories: Identity threat response · EDR containment & response
Description: A library of 12 on-demand IR playbooks covering the full spectrum of containment actions: Entra ID account disablement, Okta session revocation and suspension, MFA factor resets, password resets, Windows machine isolation, AV scan initiation, file hash blocking in Defender, IP blocklisting via Named Locations, URL/domain blocking via ZScaler, and email recipient lookups. All playbooks are designed to be triggered by the Cody AI agent or manually by analysts.
Business problem solved: Provides pre-built, pre-approved IR actions that can be executed in seconds rather than requiring manual portal access — reducing mean time to contain (MTTC) and enabling consistent, auditable response procedures.
Integrations: Microsoft Entra ID (Active Directory) · Microsoft Graph · Okta Workforce · Microsoft Defender for Endpoints · ZScaler ZIA · Azure Log Analytics
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| IR - Disable Entra ID User | On-demand | 0 | Identity threat response |
| IR - Revoke User Session Tokens | On-demand | 0 | Identity threat response |
| IR - Revoke User Sessions in Okta Workforce | On-demand | 0 | Identity threat response |
| IR - Suspend Okta Workforce Account | On-demand | 0 | Identity threat response |
| IR - Reset User Factors in Okta Workforce | On-demand | 0 | Identity threat response |
| IR - Reset Password for Okta Workforce | On-demand | 0 | Password & credential lifecycle |
| IR - Isolate a Windows Machine | On-demand | 0 | EDR containment & response |
| IR - Start AV Scan | On-demand | 0 | EDR containment & response |
| IR - Block File Hash in Defender | On-demand | 0 | EDR containment & response |
| IR - Add IP to NamedLocation Blocklist | On-demand | 0 | Identity threat response |
| IR - Add Domain to ZScaler URL Category | On-demand | 0 | Identity threat response |
| IR - Get Email Recipients Containing a URL | On-demand | 0 | Phishing detection & response |
Use Case 4 — Agentic Employee Offboarding Investigation
Category: IAM
Subcategories: Employee offboarding · Identity lifecycle automation
Description: A comprehensive agentic offboarding workflow that gathers pre-termination activity across 8 data sources — sign-in logs, Azure Activity, Okta V2, audit logs, email events, Office Activity, ProofPoint CASB, ProofPoint device and email events, and GitHub — stores findings in structured Blink Tables, and feeds all evidence to a "Cody Offboarding Agent" that produces an AI-generated risk narrative. Results are written back to the Jira incident as a completed offboarding form. Each offboarding analysis involves a dedicated set of modular read playbooks called by the AI agent.
Business problem solved: Transforms offboarding security investigations from multi-day manual data-pulls across a dozen systems into a single automated workflow that delivers a complete AI-authored risk summary to the HR/security team, typically within minutes.
Integrations: Okta Workforce · Microsoft Entra ID · Azure Log Analytics · ProofPoint ITM · GitHub · Jira · Microsoft Graph · Blink Tables
Use Case 5 — Cloud Security Posture & Azure Policy Compliance
Category: Cloud Security
Subcategories: CSPM ingest & triage · Config audit & remediation
Description: Two cloud security posture workflows. The Azure Policy Remediation automation runs weekly across all Azure subscriptions, enumerating non-compliant policy assignments and submitting remediation tasks automatically. The Orca CSPM Alert Review feeds Orca cloud security alerts into a specialist "Cody Orca Agent" for AI-driven triage and prioritization.
Business problem solved: Eliminates the manual work of periodically checking and remediating Azure Policy non-compliance across multi-subscription environments, and speeds CSPM alert review by routing alerts directly to an AI security engineer.
Integrations: Azure (HTTP/REST — Azure Management API) · Orca Security
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Azure Policy Remediation Tasks | Scheduled (weekly, Sunday 1 AM ET) | 6 | Config audit & remediation |
| SecurityOps - Orca CSPM Alert Review | Scheduled | 0 | CSPM ingest & triage |
Use Case 6 — Okta CIAM Operations & Identity Monitoring
Category: IAM
Subcategories: Identity sync & directory mgmt · Identity lifecycle automation
Description: Automations managing the customer-facing Okta CIAM platform. The Agent Activation Query runs daily to check for new agent onboarding events and processes group membership changes. The CIAM Metrics workflow is event-driven, ingesting webhook data on authentication patterns (email auth, strong auth, SSO, partner integrations) and persisting them to Blink Tables for trending. The ZeroFox User Check correlates external brand-threat intelligence against CIAM user accounts to detect account takeover risk.
Business problem solved: Provides continuous monitoring and automated data collection for a production customer-identity platform, surfacing both operational anomalies and fraud signals without requiring manual CIAM log review.
Integrations: Okta CIAM (Production) · ZeroFox · Microsoft Sentinel · Blink Tables
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Okta Agent Activation Query | Scheduled (daily, 9 AM ET) | 40 | Identity sync & directory mgmt |
| SecurityOps - Okta CIAM Metrics | Event (webhook) | 6 | Security metrics & reporting |
| Cody - ZeroFox CIAM User Check | On-demand (agent tool) | 5 | Identity threat response |
| SecurityOps - Add Agent to Agency Group Okta CIAM | Event (webhook) | 0 | Identity sync & directory mgmt |
Use Case 7 — Access Reviews & Privileged Access Governance
Category: GRC
Subcategories: RBAC review & access mgmt · Access review & group mgmt
Description: A structured program of access reviews covering both broad organizational entitlements (semi-annual review across 20+ apps, Azure role assignments, SQL database permissions, PIM group memberships, GitHub secrets) and targeted application-level reviews (WordPress, Bill.com, DropBox Sign, Grafana, SendGrid, Slack, Jira, BlinkOps, PagerDuty). An inactive user assessment identifies stale Entra ID accounts through sign-in telemetry and Graph API queries. A dedicated Azure PIM/Entra role eligibility review normalizes PIM group, Entra role, and nested group membership data (including a call to a standalone Azure SQL access review sub-automation) into a consolidated governance report, alongside standalone directory-administrator and subscription-level RBAC reviews. A newly expanded set of application- and platform-specific reviews adds Optro (AuditBoard) TPRM user access, GitHub organization membership, Stripe, Azure AD Enterprise Applications/Service Principals, Okta CIAM and Okta Workforce admin role assignments, and Intune RBAC role assignments to the governance program.
Business problem solved: Automates the evidence-gathering and report-generation phases of periodic access certifications, reducing review cycle time from days to minutes and ensuring consistent coverage across all in-scope systems.
Integrations: Okta Workforce · Okta CIAM · Microsoft Graph · Azure (REST) · Azure Log Analytics · PagerDuty · Blink (internal) · GitHub · Bill.com (HTTP) · WordPress (HTTP) · DropBox Sign (HTTP) · Grafana (HTTP) · SendGrid (HTTP) · Slack · Jira · Blink Email · AuditBoard (Optro) · Stripe (HTTP) · Microsoft Intune (via Graph)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Security Operations - Semi-Annual Access Review 1.0 | Scheduled | 0 | RBAC review & access mgmt |
| Security Operations - Semi-Annual Access Review 1.1 | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Inactive User Assessment | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - SQL Admin Review | On-demand | 0 | RBAC review & access mgmt |
| Azure PIM Group Access Review | On-demand (top-level, orchestrates SQL sub-review) | 1 | RBAC review & access mgmt |
| Azure SQL Access Review | On-demand (subflow) | 2 | RBAC review & access mgmt |
| Directory Administrators Access Review | On-demand | 0 | RBAC review & access mgmt |
| Azure Subscription Role Assignment Access Review | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Retrieve Okta Users | On-demand | 0 | Access review & group mgmt |
| SecurityOps - Remove Okta Groups | On-demand | 0 | Access review & group mgmt |
| WordPress Access Review | On-demand | 0 | Access review & group mgmt |
| Bill.com Access Review | On-demand | 0 | Access review & group mgmt |
| DropBox Sign Access Review | On-demand | 0 | Access review & group mgmt |
| Grafana Access Review | On-demand | 0 | Access review & group mgmt |
| SendGrid Access Review | On-demand | 0 | Access review & group mgmt |
| Slack Access Review | On-demand | 0 | Access review & group mgmt |
| Jira Access Review | On-demand | 0 | Access review & group mgmt |
| BlinkOps Access Review | On-demand | 0 | Access review & group mgmt |
| PagerDuty Access Review | On-demand | 0 | Access review & group mgmt |
| Optro Access Review | On-demand | 0 | Access review & group mgmt |
| GitHub Access Review | On-demand | 0 | Access review & group mgmt |
| Stripe Access Review | On-demand | 0 | Access review & group mgmt |
| Azure AD Enterprise Apps Access Review | On-demand | 0 | RBAC review & access mgmt |
| Okta CIAM Admin Access Review | On-demand | 1 | RBAC review & access mgmt |
| Okta Workforce Admin Access Review | On-demand | 0 | RBAC review & access mgmt |
| Intune Access Review | On-demand | 0 | RBAC review & access mgmt |
Use Case 8 — Application Provisioning & Directory Sync
Category: IAM
Subcategories: Identity sync & directory mgmt · Identity lifecycle automation
Description: Provisioning automations for SaaS applications and directory synchronization tasks. The SCIM Provisioning 2.0 workflow processes Okta webhook events to manage the full create/update/deactivate lifecycle. Application-specific provisioners handle Bill.com, ProofPoint, WordPress, SendGrid, and BlinkOps accounts. The Catalog Refresh populates Microsoft Teams, Channels, and SharePoint site catalogs. A utility workflow syncs Okta group memberships to Azure/Entra.
Business problem solved: Standardizes application joiner/mover/leaver processes across SaaS tools, ensuring consistent provisioning logic, validation, and error handling without per-tool manual work.
Integrations: Okta Workforce · Microsoft Graph · Bill.com (HTTP) · ProofPoint ITM · WordPress (HTTP) · SendGrid (HTTP) · Blink
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - SCIM Provisioning 2.0 | Event (Okta webhook) | 0 | Identity lifecycle automation |
| Adding Users/Groups from Okta to Azure/Entra | On-demand | 0 | Identity sync & directory mgmt |
| Catalog Refresh - Onboarding | On-demand | 0 | Employee onboarding |
| ProofPoint Provisioning | On-demand | 0 | Identity lifecycle automation |
| BlinkOps Provisioning | On-demand | 0 | Identity lifecycle automation |
| Bill.com Provisioning | On-demand | 0 | Identity lifecycle automation |
| WordPress Provisioning | On-demand | 0 | Identity lifecycle automation |
| SendGrid Provisioning | On-demand | 0 | Identity lifecycle automation |
Use Case 9 — Endpoint & Conditional Access Configuration Review
Category: Cloud Security
Subcategories: Config audit & remediation · Cloud access & SaaS policy mgmt · Endpoint hygiene & MDM ops
Description: Two distinct review programs. The Endpoint Configuration Review (1.0, 1.1, 1.2) gathers Defender for Endpoint recommendations, Intune managed devices, device configurations, compliance policies, settings catalog, group policies, device intents, and Device Configuration Policy templates, then feeds all data to a "Cody MDE Agent" for an AI-authored security assessment. The Conditional Access Policy Review suite (1.0 through 1.16, plus the agent version) performs a comprehensive set of Log Analytics and Graph queries covering CA policy inventory, named locations, MFA bypass analysis, legacy authentication, non-compliant device sign-ins, service principals without CA applied, report-only CA blocks, blocked sign-ins by policy, risky-but-unblocked sign-ins, non-interactive sign-ins, users with no CA policy applied, and policy hit counts. Modules 1.3 through 1.16 each executed once in the most recent 12-month window, marking the pipeline's first full end-to-end pass.
Business problem solved: Replaces manual endpoint and identity posture reviews — tasks that typically require a qualified engineer spending multiple hours in portals — with automated data collection pipelines that deliver ready-to-review assessment packages.
Integrations: Microsoft Defender for Endpoints · Microsoft Graph · Azure Log Analytics · Microsoft Intune (via Graph)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Endpoint Configuration Review - 1.0 | Scheduled (top-level orchestrator) | 0 | Config audit & remediation, Endpoint hygiene & MDM ops |
| SecurityOps - Endpoint Configuration Review - 1.1 | On-demand (subflow) | 0 | Config audit & remediation |
| SecurityOps - Conditional Access Policy Review 1.0 | On-demand | 0 | Cloud access & SaaS policy mgmt, Config audit & remediation |
| SecurityOps - Conditional Access Policy Review | On-demand (agent) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.1 | On-demand (subflow) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.2 | On-demand (subflow) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review | Scheduled (agent-based, Cody MDE Agent) | 0 | Endpoint hygiene & MDM ops |
| SecurityOps - Conditional Access Policy Review 1.3 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review - 1.1 | Scheduled (subflow) | 0 | Config audit & remediation |
| SecurityOps - Endpoint Configuration Review - 1.2 | Scheduled (subflow) | 0 | Config audit & remediation |
| SecurityOps - Conditional Access Policy Review 1.4 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.5 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.6 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.7 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.8 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.9 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.10 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.11 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.12 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.13 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.14 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.15 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.16 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review - 1.2 copy | Scheduled (subflow, duplicate of 1.2) | 0 | Config audit & remediation, Endpoint hygiene & MDM ops |
Use Case 10 — Microsoft Sentinel SIEM Assessment Suite
Category: SOC
Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation
Description: A 16-module Sentinel assessment framework that systematically evaluates every layer of the Sentinel deployment — analytics rules health, watchlist governance, content hub packages, data connector health, DCR configuration, workbook usage, Azure ML notebook inventory, automation/Logic App health, threat intelligence hygiene, hunting query promotion, UEBA/Fusion ML coverage, SOC Optimization recommendations, RBAC and PIM governance, and data retention/cost governance. The "Cody Sentinel Assessment Agent" orchestrates findings from all sub-modules into a consolidated assessment report.
Business problem solved: Enables rigorous periodic health checks of the Sentinel environment without requiring consultant-grade manual review. Each module produces structured data feeds that the AI agent synthesizes into actionable security engineering recommendations.
Integrations: Microsoft Sentinel (Azure Management REST API) · Azure Log Analytics · Microsoft Graph · Azure Monitor DCR API
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Sentinel Assessment | On-demand (agent orchestrator) | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.0 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.1 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.2 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.3 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.4 | On-demand | 0 | Threat intel ingest & curation |
| SecurityOps - Sentinel Assessment - 1.5 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.6 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.7 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.8 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.9 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.10 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.11 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.12 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment 1.13 | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Sentinel Watchlist Updates | Scheduled | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Log Migration | On-demand | 0 | SIEM & log pipeline monitoring |
Use Case 11 — Security Reporting & Email Security Monitoring
Category: GRC
Subcategories: Security metrics & reporting
Description: Scheduled reporting workflows that surface security and compliance telemetry on a recurring basis. The SendGrid Bounce List query runs daily, detecting unauthorized or anomalous outbound email relay activity. The ZScaler Usage Comparison runs weekly to identify users present in Okta but absent from ZScaler — a coverage gap indicator. The Documentation Gathering Agent automates evidence collection for compliance and audit documentation.
Business problem solved: Delivers repeatable security reporting with zero analyst scheduling overhead, ensuring that email relay hygiene and network security coverage gaps are surfaced on a fixed cadence.
Integrations: SendGrid (HTTP) · ZScaler ZIA · Azure Log Analytics · Okta CIAM
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Query SendGrid Bounce List | Scheduled (daily, 6:30 AM ET) | 40 | Security metrics & reporting |
| SecurityOps - ZScaler Usage Comparison | Scheduled (weekly, Monday 1 PM ET) | 6 | Security metrics & reporting |
| SecurityOps - Documentation Gathering Agent | On-demand | 0 | Compliance questionnaire |
Use Case 12 — Third-Party Risk Management (TPRM)
Category: GRC
Subcategories: Vendor risk & TPRM
Description: An event-driven vendor risk workflow triggered via a custom webhook. On each trigger, the automation retrieves the current vendor list from the Optro (AuditBoard) TPRM platform and posts related risk data onward via HTTP, keeping downstream vendor risk records synchronized in near real time.
Business problem solved: Eliminates manual export/import cycles between the TPRM system of record and downstream consumers, ensuring vendor risk data stays current without analyst intervention. With 128 executions in the last 12 months, this is the customer's highest-volume GRC automation outside of core security metrics reporting.
Integrations: AuditBoard (Optro) · HTTP (custom)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| TPRM - Optro | Event trigger (custom webhook) | 128 | Vendor risk & TPRM |
Key Observations
Strengths
Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.
Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.
CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.
Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.
Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.
High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.
Gaps & Opportunities
IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."
Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.
Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.
Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.
Integration Ecosystem
The tenant integrates 20+ distinct security and business systems through Blink:
| Domain | Integrations |
|---|---|
| SIEM / Detection | Microsoft Sentinel, Azure Log Analytics |
| Endpoint & EDR | Microsoft Defender for Endpoints |
| Identity | Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph |
| Cloud Security | Orca Security, Azure Policy (Management REST API), Microsoft Purview |
| Network Security | ZScaler ZIA |
| Email Security | ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP) |
| Threat Intel | VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI |
| ITSM / Ticketing | Jira, PagerDuty |
| DevOps | GitHub |
| SaaS / Apps | Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe |
| GRC / Vendor Risk | AuditBoard (Optro) |
| Azure Infrastructure | Azure Automation Account, Azure Monitor DCR, Azure ML |
1. Business KPIs — Last 12 Months
Metric Table
| Metric | Count | Playbook |
|---|---|---|
| Security incidents auto-enriched and investigated by AI | 303 | SecOps - Microsoft Sentinel Incident Enrichment |
| Third-party vendor risk sync cycles processed (Optro/AuditBoard TPRM) | 128 | TPRM - Optro |
| CVE SLA monitoring cycles completed (v1.0 + v2.0, combined) | 80 | SecurityOps - Orca CVE Query - 1.0 / 2.0 |
| Daily CIAM agent activation anomaly checks completed | 40 | SecurityOps - Okta Agent Activation Query |
| Email security hygiene audits of SendGrid bounce list | 40 | SecurityOps - Query SendGrid Bounce List |
| Conditional Access Policy Review modules executed (full pipeline pass, 1.3–1.16 combined) | 14 | SecurityOps - Conditional Access Policy Review 1.3–1.16 |
| Azure cloud policy remediation cycles executed | 6 | SecurityOps - Azure Policy Remediation Tasks |
| ZScaler user compliance comparisons generated | 6 | SecurityOps - ZScaler Usage Comparison |
| Trending CVE landscape analyses delivered | 6 | SecurityOps - Orca Trending CVE Query |
| CIAM security metrics collected and stored | 6 | SecurityOps - Okta CIAM Metrics |
| Employee offboarding security investigations completed | 3 | SecurityOps - User Offboarding Analysis |
| Okta CIAM administrative access reviews completed | 1 | Okta CIAM Admin Access Review |
2. Use Case Summary
| # | Use Case | Category | Playbooks | Active (exec > 0) |
|---|---|---|---|---|
| 1 | Agentic SOC — Sentinel Incident Investigation | SOC | 19 | 17 |
| 2 | CVE Lifecycle Management & Reporting | Vulnerability Mgmt | 6 | 4 |
| 3 | Identity Incident Response Runbook Library | SOC | 12 | 0 |
| 4 | Agentic Employee Offboarding Investigation | IAM | 10 | 10 |
| 5 | Cloud Security Posture & Azure Policy Compliance | Cloud Security | 2 | 1 |
| 6 | Okta CIAM Operations & Identity Monitoring | IAM | 4 | 3 |
| 7 | Access Reviews & Privileged Access Governance | GRC | 26 | 3 |
| 8 | Application Provisioning & Directory Sync | IAM | 8 | 0 |
| 9 | Endpoint & Conditional Access Configuration Review | Cloud Security | 24 | 14 |
| 10 | Microsoft Sentinel SIEM Assessment Suite | SOC | 17 | 0 |
| 11 | Security Reporting & Email Security Monitoring | GRC | 3 | 2 |
| 12 | Third-Party Risk Management (TPRM) | GRC | 1 | 1 |
| Total | 132 | 55 |
3. Use Cases
Use Case 1 — Agentic SOC: Sentinel Incident Investigation
Category: SOC
Subcategories: Agentic SOC · Alert enrichment / IOC lookup · Case mgmt & SOAR
Description: An AI-powered SOC analyst ("Cody") responds in real time to every Microsoft Sentinel alert via webhook. The agent autonomously gathers evidence from Log Analytics, enriches entity context using ProofPoint, Orca, Okta, VirusTotal, Purview, and Microsoft Graph, then writes findings directly back to the Sentinel incident. The 17 active agent tools in this use case were collectively invoked thousands of times in the past year, representing the deepest automation investment in the tenant.
Business problem solved: Eliminates analyst toil on Level 1 triage and enrichment for every Sentinel alert. Each incident arrives pre-investigated, allowing analysts to review conclusions rather than conduct evidence gathering from scratch.
Integrations: Microsoft Sentinel · Azure Log Analytics · Microsoft Graph / Entra ID · ProofPoint ITM · ProofPoint TAP · Orca Security · Okta Workforce · VirusTotal · MXToolBox · Microsoft Purview · Microsoft XDR Defender · NIST NVD · Traceable · PagerDuty
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecOps - Microsoft Sentinel Incident Enrichment | Event trigger (top-level) | 303 | Agentic SOC, Case mgmt & SOAR |
| Cody - Get Sentinel Incident | Agent tool | 304 | Agentic SOC |
| Cody - Search Log Analytics Workspace | Agent tool | 1,721 | Alert enrichment / IOC lookup |
| Cody - Comment on Sentinel Incident | Agent tool | 218 | Case mgmt & SOAR |
| Cody - Search VirusTotal | Agent tool | 255 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint Device Activity | Agent tool | 114 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint CASB Activity | Agent tool | 102 | Alert enrichment / IOC lookup |
| Cody - Get Information on Multiple Entra ID Users | Agent tool | 178 | Alert enrichment / IOC lookup |
| Cody - Search Purview Alerts | Agent tool | 97 | Alert enrichment / IOC lookup |
| Cody - Get Log Analytics Table Schema | Agent tool | 305 | Alert enrichment / IOC lookup |
| Cody - List Table Records | Agent tool | 200 | Alert enrichment / IOC lookup |
| Cody - Search Okta Workforce | Agent tool | 60 | Alert enrichment / IOC lookup |
| Cody - Search Microsoft Graph | Agent tool | 38 | Alert enrichment / IOC lookup |
| Cody - Search Orca Alerts | Agent tool | 22 | Alert enrichment / IOC lookup |
| Cody - Search MXToolBox | Agent tool | 18 | Alert enrichment / IOC lookup |
| Cody - Threat Hunting | Agent tool | 6 | Threat intel ingest & curation |
| Cody - Search NIST for CVE | Agent tool | 1 | Alert enrichment / IOC lookup |
| Cody - Search ProofPoint Blocked URLs | Agent tool | 0 | Alert enrichment / IOC lookup |
| Cody - Get Traceable Alerts | Agent tool | 0 | Alert enrichment / IOC lookup |
Use Case 2 — CVE Lifecycle Management & Reporting
Category: Vulnerability Mgmt
Subcategories: CVE lookup & remediation · Vuln scanning ingest & report · Vuln lifecycle prioritize & ticket
Description: Scheduled automations query Orca Security daily and weekly to identify cloud CVEs that are within SLA, approaching SLA, or overdue. Version 1.0 automatically creates Jira tickets for each affected team; version 2.0 converts findings to HTML and delivers email reports. A trending CVE workflow tracks longitudinal CVE posture by comparing weekly snapshots stored in Blink Tables.
Business problem solved: Eliminates manual CVE export-and-distribute workflows. Every cloud engineering team receives structured, SLA-bucketed CVE assignments without analyst intervention.
Integrations: Orca Security · Jira · Blink Tables · Blink Email · NIST NVD
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Orca CVE Query - 1.0 | Scheduled (daily, 6 AM ET) | 40 | CVE lookup & remediation, Vuln lifecycle prioritize & ticket |
| SecurityOps - Orca CVE Query - 2.0 | Scheduled (daily, 7 AM ET) | 40 | CVE lookup & remediation, Vuln scanning ingest & report |
| SecurityOps - Orca Trending CVE Query | Scheduled (weekly, Monday) | 6 | Vuln scanning ingest & report |
| Cody - Search Orca CVEs by Resource | Agent tool | 7 | CVE lookup & remediation |
| SecurityOps - Orca Trending CVE Query 1.1 | Scheduled (weekly, Friday) | 0 | Vuln scanning ingest & report |
| Cody - Search Orca CVEs by Name & Resource | Agent tool | 0 | CVE lookup & remediation |
Use Case 3 — Identity Incident Response Runbook Library
Category: SOC
Subcategories: Identity threat response · EDR containment & response
Description: A library of 12 on-demand IR playbooks covering the full spectrum of containment actions: Entra ID account disablement, Okta session revocation and suspension, MFA factor resets, password resets, Windows machine isolation, AV scan initiation, file hash blocking in Defender, IP blocklisting via Named Locations, URL/domain blocking via ZScaler, and email recipient lookups. All playbooks are designed to be triggered by the Cody AI agent or manually by analysts.
Business problem solved: Provides pre-built, pre-approved IR actions that can be executed in seconds rather than requiring manual portal access — reducing mean time to contain (MTTC) and enabling consistent, auditable response procedures.
Integrations: Microsoft Entra ID (Active Directory) · Microsoft Graph · Okta Workforce · Microsoft Defender for Endpoints · ZScaler ZIA · Azure Log Analytics
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| IR - Disable Entra ID User | On-demand | 0 | Identity threat response |
| IR - Revoke User Session Tokens | On-demand | 0 | Identity threat response |
| IR - Revoke User Sessions in Okta Workforce | On-demand | 0 | Identity threat response |
| IR - Suspend Okta Workforce Account | On-demand | 0 | Identity threat response |
| IR - Reset User Factors in Okta Workforce | On-demand | 0 | Identity threat response |
| IR - Reset Password for Okta Workforce | On-demand | 0 | Password & credential lifecycle |
| IR - Isolate a Windows Machine | On-demand | 0 | EDR containment & response |
| IR - Start AV Scan | On-demand | 0 | EDR containment & response |
| IR - Block File Hash in Defender | On-demand | 0 | EDR containment & response |
| IR - Add IP to NamedLocation Blocklist | On-demand | 0 | Identity threat response |
| IR - Add Domain to ZScaler URL Category | On-demand | 0 | Identity threat response |
| IR - Get Email Recipients Containing a URL | On-demand | 0 | Phishing detection & response |
Use Case 4 — Agentic Employee Offboarding Investigation
Category: IAM
Subcategories: Employee offboarding · Identity lifecycle automation
Description: A comprehensive agentic offboarding workflow that gathers pre-termination activity across 8 data sources — sign-in logs, Azure Activity, Okta V2, audit logs, email events, Office Activity, ProofPoint CASB, ProofPoint device and email events, and GitHub — stores findings in structured Blink Tables, and feeds all evidence to a "Cody Offboarding Agent" that produces an AI-generated risk narrative. Results are written back to the Jira incident as a completed offboarding form. Each offboarding analysis involves a dedicated set of modular read playbooks called by the AI agent.
Business problem solved: Transforms offboarding security investigations from multi-day manual data-pulls across a dozen systems into a single automated workflow that delivers a complete AI-authored risk summary to the HR/security team, typically within minutes.
Integrations: Okta Workforce · Microsoft Entra ID · Azure Log Analytics · ProofPoint ITM · GitHub · Jira · Microsoft Graph · Blink Tables
Use Case 5 — Cloud Security Posture & Azure Policy Compliance
Category: Cloud Security
Subcategories: CSPM ingest & triage · Config audit & remediation
Description: Two cloud security posture workflows. The Azure Policy Remediation automation runs weekly across all Azure subscriptions, enumerating non-compliant policy assignments and submitting remediation tasks automatically. The Orca CSPM Alert Review feeds Orca cloud security alerts into a specialist "Cody Orca Agent" for AI-driven triage and prioritization.
Business problem solved: Eliminates the manual work of periodically checking and remediating Azure Policy non-compliance across multi-subscription environments, and speeds CSPM alert review by routing alerts directly to an AI security engineer.
Integrations: Azure (HTTP/REST — Azure Management API) · Orca Security
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Azure Policy Remediation Tasks | Scheduled (weekly, Sunday 1 AM ET) | 6 | Config audit & remediation |
| SecurityOps - Orca CSPM Alert Review | Scheduled | 0 | CSPM ingest & triage |
Use Case 6 — Okta CIAM Operations & Identity Monitoring
Category: IAM
Subcategories: Identity sync & directory mgmt · Identity lifecycle automation
Description: Automations managing the customer-facing Okta CIAM platform. The Agent Activation Query runs daily to check for new agent onboarding events and processes group membership changes. The CIAM Metrics workflow is event-driven, ingesting webhook data on authentication patterns (email auth, strong auth, SSO, partner integrations) and persisting them to Blink Tables for trending. The ZeroFox User Check correlates external brand-threat intelligence against CIAM user accounts to detect account takeover risk.
Business problem solved: Provides continuous monitoring and automated data collection for a production customer-identity platform, surfacing both operational anomalies and fraud signals without requiring manual CIAM log review.
Integrations: Okta CIAM (Production) · ZeroFox · Microsoft Sentinel · Blink Tables
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Okta Agent Activation Query | Scheduled (daily, 9 AM ET) | 40 | Identity sync & directory mgmt |
| SecurityOps - Okta CIAM Metrics | Event (webhook) | 6 | Security metrics & reporting |
| Cody - ZeroFox CIAM User Check | On-demand (agent tool) | 5 | Identity threat response |
| SecurityOps - Add Agent to Agency Group Okta CIAM | Event (webhook) | 0 | Identity sync & directory mgmt |
Use Case 7 — Access Reviews & Privileged Access Governance
Category: GRC
Subcategories: RBAC review & access mgmt · Access review & group mgmt
Description: A structured program of access reviews covering both broad organizational entitlements (semi-annual review across 20+ apps, Azure role assignments, SQL database permissions, PIM group memberships, GitHub secrets) and targeted application-level reviews (WordPress, Bill.com, DropBox Sign, Grafana, SendGrid, Slack, Jira, BlinkOps, PagerDuty). An inactive user assessment identifies stale Entra ID accounts through sign-in telemetry and Graph API queries. A dedicated Azure PIM/Entra role eligibility review normalizes PIM group, Entra role, and nested group membership data (including a call to a standalone Azure SQL access review sub-automation) into a consolidated governance report, alongside standalone directory-administrator and subscription-level RBAC reviews. A newly expanded set of application- and platform-specific reviews adds Optro (AuditBoard) TPRM user access, GitHub organization membership, Stripe, Azure AD Enterprise Applications/Service Principals, Okta CIAM and Okta Workforce admin role assignments, and Intune RBAC role assignments to the governance program.
Business problem solved: Automates the evidence-gathering and report-generation phases of periodic access certifications, reducing review cycle time from days to minutes and ensuring consistent coverage across all in-scope systems.
Integrations: Okta Workforce · Okta CIAM · Microsoft Graph · Azure (REST) · Azure Log Analytics · PagerDuty · Blink (internal) · GitHub · Bill.com (HTTP) · WordPress (HTTP) · DropBox Sign (HTTP) · Grafana (HTTP) · SendGrid (HTTP) · Slack · Jira · Blink Email · AuditBoard (Optro) · Stripe (HTTP) · Microsoft Intune (via Graph)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Security Operations - Semi-Annual Access Review 1.0 | Scheduled | 0 | RBAC review & access mgmt |
| Security Operations - Semi-Annual Access Review 1.1 | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Inactive User Assessment | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - SQL Admin Review | On-demand | 0 | RBAC review & access mgmt |
| Azure PIM Group Access Review | On-demand (top-level, orchestrates SQL sub-review) | 1 | RBAC review & access mgmt |
| Azure SQL Access Review | On-demand (subflow) | 2 | RBAC review & access mgmt |
| Directory Administrators Access Review | On-demand | 0 | RBAC review & access mgmt |
| Azure Subscription Role Assignment Access Review | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Retrieve Okta Users | On-demand | 0 | Access review & group mgmt |
| SecurityOps - Remove Okta Groups | On-demand | 0 | Access review & group mgmt |
| WordPress Access Review | On-demand | 0 | Access review & group mgmt |
| Bill.com Access Review | On-demand | 0 | Access review & group mgmt |
| DropBox Sign Access Review | On-demand | 0 | Access review & group mgmt |
| Grafana Access Review | On-demand | 0 | Access review & group mgmt |
| SendGrid Access Review | On-demand | 0 | Access review & group mgmt |
| Slack Access Review | On-demand | 0 | Access review & group mgmt |
| Jira Access Review | On-demand | 0 | Access review & group mgmt |
| BlinkOps Access Review | On-demand | 0 | Access review & group mgmt |
| PagerDuty Access Review | On-demand | 0 | Access review & group mgmt |
| Optro Access Review | On-demand | 0 | Access review & group mgmt |
| GitHub Access Review | On-demand | 0 | Access review & group mgmt |
| Stripe Access Review | On-demand | 0 | Access review & group mgmt |
| Azure AD Enterprise Apps Access Review | On-demand | 0 | RBAC review & access mgmt |
| Okta CIAM Admin Access Review | On-demand | 1 | RBAC review & access mgmt |
| Okta Workforce Admin Access Review | On-demand | 0 | RBAC review & access mgmt |
| Intune Access Review | On-demand | 0 | RBAC review & access mgmt |
Use Case 8 — Application Provisioning & Directory Sync
Category: IAM
Subcategories: Identity sync & directory mgmt · Identity lifecycle automation
Description: Provisioning automations for SaaS applications and directory synchronization tasks. The SCIM Provisioning 2.0 workflow processes Okta webhook events to manage the full create/update/deactivate lifecycle. Application-specific provisioners handle Bill.com, ProofPoint, WordPress, SendGrid, and BlinkOps accounts. The Catalog Refresh populates Microsoft Teams, Channels, and SharePoint site catalogs. A utility workflow syncs Okta group memberships to Azure/Entra.
Business problem solved: Standardizes application joiner/mover/leaver processes across SaaS tools, ensuring consistent provisioning logic, validation, and error handling without per-tool manual work.
Integrations: Okta Workforce · Microsoft Graph · Bill.com (HTTP) · ProofPoint ITM · WordPress (HTTP) · SendGrid (HTTP) · Blink
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - SCIM Provisioning 2.0 | Event (Okta webhook) | 0 | Identity lifecycle automation |
| Adding Users/Groups from Okta to Azure/Entra | On-demand | 0 | Identity sync & directory mgmt |
| Catalog Refresh - Onboarding | On-demand | 0 | Employee onboarding |
| ProofPoint Provisioning | On-demand | 0 | Identity lifecycle automation |
| BlinkOps Provisioning | On-demand | 0 | Identity lifecycle automation |
| Bill.com Provisioning | On-demand | 0 | Identity lifecycle automation |
| WordPress Provisioning | On-demand | 0 | Identity lifecycle automation |
| SendGrid Provisioning | On-demand | 0 | Identity lifecycle automation |
Use Case 9 — Endpoint & Conditional Access Configuration Review
Category: Cloud Security
Subcategories: Config audit & remediation · Cloud access & SaaS policy mgmt · Endpoint hygiene & MDM ops
Description: Two distinct review programs. The Endpoint Configuration Review (1.0, 1.1, 1.2) gathers Defender for Endpoint recommendations, Intune managed devices, device configurations, compliance policies, settings catalog, group policies, device intents, and Device Configuration Policy templates, then feeds all data to a "Cody MDE Agent" for an AI-authored security assessment. The Conditional Access Policy Review suite (1.0 through 1.16, plus the agent version) performs a comprehensive set of Log Analytics and Graph queries covering CA policy inventory, named locations, MFA bypass analysis, legacy authentication, non-compliant device sign-ins, service principals without CA applied, report-only CA blocks, blocked sign-ins by policy, risky-but-unblocked sign-ins, non-interactive sign-ins, users with no CA policy applied, and policy hit counts. Modules 1.3 through 1.16 each executed once in the most recent 12-month window, marking the pipeline's first full end-to-end pass.
Business problem solved: Replaces manual endpoint and identity posture reviews — tasks that typically require a qualified engineer spending multiple hours in portals — with automated data collection pipelines that deliver ready-to-review assessment packages.
Integrations: Microsoft Defender for Endpoints · Microsoft Graph · Azure Log Analytics · Microsoft Intune (via Graph)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Endpoint Configuration Review - 1.0 | Scheduled (top-level orchestrator) | 0 | Config audit & remediation, Endpoint hygiene & MDM ops |
| SecurityOps - Endpoint Configuration Review - 1.1 | On-demand (subflow) | 0 | Config audit & remediation |
| SecurityOps - Conditional Access Policy Review 1.0 | On-demand | 0 | Cloud access & SaaS policy mgmt, Config audit & remediation |
| SecurityOps - Conditional Access Policy Review | On-demand (agent) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.1 | On-demand (subflow) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.2 | On-demand (subflow) | 0 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review | Scheduled (agent-based, Cody MDE Agent) | 0 | Endpoint hygiene & MDM ops |
| SecurityOps - Conditional Access Policy Review 1.3 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review - 1.1 | Scheduled (subflow) | 0 | Config audit & remediation |
| SecurityOps - Endpoint Configuration Review - 1.2 | Scheduled (subflow) | 0 | Config audit & remediation |
| SecurityOps - Conditional Access Policy Review 1.4 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.5 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.6 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.7 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.8 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.9 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.10 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.11 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.12 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.13 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.14 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.15 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Conditional Access Policy Review 1.16 | On-demand (subflow) | 1 | Cloud access & SaaS policy mgmt |
| SecurityOps - Endpoint Configuration Review - 1.2 copy | Scheduled (subflow, duplicate of 1.2) | 0 | Config audit & remediation, Endpoint hygiene & MDM ops |
Use Case 10 — Microsoft Sentinel SIEM Assessment Suite
Category: SOC
Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation
Description: A 16-module Sentinel assessment framework that systematically evaluates every layer of the Sentinel deployment — analytics rules health, watchlist governance, content hub packages, data connector health, DCR configuration, workbook usage, Azure ML notebook inventory, automation/Logic App health, threat intelligence hygiene, hunting query promotion, UEBA/Fusion ML coverage, SOC Optimization recommendations, RBAC and PIM governance, and data retention/cost governance. The "Cody Sentinel Assessment Agent" orchestrates findings from all sub-modules into a consolidated assessment report.
Business problem solved: Enables rigorous periodic health checks of the Sentinel environment without requiring consultant-grade manual review. Each module produces structured data feeds that the AI agent synthesizes into actionable security engineering recommendations.
Integrations: Microsoft Sentinel (Azure Management REST API) · Azure Log Analytics · Microsoft Graph · Azure Monitor DCR API
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Sentinel Assessment | On-demand (agent orchestrator) | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.0 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.1 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.2 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.3 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.4 | On-demand | 0 | Threat intel ingest & curation |
| SecurityOps - Sentinel Assessment - 1.5 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.6 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.7 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.8 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.9 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.10 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.11 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment - 1.12 | On-demand | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Sentinel Assessment 1.13 | On-demand | 0 | RBAC review & access mgmt |
| SecurityOps - Sentinel Watchlist Updates | Scheduled | 0 | SIEM & log pipeline monitoring |
| SecurityOps - Log Migration | On-demand | 0 | SIEM & log pipeline monitoring |
Use Case 11 — Security Reporting & Email Security Monitoring
Category: GRC
Subcategories: Security metrics & reporting
Description: Scheduled reporting workflows that surface security and compliance telemetry on a recurring basis. The SendGrid Bounce List query runs daily, detecting unauthorized or anomalous outbound email relay activity. The ZScaler Usage Comparison runs weekly to identify users present in Okta but absent from ZScaler — a coverage gap indicator. The Documentation Gathering Agent automates evidence collection for compliance and audit documentation.
Business problem solved: Delivers repeatable security reporting with zero analyst scheduling overhead, ensuring that email relay hygiene and network security coverage gaps are surfaced on a fixed cadence.
Integrations: SendGrid (HTTP) · ZScaler ZIA · Azure Log Analytics · Okta CIAM
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| SecurityOps - Query SendGrid Bounce List | Scheduled (daily, 6:30 AM ET) | 40 | Security metrics & reporting |
| SecurityOps - ZScaler Usage Comparison | Scheduled (weekly, Monday 1 PM ET) | 6 | Security metrics & reporting |
| SecurityOps - Documentation Gathering Agent | On-demand | 0 | Compliance questionnaire |
Use Case 12 — Third-Party Risk Management (TPRM)
Category: GRC
Subcategories: Vendor risk & TPRM
Description: An event-driven vendor risk workflow triggered via a custom webhook. On each trigger, the automation retrieves the current vendor list from the Optro (AuditBoard) TPRM platform and posts related risk data onward via HTTP, keeping downstream vendor risk records synchronized in near real time.
Business problem solved: Eliminates manual export/import cycles between the TPRM system of record and downstream consumers, ensuring vendor risk data stays current without analyst intervention. With 128 executions in the last 12 months, this is the customer's highest-volume GRC automation outside of core security metrics reporting.
Integrations: AuditBoard (Optro) · HTTP (custom)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| TPRM - Optro | Event trigger (custom webhook) | 128 | Vendor risk & TPRM |
4. Key Observations
Strengths
Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.
Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.
CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.
Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.
Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.
High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.
Gaps & Opportunities
IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."
Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.
Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.
Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.
Integration Ecosystem
The tenant integrates 20+ distinct security and business systems through Blink:
| Domain | Integrations |
|---|---|
| SIEM / Detection | Microsoft Sentinel, Azure Log Analytics |
| Endpoint & EDR | Microsoft Defender for Endpoints |
| Identity | Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph |
| Cloud Security | Orca Security, Azure Policy (Management REST API), Microsoft Purview |
| Network Security | ZScaler ZIA |
| Email Security | ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP) |
| Threat Intel | VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI |
| ITSM / Ticketing | Jira, PagerDuty |
| DevOps | GitHub |
| SaaS / Apps | Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe |
| GRC / Vendor Risk | AuditBoard (Optro) |
| Azure Infrastructure | Azure Automation Account, Azure Monitor DCR, Azure ML |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Coterie | github | my_github_connection | 2026-08-03 |