Blink Security Automation — Confidential

Coterie — Customer Success Report

Generated 2026-08-31 | coterie-value-report.md
2026-08-31Report Date
170Total Playbooks
93Unique Workflows (12m)
1,282,970Actions Automated (12m)
$329,982Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

170
Total playbooks built
all non-deleted workflows
136
Active playbooks
currently enabled
93
Unique workflows executed (12m)
distinct workflows that ran
1,282,970
Actions automated (12m)
completed action steps
7,127.6h
Hours saved (12m)
@ 20s per action
$329,982
Money saved (12m)
@ $100K avg salary
6
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
8
Active AI agents
of 8 total
2,572
AI agent tasks executed (12m)
303 in last 30d
In the last 12 months, Blink automated: - 303 Sentinel security incidents enriched and fully investigated by an AI SOC analyst — no human involvement required at initial triage - 128 third-party vendor risk sync cycles completed via the Optro (AuditBoard) TPRM integration, keeping vendor risk records current without manual export/import - 80 CVE SLA compliance cycles completed — tracking overdue, near-SLA, and within-SLA vulnerabilities across cloud infrastructure, with Jira tickets and email reports delivered automatically - 40 daily CIAM agent activation anomaly checks, ensuring customer-facing identity infrastructure is continuously monitored - 40 daily email security hygiene audits, surfacing unauthorized or suspicious email activity via the SendGrid bounce list - 14 Conditional Access Policy Review pipeline modules executed in a single full pass (1.3–1.16) — first end-to-end activation of this previously idle review program, covering CA policy inventory, named locations, MFA bypass, legacy authentication, device compliance gaps, risky sign-ins, and policy hit counts - 6 automated Azure cloud policy remediation cycles executed across all subscriptions - 3 full employee offboarding security investigations completed, each autonomously cross-referencing 8+ data sources (sign-in logs, audit logs, ProofPoint, Okta, GitHub, Office Activity, Azure Activity, email events) and generating AI-driven risk summaries - 1 Okta CIAM administrative access review completed — first execution of a newly deployed admin entitlements review for the customer-facing identity platform

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1 — Agentic SOC: Sentinel Incident Investigation5,276 executions
92.2%
19
19 active
Use Case 2 — CVE Lifecycle Management & Reporting99 executions
1.7%
6
6 active
Use Case 3 — Identity Incident Response Runbook Library0 executions
0.0%
12
12 active
Use Case 4 — Agentic Employee Offboarding Investigation51 executions
0.9%
10
10 active
Use Case 5 — Cloud Security Posture & Azure Policy Compliance6 executions
0.1%
2
2 active
Use Case 6 — Okta CIAM Operations & Identity Monitoring71 executions
1.2%
4
4 active
Use Case 7 — Access Reviews & Privileged Access Governance4 executions
0.1%
26
26 active
Use Case 8 — Application Provisioning & Directory Sync0 executions
0.0%
8
8 active
Use Case 9 — Endpoint & Conditional Access Configuration Review18 executions
0.3%
23
23 active
Use Case 10 — Microsoft Sentinel SIEM Assessment Suite15 executions
0.3%
17
17 active
Use Case 11 — Security Reporting & Email Security Monitoring46 executions
0.8%
3
3 active
Use Case 12 — Third-Party Risk Management (TPRM)128 executions
2.2%
1
1 active
Total5,714 executions100%
131
131 active

Use Case Growth Over Time

157 unique playbooks  |  12 operational use cases  |  5,723 total executions (12m)  |  2025-11 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Use Case 2 — CVE Lifecycle Management & Reporting
Orca Security Jira Email
Use Case 11 — Security Reporting & Email Security Monitoring
Zscaler Internet Access Azure Log Analytics Microsoft Graph Jira Email Agents
Use Case 1 — Agentic SOC: Sentinel Incident Investigation
Agents Microsoft Sentinel Azure Log Analytics PagerDuty VirusTotal MxToolbox Microsoft Graph Microsoft Defender XDR Proofpoint TAP Proofpoint ITM Orca Security Okta Microsoft Entra ID
Use Case 8 — Application Provisioning & Directory Sync
Okta Microsoft Graph Proofpoint ITM Email
Use Case 3 — Identity Incident Response Runbook Library
Microsoft Entra ID Microsoft Graph Azure Log Analytics Microsoft Defender For Endpoints Okta Zscaler Internet Access
Use Case 6 — Okta CIAM Operations & Identity Monitoring
Okta Jira Email PagerDuty
Use Case 4 — Agentic Employee Offboarding Investigation
Okta Microsoft Entra ID Jira Azure Log Analytics Proofpoint ITM GitHub Microsoft Graph Agents
Use Case 7 — Access Reviews & Privileged Access Governance
Okta GitHub Microsoft Graph Azure Log Analytics Email Slack Jira PagerDuty AuditBoard
Use Case 9 — Endpoint & Conditional Access Configuration Review
Microsoft Defender for Endpoint Agents Microsoft Graph Azure Log Analytics
Use Case 5 — Cloud Security Posture & Azure Policy Compliance
Orca Security Agents
Use Case 10 — Microsoft Sentinel SIEM Assessment Suite
Microsoft Graph Azure Log Analytics Agents
Use Case 12 — Third-Party Risk Management (TPRM)
AuditBoard

04Key Observations

✓  Strengths

Strengths

Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.

Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.

CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.

Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.

Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.

High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."

Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.

Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.

Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.

Integration Ecosystem

The tenant integrates 20+ distinct security and business systems through Blink:

Domain Integrations
SIEM / Detection Microsoft Sentinel, Azure Log Analytics
Endpoint & EDR Microsoft Defender for Endpoints
Identity Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph
Cloud Security Orca Security, Azure Policy (Management REST API), Microsoft Purview
Network Security ZScaler ZIA
Email Security ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP)
Threat Intel VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI
ITSM / Ticketing Jira, PagerDuty
DevOps GitHub
SaaS / Apps Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe
GRC / Vendor Risk AuditBoard (Optro)
Azure Infrastructure Azure Automation Account, Azure Monitor DCR, Azure ML
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 8 active | 2,572 tasks (12m)

AI Agents

Active Agents
8
of 8 total
Tasks Executed (12m)
2,572
303 in last 30d
Data Usage (12m)
2,821,800,046
338,194,393 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Cody Sentinel Coterie SecOps/ITSS Workspace 2,089 281 2,645,080,168
2 Cody Orca Agent Coterie SecOps/ITSS Workspace 238 0 45,332,704
3 Cody Offboarding Agent Coterie SecOps/ITSS Workspace 122 20 97,685,192
4 Cody SCIM Agent Coterie SecOps/ITSS Workspace 88 0 1,918,905
5 Cody Security Engineer I Coterie SecOps/ITSS Workspace 13 1 12,377,137
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Coterie SecOps/ITSS Workspace2,572
C Self-Service & Webforms 0 app runs | 21 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Okta CIAM Metrics 00
2 Cody Sentinel Incidents 00
3 Orca Repo Vulnerabilities 00

Webforms

Forms
2
active webforms
Total Submissions
21
all time
Completed
18
fully submitted
Submissions (30d)
21
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 New Hire - Systems and Access Confirmation 2118
2 New User Onboard Request 00
D Full Use Case Analysis 12 use cases | 5,723 executions (12m)

Business KPIs

Metric Table

Metric Count Playbook
Security incidents auto-enriched and investigated by AI 303 SecOps - Microsoft Sentinel Incident Enrichment
Third-party vendor risk sync cycles processed (Optro/AuditBoard TPRM) 128 TPRM - Optro
CVE SLA monitoring cycles completed (v1.0 + v2.0, combined) 80 SecurityOps - Orca CVE Query - 1.0 / 2.0
Daily CIAM agent activation anomaly checks completed 40 SecurityOps - Okta Agent Activation Query
Email security hygiene audits of SendGrid bounce list 40 SecurityOps - Query SendGrid Bounce List
Conditional Access Policy Review modules executed (full pipeline pass, 1.3–1.16 combined) 14 SecurityOps - Conditional Access Policy Review 1.3–1.16
Azure cloud policy remediation cycles executed 6 SecurityOps - Azure Policy Remediation Tasks
ZScaler user compliance comparisons generated 6 SecurityOps - ZScaler Usage Comparison
Trending CVE landscape analyses delivered 6 SecurityOps - Orca Trending CVE Query
CIAM security metrics collected and stored 6 SecurityOps - Okta CIAM Metrics
Employee offboarding security investigations completed 3 SecurityOps - User Offboarding Analysis
Okta CIAM administrative access reviews completed 1 Okta CIAM Admin Access Review
In the last 12 months, Blink automated: - 303 Sentinel security incidents enriched and fully investigated by an AI SOC analyst — no human involvement required at initial triage - 128 third-party vendor risk sync cycles completed via the Optro (AuditBoard) TPRM integration, keeping vendor risk records current without manual export/import - 80 CVE SLA compliance cycles completed — tracking overdue, near-SLA, and within-SLA vulnerabilities across cloud infrastructure, with Jira tickets and email reports delivered automatically - 40 daily CIAM agent activation anomaly checks, ensuring customer-facing identity infrastructure is continuously monitored - 40 daily email security hygiene audits, surfacing unauthorized or suspicious email activity via the SendGrid bounce list - 14 Conditional Access Policy Review pipeline modules executed in a single full pass (1.3–1.16) — first end-to-end activation of this previously idle review program, covering CA policy inventory, named locations, MFA bypass, legacy authentication, device compliance gaps, risky sign-ins, and policy hit counts - 6 automated Azure cloud policy remediation cycles executed across all subscriptions - 3 full employee offboarding security investigations completed, each autonomously cross-referencing 8+ data sources (sign-in logs, audit logs, ProofPoint, Okta, GitHub, Office Activity, Azure Activity, email events) and generating AI-driven risk summaries - 1 Okta CIAM administrative access review completed — first execution of a newly deployed admin entitlements review for the customer-facing identity platform

Use Case Summary

# Use Case Category Playbooks Active (exec > 0)
1 Agentic SOC — Sentinel Incident Investigation SOC 19 17
2 CVE Lifecycle Management & Reporting Vulnerability Mgmt 6 4
3 Identity Incident Response Runbook Library SOC 12 0
4 Agentic Employee Offboarding Investigation IAM 10 10
5 Cloud Security Posture & Azure Policy Compliance Cloud Security 2 1
6 Okta CIAM Operations & Identity Monitoring IAM 4 3
7 Access Reviews & Privileged Access Governance GRC 26 3
8 Application Provisioning & Directory Sync IAM 8 0
9 Endpoint & Conditional Access Configuration Review Cloud Security 24 14
10 Microsoft Sentinel SIEM Assessment Suite SOC 17 0
11 Security Reporting & Email Security Monitoring GRC 3 2
12 Third-Party Risk Management (TPRM) GRC 1 1
Total 132 55

Use Cases

Use Case 1 — Agentic SOC: Sentinel Incident Investigation

Category: SOC

Subcategories: Agentic SOC · Alert enrichment / IOC lookup · Case mgmt & SOAR

Description: An AI-powered SOC analyst ("Cody") responds in real time to every Microsoft Sentinel alert via webhook. The agent autonomously gathers evidence from Log Analytics, enriches entity context using ProofPoint, Orca, Okta, VirusTotal, Purview, and Microsoft Graph, then writes findings directly back to the Sentinel incident. The 17 active agent tools in this use case were collectively invoked thousands of times in the past year, representing the deepest automation investment in the tenant.

Business problem solved: Eliminates analyst toil on Level 1 triage and enrichment for every Sentinel alert. Each incident arrives pre-investigated, allowing analysts to review conclusions rather than conduct evidence gathering from scratch.

Integrations: Microsoft Sentinel · Azure Log Analytics · Microsoft Graph / Entra ID · ProofPoint ITM · ProofPoint TAP · Orca Security · Okta Workforce · VirusTotal · MXToolBox · Microsoft Purview · Microsoft XDR Defender · NIST NVD · Traceable · PagerDuty

Playbook Type Executions Taxonomy
SecOps - Microsoft Sentinel Incident Enrichment Event trigger (top-level) 303 Agentic SOC, Case mgmt & SOAR
Cody - Get Sentinel Incident Agent tool 304 Agentic SOC
Cody - Search Log Analytics Workspace Agent tool 1,721 Alert enrichment / IOC lookup
Cody - Comment on Sentinel Incident Agent tool 218 Case mgmt & SOAR
Cody - Search VirusTotal Agent tool 255 Alert enrichment / IOC lookup
Cody - Search ProofPoint Device Activity Agent tool 114 Alert enrichment / IOC lookup
Cody - Search ProofPoint CASB Activity Agent tool 102 Alert enrichment / IOC lookup
Cody - Get Information on Multiple Entra ID Users Agent tool 178 Alert enrichment / IOC lookup
Cody - Search Purview Alerts Agent tool 97 Alert enrichment / IOC lookup
Cody - Get Log Analytics Table Schema Agent tool 305 Alert enrichment / IOC lookup
Cody - List Table Records Agent tool 200 Alert enrichment / IOC lookup
Cody - Search Okta Workforce Agent tool 60 Alert enrichment / IOC lookup
Cody - Search Microsoft Graph Agent tool 38 Alert enrichment / IOC lookup
Cody - Search Orca Alerts Agent tool 22 Alert enrichment / IOC lookup
Cody - Search MXToolBox Agent tool 18 Alert enrichment / IOC lookup
Cody - Threat Hunting Agent tool 6 Threat intel ingest & curation
Cody - Search NIST for CVE Agent tool 1 Alert enrichment / IOC lookup
Cody - Search ProofPoint Blocked URLs Agent tool 0 Alert enrichment / IOC lookup
Cody - Get Traceable Alerts Agent tool 0 Alert enrichment / IOC lookup

Use Case 2 — CVE Lifecycle Management & Reporting

Category: Vulnerability Mgmt

Subcategories: CVE lookup & remediation · Vuln scanning ingest & report · Vuln lifecycle prioritize & ticket

Description: Scheduled automations query Orca Security daily and weekly to identify cloud CVEs that are within SLA, approaching SLA, or overdue. Version 1.0 automatically creates Jira tickets for each affected team; version 2.0 converts findings to HTML and delivers email reports. A trending CVE workflow tracks longitudinal CVE posture by comparing weekly snapshots stored in Blink Tables.

Business problem solved: Eliminates manual CVE export-and-distribute workflows. Every cloud engineering team receives structured, SLA-bucketed CVE assignments without analyst intervention.

Integrations: Orca Security · Jira · Blink Tables · Blink Email · NIST NVD

Playbook Type Executions Taxonomy
SecurityOps - Orca CVE Query - 1.0 Scheduled (daily, 6 AM ET) 40 CVE lookup & remediation, Vuln lifecycle prioritize & ticket
SecurityOps - Orca CVE Query - 2.0 Scheduled (daily, 7 AM ET) 40 CVE lookup & remediation, Vuln scanning ingest & report
SecurityOps - Orca Trending CVE Query Scheduled (weekly, Monday) 6 Vuln scanning ingest & report
Cody - Search Orca CVEs by Resource Agent tool 7 CVE lookup & remediation
SecurityOps - Orca Trending CVE Query 1.1 Scheduled (weekly, Friday) 0 Vuln scanning ingest & report
Cody - Search Orca CVEs by Name & Resource Agent tool 0 CVE lookup & remediation

Use Case 3 — Identity Incident Response Runbook Library

Category: SOC

Subcategories: Identity threat response · EDR containment & response

Description: A library of 12 on-demand IR playbooks covering the full spectrum of containment actions: Entra ID account disablement, Okta session revocation and suspension, MFA factor resets, password resets, Windows machine isolation, AV scan initiation, file hash blocking in Defender, IP blocklisting via Named Locations, URL/domain blocking via ZScaler, and email recipient lookups. All playbooks are designed to be triggered by the Cody AI agent or manually by analysts.

Business problem solved: Provides pre-built, pre-approved IR actions that can be executed in seconds rather than requiring manual portal access — reducing mean time to contain (MTTC) and enabling consistent, auditable response procedures.

Integrations: Microsoft Entra ID (Active Directory) · Microsoft Graph · Okta Workforce · Microsoft Defender for Endpoints · ZScaler ZIA · Azure Log Analytics

Playbook Type Executions Taxonomy
IR - Disable Entra ID User On-demand 0 Identity threat response
IR - Revoke User Session Tokens On-demand 0 Identity threat response
IR - Revoke User Sessions in Okta Workforce On-demand 0 Identity threat response
IR - Suspend Okta Workforce Account On-demand 0 Identity threat response
IR - Reset User Factors in Okta Workforce On-demand 0 Identity threat response
IR - Reset Password for Okta Workforce On-demand 0 Password & credential lifecycle
IR - Isolate a Windows Machine On-demand 0 EDR containment & response
IR - Start AV Scan On-demand 0 EDR containment & response
IR - Block File Hash in Defender On-demand 0 EDR containment & response
IR - Add IP to NamedLocation Blocklist On-demand 0 Identity threat response
IR - Add Domain to ZScaler URL Category On-demand 0 Identity threat response
IR - Get Email Recipients Containing a URL On-demand 0 Phishing detection & response

Use Case 4 — Agentic Employee Offboarding Investigation

Category: IAM

Subcategories: Employee offboarding · Identity lifecycle automation

Description: A comprehensive agentic offboarding workflow that gathers pre-termination activity across 8 data sources — sign-in logs, Azure Activity, Okta V2, audit logs, email events, Office Activity, ProofPoint CASB, ProofPoint device and email events, and GitHub — stores findings in structured Blink Tables, and feeds all evidence to a "Cody Offboarding Agent" that produces an AI-generated risk narrative. Results are written back to the Jira incident as a completed offboarding form. Each offboarding analysis involves a dedicated set of modular read playbooks called by the AI agent.

Business problem solved: Transforms offboarding security investigations from multi-day manual data-pulls across a dozen systems into a single automated workflow that delivers a complete AI-authored risk summary to the HR/security team, typically within minutes.

Integrations: Okta Workforce · Microsoft Entra ID · Azure Log Analytics · ProofPoint ITM · GitHub · Jira · Microsoft Graph · Blink Tables

Playbook Type Executions Taxonomy
SecurityOps - User Offboarding Analysis On-demand (top-level) 3 Employee offboarding, Identity lifecycle automation
SecurityOps - User Offboarding Jira Comment On-demand 2 Employee offboarding
SecurityOps - Read SignIn Logs from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read OktaV2_CL from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read AzureActivity from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read EmailEvents from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read Office Activity from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint Device Events from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint ITM from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint Email Events from User Offboarding Table Agent tool 2 Employee offboarding

Use Case 5 — Cloud Security Posture & Azure Policy Compliance

Category: Cloud Security

Subcategories: CSPM ingest & triage · Config audit & remediation

Description: Two cloud security posture workflows. The Azure Policy Remediation automation runs weekly across all Azure subscriptions, enumerating non-compliant policy assignments and submitting remediation tasks automatically. The Orca CSPM Alert Review feeds Orca cloud security alerts into a specialist "Cody Orca Agent" for AI-driven triage and prioritization.

Business problem solved: Eliminates the manual work of periodically checking and remediating Azure Policy non-compliance across multi-subscription environments, and speeds CSPM alert review by routing alerts directly to an AI security engineer.

Integrations: Azure (HTTP/REST — Azure Management API) · Orca Security

Playbook Type Executions Taxonomy
SecurityOps - Azure Policy Remediation Tasks Scheduled (weekly, Sunday 1 AM ET) 6 Config audit & remediation
SecurityOps - Orca CSPM Alert Review Scheduled 0 CSPM ingest & triage

Use Case 6 — Okta CIAM Operations & Identity Monitoring

Category: IAM

Subcategories: Identity sync & directory mgmt · Identity lifecycle automation

Description: Automations managing the customer-facing Okta CIAM platform. The Agent Activation Query runs daily to check for new agent onboarding events and processes group membership changes. The CIAM Metrics workflow is event-driven, ingesting webhook data on authentication patterns (email auth, strong auth, SSO, partner integrations) and persisting them to Blink Tables for trending. The ZeroFox User Check correlates external brand-threat intelligence against CIAM user accounts to detect account takeover risk.

Business problem solved: Provides continuous monitoring and automated data collection for a production customer-identity platform, surfacing both operational anomalies and fraud signals without requiring manual CIAM log review.

Integrations: Okta CIAM (Production) · ZeroFox · Microsoft Sentinel · Blink Tables

Playbook Type Executions Taxonomy
SecurityOps - Okta Agent Activation Query Scheduled (daily, 9 AM ET) 40 Identity sync & directory mgmt
SecurityOps - Okta CIAM Metrics Event (webhook) 6 Security metrics & reporting
Cody - ZeroFox CIAM User Check On-demand (agent tool) 5 Identity threat response
SecurityOps - Add Agent to Agency Group Okta CIAM Event (webhook) 0 Identity sync & directory mgmt

Use Case 7 — Access Reviews & Privileged Access Governance

Category: GRC

Subcategories: RBAC review & access mgmt · Access review & group mgmt

Description: A structured program of access reviews covering both broad organizational entitlements (semi-annual review across 20+ apps, Azure role assignments, SQL database permissions, PIM group memberships, GitHub secrets) and targeted application-level reviews (WordPress, Bill.com, DropBox Sign, Grafana, SendGrid, Slack, Jira, BlinkOps, PagerDuty). An inactive user assessment identifies stale Entra ID accounts through sign-in telemetry and Graph API queries. A dedicated Azure PIM/Entra role eligibility review normalizes PIM group, Entra role, and nested group membership data (including a call to a standalone Azure SQL access review sub-automation) into a consolidated governance report, alongside standalone directory-administrator and subscription-level RBAC reviews. A newly expanded set of application- and platform-specific reviews adds Optro (AuditBoard) TPRM user access, GitHub organization membership, Stripe, Azure AD Enterprise Applications/Service Principals, Okta CIAM and Okta Workforce admin role assignments, and Intune RBAC role assignments to the governance program.

Business problem solved: Automates the evidence-gathering and report-generation phases of periodic access certifications, reducing review cycle time from days to minutes and ensuring consistent coverage across all in-scope systems.

Integrations: Okta Workforce · Okta CIAM · Microsoft Graph · Azure (REST) · Azure Log Analytics · PagerDuty · Blink (internal) · GitHub · Bill.com (HTTP) · WordPress (HTTP) · DropBox Sign (HTTP) · Grafana (HTTP) · SendGrid (HTTP) · Slack · Jira · Blink Email · AuditBoard (Optro) · Stripe (HTTP) · Microsoft Intune (via Graph)

Playbook Type Executions Taxonomy
Security Operations - Semi-Annual Access Review 1.0 Scheduled 0 RBAC review & access mgmt
Security Operations - Semi-Annual Access Review 1.1 On-demand 0 RBAC review & access mgmt
SecurityOps - Inactive User Assessment On-demand 0 RBAC review & access mgmt
SecurityOps - SQL Admin Review On-demand 0 RBAC review & access mgmt
Azure PIM Group Access Review On-demand (top-level, orchestrates SQL sub-review) 1 RBAC review & access mgmt
Azure SQL Access Review On-demand (subflow) 2 RBAC review & access mgmt
Directory Administrators Access Review On-demand 0 RBAC review & access mgmt
Azure Subscription Role Assignment Access Review On-demand 0 RBAC review & access mgmt
SecurityOps - Retrieve Okta Users On-demand 0 Access review & group mgmt
SecurityOps - Remove Okta Groups On-demand 0 Access review & group mgmt
WordPress Access Review On-demand 0 Access review & group mgmt
Bill.com Access Review On-demand 0 Access review & group mgmt
DropBox Sign Access Review On-demand 0 Access review & group mgmt
Grafana Access Review On-demand 0 Access review & group mgmt
SendGrid Access Review On-demand 0 Access review & group mgmt
Slack Access Review On-demand 0 Access review & group mgmt
Jira Access Review On-demand 0 Access review & group mgmt
BlinkOps Access Review On-demand 0 Access review & group mgmt
PagerDuty Access Review On-demand 0 Access review & group mgmt
Optro Access Review On-demand 0 Access review & group mgmt
GitHub Access Review On-demand 0 Access review & group mgmt
Stripe Access Review On-demand 0 Access review & group mgmt
Azure AD Enterprise Apps Access Review On-demand 0 RBAC review & access mgmt
Okta CIAM Admin Access Review On-demand 1 RBAC review & access mgmt
Okta Workforce Admin Access Review On-demand 0 RBAC review & access mgmt
Intune Access Review On-demand 0 RBAC review & access mgmt

Use Case 8 — Application Provisioning & Directory Sync

Category: IAM

Subcategories: Identity sync & directory mgmt · Identity lifecycle automation

Description: Provisioning automations for SaaS applications and directory synchronization tasks. The SCIM Provisioning 2.0 workflow processes Okta webhook events to manage the full create/update/deactivate lifecycle. Application-specific provisioners handle Bill.com, ProofPoint, WordPress, SendGrid, and BlinkOps accounts. The Catalog Refresh populates Microsoft Teams, Channels, and SharePoint site catalogs. A utility workflow syncs Okta group memberships to Azure/Entra.

Business problem solved: Standardizes application joiner/mover/leaver processes across SaaS tools, ensuring consistent provisioning logic, validation, and error handling without per-tool manual work.

Integrations: Okta Workforce · Microsoft Graph · Bill.com (HTTP) · ProofPoint ITM · WordPress (HTTP) · SendGrid (HTTP) · Blink

Playbook Type Executions Taxonomy
SecurityOps - SCIM Provisioning 2.0 Event (Okta webhook) 0 Identity lifecycle automation
Adding Users/Groups from Okta to Azure/Entra On-demand 0 Identity sync & directory mgmt
Catalog Refresh - Onboarding On-demand 0 Employee onboarding
ProofPoint Provisioning On-demand 0 Identity lifecycle automation
BlinkOps Provisioning On-demand 0 Identity lifecycle automation
Bill.com Provisioning On-demand 0 Identity lifecycle automation
WordPress Provisioning On-demand 0 Identity lifecycle automation
SendGrid Provisioning On-demand 0 Identity lifecycle automation

Use Case 9 — Endpoint & Conditional Access Configuration Review

Category: Cloud Security

Subcategories: Config audit & remediation · Cloud access & SaaS policy mgmt · Endpoint hygiene & MDM ops

Description: Two distinct review programs. The Endpoint Configuration Review (1.0, 1.1, 1.2) gathers Defender for Endpoint recommendations, Intune managed devices, device configurations, compliance policies, settings catalog, group policies, device intents, and Device Configuration Policy templates, then feeds all data to a "Cody MDE Agent" for an AI-authored security assessment. The Conditional Access Policy Review suite (1.0 through 1.16, plus the agent version) performs a comprehensive set of Log Analytics and Graph queries covering CA policy inventory, named locations, MFA bypass analysis, legacy authentication, non-compliant device sign-ins, service principals without CA applied, report-only CA blocks, blocked sign-ins by policy, risky-but-unblocked sign-ins, non-interactive sign-ins, users with no CA policy applied, and policy hit counts. Modules 1.3 through 1.16 each executed once in the most recent 12-month window, marking the pipeline's first full end-to-end pass.

Business problem solved: Replaces manual endpoint and identity posture reviews — tasks that typically require a qualified engineer spending multiple hours in portals — with automated data collection pipelines that deliver ready-to-review assessment packages.

Integrations: Microsoft Defender for Endpoints · Microsoft Graph · Azure Log Analytics · Microsoft Intune (via Graph)

Playbook Type Executions Taxonomy
SecurityOps - Endpoint Configuration Review - 1.0 Scheduled (top-level orchestrator) 0 Config audit & remediation, Endpoint hygiene & MDM ops
SecurityOps - Endpoint Configuration Review - 1.1 On-demand (subflow) 0 Config audit & remediation
SecurityOps - Conditional Access Policy Review 1.0 On-demand 0 Cloud access & SaaS policy mgmt, Config audit & remediation
SecurityOps - Conditional Access Policy Review On-demand (agent) 0 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.1 On-demand (subflow) 0 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.2 On-demand (subflow) 0 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review Scheduled (agent-based, Cody MDE Agent) 0 Endpoint hygiene & MDM ops
SecurityOps - Conditional Access Policy Review 1.3 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review - 1.1 Scheduled (subflow) 0 Config audit & remediation
SecurityOps - Endpoint Configuration Review - 1.2 Scheduled (subflow) 0 Config audit & remediation
SecurityOps - Conditional Access Policy Review 1.4 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.5 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.6 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.7 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.8 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.9 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.10 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.11 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.12 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.13 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.14 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.15 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.16 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review - 1.2 copy Scheduled (subflow, duplicate of 1.2) 0 Config audit & remediation, Endpoint hygiene & MDM ops

Use Case 10 — Microsoft Sentinel SIEM Assessment Suite

Category: SOC

Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation

Description: A 16-module Sentinel assessment framework that systematically evaluates every layer of the Sentinel deployment — analytics rules health, watchlist governance, content hub packages, data connector health, DCR configuration, workbook usage, Azure ML notebook inventory, automation/Logic App health, threat intelligence hygiene, hunting query promotion, UEBA/Fusion ML coverage, SOC Optimization recommendations, RBAC and PIM governance, and data retention/cost governance. The "Cody Sentinel Assessment Agent" orchestrates findings from all sub-modules into a consolidated assessment report.

Business problem solved: Enables rigorous periodic health checks of the Sentinel environment without requiring consultant-grade manual review. Each module produces structured data feeds that the AI agent synthesizes into actionable security engineering recommendations.

Integrations: Microsoft Sentinel (Azure Management REST API) · Azure Log Analytics · Microsoft Graph · Azure Monitor DCR API

Playbook Type Executions Taxonomy
SecurityOps - Sentinel Assessment On-demand (agent orchestrator) 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.0 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.1 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.2 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.3 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.4 On-demand 0 Threat intel ingest & curation
SecurityOps - Sentinel Assessment - 1.5 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.6 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.7 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.8 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.9 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.10 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.11 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.12 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment 1.13 On-demand 0 RBAC review & access mgmt
SecurityOps - Sentinel Watchlist Updates Scheduled 0 SIEM & log pipeline monitoring
SecurityOps - Log Migration On-demand 0 SIEM & log pipeline monitoring
Note: Assessment 1.14 was read but did not appear to have a distinct workflow_id row in the parsed data; it may exist as a sub-module of the assessment suite and is covered by the agent orchestrator.

Use Case 11 — Security Reporting & Email Security Monitoring

Category: GRC

Subcategories: Security metrics & reporting

Description: Scheduled reporting workflows that surface security and compliance telemetry on a recurring basis. The SendGrid Bounce List query runs daily, detecting unauthorized or anomalous outbound email relay activity. The ZScaler Usage Comparison runs weekly to identify users present in Okta but absent from ZScaler — a coverage gap indicator. The Documentation Gathering Agent automates evidence collection for compliance and audit documentation.

Business problem solved: Delivers repeatable security reporting with zero analyst scheduling overhead, ensuring that email relay hygiene and network security coverage gaps are surfaced on a fixed cadence.

Integrations: SendGrid (HTTP) · ZScaler ZIA · Azure Log Analytics · Okta CIAM

Playbook Type Executions Taxonomy
SecurityOps - Query SendGrid Bounce List Scheduled (daily, 6:30 AM ET) 40 Security metrics & reporting
SecurityOps - ZScaler Usage Comparison Scheduled (weekly, Monday 1 PM ET) 6 Security metrics & reporting
SecurityOps - Documentation Gathering Agent On-demand 0 Compliance questionnaire

Use Case 12 — Third-Party Risk Management (TPRM)

Category: GRC

Subcategories: Vendor risk & TPRM

Description: An event-driven vendor risk workflow triggered via a custom webhook. On each trigger, the automation retrieves the current vendor list from the Optro (AuditBoard) TPRM platform and posts related risk data onward via HTTP, keeping downstream vendor risk records synchronized in near real time.

Business problem solved: Eliminates manual export/import cycles between the TPRM system of record and downstream consumers, ensuring vendor risk data stays current without analyst intervention. With 128 executions in the last 12 months, this is the customer's highest-volume GRC automation outside of core security metrics reporting.

Integrations: AuditBoard (Optro) · HTTP (custom)

Playbook Type Executions Taxonomy
TPRM - Optro Event trigger (custom webhook) 128 Vendor risk & TPRM

Key Observations

Strengths

Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.

Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.

CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.

Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.

Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.

High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.

Gaps & Opportunities

IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."

Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.

Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.

Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.

Integration Ecosystem

The tenant integrates 20+ distinct security and business systems through Blink:

Domain Integrations
SIEM / Detection Microsoft Sentinel, Azure Log Analytics
Endpoint & EDR Microsoft Defender for Endpoints
Identity Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph
Cloud Security Orca Security, Azure Policy (Management REST API), Microsoft Purview
Network Security ZScaler ZIA
Email Security ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP)
Threat Intel VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI
ITSM / Ticketing Jira, PagerDuty
DevOps GitHub
SaaS / Apps Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe
GRC / Vendor Risk AuditBoard (Optro)
Azure Infrastructure Azure Automation Account, Azure Monitor DCR, Azure ML

1. Business KPIs — Last 12 Months

Metric Table

Metric Count Playbook
Security incidents auto-enriched and investigated by AI 303 SecOps - Microsoft Sentinel Incident Enrichment
Third-party vendor risk sync cycles processed (Optro/AuditBoard TPRM) 128 TPRM - Optro
CVE SLA monitoring cycles completed (v1.0 + v2.0, combined) 80 SecurityOps - Orca CVE Query - 1.0 / 2.0
Daily CIAM agent activation anomaly checks completed 40 SecurityOps - Okta Agent Activation Query
Email security hygiene audits of SendGrid bounce list 40 SecurityOps - Query SendGrid Bounce List
Conditional Access Policy Review modules executed (full pipeline pass, 1.3–1.16 combined) 14 SecurityOps - Conditional Access Policy Review 1.3–1.16
Azure cloud policy remediation cycles executed 6 SecurityOps - Azure Policy Remediation Tasks
ZScaler user compliance comparisons generated 6 SecurityOps - ZScaler Usage Comparison
Trending CVE landscape analyses delivered 6 SecurityOps - Orca Trending CVE Query
CIAM security metrics collected and stored 6 SecurityOps - Okta CIAM Metrics
Employee offboarding security investigations completed 3 SecurityOps - User Offboarding Analysis
Okta CIAM administrative access reviews completed 1 Okta CIAM Admin Access Review
In the last 12 months, Blink automated: - 303 Sentinel security incidents enriched and fully investigated by an AI SOC analyst — no human involvement required at initial triage - 128 third-party vendor risk sync cycles completed via the Optro (AuditBoard) TPRM integration, keeping vendor risk records current without manual export/import - 80 CVE SLA compliance cycles completed — tracking overdue, near-SLA, and within-SLA vulnerabilities across cloud infrastructure, with Jira tickets and email reports delivered automatically - 40 daily CIAM agent activation anomaly checks, ensuring customer-facing identity infrastructure is continuously monitored - 40 daily email security hygiene audits, surfacing unauthorized or suspicious email activity via the SendGrid bounce list - 14 Conditional Access Policy Review pipeline modules executed in a single full pass (1.3–1.16) — first end-to-end activation of this previously idle review program, covering CA policy inventory, named locations, MFA bypass, legacy authentication, device compliance gaps, risky sign-ins, and policy hit counts - 6 automated Azure cloud policy remediation cycles executed across all subscriptions - 3 full employee offboarding security investigations completed, each autonomously cross-referencing 8+ data sources (sign-in logs, audit logs, ProofPoint, Okta, GitHub, Office Activity, Azure Activity, email events) and generating AI-driven risk summaries - 1 Okta CIAM administrative access review completed — first execution of a newly deployed admin entitlements review for the customer-facing identity platform

2. Use Case Summary

# Use Case Category Playbooks Active (exec > 0)
1 Agentic SOC — Sentinel Incident Investigation SOC 19 17
2 CVE Lifecycle Management & Reporting Vulnerability Mgmt 6 4
3 Identity Incident Response Runbook Library SOC 12 0
4 Agentic Employee Offboarding Investigation IAM 10 10
5 Cloud Security Posture & Azure Policy Compliance Cloud Security 2 1
6 Okta CIAM Operations & Identity Monitoring IAM 4 3
7 Access Reviews & Privileged Access Governance GRC 26 3
8 Application Provisioning & Directory Sync IAM 8 0
9 Endpoint & Conditional Access Configuration Review Cloud Security 24 14
10 Microsoft Sentinel SIEM Assessment Suite SOC 17 0
11 Security Reporting & Email Security Monitoring GRC 3 2
12 Third-Party Risk Management (TPRM) GRC 1 1
Total 132 55

3. Use Cases

Use Case 1 — Agentic SOC: Sentinel Incident Investigation

Category: SOC

Subcategories: Agentic SOC · Alert enrichment / IOC lookup · Case mgmt & SOAR

Description: An AI-powered SOC analyst ("Cody") responds in real time to every Microsoft Sentinel alert via webhook. The agent autonomously gathers evidence from Log Analytics, enriches entity context using ProofPoint, Orca, Okta, VirusTotal, Purview, and Microsoft Graph, then writes findings directly back to the Sentinel incident. The 17 active agent tools in this use case were collectively invoked thousands of times in the past year, representing the deepest automation investment in the tenant.

Business problem solved: Eliminates analyst toil on Level 1 triage and enrichment for every Sentinel alert. Each incident arrives pre-investigated, allowing analysts to review conclusions rather than conduct evidence gathering from scratch.

Integrations: Microsoft Sentinel · Azure Log Analytics · Microsoft Graph / Entra ID · ProofPoint ITM · ProofPoint TAP · Orca Security · Okta Workforce · VirusTotal · MXToolBox · Microsoft Purview · Microsoft XDR Defender · NIST NVD · Traceable · PagerDuty

Playbook Type Executions Taxonomy
SecOps - Microsoft Sentinel Incident Enrichment Event trigger (top-level) 303 Agentic SOC, Case mgmt & SOAR
Cody - Get Sentinel Incident Agent tool 304 Agentic SOC
Cody - Search Log Analytics Workspace Agent tool 1,721 Alert enrichment / IOC lookup
Cody - Comment on Sentinel Incident Agent tool 218 Case mgmt & SOAR
Cody - Search VirusTotal Agent tool 255 Alert enrichment / IOC lookup
Cody - Search ProofPoint Device Activity Agent tool 114 Alert enrichment / IOC lookup
Cody - Search ProofPoint CASB Activity Agent tool 102 Alert enrichment / IOC lookup
Cody - Get Information on Multiple Entra ID Users Agent tool 178 Alert enrichment / IOC lookup
Cody - Search Purview Alerts Agent tool 97 Alert enrichment / IOC lookup
Cody - Get Log Analytics Table Schema Agent tool 305 Alert enrichment / IOC lookup
Cody - List Table Records Agent tool 200 Alert enrichment / IOC lookup
Cody - Search Okta Workforce Agent tool 60 Alert enrichment / IOC lookup
Cody - Search Microsoft Graph Agent tool 38 Alert enrichment / IOC lookup
Cody - Search Orca Alerts Agent tool 22 Alert enrichment / IOC lookup
Cody - Search MXToolBox Agent tool 18 Alert enrichment / IOC lookup
Cody - Threat Hunting Agent tool 6 Threat intel ingest & curation
Cody - Search NIST for CVE Agent tool 1 Alert enrichment / IOC lookup
Cody - Search ProofPoint Blocked URLs Agent tool 0 Alert enrichment / IOC lookup
Cody - Get Traceable Alerts Agent tool 0 Alert enrichment / IOC lookup

Use Case 2 — CVE Lifecycle Management & Reporting

Category: Vulnerability Mgmt

Subcategories: CVE lookup & remediation · Vuln scanning ingest & report · Vuln lifecycle prioritize & ticket

Description: Scheduled automations query Orca Security daily and weekly to identify cloud CVEs that are within SLA, approaching SLA, or overdue. Version 1.0 automatically creates Jira tickets for each affected team; version 2.0 converts findings to HTML and delivers email reports. A trending CVE workflow tracks longitudinal CVE posture by comparing weekly snapshots stored in Blink Tables.

Business problem solved: Eliminates manual CVE export-and-distribute workflows. Every cloud engineering team receives structured, SLA-bucketed CVE assignments without analyst intervention.

Integrations: Orca Security · Jira · Blink Tables · Blink Email · NIST NVD

Playbook Type Executions Taxonomy
SecurityOps - Orca CVE Query - 1.0 Scheduled (daily, 6 AM ET) 40 CVE lookup & remediation, Vuln lifecycle prioritize & ticket
SecurityOps - Orca CVE Query - 2.0 Scheduled (daily, 7 AM ET) 40 CVE lookup & remediation, Vuln scanning ingest & report
SecurityOps - Orca Trending CVE Query Scheduled (weekly, Monday) 6 Vuln scanning ingest & report
Cody - Search Orca CVEs by Resource Agent tool 7 CVE lookup & remediation
SecurityOps - Orca Trending CVE Query 1.1 Scheduled (weekly, Friday) 0 Vuln scanning ingest & report
Cody - Search Orca CVEs by Name & Resource Agent tool 0 CVE lookup & remediation

Use Case 3 — Identity Incident Response Runbook Library

Category: SOC

Subcategories: Identity threat response · EDR containment & response

Description: A library of 12 on-demand IR playbooks covering the full spectrum of containment actions: Entra ID account disablement, Okta session revocation and suspension, MFA factor resets, password resets, Windows machine isolation, AV scan initiation, file hash blocking in Defender, IP blocklisting via Named Locations, URL/domain blocking via ZScaler, and email recipient lookups. All playbooks are designed to be triggered by the Cody AI agent or manually by analysts.

Business problem solved: Provides pre-built, pre-approved IR actions that can be executed in seconds rather than requiring manual portal access — reducing mean time to contain (MTTC) and enabling consistent, auditable response procedures.

Integrations: Microsoft Entra ID (Active Directory) · Microsoft Graph · Okta Workforce · Microsoft Defender for Endpoints · ZScaler ZIA · Azure Log Analytics

Playbook Type Executions Taxonomy
IR - Disable Entra ID User On-demand 0 Identity threat response
IR - Revoke User Session Tokens On-demand 0 Identity threat response
IR - Revoke User Sessions in Okta Workforce On-demand 0 Identity threat response
IR - Suspend Okta Workforce Account On-demand 0 Identity threat response
IR - Reset User Factors in Okta Workforce On-demand 0 Identity threat response
IR - Reset Password for Okta Workforce On-demand 0 Password & credential lifecycle
IR - Isolate a Windows Machine On-demand 0 EDR containment & response
IR - Start AV Scan On-demand 0 EDR containment & response
IR - Block File Hash in Defender On-demand 0 EDR containment & response
IR - Add IP to NamedLocation Blocklist On-demand 0 Identity threat response
IR - Add Domain to ZScaler URL Category On-demand 0 Identity threat response
IR - Get Email Recipients Containing a URL On-demand 0 Phishing detection & response

Use Case 4 — Agentic Employee Offboarding Investigation

Category: IAM

Subcategories: Employee offboarding · Identity lifecycle automation

Description: A comprehensive agentic offboarding workflow that gathers pre-termination activity across 8 data sources — sign-in logs, Azure Activity, Okta V2, audit logs, email events, Office Activity, ProofPoint CASB, ProofPoint device and email events, and GitHub — stores findings in structured Blink Tables, and feeds all evidence to a "Cody Offboarding Agent" that produces an AI-generated risk narrative. Results are written back to the Jira incident as a completed offboarding form. Each offboarding analysis involves a dedicated set of modular read playbooks called by the AI agent.

Business problem solved: Transforms offboarding security investigations from multi-day manual data-pulls across a dozen systems into a single automated workflow that delivers a complete AI-authored risk summary to the HR/security team, typically within minutes.

Integrations: Okta Workforce · Microsoft Entra ID · Azure Log Analytics · ProofPoint ITM · GitHub · Jira · Microsoft Graph · Blink Tables

Playbook Type Executions Taxonomy
SecurityOps - User Offboarding Analysis On-demand (top-level) 3 Employee offboarding, Identity lifecycle automation
SecurityOps - User Offboarding Jira Comment On-demand 2 Employee offboarding
SecurityOps - Read SignIn Logs from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read OktaV2_CL from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read AzureActivity from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read EmailEvents from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read Office Activity from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint Device Events from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint ITM from User Offboarding Table Agent tool 2 Employee offboarding
SecurityOps - Read ProofPoint Email Events from User Offboarding Table Agent tool 2 Employee offboarding

Use Case 5 — Cloud Security Posture & Azure Policy Compliance

Category: Cloud Security

Subcategories: CSPM ingest & triage · Config audit & remediation

Description: Two cloud security posture workflows. The Azure Policy Remediation automation runs weekly across all Azure subscriptions, enumerating non-compliant policy assignments and submitting remediation tasks automatically. The Orca CSPM Alert Review feeds Orca cloud security alerts into a specialist "Cody Orca Agent" for AI-driven triage and prioritization.

Business problem solved: Eliminates the manual work of periodically checking and remediating Azure Policy non-compliance across multi-subscription environments, and speeds CSPM alert review by routing alerts directly to an AI security engineer.

Integrations: Azure (HTTP/REST — Azure Management API) · Orca Security

Playbook Type Executions Taxonomy
SecurityOps - Azure Policy Remediation Tasks Scheduled (weekly, Sunday 1 AM ET) 6 Config audit & remediation
SecurityOps - Orca CSPM Alert Review Scheduled 0 CSPM ingest & triage

Use Case 6 — Okta CIAM Operations & Identity Monitoring

Category: IAM

Subcategories: Identity sync & directory mgmt · Identity lifecycle automation

Description: Automations managing the customer-facing Okta CIAM platform. The Agent Activation Query runs daily to check for new agent onboarding events and processes group membership changes. The CIAM Metrics workflow is event-driven, ingesting webhook data on authentication patterns (email auth, strong auth, SSO, partner integrations) and persisting them to Blink Tables for trending. The ZeroFox User Check correlates external brand-threat intelligence against CIAM user accounts to detect account takeover risk.

Business problem solved: Provides continuous monitoring and automated data collection for a production customer-identity platform, surfacing both operational anomalies and fraud signals without requiring manual CIAM log review.

Integrations: Okta CIAM (Production) · ZeroFox · Microsoft Sentinel · Blink Tables

Playbook Type Executions Taxonomy
SecurityOps - Okta Agent Activation Query Scheduled (daily, 9 AM ET) 40 Identity sync & directory mgmt
SecurityOps - Okta CIAM Metrics Event (webhook) 6 Security metrics & reporting
Cody - ZeroFox CIAM User Check On-demand (agent tool) 5 Identity threat response
SecurityOps - Add Agent to Agency Group Okta CIAM Event (webhook) 0 Identity sync & directory mgmt

Use Case 7 — Access Reviews & Privileged Access Governance

Category: GRC

Subcategories: RBAC review & access mgmt · Access review & group mgmt

Description: A structured program of access reviews covering both broad organizational entitlements (semi-annual review across 20+ apps, Azure role assignments, SQL database permissions, PIM group memberships, GitHub secrets) and targeted application-level reviews (WordPress, Bill.com, DropBox Sign, Grafana, SendGrid, Slack, Jira, BlinkOps, PagerDuty). An inactive user assessment identifies stale Entra ID accounts through sign-in telemetry and Graph API queries. A dedicated Azure PIM/Entra role eligibility review normalizes PIM group, Entra role, and nested group membership data (including a call to a standalone Azure SQL access review sub-automation) into a consolidated governance report, alongside standalone directory-administrator and subscription-level RBAC reviews. A newly expanded set of application- and platform-specific reviews adds Optro (AuditBoard) TPRM user access, GitHub organization membership, Stripe, Azure AD Enterprise Applications/Service Principals, Okta CIAM and Okta Workforce admin role assignments, and Intune RBAC role assignments to the governance program.

Business problem solved: Automates the evidence-gathering and report-generation phases of periodic access certifications, reducing review cycle time from days to minutes and ensuring consistent coverage across all in-scope systems.

Integrations: Okta Workforce · Okta CIAM · Microsoft Graph · Azure (REST) · Azure Log Analytics · PagerDuty · Blink (internal) · GitHub · Bill.com (HTTP) · WordPress (HTTP) · DropBox Sign (HTTP) · Grafana (HTTP) · SendGrid (HTTP) · Slack · Jira · Blink Email · AuditBoard (Optro) · Stripe (HTTP) · Microsoft Intune (via Graph)

Playbook Type Executions Taxonomy
Security Operations - Semi-Annual Access Review 1.0 Scheduled 0 RBAC review & access mgmt
Security Operations - Semi-Annual Access Review 1.1 On-demand 0 RBAC review & access mgmt
SecurityOps - Inactive User Assessment On-demand 0 RBAC review & access mgmt
SecurityOps - SQL Admin Review On-demand 0 RBAC review & access mgmt
Azure PIM Group Access Review On-demand (top-level, orchestrates SQL sub-review) 1 RBAC review & access mgmt
Azure SQL Access Review On-demand (subflow) 2 RBAC review & access mgmt
Directory Administrators Access Review On-demand 0 RBAC review & access mgmt
Azure Subscription Role Assignment Access Review On-demand 0 RBAC review & access mgmt
SecurityOps - Retrieve Okta Users On-demand 0 Access review & group mgmt
SecurityOps - Remove Okta Groups On-demand 0 Access review & group mgmt
WordPress Access Review On-demand 0 Access review & group mgmt
Bill.com Access Review On-demand 0 Access review & group mgmt
DropBox Sign Access Review On-demand 0 Access review & group mgmt
Grafana Access Review On-demand 0 Access review & group mgmt
SendGrid Access Review On-demand 0 Access review & group mgmt
Slack Access Review On-demand 0 Access review & group mgmt
Jira Access Review On-demand 0 Access review & group mgmt
BlinkOps Access Review On-demand 0 Access review & group mgmt
PagerDuty Access Review On-demand 0 Access review & group mgmt
Optro Access Review On-demand 0 Access review & group mgmt
GitHub Access Review On-demand 0 Access review & group mgmt
Stripe Access Review On-demand 0 Access review & group mgmt
Azure AD Enterprise Apps Access Review On-demand 0 RBAC review & access mgmt
Okta CIAM Admin Access Review On-demand 1 RBAC review & access mgmt
Okta Workforce Admin Access Review On-demand 0 RBAC review & access mgmt
Intune Access Review On-demand 0 RBAC review & access mgmt

Use Case 8 — Application Provisioning & Directory Sync

Category: IAM

Subcategories: Identity sync & directory mgmt · Identity lifecycle automation

Description: Provisioning automations for SaaS applications and directory synchronization tasks. The SCIM Provisioning 2.0 workflow processes Okta webhook events to manage the full create/update/deactivate lifecycle. Application-specific provisioners handle Bill.com, ProofPoint, WordPress, SendGrid, and BlinkOps accounts. The Catalog Refresh populates Microsoft Teams, Channels, and SharePoint site catalogs. A utility workflow syncs Okta group memberships to Azure/Entra.

Business problem solved: Standardizes application joiner/mover/leaver processes across SaaS tools, ensuring consistent provisioning logic, validation, and error handling without per-tool manual work.

Integrations: Okta Workforce · Microsoft Graph · Bill.com (HTTP) · ProofPoint ITM · WordPress (HTTP) · SendGrid (HTTP) · Blink

Playbook Type Executions Taxonomy
SecurityOps - SCIM Provisioning 2.0 Event (Okta webhook) 0 Identity lifecycle automation
Adding Users/Groups from Okta to Azure/Entra On-demand 0 Identity sync & directory mgmt
Catalog Refresh - Onboarding On-demand 0 Employee onboarding
ProofPoint Provisioning On-demand 0 Identity lifecycle automation
BlinkOps Provisioning On-demand 0 Identity lifecycle automation
Bill.com Provisioning On-demand 0 Identity lifecycle automation
WordPress Provisioning On-demand 0 Identity lifecycle automation
SendGrid Provisioning On-demand 0 Identity lifecycle automation

Use Case 9 — Endpoint & Conditional Access Configuration Review

Category: Cloud Security

Subcategories: Config audit & remediation · Cloud access & SaaS policy mgmt · Endpoint hygiene & MDM ops

Description: Two distinct review programs. The Endpoint Configuration Review (1.0, 1.1, 1.2) gathers Defender for Endpoint recommendations, Intune managed devices, device configurations, compliance policies, settings catalog, group policies, device intents, and Device Configuration Policy templates, then feeds all data to a "Cody MDE Agent" for an AI-authored security assessment. The Conditional Access Policy Review suite (1.0 through 1.16, plus the agent version) performs a comprehensive set of Log Analytics and Graph queries covering CA policy inventory, named locations, MFA bypass analysis, legacy authentication, non-compliant device sign-ins, service principals without CA applied, report-only CA blocks, blocked sign-ins by policy, risky-but-unblocked sign-ins, non-interactive sign-ins, users with no CA policy applied, and policy hit counts. Modules 1.3 through 1.16 each executed once in the most recent 12-month window, marking the pipeline's first full end-to-end pass.

Business problem solved: Replaces manual endpoint and identity posture reviews — tasks that typically require a qualified engineer spending multiple hours in portals — with automated data collection pipelines that deliver ready-to-review assessment packages.

Integrations: Microsoft Defender for Endpoints · Microsoft Graph · Azure Log Analytics · Microsoft Intune (via Graph)

Playbook Type Executions Taxonomy
SecurityOps - Endpoint Configuration Review - 1.0 Scheduled (top-level orchestrator) 0 Config audit & remediation, Endpoint hygiene & MDM ops
SecurityOps - Endpoint Configuration Review - 1.1 On-demand (subflow) 0 Config audit & remediation
SecurityOps - Conditional Access Policy Review 1.0 On-demand 0 Cloud access & SaaS policy mgmt, Config audit & remediation
SecurityOps - Conditional Access Policy Review On-demand (agent) 0 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.1 On-demand (subflow) 0 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.2 On-demand (subflow) 0 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review Scheduled (agent-based, Cody MDE Agent) 0 Endpoint hygiene & MDM ops
SecurityOps - Conditional Access Policy Review 1.3 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review - 1.1 Scheduled (subflow) 0 Config audit & remediation
SecurityOps - Endpoint Configuration Review - 1.2 Scheduled (subflow) 0 Config audit & remediation
SecurityOps - Conditional Access Policy Review 1.4 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.5 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.6 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.7 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.8 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.9 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.10 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.11 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.12 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.13 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.14 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.15 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Conditional Access Policy Review 1.16 On-demand (subflow) 1 Cloud access & SaaS policy mgmt
SecurityOps - Endpoint Configuration Review - 1.2 copy Scheduled (subflow, duplicate of 1.2) 0 Config audit & remediation, Endpoint hygiene & MDM ops

Use Case 10 — Microsoft Sentinel SIEM Assessment Suite

Category: SOC

Subcategories: SIEM & log pipeline monitoring · Threat intel ingest & curation

Description: A 16-module Sentinel assessment framework that systematically evaluates every layer of the Sentinel deployment — analytics rules health, watchlist governance, content hub packages, data connector health, DCR configuration, workbook usage, Azure ML notebook inventory, automation/Logic App health, threat intelligence hygiene, hunting query promotion, UEBA/Fusion ML coverage, SOC Optimization recommendations, RBAC and PIM governance, and data retention/cost governance. The "Cody Sentinel Assessment Agent" orchestrates findings from all sub-modules into a consolidated assessment report.

Business problem solved: Enables rigorous periodic health checks of the Sentinel environment without requiring consultant-grade manual review. Each module produces structured data feeds that the AI agent synthesizes into actionable security engineering recommendations.

Integrations: Microsoft Sentinel (Azure Management REST API) · Azure Log Analytics · Microsoft Graph · Azure Monitor DCR API

Playbook Type Executions Taxonomy
SecurityOps - Sentinel Assessment On-demand (agent orchestrator) 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.0 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.1 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.2 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.3 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.4 On-demand 0 Threat intel ingest & curation
SecurityOps - Sentinel Assessment - 1.5 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.6 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.7 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.8 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.9 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.10 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.11 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment - 1.12 On-demand 0 SIEM & log pipeline monitoring
SecurityOps - Sentinel Assessment 1.13 On-demand 0 RBAC review & access mgmt
SecurityOps - Sentinel Watchlist Updates Scheduled 0 SIEM & log pipeline monitoring
SecurityOps - Log Migration On-demand 0 SIEM & log pipeline monitoring
Note: Assessment 1.14 was read but did not appear to have a distinct workflow_id row in the parsed data; it may exist as a sub-module of the assessment suite and is covered by the agent orchestrator.

Use Case 11 — Security Reporting & Email Security Monitoring

Category: GRC

Subcategories: Security metrics & reporting

Description: Scheduled reporting workflows that surface security and compliance telemetry on a recurring basis. The SendGrid Bounce List query runs daily, detecting unauthorized or anomalous outbound email relay activity. The ZScaler Usage Comparison runs weekly to identify users present in Okta but absent from ZScaler — a coverage gap indicator. The Documentation Gathering Agent automates evidence collection for compliance and audit documentation.

Business problem solved: Delivers repeatable security reporting with zero analyst scheduling overhead, ensuring that email relay hygiene and network security coverage gaps are surfaced on a fixed cadence.

Integrations: SendGrid (HTTP) · ZScaler ZIA · Azure Log Analytics · Okta CIAM

Playbook Type Executions Taxonomy
SecurityOps - Query SendGrid Bounce List Scheduled (daily, 6:30 AM ET) 40 Security metrics & reporting
SecurityOps - ZScaler Usage Comparison Scheduled (weekly, Monday 1 PM ET) 6 Security metrics & reporting
SecurityOps - Documentation Gathering Agent On-demand 0 Compliance questionnaire

Use Case 12 — Third-Party Risk Management (TPRM)

Category: GRC

Subcategories: Vendor risk & TPRM

Description: An event-driven vendor risk workflow triggered via a custom webhook. On each trigger, the automation retrieves the current vendor list from the Optro (AuditBoard) TPRM platform and posts related risk data onward via HTTP, keeping downstream vendor risk records synchronized in near real time.

Business problem solved: Eliminates manual export/import cycles between the TPRM system of record and downstream consumers, ensuring vendor risk data stays current without analyst intervention. With 128 executions in the last 12 months, this is the customer's highest-volume GRC automation outside of core security metrics reporting.

Integrations: AuditBoard (Optro) · HTTP (custom)

Playbook Type Executions Taxonomy
TPRM - Optro Event trigger (custom webhook) 128 Vendor risk & TPRM

4. Key Observations

Strengths

Production-grade agentic SOC. The Cody Sentinel analyst (Use Case 1) is the most active and mature automation in the tenant, having enriched 303 incidents and autonomously executed over 4,000 individual investigation steps across VirusTotal, ProofPoint, Okta, Azure Log Analytics, Orca, Purview, and Microsoft Graph. The breadth of agent tool coverage — 19 dedicated investigation abilities — is among the deepest agentic SOC deployments in the Blink customer base.

Multi-source offboarding intelligence. The offboarding investigation (Use Case 4) cross-references 8 distinct data sources and uses an AI agent to synthesize findings. This is a high-value, difficult-to-replicate workflow that would typically require a full-day manual investigation per departing employee.

CVE SLA discipline. Running two complementary CVE workflows daily (one for Jira ticket creation, one for email reporting) demonstrates a mature vulnerability management program with clear SLA accountability across development teams.

Extensive IR runbook coverage. The 12 IR playbooks (Use Case 3) span identity containment (Okta + Entra), endpoint response (Defender + ZScaler), and network blocking — a complete first-responder toolkit that is ready to integrate with the Cody agent for fully automated containment.

Sentinel assessment depth. The 16-module Sentinel assessment suite (Use Case 10) is highly sophisticated, covering areas most organizations never systematically review: UEBA baseline age, Fusion ML TP/FP rates, DCR standardization, notebook infrastructure, Logic App execution health, and retention/cost governance.

High-volume vendor risk automation. The newly instrumented TPRM - Optro workflow (Use Case 12) has already executed 128 times in the trailing 12 months, indicating an actively used, webhook-driven integration between the Optro/AuditBoard TPRM platform and downstream systems — the highest-volume GRC automation in the tenant outside of Sentinel incident enrichment.

Gaps & Opportunities

IR runbook activation. All 12 IR runbooks have zero executions. The Cody SOC agent is actively investigating incidents but is not yet invoking automated containment actions. Wiring the agent to the IR library would complete the automated SOC loop — moving from "investigate and recommend" to "investigate and contain."

Sentinel Assessment suite not yet active. The 16-module Sentinel assessment suite remains at zero executions. The Conditional Access Policy Review pipeline has now completed its first full pass (modules 1.3–1.16, one execution each), but the Endpoint Configuration Review programs remain unactivated. Scheduling the top-level orchestrators would fully unlock this build investment.

Access review program. The semi-annual access review (Use Case 7) and nearly all application access reviews have zero executions — now spanning 26 playbooks (SendGrid, Slack, Jira, BlinkOps, PagerDuty, Azure PIM/Entra role eligibility, Azure SQL, directory administrators, subscription RBAC, Optro/AuditBoard, GitHub, Stripe, Azure AD Enterprise Apps, Okta CIAM admin, Okta Workforce admin, and Intune, in addition to the original set), with only the Azure PIM, Azure SQL, and Okta CIAM Admin Access Review playbooks showing early adoption (1–2 executions each). Activating these with a recurring schedule would directly support compliance evidence collection for SOC 2 / ISO 27001 audit cycles.

Provisioning automation not activated. Six provisioning playbooks (Use Case 8) have zero executions. These cover several high-value SaaS tools (ProofPoint, Bill.com, WordPress) and represent an opportunity to eliminate manual JML request fulfilment.

Integration Ecosystem

The tenant integrates 20+ distinct security and business systems through Blink:

Domain Integrations
SIEM / Detection Microsoft Sentinel, Azure Log Analytics
Endpoint & EDR Microsoft Defender for Endpoints
Identity Okta Workforce, Okta CIAM (Production), Microsoft Entra ID, Microsoft Graph
Cloud Security Orca Security, Azure Policy (Management REST API), Microsoft Purview
Network Security ZScaler ZIA
Email Security ProofPoint TAP, ProofPoint ITM, SendGrid (HTTP)
Threat Intel VirusTotal, MXToolBox, ZeroFox, NIST NVD, Microsoft MDTI
ITSM / Ticketing Jira, PagerDuty
DevOps GitHub
SaaS / Apps Bill.com, WordPress, DropBox Sign, Grafana, Traceable, BlinkOps, Slack, Stripe
GRC / Vendor Risk AuditBoard (Optro)
Azure Infrastructure Azure Automation Account, Azure Monitor DCR, Azure ML
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Coterie github my_github_connection 2026-08-03