Blink Security Automation — Confidential

udr — Customer Success Report

Generated 2026-08-31 | udr-value-report.md
2026-08-31Report Date
227Total Playbooks
33Unique Workflows (12m)
7,101Actions Automated (12m)
$1,826Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

227
Total playbooks built
all non-deleted workflows
128
Active playbooks
currently enabled
33
Unique workflows executed (12m)
distinct workflows that ran
7,101
Actions automated (12m)
completed action steps
39.5h
Hours saved (12m)
@ 20s per action
$1,826
Money saved (12m)
@ $100K avg salary
4
New active workflows (last 30d)
recently created & enabled
2
Total cases managed
2 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
13
Active AI agents
of 18 total
98
AI agent tasks executed (12m)
24 in last 30d
In the last 12 months, Blink automated: - 5 phishing emails parsed and investigated automatically - 3 compromised user accounts immediately suspended in Active Directory - 2 malicious files and URLs deep-analyzed through sandboxing - 1 security ticket automatically routed to the right analyst - 2 malicious content alerts analyzed automatically by an AI agent - 10 daily CVE vulnerability checks run automatically - 41 HR/compliance data imports processed automatically - 10 employee & AI-tool access block lists rebuilt automatically

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic Identity Access Management0 executions
0.0%
15
15 active
Agentic SOC — Malware & Threat Investigation
  • 2Malicious content alerts analyzed by an AI agent
  • 1Malicious URLs analyzed in sandbox
  • 1Malicious files analyzed in sandbox
2.6%
17
17 active
Automated Alert Triage & Case Management (SOAR)2 executions
1.0%
44
44 active
Phishing Detection & Response0 executions
0.0%
7
6 active
Identity Threat Response & Containment
  • 3Compromised user accounts automatically suspended
0.0%
6
6 active
Contractor & User Onboarding0 executions
0.0%
4
4 active
IT Ticket Auto-Assignment
  • 1Security tickets auto-routed to the right analyst
40.7%
1
1 active
Daily CVE Monitoring
  • 10Daily CVE vulnerability checks run automatically
5.2%
1
1 active
HR & Application Access Eligibility Automation
  • 41HR/compliance data imports processed automatically
  • 10Employee & AI-tool access block lists rebuilt automatically
26.3%
3
3 active
Total147 executions100%
98
97 active

Use Case Growth Over Time

170 unique playbooks  |  9 operational use cases  |  194 total executions (12m)  |  2026-02 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Agentic Identity Access Management
UKG HR Microsoft Entra ID ServiceNow Microsoft Teams Agents Duo Okta Email
Agentic SOC — Malware & Threat Investigation
Joe Sandbox PagerDuty SentinelOne Elasticsearch Microsoft Outlook VirusTotal Agents Email Okta Have I Been Pwned Microsoft Entra ID Microsoft Teams
Contractor & User Onboarding
Agents Microsoft Entra ID Active Directory On-Prem
Identity Threat Response & Containment
Varonis Microsoft Entra ID UKG HR Agents CrowdStrike SentinelOne Microsoft Outlook Active Directory On-Prem Have I Been Pwned Email
Phishing Detection & Response
Microsoft Outlook Proofpoint Protection Server Proofpoint Threat Protection Email Joe Sandbox
Automated Alert Triage & Case Management (SOAR)
CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan Email GitHub Slack Joe Sandbox
IT Ticket Auto-Assignment
ServiceNow Email
Daily CVE Monitoring
Email Microsoft Outlook
HR & Application Access Eligibility Automation
Okta Microsoft Outlook Email

04Key Observations

✓  Strengths

Strengths

1. Agentic IAM is the flagship use case

The Access Request agent stack is the most mature investment — a full AI Concierge agent with 14 discrete capabilities spanning the entire access provisioning lifecycle from ServiceNow ticket to Entra ID group update. Its deployment across two parallel workspaces signals active organizational rollout and likely testing across business units or environments.

2. Exceptionally broad integration ecosystem

17+ integrations are wired in across the platform: Entra ID/AD, Okta, Duo, UKG, ServiceNow, Teams, SentinelOne, CrowdStrike, Elastic, Joe Sandbox, VirusTotal, AbuseIPDB, URLScan, Proofpoint (PPS and Threat Protection), Varonis, PagerDuty, GitHub, Slack, and Google Workspace. This is a mature, enterprise-grade integration footprint.

3. Production-ready SOAR platform built on Blink Case Management

The workspace 5d0edcf6 contains a fully architected SOAR platform with 44+ playbooks: multi-source observable enrichment, deduplication, type-specific response routing, recovery workflows, and observable relationship management. This represents significant engineering investment and a sophisticated automation design.

4. Identity threat response is live

Three Active Directory account suspensions executed in the period confirm production usage of the identity containment workflow, including cross-platform Proofpoint inbox removal (3 email remediation executions).

5. HR/compliance data pipeline already at high-volume production scale

The Data Import (41 executions) and Block List build (10 executions) workflows show this eligibility-reconciliation pipeline — spanning UKG, Cornerstone, and Diligent — is already running in active, frequent production use, the highest execution volume of any single-purpose automation in this report outside the SOAR platform's core ingestion path.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. Near-zero execution counts across most workflows

The majority of playbooks — including the flagship Agent Access Request and the full SOAR platform — show 0 executions in the last 12 months. This strongly suggests the platform is in late-stage deployment or recently migrated from a prior environment, with production traffic not yet flowing. Activating the SOAR Process Alert trigger (event-driven, polling every 1 minute) would immediately drive value through the full enrichment and response pipeline.

2. Agentic IAM not yet in production

The Access Request agent is fully built with a rich ability set, but 0 executions across both workspace deployments. Connecting the production ServiceNow queue to trigger Agent Access Request is the highest-leverage activation step available.

3. Phishing response pipeline incomplete

The Response Subflow - Phishing (0 executions) is not yet connected to Process Alert, meaning phishing alerts that flow through Case Management don't currently trigger automated response. Wiring the response router to invoke the phishing subflow would automate the inbox-removal flow that currently requires manual invocation.

4. Duplicate ability inventory

Many Agent Abilities appear three or more times across workspaces (e.g., Joe Sandbox Triage exists as original + copy in c46477e8 + copy in fecceb91). Consolidating these into a shared library workspace would reduce maintenance overhead and versioning drift.

5. Daily Risky User Table Update not scheduled

The Varonis risky user workflow is automation_type: on_demand with 0 executions. Converting this to a scheduled automation (cron/daily) would populate the risky user table continuously without manual invocation.

Integration Ecosystem

Domain Integrations
Identity & Access Microsoft Entra ID / Active Directory · Okta · Duo · UKG
Ticketing & Comms ServiceNow · Microsoft Teams · Microsoft Outlook
EDR & Endpoint SentinelOne · CrowdStrike
SIEM & Log Elasticsearch
Threat Intel VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Whois · Have I Been Pwned · Zscaler
Email Security Proofpoint Protection Server · Proofpoint Threat Protection
User Directory Google Workspace · GitHub · Slack
HR & Governance Cornerstone · Diligent
Monitoring Varonis
On-Call PagerDuty
Infrastructure WinRM · Blink Tables · Blink Webforms
Appendices
A Case Management 2 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
2
2 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 2 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Security 2 2 0 N/A
B AI Agents 13 active | 98 tasks (12m)

AI Agents

Active Agents
13
of 18 total
Tasks Executed (12m)
98
24 in last 30d
Data Usage (12m)
3,414,200
761,691 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Phishing Analyizer Security 36 23 1,216,896
2 Risky User Analyzer POC 21 0 377,486
3 Concierge Backoffice 7 0 504,027
4 DemoDan Training 6 0 477,205
5 Malicious Content Review Analyzer Security 6 0 130,855
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Security42
POC30
Backoffice9
Training8
josjohnson@udr.com8
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Onboarding Table 00
2 Test Dashboard 00
3 UDR Tool Licensing 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Upload Excel File 00
2 submit eml 00
3 submit eml 00
4 Webform Training 00
D Full Use Case Analysis 9 use cases | 194 executions (12m)

Business KPIs

Metric Count Playbook
Phishing emails parsed & investigated 5 Phishing Ingestion (1) + test-phishing (4)
Compromised user accounts automatically suspended 3 Active Directory Suspend User Account
Malicious URLs analyzed in sandbox 1 Joe's Sandbox URL Analysis
Malicious files analyzed in sandbox 1 Joe's Sandbox File Analysis
Security tickets auto-routed to the right analyst 1 Auto Assign Tickets
Malicious content alerts analyzed by an AI agent 2 Malicious Content Review Alerts
Daily CVE vulnerability checks run automatically 10 Daily CVE Check
HR/compliance data imports processed automatically 41 Data Import
Employee & AI-tool access block lists rebuilt automatically 10 Block List build
In the last 12 months, Blink automated: - 5 phishing emails parsed and investigated automatically - 3 compromised user accounts immediately suspended in Active Directory - 2 malicious files and URLs deep-analyzed through sandboxing - 1 security ticket automatically routed to the right analyst - 2 malicious content alerts analyzed automatically by an AI agent - 10 daily CVE vulnerability checks run automatically - 41 HR/compliance data imports processed automatically - 10 employee & AI-tool access block lists rebuilt automatically

Use Case Summary

# Use Case Category Subcategories Playbooks
1 Agentic Identity Access Management IAM Agentic SOC, Access review & group mgmt, JIT & temporary access, Identity lifecycle automation 29
2 Agentic SOC — Malware & Threat Investigation SOC Agentic SOC, EDR containment & response, Alert enrichment / IOC lookup, Identity threat response 23
3 Automated Alert Triage & Case Management (SOAR) SOC Case mgmt & SOAR, Alert enrichment / IOC lookup, Identity threat response 45
4 Phishing Detection & Response SOC Phishing detection & response, Case mgmt & SOAR 8
5 Identity Threat Response & Containment SOC Identity threat response, EDR containment & response, SIEM & log pipeline monitoring, Threat intel ingest & curation 6
6 Contractor & User Onboarding IAM Employee onboarding, Identity lifecycle automation 4
7 IT Ticket Auto-Assignment Other IT helpdesk & ticket routing 1
8 Daily CVE Monitoring Vulnerability Mgmt CVE lookup & remediation 1
9 HR & Application Access Eligibility Automation GRC AI / HR compliance automation, RBAC review & access mgmt 3

Total: 120 playbooks across 9 use cases

Use Cases

1. Agentic Identity Access Management

Description: An AI Concierge agent autonomously processes ServiceNow access requests end-to-end — it ingests the ticket, verifies the requester's employment standing and PTO status via UKG, checks existing Entra ID group memberships, routes the approval request to the manager via Teams, and then provisions or denies the access change. Both standard group membership updates and time-limited JIT access patterns are supported, with an auto-expiry timer that removes users from groups after the approved duration. The workflow closes the originating ServiceNow ticket on completion. The full agent stack is deployed in two parallel workspaces, indicating active organizational rollout.

Business problem: Manual access provisioning requires analysts to context-switch across ServiceNow, UKG, Entra ID, and Teams — introducing delays, inconsistency, and audit gaps. This use case closes that loop autonomously with a human approval checkpoint embedded in the flow.

Integrations: Microsoft Entra ID / Active Directory · ServiceNow · UKG · Microsoft Teams · Okta · Duo · PagerDuty

Category: IAM

Subcategories: Agentic SOC · Access review & group mgmt · JIT & temporary access · Identity lifecycle automation

Playbooks — Workspace c46477e8

Playbook Executions (12 mo)
Agent Access Request 0
Agent Ability - Service Now - Ingest Access Request 0
Agent Ability - UKG - Verify Associate Standing 0
Agent Ability - UKG - Verify PTO Status 0
Agent Ability - EntraID Check Current Group Membership 0
Agent Ability - Entra ID - Update Group Membership 0
Agent Ability - Entra ID JIT Access 0
Timer - JIT 0
Agent Ability - Teams - Request Approval 0
Agent Ability - Service Now - Close Ticket 0
Agent Ability - Duo - Check Enrollment 0
Agent Ability - Okta - Get User Info 0
Agent Ability - De-active User in Okta 0
Agent Ability - Send HTML Email 0

Playbooks — Workspace fecceb91 (parallel deployment)

Playbook Executions (12 mo)
Agent Access Request 0
Agent Ability - Service Now - Ingest Access Request 0
Agent Ability - UKG - Verify Associate Standing 0
Agent Ability - UKG - Verify PTO Status 0
Agent Ability - EntraID Check Current Group Membership 0
Agent Ability - Entra ID - Update Group Membership 0
Agent Ability - Entra ID JIT Access 0
Timer - JIT 0
Agent Ability - Teams - Request Approval 0
Agent Ability - Service Now - Close Ticket 0
Agent Ability - Duo - Check Enrollment 0
Agent Ability - Okta - Get User Info 0
Agent Ability - De-active User in Okta 0
Agent Ability - Send HTML Email 0

Playbooks — Workspace 68ab09b7 (backoffice)

Playbook Executions (12 mo)
Timer - JIT (Backoffice) 0

2. Agentic SOC — Malware & Threat Investigation

Description: A modular threat investigation toolkit built for a SOC AI agent. Each "Agent Ability" is a discrete, callable tool that the agent can invoke during an investigation: sandbox analysis of files, URLs, and IPs via Joe Sandbox; endpoint isolation and hash blocklisting via SentinelOne; on-call schedule verification via PagerDuty; SIEM log search via Elasticsearch; and — via a newer ability set in workspace ce987b69 — Okta log queries, Have I Been Pwned breach checks, VirusTotal IP reputation lookups, senior-leadership classification via Entra ID, and interactive user verification over Microsoft Teams. Standalone Joe Sandbox URL/file analysis and a Zscaler-triggered malicious content review workflow (which uses an AI agent to analyze extracted URLs and email an HTML report) are also active. The ability set now spans three workspaces.

Business problem: SOC analysts spend significant time manually pivoting between tools during active investigations. This toolkit lets a security agent (or an analyst via natural language) delegate investigation sub-tasks programmatically, compressing mean time to respond.

Integrations: Joe Sandbox · SentinelOne · Elasticsearch (Elastic) · PagerDuty · VirusTotal · Okta · Have I Been Pwned · Microsoft Entra ID / Active Directory · Microsoft Teams · Zscaler · Microsoft Outlook

Category: SOC

Subcategories: Agentic SOC · EDR containment & response · Alert enrichment / IOC lookup · Identity threat response

Playbooks — Workspace c46477e8

Playbook Executions (12 mo)
Agent Ability: Joe Sandbox Triage 0
Agent Ability: Joe Sandbox Triage copy 0
Agent Ability - PagerDuty - Query OnCall 0
Agent Ability - PagerDuty - Query OnCall copy 0
Agent Ability - SentinelOne - Isolate Endpoint 0
Agent Ability - Sentinel One - Add Hash to Block LIst 0
Agent Ability - Elastic - Get Index 0
Agent Ability - Elastic - Search Query 0

Playbooks — Workspace fecceb91

Playbook Executions (12 mo)
Agent Ability: Joe Sandbox Triage copy 0
Agent Ability - PagerDuty - Query OnCall copy 0
Agent Ability - SentinelOne - Isolate Endpoint 0
Agent Ability - Sentinel One - Add Hash to Block LIst 0
Agent Ability - Elastic - Get Index 0
Agent Ability - Elastic - Search Query 0

Playbooks — Workspace 5d0edcf6 (standalone)

Playbook Executions (12 mo)
Joe's Sandbox URL Analysis 1
Joe's Sandbox File Analysis 1
Virustotal Scan 0
Malicious Content Review Alerts 2

Playbooks — Workspace ce987b69 (agent toolkit)

Playbook Executions (12 mo)
Agent Ability - Okta Logs 1
Agent Ability - HIBP Breaches 1
Agent Ability - Check Seniority 0
Agent Ability - VT IP Investigation 1
Agent Ability - Ask a user a question on MS Teams 0

3. Automated Alert Triage & Case Management (SOAR)

Description: A comprehensive automated security operations platform built on Blink's native Case Management. The platform ingests security alerts via polling, extracts and deduplicates observables (IPs, URLs, hashes, usernames, agent IDs), routes each observable type to the appropriate enrichment subflow (VirusTotal, AbuseIPDB, URLScan, Joe Sandbox, CrowdStrike, Whois, Okta, Google Workspace, Entra ID, GitHub, Slack), correlates results into cases, and routes cases to type-specific response playbooks (phishing, malware). Utility automation handles case hygiene: stale case closure, observable relation management, and similar-case deduplication. Recovery workflows process any alerts that missed initial automation. This represents a fully self-contained SOC automation stack.

Business problem: Analysts are overwhelmed by alert volume and spend the majority of their time on mechanical triage tasks — looking up IPs, checking user accounts, pulling endpoint data — before they can make a decision. This SOAR platform automates the full triage loop, surfacing enriched, correlated cases ready for analyst judgment.

Integrations: CrowdStrike · Okta · Microsoft Entra ID / Active Directory · Google Workspace · VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Proofpoint (PPS) · GitHub · Slack · ServiceNow · Microsoft Outlook

Category: SOC

Subcategories: Case mgmt & SOAR · Alert enrichment / IOC lookup · Identity threat response

Playbooks — Workspace 5d0edcf6

Playbook Executions (12 mo)
Process Alert 0
Subflow - Response - Main Router 0
Response Subflow - Malware 0
Subflow - Enrich Observables - Main Router 0
Subflow - Update Enrichment Data 0
Enrich - Agent ID - Crowdstrike 0
Enrich - Username or Email - Okta 0
Enrich - Username or Email - Google Workspace 0
Enrich - Username or Email - Microsoft Entra ID 0
Enrich - Username - Github 0
Enrich - Email Address - Slack 0
Enrich - IP - IPDB 0
Enrich - IP - VT 0
Enrich - IP or Domain - Whois 0
Enrich - URL - VT 0
Enrich - URL - URLScan 0
Enrich - URL - Joes Sandbox 0
Enrich - Hash - VT 0
Enrich - Hash - Crowdstrike 0
Enrich - Joes Sandbox Attachment 0
Get User Information Using Google Workspace 0
Get User Information Using Microsoft Entra ID 0
Get User Information Using Github 0
Get User Information Using Okta 0
Get User Information on Email Address Using Slack 0
Get Hash Info Using VirusTotal 0
Enrich IP or Domain Using Whois 0
Analyze URL with URLScan 0
Secure URL Screenshot Capture 0
Run Dig Command 0
Get End of Life Date for a Product 0
Okta Search for User Activity 0
Utility - Set Or Update Observable Relation 0
Utility - List Observable Alert Relations 0
Utility - List Alert Observable Relations 0
Utility - Find Similar Cases Based on Observables 0
Utility - Delete Observable Relation 0
Utility - Update Enrichment 0
Utility - Close Stale Cases 0
Table Action - Validate Observables Extraction Template 0
Subflow - Missing Alert Template Notification 0
Recovery - Enrich Non-Enriched Observables 0
Recovery - Handle Unprocessed Alerts 0
Error Handling - Send Error Notification Email 0
Webhook Example 1

4. Phishing Detection & Response

Description: End-to-end phishing email handling — analysts or automated triggers submit EML files for parsing, IOC and attachment hash extraction, and Proofpoint searches. When a phishing campaign is confirmed, Proofpoint Threat Protection creates an incident and removes matching emails from recipient inboxes across the organization. A webform enables the security team to submit suspicious emails for analysis without leaving a browser.

Business problem: Phishing response is extremely time-sensitive. Manually searching Proofpoint for campaign variants, extracting IOCs, and removing emails from inboxes is a multi-step process that takes 30–60 minutes manually. Blink compresses this to seconds.

Integrations: Proofpoint Protection Server (PPS) · Proofpoint Threat Protection · Microsoft Outlook · Blink Webforms

Category: SOC

Subcategories: Phishing detection & response · Case mgmt & SOAR

Playbook Workspace Executions (12 mo)
Phishing Ingestion 5d0edcf6 1
test-phishing 5d0edcf6 4
Proofpoint Search for Emails 5d0edcf6 0
Proofpoint Search for Emails via Eml File 5d0edcf6 0
Subflow - Proofpoint Remove Emails from Inbox 5d0edcf6 3
Response Subflow - Phishing 5d0edcf6 0
Webform File Upload fecceb91 0
Webform File Upload (POC) 68ab09b7 0

5. Identity Threat Response & Containment

Description: Rapid automated response to identity-based threats and high-risk user signals. Capabilities include: immediate AD account suspension via WinRM/ADOP with email confirmation; Entra ID session revocation for compromised accounts; SentinelOne endpoint isolation triggered by hostname; CrowdStrike endpoint quarantine/lift orchestration; a daily Varonis-driven risky user table that ingests the last 24 hours of Varonis alerts, extracts unique risky users, and populates a Blink table for downstream triage; and a mailbox-polling workflow that watches for Have I Been Pwned breach notifications, pulls the latest breach details, filters for the udr.com domain, and emails the security team a breach report.

Business problem: When a user account is compromised, every minute the account remains active increases blast radius. Manual containment across AD, Entra, and EDR tools requires multiple logins and context switches. This use case drives mean time to contain (MTTC) down to seconds.

Integrations: Active Directory (WinRM/ADOP) · Microsoft Entra ID · SentinelOne · CrowdStrike · Varonis · Microsoft Outlook · Have I Been Pwned

Category: SOC

Subcategories: Identity threat response · EDR containment & response · SIEM & log pipeline monitoring · Threat intel ingest & curation

Playbook Workspace Executions (12 mo)
Active Directory Suspend User Account 5d0edcf6 3
Entra - Revoke User Sessions 5d0edcf6 0
SentinelOne Isolate Device by Hostname 5d0edcf6 0
Manage Endpoint Quarantine Status in Crowdstrike 5d0edcf6 0
Daily Risky User Table Update fecceb91 0
HIBP - List Users from Breach e6ad6f07 0

6. Contractor & User Onboarding

Description: An AI-agent-driven contractor onboarding flow ("Agent Tom") that provisions new users end-to-end in Microsoft Entra ID. Supporting abilities handle email/username uniqueness validation (with numeric suffix collision resolution), AD group assignment, and AD group lookup. Triggers include both on-demand invocation and a one-off onboarding intake form.

Business problem: Ad-hoc contractor onboarding is typically handled via email requests to IT, creating inconsistent provisioning and audit gaps. This use case standardizes and accelerates the process, ensuring all required systems are provisioned consistently.

Integrations: Microsoft Entra ID / Active Directory · Blink Tables

Category: IAM

Subcategories: Employee onboarding · Identity lifecycle automation

Playbook Workspace Executions (12 mo)
One off User Creation 68ab09b7 0
Email Check & Creation 68ab09b7 0
Add User to Group with Microsoft Entra ID 68ab09b7 0
Search for AD Groups 68ab09b7 0

7. IT Ticket Auto-Assignment

Description: Polls ServiceNow every minute for unassigned IT Security incidents and routes them to the correct owner. Removes the manual triage step of assigning tickets from the queue.

Business problem: Unassigned tickets in IT Security queues sit idle until someone manually picks them up, increasing response times and creating accountability gaps.

Integrations: ServiceNow

Category: Other

Subcategories: IT helpdesk & ticket routing

Playbook Workspace Executions (12 mo)
Auto Assign Tickets 5d0edcf6 1

8. Daily CVE Monitoring

Description: A scheduled daily automation that extracts newly published CVEs filtered by a configured set of included severities and evaluates whether any qualify for reporting.

Business problem: Keeping pace with newly disclosed vulnerabilities requires continuous manual polling of CVE feeds. This automation runs the check daily without analyst involvement, surfacing only the CVEs that meet the severity threshold worth reporting.

Integrations: CVE data source (via Python)

Category: Vulnerability Mgmt

Subcategories: CVE lookup & remediation

Playbook Workspace Executions (12 mo)
Daily CVE Check 5d0edcf6 10

9. HR & Application Access Eligibility Automation

Description: A data pipeline that ingests HR, learning-management, and governance data via a dedicated mailbox intake (keyword-routed from a designated internal sender into Blink Tables), cross-references active-associate records from UKG, Cornerstone, and Diligent against "Do Not Block" and "AI Block List" exception tables, and rebuilds consolidated block lists as a CSV emailed to stakeholders. A companion webhook-triggered workflow propagates the resulting user eligibility updates out to the SmartZone application.

Business problem: Determining which employees should retain or lose access to specific applications and AI tools requires reconciling employment and standing data spread across HR (UKG), training (Cornerstone), and governance (Diligent) systems. Manually cross-referencing these feeds and pushing updates downstream is slow and error-prone; this pipeline automates ingestion, reconciliation, and propagation.

Integrations: UKG · Cornerstone · Diligent · Blink Tables · Microsoft Outlook

Category: GRC

Subcategories: AI / HR compliance automation · RBAC review & access mgmt

Playbook Workspace Executions (12 mo)
Data Import b43335bd 41
Block List build b43335bd 10
SmartZone User Updates b43335bd 0

Key Observations

Strengths

1. Agentic IAM is the flagship use case

The Access Request agent stack is the most mature investment — a full AI Concierge agent with 14 discrete capabilities spanning the entire access provisioning lifecycle from ServiceNow ticket to Entra ID group update. Its deployment across two parallel workspaces signals active organizational rollout and likely testing across business units or environments.

2. Exceptionally broad integration ecosystem

17+ integrations are wired in across the platform: Entra ID/AD, Okta, Duo, UKG, ServiceNow, Teams, SentinelOne, CrowdStrike, Elastic, Joe Sandbox, VirusTotal, AbuseIPDB, URLScan, Proofpoint (PPS and Threat Protection), Varonis, PagerDuty, GitHub, Slack, and Google Workspace. This is a mature, enterprise-grade integration footprint.

3. Production-ready SOAR platform built on Blink Case Management

The workspace 5d0edcf6 contains a fully architected SOAR platform with 44+ playbooks: multi-source observable enrichment, deduplication, type-specific response routing, recovery workflows, and observable relationship management. This represents significant engineering investment and a sophisticated automation design.

4. Identity threat response is live

Three Active Directory account suspensions executed in the period confirm production usage of the identity containment workflow, including cross-platform Proofpoint inbox removal (3 email remediation executions).

5. HR/compliance data pipeline already at high-volume production scale

The Data Import (41 executions) and Block List build (10 executions) workflows show this eligibility-reconciliation pipeline — spanning UKG, Cornerstone, and Diligent — is already running in active, frequent production use, the highest execution volume of any single-purpose automation in this report outside the SOAR platform's core ingestion path.

Gaps & Opportunities

1. Near-zero execution counts across most workflows

The majority of playbooks — including the flagship Agent Access Request and the full SOAR platform — show 0 executions in the last 12 months. This strongly suggests the platform is in late-stage deployment or recently migrated from a prior environment, with production traffic not yet flowing. Activating the SOAR Process Alert trigger (event-driven, polling every 1 minute) would immediately drive value through the full enrichment and response pipeline.

2. Agentic IAM not yet in production

The Access Request agent is fully built with a rich ability set, but 0 executions across both workspace deployments. Connecting the production ServiceNow queue to trigger Agent Access Request is the highest-leverage activation step available.

3. Phishing response pipeline incomplete

The Response Subflow - Phishing (0 executions) is not yet connected to Process Alert, meaning phishing alerts that flow through Case Management don't currently trigger automated response. Wiring the response router to invoke the phishing subflow would automate the inbox-removal flow that currently requires manual invocation.

4. Duplicate ability inventory

Many Agent Abilities appear three or more times across workspaces (e.g., Joe Sandbox Triage exists as original + copy in c46477e8 + copy in fecceb91). Consolidating these into a shared library workspace would reduce maintenance overhead and versioning drift.

5. Daily Risky User Table Update not scheduled

The Varonis risky user workflow is automation_type: on_demand with 0 executions. Converting this to a scheduled automation (cron/daily) would populate the risky user table continuously without manual invocation.

Integration Ecosystem

Domain Integrations
Identity & Access Microsoft Entra ID / Active Directory · Okta · Duo · UKG
Ticketing & Comms ServiceNow · Microsoft Teams · Microsoft Outlook
EDR & Endpoint SentinelOne · CrowdStrike
SIEM & Log Elasticsearch
Threat Intel VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Whois · Have I Been Pwned · Zscaler
Email Security Proofpoint Protection Server · Proofpoint Threat Protection
User Directory Google Workspace · GitHub · Slack
HR & Governance Cornerstone · Diligent
Monitoring Varonis
On-Call PagerDuty
Infrastructure WinRM · Blink Tables · Blink Webforms
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
udr blink my_blink_connection 2026-08-21
udr okta my_okta_connection_bhunnicutt 2026-08-05