01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic Identity Access Management | 0 executions | 0.0% | 15 15 active |
| Agentic SOC — Malware & Threat Investigation |
| 2.6% | 17 17 active |
| Automated Alert Triage & Case Management (SOAR) | 2 executions | 1.0% | 44 44 active |
| Phishing Detection & Response | 0 executions | 0.0% | 7 6 active |
| Identity Threat Response & Containment |
| 0.0% | 6 6 active |
| Contractor & User Onboarding | 0 executions | 0.0% | 4 4 active |
| IT Ticket Auto-Assignment |
| 40.7% | 1 1 active |
| Daily CVE Monitoring |
| 5.2% | 1 1 active |
| HR & Application Access Eligibility Automation |
| 26.3% | 3 3 active |
| Total | 147 executions | 100% | 98 97 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Agentic IAM is the flagship use case
The Access Request agent stack is the most mature investment — a full AI Concierge agent with 14 discrete capabilities spanning the entire access provisioning lifecycle from ServiceNow ticket to Entra ID group update. Its deployment across two parallel workspaces signals active organizational rollout and likely testing across business units or environments.
2. Exceptionally broad integration ecosystem
17+ integrations are wired in across the platform: Entra ID/AD, Okta, Duo, UKG, ServiceNow, Teams, SentinelOne, CrowdStrike, Elastic, Joe Sandbox, VirusTotal, AbuseIPDB, URLScan, Proofpoint (PPS and Threat Protection), Varonis, PagerDuty, GitHub, Slack, and Google Workspace. This is a mature, enterprise-grade integration footprint.
3. Production-ready SOAR platform built on Blink Case Management
The workspace 5d0edcf6 contains a fully architected SOAR platform with 44+ playbooks: multi-source observable enrichment, deduplication, type-specific response routing, recovery workflows, and observable relationship management. This represents significant engineering investment and a sophisticated automation design.
4. Identity threat response is live
Three Active Directory account suspensions executed in the period confirm production usage of the identity containment workflow, including cross-platform Proofpoint inbox removal (3 email remediation executions).
5. HR/compliance data pipeline already at high-volume production scale
The Data Import (41 executions) and Block List build (10 executions) workflows show this eligibility-reconciliation pipeline — spanning UKG, Cornerstone, and Diligent — is already running in active, frequent production use, the highest execution volume of any single-purpose automation in this report outside the SOAR platform's core ingestion path.
###
Gaps & Opportunities
1. Near-zero execution counts across most workflows
The majority of playbooks — including the flagship Agent Access Request and the full SOAR platform — show 0 executions in the last 12 months. This strongly suggests the platform is in late-stage deployment or recently migrated from a prior environment, with production traffic not yet flowing. Activating the SOAR Process Alert trigger (event-driven, polling every 1 minute) would immediately drive value through the full enrichment and response pipeline.
2. Agentic IAM not yet in production
The Access Request agent is fully built with a rich ability set, but 0 executions across both workspace deployments. Connecting the production ServiceNow queue to trigger Agent Access Request is the highest-leverage activation step available.
3. Phishing response pipeline incomplete
The Response Subflow - Phishing (0 executions) is not yet connected to Process Alert, meaning phishing alerts that flow through Case Management don't currently trigger automated response. Wiring the response router to invoke the phishing subflow would automate the inbox-removal flow that currently requires manual invocation.
4. Duplicate ability inventory
Many Agent Abilities appear three or more times across workspaces (e.g., Joe Sandbox Triage exists as original + copy in c46477e8 + copy in fecceb91). Consolidating these into a shared library workspace would reduce maintenance overhead and versioning drift.
5. Daily Risky User Table Update not scheduled
The Varonis risky user workflow is automation_type: on_demand with 0 executions. Converting this to a scheduled automation (cron/daily) would populate the risky user table continuously without manual invocation.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| Identity & Access | Microsoft Entra ID / Active Directory · Okta · Duo · UKG |
| Ticketing & Comms | ServiceNow · Microsoft Teams · Microsoft Outlook |
| EDR & Endpoint | SentinelOne · CrowdStrike |
| SIEM & Log | Elasticsearch |
| Threat Intel | VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Whois · Have I Been Pwned · Zscaler |
| Email Security | Proofpoint Protection Server · Proofpoint Threat Protection |
| User Directory | Google Workspace · GitHub · Slack |
| HR & Governance | Cornerstone · Diligent |
| Monitoring | Varonis |
| On-Call | PagerDuty |
| Infrastructure | WinRM · Blink Tables · Blink Webforms |
A Case Management 2 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Security | 2 | 2 | 0 | N/A |
B AI Agents 13 active | 98 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Phishing Analyizer | Security | 36 | 23 | 1,216,896 |
| 2 | Risky User Analyzer | POC | 21 | 0 | 377,486 |
| 3 | Concierge | Backoffice | 7 | 0 | 504,027 |
| 4 | DemoDan | Training | 6 | 0 | 477,205 |
| 5 | Malicious Content Review Analyzer | Security | 6 | 0 | 130,855 |
| Workspace | Tasks (12m) |
|---|---|
| Security | 42 |
| POC | 30 |
| Backoffice | 9 |
| Training | 8 |
| josjohnson@udr.com | 8 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Onboarding Table | 0 | 0 |
| 2 | Test Dashboard | 0 | 0 |
| 3 | UDR Tool Licensing | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Upload Excel File | 0 | 0 |
| 2 | submit eml | 0 | 0 |
| 3 | submit eml | 0 | 0 |
| 4 | Webform Training | 0 | 0 |
D Full Use Case Analysis 9 use cases | 194 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Phishing emails parsed & investigated | 5 | Phishing Ingestion (1) + test-phishing (4) |
| Compromised user accounts automatically suspended | 3 | Active Directory Suspend User Account |
| Malicious URLs analyzed in sandbox | 1 | Joe's Sandbox URL Analysis |
| Malicious files analyzed in sandbox | 1 | Joe's Sandbox File Analysis |
| Security tickets auto-routed to the right analyst | 1 | Auto Assign Tickets |
| Malicious content alerts analyzed by an AI agent | 2 | Malicious Content Review Alerts |
| Daily CVE vulnerability checks run automatically | 10 | Daily CVE Check |
| HR/compliance data imports processed automatically | 41 | Data Import |
| Employee & AI-tool access block lists rebuilt automatically | 10 | Block List build |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks |
|---|---|---|---|---|
| 1 | Agentic Identity Access Management | IAM | Agentic SOC, Access review & group mgmt, JIT & temporary access, Identity lifecycle automation | 29 |
| 2 | Agentic SOC — Malware & Threat Investigation | SOC | Agentic SOC, EDR containment & response, Alert enrichment / IOC lookup, Identity threat response | 23 |
| 3 | Automated Alert Triage & Case Management (SOAR) | SOC | Case mgmt & SOAR, Alert enrichment / IOC lookup, Identity threat response | 45 |
| 4 | Phishing Detection & Response | SOC | Phishing detection & response, Case mgmt & SOAR | 8 |
| 5 | Identity Threat Response & Containment | SOC | Identity threat response, EDR containment & response, SIEM & log pipeline monitoring, Threat intel ingest & curation | 6 |
| 6 | Contractor & User Onboarding | IAM | Employee onboarding, Identity lifecycle automation | 4 |
| 7 | IT Ticket Auto-Assignment | Other | IT helpdesk & ticket routing | 1 |
| 8 | Daily CVE Monitoring | Vulnerability Mgmt | CVE lookup & remediation | 1 |
| 9 | HR & Application Access Eligibility Automation | GRC | AI / HR compliance automation, RBAC review & access mgmt | 3 |
Total: 120 playbooks across 9 use cases
Use Cases
1. Agentic Identity Access Management
Description: An AI Concierge agent autonomously processes ServiceNow access requests end-to-end — it ingests the ticket, verifies the requester's employment standing and PTO status via UKG, checks existing Entra ID group memberships, routes the approval request to the manager via Teams, and then provisions or denies the access change. Both standard group membership updates and time-limited JIT access patterns are supported, with an auto-expiry timer that removes users from groups after the approved duration. The workflow closes the originating ServiceNow ticket on completion. The full agent stack is deployed in two parallel workspaces, indicating active organizational rollout.
Business problem: Manual access provisioning requires analysts to context-switch across ServiceNow, UKG, Entra ID, and Teams — introducing delays, inconsistency, and audit gaps. This use case closes that loop autonomously with a human approval checkpoint embedded in the flow.
Integrations: Microsoft Entra ID / Active Directory · ServiceNow · UKG · Microsoft Teams · Okta · Duo · PagerDuty
Category: IAM
Subcategories: Agentic SOC · Access review & group mgmt · JIT & temporary access · Identity lifecycle automation
Playbooks — Workspace c46477e8
Playbooks — Workspace fecceb91 (parallel deployment)
Playbooks — Workspace 68ab09b7 (backoffice)
| Playbook | Executions (12 mo) |
|---|---|
| Timer - JIT (Backoffice) | 0 |
2. Agentic SOC — Malware & Threat Investigation
Description: A modular threat investigation toolkit built for a SOC AI agent. Each "Agent Ability" is a discrete, callable tool that the agent can invoke during an investigation: sandbox analysis of files, URLs, and IPs via Joe Sandbox; endpoint isolation and hash blocklisting via SentinelOne; on-call schedule verification via PagerDuty; SIEM log search via Elasticsearch; and — via a newer ability set in workspace ce987b69 — Okta log queries, Have I Been Pwned breach checks, VirusTotal IP reputation lookups, senior-leadership classification via Entra ID, and interactive user verification over Microsoft Teams. Standalone Joe Sandbox URL/file analysis and a Zscaler-triggered malicious content review workflow (which uses an AI agent to analyze extracted URLs and email an HTML report) are also active. The ability set now spans three workspaces.
Business problem: SOC analysts spend significant time manually pivoting between tools during active investigations. This toolkit lets a security agent (or an analyst via natural language) delegate investigation sub-tasks programmatically, compressing mean time to respond.
Integrations: Joe Sandbox · SentinelOne · Elasticsearch (Elastic) · PagerDuty · VirusTotal · Okta · Have I Been Pwned · Microsoft Entra ID / Active Directory · Microsoft Teams · Zscaler · Microsoft Outlook
Category: SOC
Subcategories: Agentic SOC · EDR containment & response · Alert enrichment / IOC lookup · Identity threat response
Playbooks — Workspace c46477e8
Playbooks — Workspace fecceb91
Playbooks — Workspace 5d0edcf6 (standalone)
| Playbook | Executions (12 mo) |
|---|---|
| Joe's Sandbox URL Analysis | 1 |
| Joe's Sandbox File Analysis | 1 |
| Virustotal Scan | 0 |
| Malicious Content Review Alerts | 2 |
Playbooks — Workspace ce987b69 (agent toolkit)
3. Automated Alert Triage & Case Management (SOAR)
Description: A comprehensive automated security operations platform built on Blink's native Case Management. The platform ingests security alerts via polling, extracts and deduplicates observables (IPs, URLs, hashes, usernames, agent IDs), routes each observable type to the appropriate enrichment subflow (VirusTotal, AbuseIPDB, URLScan, Joe Sandbox, CrowdStrike, Whois, Okta, Google Workspace, Entra ID, GitHub, Slack), correlates results into cases, and routes cases to type-specific response playbooks (phishing, malware). Utility automation handles case hygiene: stale case closure, observable relation management, and similar-case deduplication. Recovery workflows process any alerts that missed initial automation. This represents a fully self-contained SOC automation stack.
Business problem: Analysts are overwhelmed by alert volume and spend the majority of their time on mechanical triage tasks — looking up IPs, checking user accounts, pulling endpoint data — before they can make a decision. This SOAR platform automates the full triage loop, surfacing enriched, correlated cases ready for analyst judgment.
Integrations: CrowdStrike · Okta · Microsoft Entra ID / Active Directory · Google Workspace · VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Proofpoint (PPS) · GitHub · Slack · ServiceNow · Microsoft Outlook
Category: SOC
Subcategories: Case mgmt & SOAR · Alert enrichment / IOC lookup · Identity threat response
Playbooks — Workspace 5d0edcf6
4. Phishing Detection & Response
Description: End-to-end phishing email handling — analysts or automated triggers submit EML files for parsing, IOC and attachment hash extraction, and Proofpoint searches. When a phishing campaign is confirmed, Proofpoint Threat Protection creates an incident and removes matching emails from recipient inboxes across the organization. A webform enables the security team to submit suspicious emails for analysis without leaving a browser.
Business problem: Phishing response is extremely time-sensitive. Manually searching Proofpoint for campaign variants, extracting IOCs, and removing emails from inboxes is a multi-step process that takes 30–60 minutes manually. Blink compresses this to seconds.
Integrations: Proofpoint Protection Server (PPS) · Proofpoint Threat Protection · Microsoft Outlook · Blink Webforms
Category: SOC
Subcategories: Phishing detection & response · Case mgmt & SOAR
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| Phishing Ingestion | 5d0edcf6 |
1 |
| test-phishing | 5d0edcf6 |
4 |
| Proofpoint Search for Emails | 5d0edcf6 |
0 |
| Proofpoint Search for Emails via Eml File | 5d0edcf6 |
0 |
| Subflow - Proofpoint Remove Emails from Inbox | 5d0edcf6 |
3 |
| Response Subflow - Phishing | 5d0edcf6 |
0 |
| Webform File Upload | fecceb91 |
0 |
| Webform File Upload (POC) | 68ab09b7 |
0 |
5. Identity Threat Response & Containment
Description: Rapid automated response to identity-based threats and high-risk user signals. Capabilities include: immediate AD account suspension via WinRM/ADOP with email confirmation; Entra ID session revocation for compromised accounts; SentinelOne endpoint isolation triggered by hostname; CrowdStrike endpoint quarantine/lift orchestration; a daily Varonis-driven risky user table that ingests the last 24 hours of Varonis alerts, extracts unique risky users, and populates a Blink table for downstream triage; and a mailbox-polling workflow that watches for Have I Been Pwned breach notifications, pulls the latest breach details, filters for the udr.com domain, and emails the security team a breach report.
Business problem: When a user account is compromised, every minute the account remains active increases blast radius. Manual containment across AD, Entra, and EDR tools requires multiple logins and context switches. This use case drives mean time to contain (MTTC) down to seconds.
Integrations: Active Directory (WinRM/ADOP) · Microsoft Entra ID · SentinelOne · CrowdStrike · Varonis · Microsoft Outlook · Have I Been Pwned
Category: SOC
Subcategories: Identity threat response · EDR containment & response · SIEM & log pipeline monitoring · Threat intel ingest & curation
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| Active Directory Suspend User Account | 5d0edcf6 |
3 |
| Entra - Revoke User Sessions | 5d0edcf6 |
0 |
| SentinelOne Isolate Device by Hostname | 5d0edcf6 |
0 |
| Manage Endpoint Quarantine Status in Crowdstrike | 5d0edcf6 |
0 |
| Daily Risky User Table Update | fecceb91 |
0 |
| HIBP - List Users from Breach | e6ad6f07 |
0 |
6. Contractor & User Onboarding
Description: An AI-agent-driven contractor onboarding flow ("Agent Tom") that provisions new users end-to-end in Microsoft Entra ID. Supporting abilities handle email/username uniqueness validation (with numeric suffix collision resolution), AD group assignment, and AD group lookup. Triggers include both on-demand invocation and a one-off onboarding intake form.
Business problem: Ad-hoc contractor onboarding is typically handled via email requests to IT, creating inconsistent provisioning and audit gaps. This use case standardizes and accelerates the process, ensuring all required systems are provisioned consistently.
Integrations: Microsoft Entra ID / Active Directory · Blink Tables
Category: IAM
Subcategories: Employee onboarding · Identity lifecycle automation
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| One off User Creation | 68ab09b7 |
0 |
| Email Check & Creation | 68ab09b7 |
0 |
| Add User to Group with Microsoft Entra ID | 68ab09b7 |
0 |
| Search for AD Groups | 68ab09b7 |
0 |
7. IT Ticket Auto-Assignment
Description: Polls ServiceNow every minute for unassigned IT Security incidents and routes them to the correct owner. Removes the manual triage step of assigning tickets from the queue.
Business problem: Unassigned tickets in IT Security queues sit idle until someone manually picks them up, increasing response times and creating accountability gaps.
Integrations: ServiceNow
Category: Other
Subcategories: IT helpdesk & ticket routing
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| Auto Assign Tickets | 5d0edcf6 |
1 |
8. Daily CVE Monitoring
Description: A scheduled daily automation that extracts newly published CVEs filtered by a configured set of included severities and evaluates whether any qualify for reporting.
Business problem: Keeping pace with newly disclosed vulnerabilities requires continuous manual polling of CVE feeds. This automation runs the check daily without analyst involvement, surfacing only the CVEs that meet the severity threshold worth reporting.
Integrations: CVE data source (via Python)
Category: Vulnerability Mgmt
Subcategories: CVE lookup & remediation
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| Daily CVE Check | 5d0edcf6 |
10 |
9. HR & Application Access Eligibility Automation
Description: A data pipeline that ingests HR, learning-management, and governance data via a dedicated mailbox intake (keyword-routed from a designated internal sender into Blink Tables), cross-references active-associate records from UKG, Cornerstone, and Diligent against "Do Not Block" and "AI Block List" exception tables, and rebuilds consolidated block lists as a CSV emailed to stakeholders. A companion webhook-triggered workflow propagates the resulting user eligibility updates out to the SmartZone application.
Business problem: Determining which employees should retain or lose access to specific applications and AI tools requires reconciling employment and standing data spread across HR (UKG), training (Cornerstone), and governance (Diligent) systems. Manually cross-referencing these feeds and pushing updates downstream is slow and error-prone; this pipeline automates ingestion, reconciliation, and propagation.
Integrations: UKG · Cornerstone · Diligent · Blink Tables · Microsoft Outlook
Category: GRC
Subcategories: AI / HR compliance automation · RBAC review & access mgmt
| Playbook | Workspace | Executions (12 mo) |
|---|---|---|
| Data Import | b43335bd |
41 |
| Block List build | b43335bd |
10 |
| SmartZone User Updates | b43335bd |
0 |
Key Observations
Strengths
1. Agentic IAM is the flagship use case
The Access Request agent stack is the most mature investment — a full AI Concierge agent with 14 discrete capabilities spanning the entire access provisioning lifecycle from ServiceNow ticket to Entra ID group update. Its deployment across two parallel workspaces signals active organizational rollout and likely testing across business units or environments.
2. Exceptionally broad integration ecosystem
17+ integrations are wired in across the platform: Entra ID/AD, Okta, Duo, UKG, ServiceNow, Teams, SentinelOne, CrowdStrike, Elastic, Joe Sandbox, VirusTotal, AbuseIPDB, URLScan, Proofpoint (PPS and Threat Protection), Varonis, PagerDuty, GitHub, Slack, and Google Workspace. This is a mature, enterprise-grade integration footprint.
3. Production-ready SOAR platform built on Blink Case Management
The workspace 5d0edcf6 contains a fully architected SOAR platform with 44+ playbooks: multi-source observable enrichment, deduplication, type-specific response routing, recovery workflows, and observable relationship management. This represents significant engineering investment and a sophisticated automation design.
4. Identity threat response is live
Three Active Directory account suspensions executed in the period confirm production usage of the identity containment workflow, including cross-platform Proofpoint inbox removal (3 email remediation executions).
5. HR/compliance data pipeline already at high-volume production scale
The Data Import (41 executions) and Block List build (10 executions) workflows show this eligibility-reconciliation pipeline — spanning UKG, Cornerstone, and Diligent — is already running in active, frequent production use, the highest execution volume of any single-purpose automation in this report outside the SOAR platform's core ingestion path.
Gaps & Opportunities
1. Near-zero execution counts across most workflows
The majority of playbooks — including the flagship Agent Access Request and the full SOAR platform — show 0 executions in the last 12 months. This strongly suggests the platform is in late-stage deployment or recently migrated from a prior environment, with production traffic not yet flowing. Activating the SOAR Process Alert trigger (event-driven, polling every 1 minute) would immediately drive value through the full enrichment and response pipeline.
2. Agentic IAM not yet in production
The Access Request agent is fully built with a rich ability set, but 0 executions across both workspace deployments. Connecting the production ServiceNow queue to trigger Agent Access Request is the highest-leverage activation step available.
3. Phishing response pipeline incomplete
The Response Subflow - Phishing (0 executions) is not yet connected to Process Alert, meaning phishing alerts that flow through Case Management don't currently trigger automated response. Wiring the response router to invoke the phishing subflow would automate the inbox-removal flow that currently requires manual invocation.
4. Duplicate ability inventory
Many Agent Abilities appear three or more times across workspaces (e.g., Joe Sandbox Triage exists as original + copy in c46477e8 + copy in fecceb91). Consolidating these into a shared library workspace would reduce maintenance overhead and versioning drift.
5. Daily Risky User Table Update not scheduled
The Varonis risky user workflow is automation_type: on_demand with 0 executions. Converting this to a scheduled automation (cron/daily) would populate the risky user table continuously without manual invocation.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| Identity & Access | Microsoft Entra ID / Active Directory · Okta · Duo · UKG |
| Ticketing & Comms | ServiceNow · Microsoft Teams · Microsoft Outlook |
| EDR & Endpoint | SentinelOne · CrowdStrike |
| SIEM & Log | Elasticsearch |
| Threat Intel | VirusTotal · AbuseIPDB · URLScan · Joe Sandbox · Whois · Have I Been Pwned · Zscaler |
| Email Security | Proofpoint Protection Server · Proofpoint Threat Protection |
| User Directory | Google Workspace · GitHub · Slack |
| HR & Governance | Cornerstone · Diligent |
| Monitoring | Varonis |
| On-Call | PagerDuty |
| Infrastructure | WinRM · Blink Tables · Blink Webforms |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| udr | blink | my_blink_connection | 2026-08-21 |
| udr | okta | my_okta_connection_bhunnicutt | 2026-08-05 |