Blink Security Automation — Confidential

usana — Customer Success Report

Generated 2026-08-31 | usana-value-report.md
2026-08-31Report Date
277Total Playbooks
75Unique Workflows (12m)
490,186Actions Automated (12m)
$126,077Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

277
Total playbooks built
all non-deleted workflows
107
Active playbooks
currently enabled
75
Unique workflows executed (12m)
distinct workflows that ran
490,186
Actions automated (12m)
completed action steps
2,723.3h
Hours saved (12m)
@ 20s per action
$126,077
Money saved (12m)
@ $100K avg salary
4
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
21
Active AI agents
of 23 total
4,096
AI agent tasks executed (12m)
375 in last 30d
In the last 12 months, Blink automated: - 1,112 SentinelOne agent activity events processed automatically via webhook — no manual monitoring required - 585 on-call roster updates pushed across Teams channels and Slack — zero manual channel edits - 185 Azure AD user profiles enriched automatically on analyst demand - 131 Guard Detect security alerts converted to enriched Jira tickets without analyst involvement - 120 HashiCorp Vault credential renewals executed autonomously (every 8 hours, around the clock) - 40 suspicious Office 365 foreign login events automatically investigated and routed - 40 transit key deletion tickets processed through full lifecycle - 21 Jira agent package alerts auto-closed without analyst involvement - 20 Jira security tickets auto-reassigned based on on-call schedules - 17 weekly SentinelOne workstation dashboard reports emailed to SecOps

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Guard Detect Alert Management
  • 131Guard Detect security alerts auto-ticketed & enriched in Jira
7.3%
3
3 active
O365 Suspicious Login Detection
  • 40Suspicious O365 foreign logins auto-investigated
0.0%
1
1 active
Recorded Future Threat Intel Enrichment0 executions
0.0%
5
5 active
AI-Driven Security Operations0 executions
0.0%
4
4 active
Avanan Email Security Investigation0 executions
0.0%
2
2 active
IOC Verification0 executions
0.0%
1
1 active
Azure AD Identity Enrichment
  • 185Azure AD user profiles enriched on demand
0.0%
5
5 active
Vault & Credential Lifecycle Management
  • 120Vault credential auto-renewals (every 8 hours, 24×7)
  • 40Transit key deletion tickets processed end-to-end
1.2%
11
9 active
SentinelOne Endpoint Agent Management
  • 1,112SentinelOne agent activity events auto-processed via webhook
  • 21Jira agent package alerts auto-closed
  • 17Weekly SentinelOne workstation dashboard reports emailed to SecOps
37.4%
27
25 active
Rapid7 Vulnerability Intelligence71 executions
2.1%
8
8 active
On-Call Management & Cross-Platform Notification
  • 585On-call roster updates pushed to Teams & Slack
  • 40Daily PagerDuty on-call syncs to Teams channels
2.3%
8
8 active
Jira Operations & Sprint Automation
  • 20Security tickets auto-reassigned to analysts
  • 1Jira sprint transitions automated
0.7%
4
4 active
Infrastructure Asset Inventory0 executions
0.0%
4
4 active
AD Password Policy Compliance Evidence Collection0 executions
0.0%
1
1 active
Total1,725 executions100%
84
80 active

Use Case Growth Over Time

223 unique playbooks  |  14 operational use cases  |  3,389 total executions (12m)  |  2025-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Vault & Credential Lifecycle Management
Jira 1Password Vault Email
IOC Verification
VirusTotal
Guard Detect Alert Management
Jira Agents
SentinelOne Endpoint Agent Management
Jira Microsoft Graph Microsoft Entra ID IP API Jamf SentinelOne Agents Email Dashboards
Azure AD Identity Enrichment
Microsoft Entra ID Microsoft Graph Azure Jira
Rapid7 Vulnerability Intelligence
Rapid7 Agents Jira Rapid7 InsightVM Cloud
Jira Operations & Sprint Automation
Jira
Infrastructure Asset Inventory
SentinelOne Microsoft Graph Jamf VMware vSphere SharePoint
AI-Driven Security Operations
Agents
Avanan Email Security Investigation
Jira Agents Microsoft Entra ID
On-Call Management & Cross-Platform Notification
PagerDuty Microsoft Entra ID Microsoft Graph Agents
O365 Suspicious Login Detection
Jira PagerDuty
Recorded Future Threat Intel Enrichment
Jira Recorded Future Agents

04Key Observations

✓  Strengths

Strengths

Deep integration ecosystem. The automation library spans 14 integrated platforms: Jira, SentinelOne, Microsoft Graph/Entra ID, Rapid7 InsightVM, PagerDuty, HashiCorp Vault, 1Password, Microsoft Teams, Slack, Avanan, VMware vSphere, JAMF, Recorded Future, and SharePoint. This breadth places the environment among the more mature integration footprints.

Autonomous credential governance. The vault_creds_renewal workflow running every 8 hours represents a sophisticated, fully autonomous secret lifecycle. It checks token TTL via 1Password, creates an orphaned token via Vault API, updates the Blink connection, and syncs back to 1Password — all without human intervention. 120 executions over 12 months means this has reliably prevented at least 120 potential automation outages from credential expiry.

On-call propagation at scale. Pushing the SecOps on-call identity to five separate Teams channel topics plus a Slack group — every hour — is operationally significant. 585 executions with no manual involvement means the on-call channel topic has never been stale during business hours.

AI-first architecture emerging. Multiple workflows use Blink AI agents (agents.*) as reasoning steps — for sprint planning assistance, CVE summarization, SentinelOne version resolution, and prompt-driven workflow orchestration. The jira_automation_rule_triggering_blinkops_ai and AI_based_workflow_choose_and_execute_from_prompt patterns indicate investment in an agentic SecOps model where natural language drives automation selection.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

SentinelOne upgrade pipeline has begun activating. Staggered upgrade testing has started (sentinelone_stagger_test_report: 4 runs, sentinelone_staggered_based_agent_upgrade: 2 runs), alongside a new high-volume agent activity webhook (sentinelone_agent_activity_update: 1,112 runs) and a weekly dashboard email report (17 runs) that give SecOps ongoing visibility. The bulk upgrade initiation and task-status-tracking playbooks still show 0 executions, so full-scale rollout has not yet followed the successful staggered tests. Converting the validated stagger pattern into a scheduled, group-by-group rollout would realize the remaining endpoint hygiene value.

Rapid7 and Recorded Future libraries are unused. 10 Rapid7 and 5 Recorded Future workflows show 0 executions. These are well-structured (proper inputs/outputs, AI-assisted summaries) but appear to be capabilities built for future use. A defined trigger — such as a Jira CVE ticket label or a new Recorded Future alert — would activate this investment.

Avanan email investigation not triggered. The Avanan workflows exist with multi-step API token generation and AI analysis, but have never executed. This may reflect the integration being in a readiness/standby state pending a phishing incident type, or a missing Jira trigger that routes Avanan alert tickets into this flow.

Guard Detect redaction workflows are passive. Redact and redact_guard_detect_sensitive_data_alerts both sit at 0 executions despite generate_jira_guard_detect_alerts having 131 runs. If Guard Detect alerts contain sensitive data (PII, credentials), these redaction workflows should either fire as part of the alert creation flow or be confirmed as intentionally inactive.

Multiple workspace variants of the same workflow. Several workflows exist in 3–4 workspace variants with nearly identical names (e.g., three get_sentinelOne_latest_version_by_os across workspaces 349f0c7e, c35962f2, 57442628). This fragmentation across workspaces creates maintenance overhead and operational confusion about which is canonical. Consolidating to a single production workspace with a shared library pattern would reduce duplication.

Integration Ecosystem Map

Integration Use Cases Executions
Jira Alert mgmt, O365 detection, Vault lifecycle, On-call, Sprint mgmt, CVE 131+
PagerDuty On-call mgmt 625
Microsoft Graph / Entra ID Identity enrichment, On-call, O365 detection 185+
HashiCorp Vault Credential lifecycle 120+
1Password Credential lifecycle 120+
Microsoft Teams On-call notification, Asset inventory 625+
Guard Detect Alert management 131
SentinelOne Endpoint management 1,182
Rapid7 InsightVM Vulnerability management 0
Recorded Future Threat intel enrichment 0
Avanan Email security 0
VMware vSphere Asset inventory 0
JAMF Asset inventory 0
SharePoint Traveler registry 0
VirusTotal IOC verification 0
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 21 active | 4,096 tasks (12m)

AI Agents

Active Agents
21
of 23 total
Tasks Executed (12m)
4,096
375 in last 30d
Data Usage (12m)
150,565,169
23,131,706 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Eswar's Agent INFOSEC TEST Workspace 1,673 0 41,419,272
2 RF_IOC_extractor INFOSEC PROD Workspace 1,174 209 44,492,037
3 SOC Analyst for BlinkOps INFOSEC TEST Workspace 313 0 11,655,399
4 SOC Analyst for BlinkOps INFOSEC PROD Workspace 223 32 12,751,259
5 SentinelOne Discovery INFOSEC PROD Workspace 177 30 6,214,598
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
INFOSEC TEST Workspace2,134
INFOSEC PROD Workspace1,874
Sivahari.Jeyapandian@usanainc.com78
INFOSEC STAGE Workspace10
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
7
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 SentinelOne 00
2 test 00
3 Sentinelone_Agent_summary_Dashboard 00
4 testing 00
5 Test Dash Board 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 14 use cases | 3,389 executions (12m)

Business KPIs

Metric Count Playbook
Guard Detect security alerts auto-ticketed & enriched in Jira 131 generate_jira_guard_detect_alerts
Azure AD user profiles enriched on demand 185 get_azure_ad_users_details_by_email
On-call roster updates pushed to Teams & Slack 585 Update Teams and Slack PagerDuty On-call Group Name
Daily PagerDuty on-call syncs to Teams channels 40 update_PagerDuty_On-call_user_name_in_teams
Suspicious O365 foreign logins auto-investigated 40 Office 365 Successful Login from Foreign Country
Vault credential auto-renewals (every 8 hours, 24×7) 120 vault_creds_renewal
Transit key deletion tickets processed end-to-end 40 Transit Key Deletion Workflow
Security tickets auto-reassigned to analysts 20 jira_reassign_issue_to_user_by_email_address
Jira sprint transitions automated 1 jira_transition_new_sprint
SentinelOne agent activity events auto-processed via webhook 1,112 sentinelone_agent_activity_update
Jira agent package alerts auto-closed 21 jira_auto_close_agent_package_alerts
Weekly SentinelOne workstation dashboard reports emailed to SecOps 17 sentinelone_workstation_dashboard_email_report
In the last 12 months, Blink automated: - 1,112 SentinelOne agent activity events processed automatically via webhook — no manual monitoring required - 585 on-call roster updates pushed across Teams channels and Slack — zero manual channel edits - 185 Azure AD user profiles enriched automatically on analyst demand - 131 Guard Detect security alerts converted to enriched Jira tickets without analyst involvement - 120 HashiCorp Vault credential renewals executed autonomously (every 8 hours, around the clock) - 40 suspicious Office 365 foreign login events automatically investigated and routed - 40 transit key deletion tickets processed through full lifecycle - 21 Jira agent package alerts auto-closed without analyst involvement - 20 Jira security tickets auto-reassigned based on on-call schedules - 17 weekly SentinelOne workstation dashboard reports emailed to SecOps

Use Case Summary

# Use Case Category Subcategory Playbooks Executions (12 mo)
1 Guard Detect Alert Management SOC Case mgmt & SOAR 3 131
2 O365 Suspicious Login Detection SOC Identity threat response, SIEM & log pipeline monitoring 1 40
3 Recorded Future Threat Intel Enrichment SOC Threat intel ingest & curation 5 0
4 AI-Driven Security Operations SOC Agentic SOC 4 0
5 Avanan Email Security Investigation SOC Phishing detection & response 2 0
6 IOC Verification SOC Alert enrichment / IOC lookup 1 0
7 Azure AD Identity Enrichment IAM Identity sync & directory mgmt 5 185
8 Vault & Credential Lifecycle Management IAM Password & credential lifecycle 12 160
9 SentinelOne Endpoint Agent Management Other Endpoint hygiene & MDM ops 31 1,182
10 Rapid7 Vulnerability Intelligence Vulnerability Mgmt CVE lookup & remediation, Vuln lifecycle prioritize & ticket 10 0
11 On-Call Management & Cross-Platform Notification Other SaaS / IT administration 8 625
12 Jira Operations & Sprint Automation Other IT helpdesk & ticket routing 4 21
13 Infrastructure Asset Inventory Other IT/OT & network infra monitoring 3 0
14 Development & Sandbox — — 5 0
15 AD Password Policy Compliance Evidence Collection GRC Security metrics & reporting 1 0
Total 95 2,344

Use Cases

1. Guard Detect Alert Management

Description: Converts raw Guard Detect webhook events into enriched, structured Jira tickets and handles post-creation sensitive data redaction. Ensures every detection surfaces as a trackable security case within seconds of the alert firing.

Business problem solved: Guard Detect generates high volumes of security alerts that previously required manual ticket creation and sensitive-data cleanup. This use case eliminates that manual bottleneck and ensures consistent, auditable case records.

Key integrations: Guard Detect (webhook), Jira, Microsoft Graph (GraphQL)

Taxonomy: SOC → Case mgmt & SOAR

Playbook Executions Type Link
generate_jira_guard_detect_alerts 131 Event (webhook) Open
Redact 0 Event (Jira webhook) Open
redact_guard_detect_sensitive_data_alerts 0 Event (webhook) Open

2. O365 Suspicious Login Detection

Description: Runs daily at 8:05 AM MT to pull open Jira issues flagged as O365 successful logins from foreign countries, looks up the current SecOps on-call user via PagerDuty, and routes each alert through a per-issue investigation loop.

Business problem solved: Foreign login events in Office 365 require timely investigation but are easily missed in Jira queues. This use case ensures daily sweep coverage and automatic on-call routing without analyst calendar coordination.

Key integrations: Jira, PagerDuty, Microsoft 365

Taxonomy: SOC → Identity threat response, SIEM & log pipeline monitoring

Playbook Executions Type Link
Office 365 Successful Login from Foreign Country 40 Scheduled (daily 8:05 AM MT) Open

3. Recorded Future Threat Intel Enrichment

Description: Fetches and structures Recorded Future API reference documentation, loops through observable items to gather triage context, and annotates Jira tickets with enriched threat intelligence in Atlassian Document Format.

Business problem solved: Analysts manually consulting Recorded Future for each observable is slow and inconsistent. This use case automates intel retrieval and formats it directly onto the Jira ticket, reducing mean time to context.

Key integrations: Recorded Future, Jira, HTTP

Taxonomy: SOC → Threat intel ingest & curation

Playbook Executions Type Link
get_recorded_future_triage_context 0 On demand Open
get_cybersecurity_news_enrichment_details 0 On demand Open
get_recorded_future_api_references 0 On demand Open
get_recorded_future_api_references_context 0 On demand Open
get_recorded_future_api_reference_md_details 0 On demand Open

4. AI-Driven Security Operations

Description: A suite of agentic workflows that use Blink AI agents to select and execute the right workflow based on a natural-language prompt, evaluate risk decisions through an AI Risk Management Framework agent, and trigger the full capability set from Jira automation rules.

Business problem solved: Complex multi-step investigations previously required an analyst to know which workflow to run and manually chain lookups. These workflows enable prompt-driven automation — an analyst or Jira rule can describe intent in plain language and Blink orchestrates the rest.

Key integrations: Blink AI agents, Jira, Blink API

Taxonomy: SOC → Agentic SOC

Playbook Executions Type Link
jira_automation_rule_triggering_blinkops_ai 0 Event (Jira webhook) Open
AI_based_workflow_choose_and_execute_from_prompt 0 On demand Open
get_AI_RMF_Agent_decision_by_prompt 0 On demand Open
generate_documentation 0 On demand Open

5. Avanan Email Security Investigation

Description: Authenticates to the Avanan API using a HMAC-SHA256 token generation process and retrieves event details tied to email addresses extracted from Jira issues, with AI-assisted analysis of the event data for security insights.

Business problem solved: Investigating Avanan email security events requires multi-step API authentication and manual correlation with Jira case data. This use case automates the full enrichment pipeline from ticket context to Avanan event retrieval.

Key integrations: Avanan (HTTP), Jira, Microsoft Entra ID, Blink AI agents

Taxonomy: SOC → Phishing detection & response

Playbook Executions Type Link
get_avanan_event_details_email_address 0 On demand Open
get_avanan_auth_token 0 On demand Open

6. IOC Verification

Description: Accepts a CSV file of indicators, extracts the third column (IP addresses), and loops each through VirusTotal for scan results, storing findings in a table.

Business problem solved: Bulk IOC lookups against VirusTotal are tedious to run manually at scale. This use case automates batch IOC verification from structured input files.

Key integrations: VirusTotal (HTTP), Blink Tables

Taxonomy: SOC → Alert enrichment / IOC lookup

Playbook Executions Type Link
Verify IOC with VirusTotal 0 On demand Open

7. Azure AD Identity Enrichment

Description: Provides on-demand Azure AD / Entra ID lookups covering user profiles (with manager details), group memberships, email-to-name resolution, and Intune-managed device details by hostname. Used as a data enrichment layer across multiple SOC workflows.

Business problem solved: Analyst investigations regularly require user context (job title, manager, groups, enrolled devices) that spans multiple Microsoft Graph API calls. This use case consolidates those lookups into callable service functions, eliminating repetitive manual AD queries.

Key integrations: Microsoft Graph / Entra ID, Microsoft Intune

Taxonomy: IAM → Identity sync & directory mgmt

Playbook Executions Type Link
get_azure_ad_users_details_by_email 185 On demand Open
get_azure_ad_email_by_name 0 On demand Open
Get User's Groups 0 On demand Open
get_intune_device_details_by_hostname 0 On demand Open
get_azure_user_email_by_full_name 0 On demand Open

8. Vault & Credential Lifecycle Management

Description: Manages the full lifecycle of HashiCorp Vault credentials and 1Password secrets used by SecOps automation — from 32-day token creation through scheduled renewal, orphaned token recovery, and synchronized updates to Blink connections and 1Password vaults. A separate scheduled workflow handles Jira-ticketed transit key deletions.

Business problem solved: Vault tokens expire and if not renewed proactively, all downstream automation fails silently. This use case implements a fully autonomous credential renewal loop (every 8 hours) and provides Jira-driven transit key governance to eliminate operational gaps and audit trail deficiencies.

Key integrations: HashiCorp Vault, 1Password, Jira, Blink API

Taxonomy: IAM → Password & credential lifecycle

Playbook Executions Type Link
vault_creds_renewal 120 Scheduled (every 8 hrs) Open
Transit Key Deletion Workflow 40 Scheduled (daily 8 AM MT) Open
vault_creds_renewal - NEW 0 On demand Open
vault_32_day_token_renewal 0 On demand Open
get_vault_secrets 0 On demand Open
get_vault_secret() 0 On demand Open
get_vault_secrets_by_path 0 On demand Open
1password_get_vault_token 0 On demand Open
retrieve_vault_creds_from_1password 0 On demand Open
update_1Password_vault_token 0 On demand Open
get_new_orphaned_vault_token 0 On demand Open
Auth Creds Flow 0 On demand Open

9. SentinelOne Endpoint Agent Management

Description: A comprehensive set of workflows covering the full SentinelOne agent lifecycle: enumerating agents by group and machine type, identifying outdated or inactive machines, retrieving the latest available version per OS, initiating bulk upgrades, and monitoring upgrade task status. Multiple workspace variants reflect iterative development across sandbox and production environments.

Business problem solved: Keeping hundreds of workstation SentinelOne agents on the latest version is operationally intensive — agents must be inventoried by group, compared against the latest release, and upgraded in batches while tracking success/failure per host. This use case automates the entire identify-compare-upgrade-verify cycle.

Key integrations: SentinelOne, Jira, Blink AI agents (version resolution), Blink API (subflow orchestration)

Taxonomy: Other → Endpoint hygiene & MDM ops

Playbook Executions Type Link
get_sentinelOne_latest_version_by_os (prod) 24 On demand Open
SentinelOne Agent Version Validation and Upgrade Workflow 0 On demand Open
run_sentinelone_workstation_agent_upgrades_by_list (prod) 0 On demand Open
upgrade_the_workstation_to_the_latest_sentinelone_agent_version 0 On demand Open
get_sentinelone_agent_by_group_id 0 On demand (subflow) Open
run_sentinelone_workstation_agent_upgrades_by_list 0 On demand Open
get_sentinelone_upgrade_workstations_agents 0 On demand (subflow) Open
get_sentinelone_agents_workstation_group_ids 0 On demand Open
get_sentinelone_groups 0 On demand Open
get_sentinelone_agents_versions_by_group_id 0 On demand Open
get_sentinelone_workstation_agents_by_group_id 0 On demand Open
get_sentinelone_workstation_agents_task_status_by_hostname 0 On demand Open
get_sentinelone_by_hostname 0 On demand Open
get_sentinelOne_latest_version_by_os 0 On demand Open
get_sentinelone_machine_details_through_prompt_or_issueKey 0 On demand Open
sentinelone_get_outdated_workstations_agents_list 0 Event (Jira polling) Open
get_sentinelone_workstation_agents_by_group_id (poc) 0 On demand Open
get_sentinelOne_latest_version_by_os (poc) 0 On demand Open
sentinelone_upgrade_agents_bulk 0 On demand Open
Security Event Detected Multi 0 On demand Open
S1 Inactive Machine check - Sub Flow 0 Subflow Open
S1 Subflow - Latest Version Check 0 Subflow Open
Loop Through Site Ids and Groups Subflow 0 Subflow Open
Computer Subflow 0 Subflow Open
sentinelone_agent_activity_update 1112 Event (webhook) Open
jira_auto_close_agent_package_alerts 21 Event (Jira webhook) Open
sentinelone_workstation_dashboard_email_report 17 Scheduled (weekly Mon 8 AM MT) Open
sentinelone_stagger_test_report 4 On demand Open
sentinelone_staggered_based_agent_upgrade 2 On demand Open
winops_agents-list 1 On demand Open
china_stagger_agents_list 1 On demand Open

10. Rapid7 Vulnerability Intelligence

Description: Provides a complete CVE investigation toolkit: asset lookup by hostname or IP, CVE-to-affected-hosts mapping, vulnerability solution retrieval by CVE or vulnerability ID, and bulk asset deletion for decommissioned hosts. The CVE search workflow ties these together into a Jira-initiated investigation flow with AI-generated summaries.

Business problem solved: CVE investigations require correlating scanner data (which assets are affected) with remediation guidance (what to fix) and Jira ticket context — steps that span multiple Rapid7 API calls and manual lookups. This use case provides a single-entry-point investigation chain callable from Jira or on demand.

Key integrations: Rapid7 InsightVM / Nexpose, Jira, Blink AI agents

Taxonomy: Vulnerability Mgmt → CVE lookup & remediation, Vuln lifecycle prioritize & ticket

Playbook Executions Type Link
CVE search 0 On demand Open
Rapid7 CVE Search - subflow 0 On demand (subflow) Open
get_rapid7_nexpose_asset_details_by_hostname 0 On demand Open
get_rapid7_nexpose_asset_details_by_ip_address 0 On demand Open
get_rapid7_nexpose_vuln_hosts_by_cve_id 0 On demand Open
rapid7_get_solutions_for_cve_id 0 On demand Open
rapid7_get_vulnerability_solutions_by_vuln_Id 0 On demand Open
rapid7_get_asset_vulnerabilities_by_hostname 0 On demand Open
get_device_profile 0 On demand Open
delete_rapid7_asset_by_asset_id 0 On demand Open

11. On-Call Management & Cross-Platform Notification

Description: Maintains real-time on-call identity across Microsoft Teams channels and Slack by polling PagerDuty for the current SecOps on-call user (including override schedules) and propagating name/email updates to five Teams channel topics and the Slack on-call group — hourly for the main sync and daily for the Teams-specific update.

Business problem solved: When on-call rotates, Teams channel topics and Slack groups become stale within minutes unless manually updated — a toil-heavy process that fails silently during incident response. This use case makes on-call identity always current across all collaboration surfaces without any manual action.

Key integrations: PagerDuty, Microsoft Teams (Graph API), Slack, Blink Templates

Taxonomy: Other → SaaS / IT administration

Playbook Executions Type Link
Update Teams and Slack PagerDuty On-call Group Name 585 Scheduled (hourly) Open
get_pagerduty_secops_on_call_overrides 585 On demand (subflow) Open
update_PagerDuty_On-call_user_name_in_teams 40 Scheduled (daily 8:15 AM MT) Open
get_pagerduty_oncall_user_by_team 0 On demand Open
get_pagerduty_secops_oncall_user 0 On demand Open
get_on_call_user 0 On demand Open
get_on-call_user 0 On demand Open
get_pagerduty_oncall_by_creation_date 0 On demand Open

12. Jira Operations & Sprint Automation

Description: Provides Jira lifecycle utilities — searching issues by arbitrary JQL, reassigning tickets to on-call users by email, and fully automating bi-weekly sprint transitions (close old sprint, create new sprint, move open issues).

Business problem solved: Sprint management and ticket routing are recurring manual tasks that interrupt SecOps analysts. Auto-reassignment ensures tickets immediately reach the active on-call owner, while sprint transition eliminates a repetitive 7-step admin procedure.

Key integrations: Jira, Blink AI agents (sprint planning assistance)

Taxonomy: Other → IT helpdesk & ticket routing

Playbook Executions Type Link
jira_reassign_issue_to_user_by_email_address 20 On demand Open
jira_transition_new_sprint 1 Scheduled (bi-weekly Mon 8 AM MT) Open
search_by_jql 0 On demand Open
get_jira_attachment_file_content_by_attachment_id 0 On demand Open

13. Infrastructure Asset Inventory

Description: Cross-platform device and infrastructure lookup toolkit — retrieving VMware vSphere VM details by hostname, compiling a unified device profile from SentinelOne, Rapid7, Intune, JAMF, and vSphere in a single call, posting notification messages to Teams, and querying SharePoint for international traveler registrations.

Business problem solved: Device context during incidents requires querying 4–5 separate systems. The get_device_profile workflow aggregates SentinelOne agent details, Rapid7 asset data, Intune enrollment, JAMF records, and vSphere VM data into one structured output, cutting investigation time significantly.

Key integrations: VMware vSphere, SentinelOne, Rapid7, Microsoft Intune, JAMF, SharePoint, Microsoft Teams

Taxonomy: Other → IT/OT & network infra monitoring

Playbook Executions Type Link
get_device_profile 0 On demand Open
get_vsphere_vm_details_by_hostname 0 On demand Open
get_sharepoint_forms_travelers_data 0 On demand Open
post_to_teams 0 On demand Open

15. AD Password Policy Compliance Evidence Collection

Description: Remotely connects to a target Windows host over WinRM and executes a PowerShell script to collect Active Directory password policy configuration as auditable evidence.

Business problem solved: Compliance audits require documented proof of AD password policy settings, which is normally gathered through manual remote sessions and screenshots. This use case automates remote evidence collection via WinRM, producing a repeatable, auditable capture of policy state.

Key integrations: Windows Remote Management (WinRM), PowerShell

Taxonomy: GRC → Security metrics & reporting

Playbook Executions Type Link
ad_password_policy_powershell_evidence_collection 0 On demand Open

Key Observations

Strengths

Deep integration ecosystem. The automation library spans 14 integrated platforms: Jira, SentinelOne, Microsoft Graph/Entra ID, Rapid7 InsightVM, PagerDuty, HashiCorp Vault, 1Password, Microsoft Teams, Slack, Avanan, VMware vSphere, JAMF, Recorded Future, and SharePoint. This breadth places the environment among the more mature integration footprints.

Autonomous credential governance. The vault_creds_renewal workflow running every 8 hours represents a sophisticated, fully autonomous secret lifecycle. It checks token TTL via 1Password, creates an orphaned token via Vault API, updates the Blink connection, and syncs back to 1Password — all without human intervention. 120 executions over 12 months means this has reliably prevented at least 120 potential automation outages from credential expiry.

On-call propagation at scale. Pushing the SecOps on-call identity to five separate Teams channel topics plus a Slack group — every hour — is operationally significant. 585 executions with no manual involvement means the on-call channel topic has never been stale during business hours.

AI-first architecture emerging. Multiple workflows use Blink AI agents (agents.*) as reasoning steps — for sprint planning assistance, CVE summarization, SentinelOne version resolution, and prompt-driven workflow orchestration. The jira_automation_rule_triggering_blinkops_ai and AI_based_workflow_choose_and_execute_from_prompt patterns indicate investment in an agentic SecOps model where natural language drives automation selection.

Gaps & Opportunities

SentinelOne upgrade pipeline has begun activating. Staggered upgrade testing has started (sentinelone_stagger_test_report: 4 runs, sentinelone_staggered_based_agent_upgrade: 2 runs), alongside a new high-volume agent activity webhook (sentinelone_agent_activity_update: 1,112 runs) and a weekly dashboard email report (17 runs) that give SecOps ongoing visibility. The bulk upgrade initiation and task-status-tracking playbooks still show 0 executions, so full-scale rollout has not yet followed the successful staggered tests. Converting the validated stagger pattern into a scheduled, group-by-group rollout would realize the remaining endpoint hygiene value.

Rapid7 and Recorded Future libraries are unused. 10 Rapid7 and 5 Recorded Future workflows show 0 executions. These are well-structured (proper inputs/outputs, AI-assisted summaries) but appear to be capabilities built for future use. A defined trigger — such as a Jira CVE ticket label or a new Recorded Future alert — would activate this investment.

Avanan email investigation not triggered. The Avanan workflows exist with multi-step API token generation and AI analysis, but have never executed. This may reflect the integration being in a readiness/standby state pending a phishing incident type, or a missing Jira trigger that routes Avanan alert tickets into this flow.

Guard Detect redaction workflows are passive. Redact and redact_guard_detect_sensitive_data_alerts both sit at 0 executions despite generate_jira_guard_detect_alerts having 131 runs. If Guard Detect alerts contain sensitive data (PII, credentials), these redaction workflows should either fire as part of the alert creation flow or be confirmed as intentionally inactive.

Multiple workspace variants of the same workflow. Several workflows exist in 3–4 workspace variants with nearly identical names (e.g., three get_sentinelOne_latest_version_by_os across workspaces 349f0c7e, c35962f2, 57442628). This fragmentation across workspaces creates maintenance overhead and operational confusion about which is canonical. Consolidating to a single production workspace with a shared library pattern would reduce duplication.

Integration Ecosystem Map

Integration Use Cases Executions
Jira Alert mgmt, O365 detection, Vault lifecycle, On-call, Sprint mgmt, CVE 131+
PagerDuty On-call mgmt 625
Microsoft Graph / Entra ID Identity enrichment, On-call, O365 detection 185+
HashiCorp Vault Credential lifecycle 120+
1Password Credential lifecycle 120+
Microsoft Teams On-call notification, Asset inventory 625+
Guard Detect Alert management 131
SentinelOne Endpoint management 1,182
Rapid7 InsightVM Vulnerability management 0
Recorded Future Threat intel enrichment 0
Avanan Email security 0
VMware vSphere Asset inventory 0
JAMF Asset inventory 0
SharePoint Traveler registry 0
VirusTotal IOC verification 0
E New Integrations (detail) 6 added in last 30d

New Integrations Added - Last 30 Days

6 new connections
TenantIntegrationConnection NameAdded
usana bearer-token testing_beaerer_guard_detect_siva 2026-08-19
usana basic-auth testing_basic_auth_guard_detect_siva 2026-08-19
usana bearer-token testing_redat_guard 2026-08-18
usana basic-auth testing_guard_detect_redact 2026-08-18
usana kubernetes aws_kubernetes_runner_default_kubernetes_connection 2026-08-03
usana kubernetes aws_test_runner_k8s_default_kubernetes_connection 2026-08-03