01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Guard Detect Alert Management |
| 7.3% | 3 3 active |
| O365 Suspicious Login Detection |
| 0.0% | 1 1 active |
| Recorded Future Threat Intel Enrichment | 0 executions | 0.0% | 5 5 active |
| AI-Driven Security Operations | 0 executions | 0.0% | 4 4 active |
| Avanan Email Security Investigation | 0 executions | 0.0% | 2 2 active |
| IOC Verification | 0 executions | 0.0% | 1 1 active |
| Azure AD Identity Enrichment |
| 0.0% | 5 5 active |
| Vault & Credential Lifecycle Management |
| 1.2% | 11 9 active |
| SentinelOne Endpoint Agent Management |
| 37.4% | 27 25 active |
| Rapid7 Vulnerability Intelligence | 71 executions | 2.1% | 8 8 active |
| On-Call Management & Cross-Platform Notification |
| 2.3% | 8 8 active |
| Jira Operations & Sprint Automation |
| 0.7% | 4 4 active |
| Infrastructure Asset Inventory | 0 executions | 0.0% | 4 4 active |
| AD Password Policy Compliance Evidence Collection | 0 executions | 0.0% | 1 1 active |
| Total | 1,725 executions | 100% | 84 80 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep integration ecosystem. The automation library spans 14 integrated platforms: Jira, SentinelOne, Microsoft Graph/Entra ID, Rapid7 InsightVM, PagerDuty, HashiCorp Vault, 1Password, Microsoft Teams, Slack, Avanan, VMware vSphere, JAMF, Recorded Future, and SharePoint. This breadth places the environment among the more mature integration footprints.
Autonomous credential governance. The vault_creds_renewal workflow running every 8 hours represents a sophisticated, fully autonomous secret lifecycle. It checks token TTL via 1Password, creates an orphaned token via Vault API, updates the Blink connection, and syncs back to 1Password — all without human intervention. 120 executions over 12 months means this has reliably prevented at least 120 potential automation outages from credential expiry.
On-call propagation at scale. Pushing the SecOps on-call identity to five separate Teams channel topics plus a Slack group — every hour — is operationally significant. 585 executions with no manual involvement means the on-call channel topic has never been stale during business hours.
AI-first architecture emerging. Multiple workflows use Blink AI agents (agents.*) as reasoning steps — for sprint planning assistance, CVE summarization, SentinelOne version resolution, and prompt-driven workflow orchestration. The jira_automation_rule_triggering_blinkops_ai and AI_based_workflow_choose_and_execute_from_prompt patterns indicate investment in an agentic SecOps model where natural language drives automation selection.
###
Gaps & Opportunities
SentinelOne upgrade pipeline has begun activating. Staggered upgrade testing has started (sentinelone_stagger_test_report: 4 runs, sentinelone_staggered_based_agent_upgrade: 2 runs), alongside a new high-volume agent activity webhook (sentinelone_agent_activity_update: 1,112 runs) and a weekly dashboard email report (17 runs) that give SecOps ongoing visibility. The bulk upgrade initiation and task-status-tracking playbooks still show 0 executions, so full-scale rollout has not yet followed the successful staggered tests. Converting the validated stagger pattern into a scheduled, group-by-group rollout would realize the remaining endpoint hygiene value.
Rapid7 and Recorded Future libraries are unused. 10 Rapid7 and 5 Recorded Future workflows show 0 executions. These are well-structured (proper inputs/outputs, AI-assisted summaries) but appear to be capabilities built for future use. A defined trigger — such as a Jira CVE ticket label or a new Recorded Future alert — would activate this investment.
Avanan email investigation not triggered. The Avanan workflows exist with multi-step API token generation and AI analysis, but have never executed. This may reflect the integration being in a readiness/standby state pending a phishing incident type, or a missing Jira trigger that routes Avanan alert tickets into this flow.
Guard Detect redaction workflows are passive. Redact and redact_guard_detect_sensitive_data_alerts both sit at 0 executions despite generate_jira_guard_detect_alerts having 131 runs. If Guard Detect alerts contain sensitive data (PII, credentials), these redaction workflows should either fire as part of the alert creation flow or be confirmed as intentionally inactive.
Multiple workspace variants of the same workflow. Several workflows exist in 3–4 workspace variants with nearly identical names (e.g., three get_sentinelOne_latest_version_by_os across workspaces 349f0c7e, c35962f2, 57442628). This fragmentation across workspaces creates maintenance overhead and operational confusion about which is canonical. Consolidating to a single production workspace with a shared library pattern would reduce duplication.
Integration Ecosystem Map
| Integration | Use Cases | Executions |
|---|---|---|
| Jira | Alert mgmt, O365 detection, Vault lifecycle, On-call, Sprint mgmt, CVE | 131+ |
| PagerDuty | On-call mgmt | 625 |
| Microsoft Graph / Entra ID | Identity enrichment, On-call, O365 detection | 185+ |
| HashiCorp Vault | Credential lifecycle | 120+ |
| 1Password | Credential lifecycle | 120+ |
| Microsoft Teams | On-call notification, Asset inventory | 625+ |
| Guard Detect | Alert management | 131 |
| SentinelOne | Endpoint management | 1,182 |
| Rapid7 InsightVM | Vulnerability management | 0 |
| Recorded Future | Threat intel enrichment | 0 |
| Avanan | Email security | 0 |
| VMware vSphere | Asset inventory | 0 |
| JAMF | Asset inventory | 0 |
| SharePoint | Traveler registry | 0 |
| VirusTotal | IOC verification | 0 |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 21 active | 4,096 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Eswar's Agent | INFOSEC TEST Workspace | 1,673 | 0 | 41,419,272 |
| 2 | RF_IOC_extractor | INFOSEC PROD Workspace | 1,174 | 209 | 44,492,037 |
| 3 | SOC Analyst for BlinkOps | INFOSEC TEST Workspace | 313 | 0 | 11,655,399 |
| 4 | SOC Analyst for BlinkOps | INFOSEC PROD Workspace | 223 | 32 | 12,751,259 |
| 5 | SentinelOne Discovery | INFOSEC PROD Workspace | 177 | 30 | 6,214,598 |
| Workspace | Tasks (12m) |
|---|---|
| INFOSEC TEST Workspace | 2,134 |
| INFOSEC PROD Workspace | 1,874 |
| Sivahari.Jeyapandian@usanainc.com | 78 |
| INFOSEC STAGE Workspace | 10 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | SentinelOne | 0 | 0 |
| 2 | test | 0 | 0 |
| 3 | Sentinelone_Agent_summary_Dashboard | 0 | 0 |
| 4 | testing | 0 | 0 |
| 5 | Test Dash Board | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 14 use cases | 3,389 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Guard Detect security alerts auto-ticketed & enriched in Jira | 131 | generate_jira_guard_detect_alerts |
| Azure AD user profiles enriched on demand | 185 | get_azure_ad_users_details_by_email |
| On-call roster updates pushed to Teams & Slack | 585 | Update Teams and Slack PagerDuty On-call Group Name |
| Daily PagerDuty on-call syncs to Teams channels | 40 | update_PagerDuty_On-call_user_name_in_teams |
| Suspicious O365 foreign logins auto-investigated | 40 | Office 365 Successful Login from Foreign Country |
| Vault credential auto-renewals (every 8 hours, 24×7) | 120 | vault_creds_renewal |
| Transit key deletion tickets processed end-to-end | 40 | Transit Key Deletion Workflow |
| Security tickets auto-reassigned to analysts | 20 | jira_reassign_issue_to_user_by_email_address |
| Jira sprint transitions automated | 1 | jira_transition_new_sprint |
| SentinelOne agent activity events auto-processed via webhook | 1,112 | sentinelone_agent_activity_update |
| Jira agent package alerts auto-closed | 21 | jira_auto_close_agent_package_alerts |
| Weekly SentinelOne workstation dashboard reports emailed to SecOps | 17 | sentinelone_workstation_dashboard_email_report |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks | Executions (12 mo) |
|---|---|---|---|---|---|
| 1 | Guard Detect Alert Management | SOC | Case mgmt & SOAR | 3 | 131 |
| 2 | O365 Suspicious Login Detection | SOC | Identity threat response, SIEM & log pipeline monitoring | 1 | 40 |
| 3 | Recorded Future Threat Intel Enrichment | SOC | Threat intel ingest & curation | 5 | 0 |
| 4 | AI-Driven Security Operations | SOC | Agentic SOC | 4 | 0 |
| 5 | Avanan Email Security Investigation | SOC | Phishing detection & response | 2 | 0 |
| 6 | IOC Verification | SOC | Alert enrichment / IOC lookup | 1 | 0 |
| 7 | Azure AD Identity Enrichment | IAM | Identity sync & directory mgmt | 5 | 185 |
| 8 | Vault & Credential Lifecycle Management | IAM | Password & credential lifecycle | 12 | 160 |
| 9 | SentinelOne Endpoint Agent Management | Other | Endpoint hygiene & MDM ops | 31 | 1,182 |
| 10 | Rapid7 Vulnerability Intelligence | Vulnerability Mgmt | CVE lookup & remediation, Vuln lifecycle prioritize & ticket | 10 | 0 |
| 11 | On-Call Management & Cross-Platform Notification | Other | SaaS / IT administration | 8 | 625 |
| 12 | Jira Operations & Sprint Automation | Other | IT helpdesk & ticket routing | 4 | 21 |
| 13 | Infrastructure Asset Inventory | Other | IT/OT & network infra monitoring | 3 | 0 |
| 14 | Development & Sandbox | — | — | 5 | 0 |
| 15 | AD Password Policy Compliance Evidence Collection | GRC | Security metrics & reporting | 1 | 0 |
| Total | 95 | 2,344 |
Use Cases
1. Guard Detect Alert Management
Description: Converts raw Guard Detect webhook events into enriched, structured Jira tickets and handles post-creation sensitive data redaction. Ensures every detection surfaces as a trackable security case within seconds of the alert firing.
Business problem solved: Guard Detect generates high volumes of security alerts that previously required manual ticket creation and sensitive-data cleanup. This use case eliminates that manual bottleneck and ensures consistent, auditable case records.
Key integrations: Guard Detect (webhook), Jira, Microsoft Graph (GraphQL)
Taxonomy: SOC → Case mgmt & SOAR
| Playbook | Executions | Type | Link |
|---|---|---|---|
| generate_jira_guard_detect_alerts | 131 | Event (webhook) | Open |
| Redact | 0 | Event (Jira webhook) | Open |
| redact_guard_detect_sensitive_data_alerts | 0 | Event (webhook) | Open |
2. O365 Suspicious Login Detection
Description: Runs daily at 8:05 AM MT to pull open Jira issues flagged as O365 successful logins from foreign countries, looks up the current SecOps on-call user via PagerDuty, and routes each alert through a per-issue investigation loop.
Business problem solved: Foreign login events in Office 365 require timely investigation but are easily missed in Jira queues. This use case ensures daily sweep coverage and automatic on-call routing without analyst calendar coordination.
Key integrations: Jira, PagerDuty, Microsoft 365
Taxonomy: SOC → Identity threat response, SIEM & log pipeline monitoring
| Playbook | Executions | Type | Link |
|---|---|---|---|
| Office 365 Successful Login from Foreign Country | 40 | Scheduled (daily 8:05 AM MT) | Open |
3. Recorded Future Threat Intel Enrichment
Description: Fetches and structures Recorded Future API reference documentation, loops through observable items to gather triage context, and annotates Jira tickets with enriched threat intelligence in Atlassian Document Format.
Business problem solved: Analysts manually consulting Recorded Future for each observable is slow and inconsistent. This use case automates intel retrieval and formats it directly onto the Jira ticket, reducing mean time to context.
Key integrations: Recorded Future, Jira, HTTP
Taxonomy: SOC → Threat intel ingest & curation
| Playbook | Executions | Type | Link |
|---|---|---|---|
| get_recorded_future_triage_context | 0 | On demand | Open |
| get_cybersecurity_news_enrichment_details | 0 | On demand | Open |
| get_recorded_future_api_references | 0 | On demand | Open |
| get_recorded_future_api_references_context | 0 | On demand | Open |
| get_recorded_future_api_reference_md_details | 0 | On demand | Open |
4. AI-Driven Security Operations
Description: A suite of agentic workflows that use Blink AI agents to select and execute the right workflow based on a natural-language prompt, evaluate risk decisions through an AI Risk Management Framework agent, and trigger the full capability set from Jira automation rules.
Business problem solved: Complex multi-step investigations previously required an analyst to know which workflow to run and manually chain lookups. These workflows enable prompt-driven automation — an analyst or Jira rule can describe intent in plain language and Blink orchestrates the rest.
Key integrations: Blink AI agents, Jira, Blink API
Taxonomy: SOC → Agentic SOC
| Playbook | Executions | Type | Link |
|---|---|---|---|
| jira_automation_rule_triggering_blinkops_ai | 0 | Event (Jira webhook) | Open |
| AI_based_workflow_choose_and_execute_from_prompt | 0 | On demand | Open |
| get_AI_RMF_Agent_decision_by_prompt | 0 | On demand | Open |
| generate_documentation | 0 | On demand | Open |
5. Avanan Email Security Investigation
Description: Authenticates to the Avanan API using a HMAC-SHA256 token generation process and retrieves event details tied to email addresses extracted from Jira issues, with AI-assisted analysis of the event data for security insights.
Business problem solved: Investigating Avanan email security events requires multi-step API authentication and manual correlation with Jira case data. This use case automates the full enrichment pipeline from ticket context to Avanan event retrieval.
Key integrations: Avanan (HTTP), Jira, Microsoft Entra ID, Blink AI agents
Taxonomy: SOC → Phishing detection & response
| Playbook | Executions | Type | Link |
|---|---|---|---|
| get_avanan_event_details_email_address | 0 | On demand | Open |
| get_avanan_auth_token | 0 | On demand | Open |
6. IOC Verification
Description: Accepts a CSV file of indicators, extracts the third column (IP addresses), and loops each through VirusTotal for scan results, storing findings in a table.
Business problem solved: Bulk IOC lookups against VirusTotal are tedious to run manually at scale. This use case automates batch IOC verification from structured input files.
Key integrations: VirusTotal (HTTP), Blink Tables
Taxonomy: SOC → Alert enrichment / IOC lookup
| Playbook | Executions | Type | Link |
|---|---|---|---|
| Verify IOC with VirusTotal | 0 | On demand | Open |
7. Azure AD Identity Enrichment
Description: Provides on-demand Azure AD / Entra ID lookups covering user profiles (with manager details), group memberships, email-to-name resolution, and Intune-managed device details by hostname. Used as a data enrichment layer across multiple SOC workflows.
Business problem solved: Analyst investigations regularly require user context (job title, manager, groups, enrolled devices) that spans multiple Microsoft Graph API calls. This use case consolidates those lookups into callable service functions, eliminating repetitive manual AD queries.
Key integrations: Microsoft Graph / Entra ID, Microsoft Intune
Taxonomy: IAM → Identity sync & directory mgmt
| Playbook | Executions | Type | Link |
|---|---|---|---|
| get_azure_ad_users_details_by_email | 185 | On demand | Open |
| get_azure_ad_email_by_name | 0 | On demand | Open |
| Get User's Groups | 0 | On demand | Open |
| get_intune_device_details_by_hostname | 0 | On demand | Open |
| get_azure_user_email_by_full_name | 0 | On demand | Open |
8. Vault & Credential Lifecycle Management
Description: Manages the full lifecycle of HashiCorp Vault credentials and 1Password secrets used by SecOps automation — from 32-day token creation through scheduled renewal, orphaned token recovery, and synchronized updates to Blink connections and 1Password vaults. A separate scheduled workflow handles Jira-ticketed transit key deletions.
Business problem solved: Vault tokens expire and if not renewed proactively, all downstream automation fails silently. This use case implements a fully autonomous credential renewal loop (every 8 hours) and provides Jira-driven transit key governance to eliminate operational gaps and audit trail deficiencies.
Key integrations: HashiCorp Vault, 1Password, Jira, Blink API
Taxonomy: IAM → Password & credential lifecycle
| Playbook | Executions | Type | Link |
|---|---|---|---|
| vault_creds_renewal | 120 | Scheduled (every 8 hrs) | Open |
| Transit Key Deletion Workflow | 40 | Scheduled (daily 8 AM MT) | Open |
| vault_creds_renewal - NEW | 0 | On demand | Open |
| vault_32_day_token_renewal | 0 | On demand | Open |
| get_vault_secrets | 0 | On demand | Open |
| get_vault_secret() | 0 | On demand | Open |
| get_vault_secrets_by_path | 0 | On demand | Open |
| 1password_get_vault_token | 0 | On demand | Open |
| retrieve_vault_creds_from_1password | 0 | On demand | Open |
| update_1Password_vault_token | 0 | On demand | Open |
| get_new_orphaned_vault_token | 0 | On demand | Open |
| Auth Creds Flow | 0 | On demand | Open |
9. SentinelOne Endpoint Agent Management
Description: A comprehensive set of workflows covering the full SentinelOne agent lifecycle: enumerating agents by group and machine type, identifying outdated or inactive machines, retrieving the latest available version per OS, initiating bulk upgrades, and monitoring upgrade task status. Multiple workspace variants reflect iterative development across sandbox and production environments.
Business problem solved: Keeping hundreds of workstation SentinelOne agents on the latest version is operationally intensive — agents must be inventoried by group, compared against the latest release, and upgraded in batches while tracking success/failure per host. This use case automates the entire identify-compare-upgrade-verify cycle.
Key integrations: SentinelOne, Jira, Blink AI agents (version resolution), Blink API (subflow orchestration)
Taxonomy: Other → Endpoint hygiene & MDM ops
| Playbook | Executions | Type | Link |
|---|---|---|---|
| get_sentinelOne_latest_version_by_os (prod) | 24 | On demand | Open |
| SentinelOne Agent Version Validation and Upgrade Workflow | 0 | On demand | Open |
| run_sentinelone_workstation_agent_upgrades_by_list (prod) | 0 | On demand | Open |
| upgrade_the_workstation_to_the_latest_sentinelone_agent_version | 0 | On demand | Open |
| get_sentinelone_agent_by_group_id | 0 | On demand (subflow) | Open |
| run_sentinelone_workstation_agent_upgrades_by_list | 0 | On demand | Open |
| get_sentinelone_upgrade_workstations_agents | 0 | On demand (subflow) | Open |
| get_sentinelone_agents_workstation_group_ids | 0 | On demand | Open |
| get_sentinelone_groups | 0 | On demand | Open |
| get_sentinelone_agents_versions_by_group_id | 0 | On demand | Open |
| get_sentinelone_workstation_agents_by_group_id | 0 | On demand | Open |
| get_sentinelone_workstation_agents_task_status_by_hostname | 0 | On demand | Open |
| get_sentinelone_by_hostname | 0 | On demand | Open |
| get_sentinelOne_latest_version_by_os | 0 | On demand | Open |
| get_sentinelone_machine_details_through_prompt_or_issueKey | 0 | On demand | Open |
| sentinelone_get_outdated_workstations_agents_list | 0 | Event (Jira polling) | Open |
| get_sentinelone_workstation_agents_by_group_id (poc) | 0 | On demand | Open |
| get_sentinelOne_latest_version_by_os (poc) | 0 | On demand | Open |
| sentinelone_upgrade_agents_bulk | 0 | On demand | Open |
| Security Event Detected Multi | 0 | On demand | Open |
| S1 Inactive Machine check - Sub Flow | 0 | Subflow | Open |
| S1 Subflow - Latest Version Check | 0 | Subflow | Open |
| Loop Through Site Ids and Groups Subflow | 0 | Subflow | Open |
| Computer Subflow | 0 | Subflow | Open |
| sentinelone_agent_activity_update | 1112 | Event (webhook) | Open |
| jira_auto_close_agent_package_alerts | 21 | Event (Jira webhook) | Open |
| sentinelone_workstation_dashboard_email_report | 17 | Scheduled (weekly Mon 8 AM MT) | Open |
| sentinelone_stagger_test_report | 4 | On demand | Open |
| sentinelone_staggered_based_agent_upgrade | 2 | On demand | Open |
| winops_agents-list | 1 | On demand | Open |
| china_stagger_agents_list | 1 | On demand | Open |
10. Rapid7 Vulnerability Intelligence
Description: Provides a complete CVE investigation toolkit: asset lookup by hostname or IP, CVE-to-affected-hosts mapping, vulnerability solution retrieval by CVE or vulnerability ID, and bulk asset deletion for decommissioned hosts. The CVE search workflow ties these together into a Jira-initiated investigation flow with AI-generated summaries.
Business problem solved: CVE investigations require correlating scanner data (which assets are affected) with remediation guidance (what to fix) and Jira ticket context — steps that span multiple Rapid7 API calls and manual lookups. This use case provides a single-entry-point investigation chain callable from Jira or on demand.
Key integrations: Rapid7 InsightVM / Nexpose, Jira, Blink AI agents
Taxonomy: Vulnerability Mgmt → CVE lookup & remediation, Vuln lifecycle prioritize & ticket
| Playbook | Executions | Type | Link |
|---|---|---|---|
| CVE search | 0 | On demand | Open |
| Rapid7 CVE Search - subflow | 0 | On demand (subflow) | Open |
| get_rapid7_nexpose_asset_details_by_hostname | 0 | On demand | Open |
| get_rapid7_nexpose_asset_details_by_ip_address | 0 | On demand | Open |
| get_rapid7_nexpose_vuln_hosts_by_cve_id | 0 | On demand | Open |
| rapid7_get_solutions_for_cve_id | 0 | On demand | Open |
| rapid7_get_vulnerability_solutions_by_vuln_Id | 0 | On demand | Open |
| rapid7_get_asset_vulnerabilities_by_hostname | 0 | On demand | Open |
| get_device_profile | 0 | On demand | Open |
| delete_rapid7_asset_by_asset_id | 0 | On demand | Open |
11. On-Call Management & Cross-Platform Notification
Description: Maintains real-time on-call identity across Microsoft Teams channels and Slack by polling PagerDuty for the current SecOps on-call user (including override schedules) and propagating name/email updates to five Teams channel topics and the Slack on-call group — hourly for the main sync and daily for the Teams-specific update.
Business problem solved: When on-call rotates, Teams channel topics and Slack groups become stale within minutes unless manually updated — a toil-heavy process that fails silently during incident response. This use case makes on-call identity always current across all collaboration surfaces without any manual action.
Key integrations: PagerDuty, Microsoft Teams (Graph API), Slack, Blink Templates
Taxonomy: Other → SaaS / IT administration
| Playbook | Executions | Type | Link |
|---|---|---|---|
| Update Teams and Slack PagerDuty On-call Group Name | 585 | Scheduled (hourly) | Open |
| get_pagerduty_secops_on_call_overrides | 585 | On demand (subflow) | Open |
| update_PagerDuty_On-call_user_name_in_teams | 40 | Scheduled (daily 8:15 AM MT) | Open |
| get_pagerduty_oncall_user_by_team | 0 | On demand | Open |
| get_pagerduty_secops_oncall_user | 0 | On demand | Open |
| get_on_call_user | 0 | On demand | Open |
| get_on-call_user | 0 | On demand | Open |
| get_pagerduty_oncall_by_creation_date | 0 | On demand | Open |
12. Jira Operations & Sprint Automation
Description: Provides Jira lifecycle utilities — searching issues by arbitrary JQL, reassigning tickets to on-call users by email, and fully automating bi-weekly sprint transitions (close old sprint, create new sprint, move open issues).
Business problem solved: Sprint management and ticket routing are recurring manual tasks that interrupt SecOps analysts. Auto-reassignment ensures tickets immediately reach the active on-call owner, while sprint transition eliminates a repetitive 7-step admin procedure.
Key integrations: Jira, Blink AI agents (sprint planning assistance)
Taxonomy: Other → IT helpdesk & ticket routing
| Playbook | Executions | Type | Link |
|---|---|---|---|
| jira_reassign_issue_to_user_by_email_address | 20 | On demand | Open |
| jira_transition_new_sprint | 1 | Scheduled (bi-weekly Mon 8 AM MT) | Open |
| search_by_jql | 0 | On demand | Open |
| get_jira_attachment_file_content_by_attachment_id | 0 | On demand | Open |
13. Infrastructure Asset Inventory
Description: Cross-platform device and infrastructure lookup toolkit — retrieving VMware vSphere VM details by hostname, compiling a unified device profile from SentinelOne, Rapid7, Intune, JAMF, and vSphere in a single call, posting notification messages to Teams, and querying SharePoint for international traveler registrations.
Business problem solved: Device context during incidents requires querying 4–5 separate systems. The get_device_profile workflow aggregates SentinelOne agent details, Rapid7 asset data, Intune enrollment, JAMF records, and vSphere VM data into one structured output, cutting investigation time significantly.
Key integrations: VMware vSphere, SentinelOne, Rapid7, Microsoft Intune, JAMF, SharePoint, Microsoft Teams
Taxonomy: Other → IT/OT & network infra monitoring
| Playbook | Executions | Type | Link |
|---|---|---|---|
| get_device_profile | 0 | On demand | Open |
| get_vsphere_vm_details_by_hostname | 0 | On demand | Open |
| get_sharepoint_forms_travelers_data | 0 | On demand | Open |
| post_to_teams | 0 | On demand | Open |
15. AD Password Policy Compliance Evidence Collection
Description: Remotely connects to a target Windows host over WinRM and executes a PowerShell script to collect Active Directory password policy configuration as auditable evidence.
Business problem solved: Compliance audits require documented proof of AD password policy settings, which is normally gathered through manual remote sessions and screenshots. This use case automates remote evidence collection via WinRM, producing a repeatable, auditable capture of policy state.
Key integrations: Windows Remote Management (WinRM), PowerShell
Taxonomy: GRC → Security metrics & reporting
| Playbook | Executions | Type | Link |
|---|---|---|---|
| ad_password_policy_powershell_evidence_collection | 0 | On demand | Open |
Key Observations
Strengths
Deep integration ecosystem. The automation library spans 14 integrated platforms: Jira, SentinelOne, Microsoft Graph/Entra ID, Rapid7 InsightVM, PagerDuty, HashiCorp Vault, 1Password, Microsoft Teams, Slack, Avanan, VMware vSphere, JAMF, Recorded Future, and SharePoint. This breadth places the environment among the more mature integration footprints.
Autonomous credential governance. The vault_creds_renewal workflow running every 8 hours represents a sophisticated, fully autonomous secret lifecycle. It checks token TTL via 1Password, creates an orphaned token via Vault API, updates the Blink connection, and syncs back to 1Password — all without human intervention. 120 executions over 12 months means this has reliably prevented at least 120 potential automation outages from credential expiry.
On-call propagation at scale. Pushing the SecOps on-call identity to five separate Teams channel topics plus a Slack group — every hour — is operationally significant. 585 executions with no manual involvement means the on-call channel topic has never been stale during business hours.
AI-first architecture emerging. Multiple workflows use Blink AI agents (agents.*) as reasoning steps — for sprint planning assistance, CVE summarization, SentinelOne version resolution, and prompt-driven workflow orchestration. The jira_automation_rule_triggering_blinkops_ai and AI_based_workflow_choose_and_execute_from_prompt patterns indicate investment in an agentic SecOps model where natural language drives automation selection.
Gaps & Opportunities
SentinelOne upgrade pipeline has begun activating. Staggered upgrade testing has started (sentinelone_stagger_test_report: 4 runs, sentinelone_staggered_based_agent_upgrade: 2 runs), alongside a new high-volume agent activity webhook (sentinelone_agent_activity_update: 1,112 runs) and a weekly dashboard email report (17 runs) that give SecOps ongoing visibility. The bulk upgrade initiation and task-status-tracking playbooks still show 0 executions, so full-scale rollout has not yet followed the successful staggered tests. Converting the validated stagger pattern into a scheduled, group-by-group rollout would realize the remaining endpoint hygiene value.
Rapid7 and Recorded Future libraries are unused. 10 Rapid7 and 5 Recorded Future workflows show 0 executions. These are well-structured (proper inputs/outputs, AI-assisted summaries) but appear to be capabilities built for future use. A defined trigger — such as a Jira CVE ticket label or a new Recorded Future alert — would activate this investment.
Avanan email investigation not triggered. The Avanan workflows exist with multi-step API token generation and AI analysis, but have never executed. This may reflect the integration being in a readiness/standby state pending a phishing incident type, or a missing Jira trigger that routes Avanan alert tickets into this flow.
Guard Detect redaction workflows are passive. Redact and redact_guard_detect_sensitive_data_alerts both sit at 0 executions despite generate_jira_guard_detect_alerts having 131 runs. If Guard Detect alerts contain sensitive data (PII, credentials), these redaction workflows should either fire as part of the alert creation flow or be confirmed as intentionally inactive.
Multiple workspace variants of the same workflow. Several workflows exist in 3–4 workspace variants with nearly identical names (e.g., three get_sentinelOne_latest_version_by_os across workspaces 349f0c7e, c35962f2, 57442628). This fragmentation across workspaces creates maintenance overhead and operational confusion about which is canonical. Consolidating to a single production workspace with a shared library pattern would reduce duplication.
Integration Ecosystem Map
| Integration | Use Cases | Executions |
|---|---|---|
| Jira | Alert mgmt, O365 detection, Vault lifecycle, On-call, Sprint mgmt, CVE | 131+ |
| PagerDuty | On-call mgmt | 625 |
| Microsoft Graph / Entra ID | Identity enrichment, On-call, O365 detection | 185+ |
| HashiCorp Vault | Credential lifecycle | 120+ |
| 1Password | Credential lifecycle | 120+ |
| Microsoft Teams | On-call notification, Asset inventory | 625+ |
| Guard Detect | Alert management | 131 |
| SentinelOne | Endpoint management | 1,182 |
| Rapid7 InsightVM | Vulnerability management | 0 |
| Recorded Future | Threat intel enrichment | 0 |
| Avanan | Email security | 0 |
| VMware vSphere | Asset inventory | 0 |
| JAMF | Asset inventory | 0 |
| SharePoint | Traveler registry | 0 |
| VirusTotal | IOC verification | 0 |
E New Integrations (detail) 6 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| usana | bearer-token | testing_beaerer_guard_detect_siva | 2026-08-19 |
| usana | basic-auth | testing_basic_auth_guard_detect_siva | 2026-08-19 |
| usana | bearer-token | testing_redat_guard | 2026-08-18 |
| usana | basic-auth | testing_guard_detect_redact | 2026-08-18 |
| usana | kubernetes | aws_kubernetes_runner_default_kubernetes_connection | 2026-08-03 |
| usana | kubernetes | aws_test_runner_k8s_default_kubernetes_connection | 2026-08-03 |