Blink Security Automation — Confidential

Vinmar — Customer Success Report

Generated 2026-08-31 | vinmar-value-report.md
2026-08-31Report Date
49Total Playbooks
22Unique Workflows (12m)
4,343Actions Automated (12m)
$1,117Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

49
Total playbooks built
all non-deleted workflows
25
Active playbooks
currently enabled
22
Unique workflows executed (12m)
distinct workflows that ran
4,343
Actions automated (12m)
completed action steps
24.1h
Hours saved (12m)
@ 20s per action
$1,117
Money saved (12m)
@ $100K avg salary
4
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
2
Active AI agents
of 2 total
41
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1 endpoint device inventory sync completed - 6 device inventory table updates completed - 7 device compliance dashboard refreshes - 5 device compliance dashboards sent to management - 4 device compliance reports sent to IT team - 26 device registration type change reports generated - 1 Tanium vulnerability severity report generated - 1 Tanium vulnerability dashboard refresh - 1 Tanium vulnerabilities dashboard sent to management

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Legal Document Automation & AI Review0 executions
0.0%
3
3 active
Endpoint & Asset Inventory
  • 26Device registration type change reports generated
  • 7Device compliance dashboard refreshes
  • 6Device inventory table updates completed
81.5%
9
9 active
Agentic Data-Driven Investigation0 executions
0.0%
1
1 active
Utilities & Subflows0 executions
0.0%
6
6 active
Tanium Vulnerability Reporting
  • 1Tanium vulnerability severity reports generated
  • 1Tanium vulnerability dashboard refreshes
  • 1Tanium vulnerabilities dashboards sent to management
3.7%
3
3 active
Total69 executions100%
22
22 active

Use Case Growth Over Time

41 unique playbooks  |  5 operational use cases  |  81 total executions (12m)  |  2026-02 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Utilities & Subflows
Email Microsoft Entra ID
Agentic Data-Driven Investigation
Agents
Legal Document Automation & AI Review
Email Docusign Web Form Agents
Endpoint & Asset Inventory
Absolute SentinelOne Tanium Dashboards Email Microsoft Entra ID
Tanium Vulnerability Reporting
Tanium Dashboards Email

04Key Observations

✓  Strengths

Strengths

  • Differentiated AI-native use case: The legal automation suite (NDA generation + agentic contract review) is a non-standard Blink deployment that extends automation into legal operations — a high-value, underserved domain. The "Vinmar Legal Triage Agent | AI Corporate Paralegal & Contract Analyst" is a purpose-built AI agent, reflecting real investment in agentic capability.
  • Multi-source endpoint inventory architecture: Building a unified asset registry from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker simultaneously demonstrates a mature understanding of how to use Blink Tables as a normalization layer across heterogeneous security tooling.
  • Governed self-service via Web Forms: The NDA Secure Submission Workflow uses a branded web form with an approval gate — a production-ready pattern that enables business users to self-serve without bypassing legal controls.
  • Security-conscious agent tooling: The Agent SQL Query Data subflow includes a Python-based SQL injection threat analysis step before execution — showing deliberate attention to safe agentic tool design.
  • Endpoint use case matured into a full reporting pipeline: What began as three device-ingestion workflows has grown into a nine-playbook pipeline — adding Entra and ThreatLocker as sources, a consolidated device table, an HTML compliance widget, and scheduled email distribution to both IT and management. The daily Device Registration Type Changes Report (26 executions/12mo) is the account's highest-volume workflow.
  • First production vulnerability metrics pipeline: The new Tanium Vulnerability Reporting use case chains data collection, historical recording, dashboard refresh, and executive email distribution into one weekly scheduled flow — establishing a repeatable pattern that could extend to other vulnerability or EDR data sources.

###

△  Gaps & Growth Opportunities

Gaps

  • Low production execution volume: 14 of 23 workflows have zero executions in the last 12 months. Legal operations, agentic investigation, and infrastructure subflows are well-designed but not yet in active production use. The priority should be identifying what is blocking go-live across the legal and SOC workspaces.
  • Scheduled triggers now live for device workflows: The Device Registration Type Changes Report (daily) and Tanium - Vulnerability Count By Severity (weekly) now run on scheduled triggers, driving the bulk of the account's execution volume. Extending scheduled triggers to the remaining on_demand device inventory workflows (SentinelOne, Tanium, ThreatLocker device syncs) would further increase asset hygiene coverage.
  • SOC coverage is nascent: The Agentic Data-Driven Investigation workflow is the only SOC-category automation, and it has no executions. With SentinelOne already connected in the endpoint workspace, there is a clear opportunity to extend into alert triage and EDR response.
  • Metric tracking infrastructure is idle: The Calculate/Update Metrics subflow tracks Protection_Rate, Automation_ROI, and MTTR — but the parent workflows feeding it have zero executions, meaning the metrics dashboard has no data.

Integration Ecosystem

Integration Workflows Status
Blink AI Agents 3 Configured
Blink Tables 12 Configured
SentinelOne 1 Configured
Absolute 1 Connected (1 run)
Tanium 2 Connected (1 run)
Entra 2 Configured
ThreatLocker 1 Configured
Email (Blink native) 5 Configured
Web Forms 1 Configured
HTTP / REST 1 Configured
PDF Generation 4 Configured
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 2 active | 41 tasks (12m)

AI Agents

Active Agents
2
of 2 total
Tasks Executed (12m)
41
0 in last 30d
Data Usage (12m)
12,151,921
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Vinmar Legal Triage Agent PoV - Legal Use Cases 33 0 9,184,244
2 Agent Investigator PoV 8 0 2,967,677
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
PoV - Legal Use Cases33
PoV8
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
7
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Unified Asset Hygiene & Risk Command 00
2 Executive Reporting 00
3 Asset Management 00
4 Entra Devices 00
5 Asset Management - HTML Version 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Standard NDA Request Form 00
D Full Use Case Analysis 5 use cases | 81 executions (12m)

Business KPIs

Metric Count Playbook
Endpoint device inventory syncs completed 1 Absolute Devices
Device inventory table updates completed 6 Update Device Table Run Results
Device compliance dashboard refreshes 7 Update Device Compliance HTML Widget
Device compliance dashboards sent to management 5 Send Device Compliance Dashboard to Management
Device compliance reports sent to IT team 4 Send Device Compliance Data to IT Team
Device registration type change reports generated 26 Device Registration Type Changes Report
Tanium vulnerability severity reports generated 1 Tanium - Vulnerability Count By Severity
Tanium vulnerability dashboard refreshes 1 Tanium - Update Vulnerability Over Time HTML Widget
Tanium vulnerabilities dashboards sent to management 1 Send Tanium Vulnerabilities Dashboard to Management
In the last 12 months, Blink automated: - 1 endpoint device inventory sync completed - 6 device inventory table updates completed - 7 device compliance dashboard refreshes - 5 device compliance dashboards sent to management - 4 device compliance reports sent to IT team - 26 device registration type change reports generated - 1 Tanium vulnerability severity report generated - 1 Tanium vulnerability dashboard refresh - 1 Tanium vulnerabilities dashboard sent to management
Note: Endpoint device management workflows — asset inventory, compliance reporting, and Tanium vulnerability tracking — are now running in production with regular execution volume. Vinmar's legal operations and agentic investigation workflows remain in active development or pre-production configuration; execution volume there is expected to grow as those workflows move to production.

Use Case Summary

Use Case Category Subcategory Playbooks Executions (12 mo)
Legal Document Automation & AI Review GRC AI / HR compliance automation 4 0
Endpoint & Asset Inventory Other Endpoint hygiene & MDM ops 9 49
Agentic Data-Driven Investigation SOC Agentic SOC 1 0
Tanium Vulnerability Reporting Vulnerability Mgmt Vuln scanning ingest & report 3 3
Utilities & Subflows — — 6 0
Total 23 52

Use Cases

1. Legal Document Automation & AI Review

Category: GRC — AI / HR compliance automation

Description: A full legal operations automation suite covering self-service NDA generation, AI-powered contract review, and a governed approval workflow. Requestors submit an NDA request via a branded web form; the system formats the document, routes it for approval, and generates a countersigned PDF — without requiring manual legal team involvement for standard agreements.

Business Problem Solved: Legal and compliance teams spend significant time on routine contract requests and document review. This use case automates the end-to-end NDA lifecycle and uses an AI Corporate Paralegal agent to triage and analyze third-party documents, freeing legal staff for higher-value work.

Integrations: Blink Web Forms, Blink AI Agents (Vinmar Legal Triage Agent), PDF generation, Email (Blink native)

Playbook Executions Link
NDA Secure Submission Workflow 0 Open
NDA Generation 0 Open
Agentic Legal Doc Review 0 Open
New Workflow *(Legal Doc via HTTP)* 0 Open

2. Endpoint & Asset Inventory

Category: Other — Endpoint hygiene & MDM ops

Description: A multi-source endpoint inventory automation that pulls device records from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker, normalizes and deduplicates the data against Blink Tables, and produces a unified asset registry. Each source runs as a discrete workflow feeding a shared data model; a consolidated device table, an HTML compliance dashboard widget, and scheduled email reporting distribute inventory and registration-change insights to IT and management.

Business Problem Solved: Enterprises managing endpoints across multiple security and MDM tools lack a single authoritative device inventory. This use case aggregates device data from five distinct platforms into one normalized view, enabling accurate asset coverage analysis, identifying unmanaged or orphaned endpoints, and surfacing device registration changes and compliance status to both IT and management on a recurring basis.

Integrations: Absolute, SentinelOne, Tanium, Entra, ThreatLocker, Blink Tables, Email (Blink native), PDF Generation

Playbook Executions Link
Absolute Devices 1 Open
Sentinel One Devices 0 Open
Tanium Devices 0 Open
ThreatLocker Devices 0 Open
Update Device Table Run Results 6 Open
Update Device Compliance HTML Widget 7 Open
Send Device Compliance Dashboard to Management 5 Open
Send Device Compliance Data to IT Team 4 Open
Device Registration Type Changes Report 26 Open

3. Agentic Data-Driven Investigation

Category: SOC — Agentic SOC

Description: An on-demand agentic investigation workflow where analysts submit a natural-language question and receive an AI-generated HTML report. The underlying agent has access to data query tooling (SQL) and email capabilities, enabling autonomous multi-step investigation without predefined logic paths.

Business Problem Solved: Security analysts face high cognitive load when correlating data across disparate sources. This use case deploys a conversational AI investigator that can autonomously query structured data, reason over findings, and produce formatted investigation reports — reducing time-to-insight for ad hoc security questions.

Integrations: Blink AI Agents (Data Assistant), Blink Tables (via SQL query agent tool), Email

Playbook Executions Link
Agentic Data-Driven Investigation 0 Open

4. Utilities & Subflows

These workflows are infrastructure components — subflows invoked by parent workflows, test data generators, or standalone agent tools. They do not represent end-to-end business outcomes and are excluded from KPI counts.

Playbook Role Link
Calculate/Update Metrics Subflow — computes Protection_Rate, Automation_ROI, MTTR from table data Open
Agent Send Email Utility subflow — email dispatch with @blinkops.com guard Open
Agent SQL Query Data Utility subflow — SQL query execution with injection threat analysis Open
Generate Sample Data Test data generator — populates sample alert records Open
Generate Mock Asset Data Test data generator — populates mock asset records Open
Device Registration Type Changes - Init Table and Save Delta Link Subflow — initializes device registration table and stores delta link for incremental sync Open

5. Tanium Vulnerability Reporting

Category: Vulnerability Mgmt — Vuln scanning ingest & report

Description: A scheduled pipeline that queries Tanium for vulnerability findings counted by severity, records the results in Blink Tables for trending, refreshes an HTML dashboard widget showing vulnerability counts over time, and distributes a PDF vulnerability dashboard to management on a recurring basis.

Business Problem Solved: Security and IT leadership need a recurring, trackable view of vulnerability exposure by severity without manually pulling reports from Tanium. This use case automates weekly vulnerability data collection, historical trending, and executive-ready reporting in a single chained workflow.

Integrations: Tanium, Blink Tables, Email (Blink native), PDF Generation

Playbook Executions Link
Tanium - Vulnerability Count By Severity 1 Open
Tanium - Update Vulnerability Over Time HTML Widget 1 Open
Send Tanium Vulnerabilities Dashboard to Management 1 Open

Key Observations

Strengths

  • Differentiated AI-native use case: The legal automation suite (NDA generation + agentic contract review) is a non-standard Blink deployment that extends automation into legal operations — a high-value, underserved domain. The "Vinmar Legal Triage Agent | AI Corporate Paralegal & Contract Analyst" is a purpose-built AI agent, reflecting real investment in agentic capability.
  • Multi-source endpoint inventory architecture: Building a unified asset registry from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker simultaneously demonstrates a mature understanding of how to use Blink Tables as a normalization layer across heterogeneous security tooling.
  • Governed self-service via Web Forms: The NDA Secure Submission Workflow uses a branded web form with an approval gate — a production-ready pattern that enables business users to self-serve without bypassing legal controls.
  • Security-conscious agent tooling: The Agent SQL Query Data subflow includes a Python-based SQL injection threat analysis step before execution — showing deliberate attention to safe agentic tool design.
  • Endpoint use case matured into a full reporting pipeline: What began as three device-ingestion workflows has grown into a nine-playbook pipeline — adding Entra and ThreatLocker as sources, a consolidated device table, an HTML compliance widget, and scheduled email distribution to both IT and management. The daily Device Registration Type Changes Report (26 executions/12mo) is the account's highest-volume workflow.
  • First production vulnerability metrics pipeline: The new Tanium Vulnerability Reporting use case chains data collection, historical recording, dashboard refresh, and executive email distribution into one weekly scheduled flow — establishing a repeatable pattern that could extend to other vulnerability or EDR data sources.

Gaps

  • Low production execution volume: 14 of 23 workflows have zero executions in the last 12 months. Legal operations, agentic investigation, and infrastructure subflows are well-designed but not yet in active production use. The priority should be identifying what is blocking go-live across the legal and SOC workspaces.
  • Scheduled triggers now live for device workflows: The Device Registration Type Changes Report (daily) and Tanium - Vulnerability Count By Severity (weekly) now run on scheduled triggers, driving the bulk of the account's execution volume. Extending scheduled triggers to the remaining on_demand device inventory workflows (SentinelOne, Tanium, ThreatLocker device syncs) would further increase asset hygiene coverage.
  • SOC coverage is nascent: The Agentic Data-Driven Investigation workflow is the only SOC-category automation, and it has no executions. With SentinelOne already connected in the endpoint workspace, there is a clear opportunity to extend into alert triage and EDR response.
  • Metric tracking infrastructure is idle: The Calculate/Update Metrics subflow tracks Protection_Rate, Automation_ROI, and MTTR — but the parent workflows feeding it have zero executions, meaning the metrics dashboard has no data.

Integration Ecosystem

Integration Workflows Status
Blink AI Agents 3 Configured
Blink Tables 12 Configured
SentinelOne 1 Configured
Absolute 1 Connected (1 run)
Tanium 2 Connected (1 run)
Entra 2 Configured
ThreatLocker 1 Configured
Email (Blink native) 5 Configured
Web Forms 1 Configured
HTTP / REST 1 Configured
PDF Generation 4 Configured
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Vinmar apikey-auth threatlocker_http_custom_authentication 2026-08-21