01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Legal Document Automation & AI Review | 0 executions | 0.0% | 3 3 active |
| Endpoint & Asset Inventory |
| 81.5% | 9 9 active |
| Agentic Data-Driven Investigation | 0 executions | 0.0% | 1 1 active |
| Utilities & Subflows | 0 executions | 0.0% | 6 6 active |
| Tanium Vulnerability Reporting |
| 3.7% | 3 3 active |
| Total | 69 executions | 100% | 22 22 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Differentiated AI-native use case: The legal automation suite (NDA generation + agentic contract review) is a non-standard Blink deployment that extends automation into legal operations — a high-value, underserved domain. The "Vinmar Legal Triage Agent | AI Corporate Paralegal & Contract Analyst" is a purpose-built AI agent, reflecting real investment in agentic capability.
- Multi-source endpoint inventory architecture: Building a unified asset registry from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker simultaneously demonstrates a mature understanding of how to use Blink Tables as a normalization layer across heterogeneous security tooling.
- Governed self-service via Web Forms: The NDA Secure Submission Workflow uses a branded web form with an approval gate — a production-ready pattern that enables business users to self-serve without bypassing legal controls.
- Security-conscious agent tooling: The
Agent SQL Query Datasubflow includes a Python-based SQL injection threat analysis step before execution — showing deliberate attention to safe agentic tool design. - Endpoint use case matured into a full reporting pipeline: What began as three device-ingestion workflows has grown into a nine-playbook pipeline — adding Entra and ThreatLocker as sources, a consolidated device table, an HTML compliance widget, and scheduled email distribution to both IT and management. The daily Device Registration Type Changes Report (26 executions/12mo) is the account's highest-volume workflow.
- First production vulnerability metrics pipeline: The new Tanium Vulnerability Reporting use case chains data collection, historical recording, dashboard refresh, and executive email distribution into one weekly scheduled flow — establishing a repeatable pattern that could extend to other vulnerability or EDR data sources.
###
Gaps
- Low production execution volume: 14 of 23 workflows have zero executions in the last 12 months. Legal operations, agentic investigation, and infrastructure subflows are well-designed but not yet in active production use. The priority should be identifying what is blocking go-live across the legal and SOC workspaces.
- Scheduled triggers now live for device workflows: The Device Registration Type Changes Report (daily) and Tanium - Vulnerability Count By Severity (weekly) now run on scheduled triggers, driving the bulk of the account's execution volume. Extending scheduled triggers to the remaining
on_demanddevice inventory workflows (SentinelOne, Tanium, ThreatLocker device syncs) would further increase asset hygiene coverage. - SOC coverage is nascent: The Agentic Data-Driven Investigation workflow is the only SOC-category automation, and it has no executions. With SentinelOne already connected in the endpoint workspace, there is a clear opportunity to extend into alert triage and EDR response.
- Metric tracking infrastructure is idle: The Calculate/Update Metrics subflow tracks Protection_Rate, Automation_ROI, and MTTR — but the parent workflows feeding it have zero executions, meaning the metrics dashboard has no data.
Integration Ecosystem
| Integration | Workflows | Status |
|---|---|---|
| Blink AI Agents | 3 | Configured |
| Blink Tables | 12 | Configured |
| SentinelOne | 1 | Configured |
| Absolute | 1 | Connected (1 run) |
| Tanium | 2 | Connected (1 run) |
| Entra | 2 | Configured |
| ThreatLocker | 1 | Configured |
| Email (Blink native) | 5 | Configured |
| Web Forms | 1 | Configured |
| HTTP / REST | 1 | Configured |
| PDF Generation | 4 | Configured |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 2 active | 41 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Vinmar Legal Triage Agent | PoV - Legal Use Cases | 33 | 0 | 9,184,244 |
| 2 | Agent Investigator | PoV | 8 | 0 | 2,967,677 |
| Workspace | Tasks (12m) |
|---|---|
| PoV - Legal Use Cases | 33 |
| PoV | 8 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Unified Asset Hygiene & Risk Command | 0 | 0 |
| 2 | Executive Reporting | 0 | 0 |
| 3 | Asset Management | 0 | 0 |
| 4 | Entra Devices | 0 | 0 |
| 5 | Asset Management - HTML Version | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Standard NDA Request Form | 0 | 0 |
D Full Use Case Analysis 5 use cases | 81 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Endpoint device inventory syncs completed | 1 | Absolute Devices |
| Device inventory table updates completed | 6 | Update Device Table Run Results |
| Device compliance dashboard refreshes | 7 | Update Device Compliance HTML Widget |
| Device compliance dashboards sent to management | 5 | Send Device Compliance Dashboard to Management |
| Device compliance reports sent to IT team | 4 | Send Device Compliance Data to IT Team |
| Device registration type change reports generated | 26 | Device Registration Type Changes Report |
| Tanium vulnerability severity reports generated | 1 | Tanium - Vulnerability Count By Severity |
| Tanium vulnerability dashboard refreshes | 1 | Tanium - Update Vulnerability Over Time HTML Widget |
| Tanium vulnerabilities dashboards sent to management | 1 | Send Tanium Vulnerabilities Dashboard to Management |
Use Case Summary
| Use Case | Category | Subcategory | Playbooks | Executions (12 mo) |
|---|---|---|---|---|
| Legal Document Automation & AI Review | GRC | AI / HR compliance automation | 4 | 0 |
| Endpoint & Asset Inventory | Other | Endpoint hygiene & MDM ops | 9 | 49 |
| Agentic Data-Driven Investigation | SOC | Agentic SOC | 1 | 0 |
| Tanium Vulnerability Reporting | Vulnerability Mgmt | Vuln scanning ingest & report | 3 | 3 |
| Utilities & Subflows | — | — | 6 | 0 |
| Total | 23 | 52 |
Use Cases
1. Legal Document Automation & AI Review
Category: GRC — AI / HR compliance automation
Description: A full legal operations automation suite covering self-service NDA generation, AI-powered contract review, and a governed approval workflow. Requestors submit an NDA request via a branded web form; the system formats the document, routes it for approval, and generates a countersigned PDF — without requiring manual legal team involvement for standard agreements.
Business Problem Solved: Legal and compliance teams spend significant time on routine contract requests and document review. This use case automates the end-to-end NDA lifecycle and uses an AI Corporate Paralegal agent to triage and analyze third-party documents, freeing legal staff for higher-value work.
Integrations: Blink Web Forms, Blink AI Agents (Vinmar Legal Triage Agent), PDF generation, Email (Blink native)
| Playbook | Executions | Link |
|---|---|---|
| NDA Secure Submission Workflow | 0 | Open |
| NDA Generation | 0 | Open |
| Agentic Legal Doc Review | 0 | Open |
| New Workflow *(Legal Doc via HTTP)* | 0 | Open |
2. Endpoint & Asset Inventory
Category: Other — Endpoint hygiene & MDM ops
Description: A multi-source endpoint inventory automation that pulls device records from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker, normalizes and deduplicates the data against Blink Tables, and produces a unified asset registry. Each source runs as a discrete workflow feeding a shared data model; a consolidated device table, an HTML compliance dashboard widget, and scheduled email reporting distribute inventory and registration-change insights to IT and management.
Business Problem Solved: Enterprises managing endpoints across multiple security and MDM tools lack a single authoritative device inventory. This use case aggregates device data from five distinct platforms into one normalized view, enabling accurate asset coverage analysis, identifying unmanaged or orphaned endpoints, and surfacing device registration changes and compliance status to both IT and management on a recurring basis.
Integrations: Absolute, SentinelOne, Tanium, Entra, ThreatLocker, Blink Tables, Email (Blink native), PDF Generation
| Playbook | Executions | Link |
|---|---|---|
| Absolute Devices | 1 | Open |
| Sentinel One Devices | 0 | Open |
| Tanium Devices | 0 | Open |
| ThreatLocker Devices | 0 | Open |
| Update Device Table Run Results | 6 | Open |
| Update Device Compliance HTML Widget | 7 | Open |
| Send Device Compliance Dashboard to Management | 5 | Open |
| Send Device Compliance Data to IT Team | 4 | Open |
| Device Registration Type Changes Report | 26 | Open |
3. Agentic Data-Driven Investigation
Category: SOC — Agentic SOC
Description: An on-demand agentic investigation workflow where analysts submit a natural-language question and receive an AI-generated HTML report. The underlying agent has access to data query tooling (SQL) and email capabilities, enabling autonomous multi-step investigation without predefined logic paths.
Business Problem Solved: Security analysts face high cognitive load when correlating data across disparate sources. This use case deploys a conversational AI investigator that can autonomously query structured data, reason over findings, and produce formatted investigation reports — reducing time-to-insight for ad hoc security questions.
Integrations: Blink AI Agents (Data Assistant), Blink Tables (via SQL query agent tool), Email
| Playbook | Executions | Link |
|---|---|---|
| Agentic Data-Driven Investigation | 0 | Open |
4. Utilities & Subflows
These workflows are infrastructure components — subflows invoked by parent workflows, test data generators, or standalone agent tools. They do not represent end-to-end business outcomes and are excluded from KPI counts.
| Playbook | Role | Link |
|---|---|---|
| Calculate/Update Metrics | Subflow — computes Protection_Rate, Automation_ROI, MTTR from table data | Open |
| Agent Send Email | Utility subflow — email dispatch with @blinkops.com guard | Open |
| Agent SQL Query Data | Utility subflow — SQL query execution with injection threat analysis | Open |
| Generate Sample Data | Test data generator — populates sample alert records | Open |
| Generate Mock Asset Data | Test data generator — populates mock asset records | Open |
| Device Registration Type Changes - Init Table and Save Delta Link | Subflow — initializes device registration table and stores delta link for incremental sync | Open |
5. Tanium Vulnerability Reporting
Category: Vulnerability Mgmt — Vuln scanning ingest & report
Description: A scheduled pipeline that queries Tanium for vulnerability findings counted by severity, records the results in Blink Tables for trending, refreshes an HTML dashboard widget showing vulnerability counts over time, and distributes a PDF vulnerability dashboard to management on a recurring basis.
Business Problem Solved: Security and IT leadership need a recurring, trackable view of vulnerability exposure by severity without manually pulling reports from Tanium. This use case automates weekly vulnerability data collection, historical trending, and executive-ready reporting in a single chained workflow.
Integrations: Tanium, Blink Tables, Email (Blink native), PDF Generation
| Playbook | Executions | Link |
|---|---|---|
| Tanium - Vulnerability Count By Severity | 1 | Open |
| Tanium - Update Vulnerability Over Time HTML Widget | 1 | Open |
| Send Tanium Vulnerabilities Dashboard to Management | 1 | Open |
Key Observations
Strengths
- Differentiated AI-native use case: The legal automation suite (NDA generation + agentic contract review) is a non-standard Blink deployment that extends automation into legal operations — a high-value, underserved domain. The "Vinmar Legal Triage Agent | AI Corporate Paralegal & Contract Analyst" is a purpose-built AI agent, reflecting real investment in agentic capability.
- Multi-source endpoint inventory architecture: Building a unified asset registry from Absolute, SentinelOne, Tanium, Entra, and ThreatLocker simultaneously demonstrates a mature understanding of how to use Blink Tables as a normalization layer across heterogeneous security tooling.
- Governed self-service via Web Forms: The NDA Secure Submission Workflow uses a branded web form with an approval gate — a production-ready pattern that enables business users to self-serve without bypassing legal controls.
- Security-conscious agent tooling: The
Agent SQL Query Datasubflow includes a Python-based SQL injection threat analysis step before execution — showing deliberate attention to safe agentic tool design. - Endpoint use case matured into a full reporting pipeline: What began as three device-ingestion workflows has grown into a nine-playbook pipeline — adding Entra and ThreatLocker as sources, a consolidated device table, an HTML compliance widget, and scheduled email distribution to both IT and management. The daily Device Registration Type Changes Report (26 executions/12mo) is the account's highest-volume workflow.
- First production vulnerability metrics pipeline: The new Tanium Vulnerability Reporting use case chains data collection, historical recording, dashboard refresh, and executive email distribution into one weekly scheduled flow — establishing a repeatable pattern that could extend to other vulnerability or EDR data sources.
Gaps
- Low production execution volume: 14 of 23 workflows have zero executions in the last 12 months. Legal operations, agentic investigation, and infrastructure subflows are well-designed but not yet in active production use. The priority should be identifying what is blocking go-live across the legal and SOC workspaces.
- Scheduled triggers now live for device workflows: The Device Registration Type Changes Report (daily) and Tanium - Vulnerability Count By Severity (weekly) now run on scheduled triggers, driving the bulk of the account's execution volume. Extending scheduled triggers to the remaining
on_demanddevice inventory workflows (SentinelOne, Tanium, ThreatLocker device syncs) would further increase asset hygiene coverage. - SOC coverage is nascent: The Agentic Data-Driven Investigation workflow is the only SOC-category automation, and it has no executions. With SentinelOne already connected in the endpoint workspace, there is a clear opportunity to extend into alert triage and EDR response.
- Metric tracking infrastructure is idle: The Calculate/Update Metrics subflow tracks Protection_Rate, Automation_ROI, and MTTR — but the parent workflows feeding it have zero executions, meaning the metrics dashboard has no data.
Integration Ecosystem
| Integration | Workflows | Status |
|---|---|---|
| Blink AI Agents | 3 | Configured |
| Blink Tables | 12 | Configured |
| SentinelOne | 1 | Configured |
| Absolute | 1 | Connected (1 run) |
| Tanium | 2 | Connected (1 run) |
| Entra | 2 | Configured |
| ThreatLocker | 1 | Configured |
| Email (Blink native) | 5 | Configured |
| Web Forms | 1 | Configured |
| HTTP / REST | 1 | Configured |
| PDF Generation | 4 | Configured |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Vinmar | apikey-auth | threatlocker_http_custom_authentication | 2026-08-21 |