01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Phishing Detection & Response |
| 12.0% | 20 20 active |
| Agentic SOC — AI Investigation Engine |
| 0.1% | 9 9 active |
| Case Management & SOAR Platform |
| 0.6% | 12 12 active |
| Alert Enrichment & IOC Lookup |
| 0.8% | 46 46 active |
| EDR Containment & Response |
| 21.3% | 16 16 active |
| Identity Threat Response | 0 executions | 0.0% | 3 3 active |
| Cloud Exposure Review & Remediation | 0 executions | 0.0% | 2 2 active |
| SOC Reporting & Command Intelligence |
| 0.7% | 8 8 active |
| Employee Onboarding | 0 executions | 0.0% | 0 0 active |
| Vulnerability Scanning & Reporting | 0 executions | 0.0% | 1 1 active |
| Platform Administration & DevOps Automation | 0 executions | 0.0% | 3 3 active |
| Total | 19,126 executions | 100% | 120 120 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Phishing is the primary production workload. Five ingestion playbooks are running at scale — Google Workspace (reclassification + user-reported), Microsoft Defender XDR, Abnormal Security, and a Microsoft Graph Security API poller running on a 5-minute cycle — collectively ingesting over 49,000 alerts per year. This is a mature, multi-source phishing pipeline covering every major email security tool in the WAB stack, now including a second, independently deployed Microsoft Graph-based alert poller.
2. Deep Agentic SOC investment. Western Alliance Bank has built a full agentic investigation layer: a Decision Layer, Expert Agents, and a Close Case flow, all wired into a rich library of 47 enrichment abilities. The architecture is production-ready and represents one of the more complete Agentic SOC deployments — early production usage has begun (9 AI investigations processed via the main investigation flow, backed by new case-sanitization and truncation utilities), though volume remains well below the pipeline's full capacity.
3. Broad integration ecosystem. The playbook library spans 20+ distinct security tools: CrowdStrike Falcon (EDR, RTR, Identity Protection, Falcon Surface), Microsoft Defender for Endpoint/XDR/Cloud, Microsoft Graph Security API, Google Workspace, Okta, Proofpoint TAP/TRAP, Abnormal, Recorded Future, VirusTotal, Elasticsearch, URLScan, AbuseIPDB, WHOIS, DNS Dumpster, Slack, GitHub, SentinelOne, Shodan, and ServiceNow. This breadth positions Blink as the connective tissue across WAB's entire security stack.
4. WAB-native self-service and copilot layer. The WAB-branded self-service flows (phishing campaign investigation, endpoint malware containment drill, identity lateral movement response, cloud risk remediation) and the WAB SOC Copilot abilities represent a purpose-built, bank-specific automation layer — a strong signal of deep product adoption and customization.
5. Analyst approval gating throughout. Destructive actions (endpoint isolation, email quarantine, session revocation) are consistently gated behind approval_decision inputs, reflecting a security-appropriate human-in-the-loop design for a regulated financial institution.
###
Gaps & Opportunities
1. Agentic SOC and enrichment library are still mostly unexercised. The Agentic SOC pipeline has begun processing cases in production (9 AI investigations recorded), but the bulk of the 47-playbook enrichment library, identity and cloud response flows, and the employee onboarding suite still show no executions in the trailing 12 months. Fully enabling and routing production alerts through the Agentic SOC pipeline would multiply measurable automation value.
2. Process Alert volume (147) is low relative to ingestion volume (46,080+). The four ingestion playbooks are running at full scale, but only 147 alerts have been processed through the end-to-end pipeline. This gap suggests the Process Alert workflow is either connected to a different alert source than the four ingestion playbooks, or is underutilized relative to potential.
3. SentinelOne and Okta ingestion connectors are dormant. Both the SentinelOne webhook ingest and the Okta webhook ingest show 0 executions, while WAB has Okta deployed (used in enrichment playbooks). Activating these would expand log coverage without additional development work.
4. Employee onboarding not yet in production. The IAM onboarding workspace has 0 executions. With Okta already integrated and the provisioning logic built, activating the HR webhook trigger would deliver measurable time-to-access reduction for new hires.
5. Cloud security coverage is thin. Three playbooks cover cloud exposure and remediation, all with 0 executions and no ingestion trigger for cloud-native alert sources. Given WAB's Azure footprint (Microsoft Defender for Cloud is connected), adding scheduled or event-triggered cloud alert ingestion would expand the use case without significant new build effort.
6. Duplicate agent abilities. Agent_Ability_Enrich_domain and Agent_Ability_Enrich_domain copy are identical. Consolidating these would reduce maintenance overhead.
7. A second, separately deployed alert-polling pipeline has emerged. The Microsoft Graph Security Alert Poller Workflow, its lookback-time subflow, and the Microsoft Defender for Office 365 / Check SM list processing steps live in a distinct workspace from the primary SOC pipeline, yet are already running at high volume (3,210 executions). Consolidating this into the main workspace would reduce duplicated maintenance and give a single pane of glass over phishing ingestion.
8. Vulnerability scanning is a single, isolated, unexercised playbook. The new Shodan-based vulnerability search-and-summarize workflow has 0 executions and no scheduled trigger or ticketing integration. Wiring it to a recurring schedule and a downstream ticket/case creation step would turn it into a repeatable vulnerability management workflow rather than a one-off utility.
Integration Ecosystem Summary
| Category | Tools |
|---|---|
| EDR / Endpoint | CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne |
| Email Security | Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph Security API, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook |
| Identity | Microsoft Entra ID, Okta, CrowdStrike Identity Protection |
| Cloud Security | Microsoft Defender for Cloud, Azure Monitor, AWS CloudTrail |
| Threat Intelligence | VirusTotal, Recorded Future, CrowdStrike ThreatGraph, AbuseIPDB, DNS Dumpster |
| Vulnerability Management | Shodan |
| SIEM / Logging | Elasticsearch |
| URL / Domain | URLScan, WHOIS |
| Collaboration | Slack, Microsoft Teams |
| ITSM | ServiceNow |
| Developer | GitHub |
| Case Management | Blink native (case management, tables, agents) |
A Case Management 42 cases (12m) | MTTR 1d
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Agentic SOC | 32 | 32 | 19 | 1d 4h |
| Agentic SOC - Development | 10 | 10 | 3 | 4m |
B AI Agents 13 active | 487 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Micro Agent - Context Enrichment | Agentic SOC - Development | 271 | 271 | 9,409,781 |
| 2 | Agent Blink - Decision Maker | Agentic SOC | 67 | 0 | 6,106,446 |
| 3 | Micro Agent - Response Recommendation | Agentic SOC - Development | 36 | 36 | 3,023,169 |
| 4 | Micro Agent - Historical Case Check | Agentic SOC | 33 | 0 | 1,095,084 |
| 5 | SOC Analyst | Agentic SOC - Development | 18 | 18 | 1,483,773 |
| Workspace | Tasks (12m) |
|---|---|
| Agentic SOC - Development | 334 |
| Agentic SOC | 139 |
| Building | 14 |
| CD Development Workspace | 0 |
| jeffery.brown@blinkops.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Test | 0 | 0 |
| 2 | Agentic SOC | 0 | 0 |
| 3 | TEST - Threat Intel Dashboard | 0 | 0 |
| 4 | WAB PM Tracker Metrics | 0 | 0 |
| 5 | WAB - Kanban Board | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 10 use cases | 54,026 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Phishing alerts auto-ingested from Google Workspace (reclassification) | 11,520 | Google Workspace Alert Center — Phishing reclassification Alert |
| User-reported phishing alerts auto-ingested from Google Workspace | 11,520 | Google Workspace Alert Center — User reported phishing Alert |
| Phishing alerts auto-ingested from Microsoft Defender XDR | 11,520 | Defender XDR — Phishing Alerts |
| Endpoint alerts auto-ingested from Microsoft Defender for Endpoint | 11,520 | Microsoft Defender for endpoint ingestion |
| Security alerts polled from Microsoft Graph Security API (5-min cycle) | 3,210 | Microsoft Graph Security Alert Poller Workflow |
| Security alerts fully processed through the automated SOC pipeline | 147 | Process Alert |
| Abnormal Security email threat scan batches executed | 40 | Abnormal Ingest |
| Observables enriched via automated enrichment router | 408 | Subflow - Enrich Observables - Main Router |
| Case observable enrichment lookups served to analysts and AI agents | 45 | Agent Ability - Get Case Observable's Enrichment |
| Org asset lookups served to analysts and AI agents | 263 | Agent Ability - Get Org Assets |
| Response actions routed through the automated response engine | 36 | Subflow - Response - Main Router |
| VIP user lookups served to analysts and AI agents | 53 | Agent Ability - Get VIP Users |
| Org technology stack lookups served to analysts and AI agents | 36 | Agent Ability - Get Org Technological Stack |
| Missing alert template notifications handled | 21 | Subflow - Missing Alert Template Notification |
| AI investigations processed through the Agentic SOC pipeline | 9 | Subflow - Agentic SOC - Main - AI Investigation |
| Investigation guideline lookups served to the Agentic SOC pipeline | 9 | Agent Ability - Get Investigation Guidelines |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbook Count |
|---|---|---|---|---|
| 1 | Phishing Detection & Response | SOC | Phishing detection & response, SIEM & log pipeline monitoring | 35 |
| 2 | Agentic SOC — AI Investigation Engine | SOC | Agentic SOC, Case mgmt & SOAR | 16 |
| 3 | Case Management & SOAR Platform | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring | 28 |
| 4 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation | 93 |
| 5 | EDR Containment & Response | SOC | EDR containment & response, Alert enrichment / IOC lookup | 25 |
| 6 | Identity Threat Response | SOC | Identity threat response | 5 |
| 7 | Cloud Exposure Review & Remediation | Cloud Security | CSPM ingest & triage, Config audit & remediation | 3 |
| 8 | SOC Reporting & Command Intelligence | GRC | Security metrics & reporting | 16 |
| 9 | Employee Onboarding | IAM | Employee onboarding, Identity lifecycle automation | 4 |
| 10 | Vulnerability Scanning & Reporting | Vulnerability Mgmt | Vuln scanning ingest & report, Threat hunting & detection | 1 |
| 11 | Platform Administration & DevOps Automation | Other | SaaS / IT administration, DevOps & release automation | 3 |
Use Cases
1. Phishing Detection & Response
Description: End-to-end phishing coverage from multi-source alert ingestion through AI-powered triage, IOC capture, analyst-assisted containment, and evidence archival. Purpose-built around Western Alliance Bank's email security stack.
Business problem: Phishing is the dominant initial access vector in financial services. Analyst capacity cannot match alert volume across Google Workspace, Microsoft Defender XDR, Proofpoint, Abnormal, and Cofense simultaneously. Blink unifies ingestion, automates triage, and gates containment actions behind analyst approval.
Key integrations: Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph / Exchange Online, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook, VirusTotal, URLScan, Recorded Future, WHOIS, Elasticsearch, Blink Case Management
Category: SOC | Subcategories: Phishing detection & response, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup
2. Agentic SOC — AI Investigation Engine
Description: A fully autonomous AI-driven investigation layer that receives cases, runs specialized expert agents, produces close/escalate recommendations, and executes closure or escalation actions — without waiting for analyst input on routine alerts.
Business problem: SOC analysts are bottlenecked by high alert volume and repetitive investigation steps. The Agentic SOC shifts routine triage to AI, freeing analysts for complex, high-judgment work and reducing mean-time-to-respond on lower-severity alerts.
Key integrations: Blink Case Management, Blink AI Agents / Micro Agents, all enrichment and response subflows as agent abilities
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Agentic SOC — Decision Layer | 0 | Core Engine |
| Agentic SOC — Expert Agents | 0 | Core Engine |
| Agentic SOC — Close Case | 0 | Core Engine |
| Subflow — Agentic SOC — Main — AI Investigation | 0 | Orchestration |
| Utility — Refresh Investigation | 0 | Utility |
| Agent Ability — Recommendation for Case | 0 | Agent Ability |
| Agent Ability — Historical Case Checks | 0 | Agent Ability |
| Load cases predictions from conclusions | 0 | Utility |
| Subflow - Agentic SOC - Main - AI Investigation | 9 | Orchestration |
| Utility - Sanitize Case From Prior Investigation | 9 | Utility |
| Utility - Truncate Case & Alert | 9 | Utility |
| Agent Ability - Get Investigation Guidelines | 9 | Agent Ability |
| Utility - Refresh investigation | 0 | Utility |
| Refresh investigations on case dataset | 0 | Utility |
| Load cases taggings from csv | 0 | Evaluation |
| Main Evaluation - Evaluate On Cases dataset | 0 | Evaluation |
3. Case Management & SOAR Platform
Description: The core SOAR backbone: ingesting alerts from any source, deduplicating into cases, extracting observables, routing enrichment and response subflows, managing recovery for missed or stale events, and providing the foundational query/comment/update operations that all other use cases depend on.
Business problem: A financial institution handling alerts from a dozen security tools needs a single, auditable system of record for every alert and case. Blink Case Management provides that backbone, with built-in deduplication, observable extraction, and recovery logic to ensure no alert goes unprocessed.
Key integrations: Blink Case Management, SentinelOne, Okta, Microsoft Defender for Endpoint, AWS CloudTrail, Azure Monitor, CrowdStrike, Sumo Logic
Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring
4. Alert Enrichment & IOC Lookup
Description: A deep library of enrichment subflows covering every observable type — IP, domain, URL, file hash, username, email address, and agent ID — across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, Slack, GitHub, AbuseIPDB, URLScan, WHOIS, and CrowdStrike ThreatGraph. Includes observable relationship management and similarity scoring between cases.
Business problem: Analysts and agentic workflows need instant, normalized context on any indicator without switching tools. This library provides a single callable interface for every enrichment source WAB has licensed, invocable by both the Agentic SOC and human analysts via the copilot.
Key integrations: VirusTotal, CrowdStrike (EDR + ThreatGraph + Falcon Surface), AbuseIPDB, URLScan, WHOIS, Recorded Future, Okta, Microsoft Entra ID (Active Directory), Google Workspace, Slack, GitHub, DNS Dumpster, Blink Case Management
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation
5. EDR Containment & Response
Description: Endpoint investigation and containment across CrowdStrike Falcon and Microsoft Defender for Endpoint. Covers alert ingestion, host and file context gathering, advanced Elasticsearch hunting, and approval-gated isolation actions. Includes purpose-built WAB self-service and analyst-copilot flows for malware containment drills.
Business problem: When a workstation at a financial institution is suspected of compromise, analysts need host context, process telemetry, file hash intelligence, and a safe containment path — all in minutes. Blink orchestrates multi-tool evidence gathering and gates destructive actions (isolation, quarantine) behind explicit analyst approval.
Key integrations: CrowdStrike Falcon (EDR, RTR, identity protection, Falcon Surface), Microsoft Defender for Endpoint, Elasticsearch, Recorded Future, Blink Case Management
Category: SOC | Subcategories: EDR containment & response, Alert enrichment / IOC lookup
6. Identity Threat Response
Description: Investigation and response for identity-based threats including lateral movement, Entra ID risk scoring, CrowdStrike Identity Protection lookups, Elasticsearch identity hunting, and approval-gated session revocation.
Business problem: Lateral movement and compromised credentials are high-priority threats for a financial institution. Blink provides a structured investigation path that correlates Microsoft Entra risk scores, CrowdStrike Identity Protection signals, and Elasticsearch timeline data before surfacing an analyst-approved remediation action.
Key integrations: Microsoft Entra ID (Active Directory), CrowdStrike Identity Protection, Microsoft Defender for Endpoint, Elasticsearch, Blink Case Management
Category: SOC | Subcategories: Identity threat response
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| WAB Self Service — Identity Lateral Movement Response | 0 | Self-Service |
| WAB SOC — Entra And Azure Identity Risk Review | 0 | SOC Copilot Ability |
| Get Entra User Risk | 0 | Investigation |
| Review Azure Identity Anomaly | 0 | Investigation |
| Revoke User Sessions | 0 | Response |
7. Cloud Exposure Review & Remediation
Description: Cloud security alert correlation and remediation packaging — correlating Microsoft Defender for Cloud alerts with Recorded Future external exposure context and Elasticsearch activity logs, then producing a structured remediation package for the asset owner.
Business problem: Cloud misconfigurations and externally exposed resources require rapid triage across multiple signals. Blink aggregates cloud security alerts, external threat intelligence, and log data into a single remediation package that can be routed to business owners without analyst manual effort.
Key integrations: Microsoft Defender for Cloud, Recorded Future, Elasticsearch, Blink Tables
Category: Cloud Security | Subcategories: CSPM ingest & triage, Config audit & remediation
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| WAB Self Service — Cloud Risk Remediation Package | 0 | Self-Service |
| Review Cloud Exposure | 0 | Investigation |
| Create Cloud Remediation Package | 0 | Response |
8. SOC Reporting & Command Intelligence
Description: Real-time SOC command metrics, risk register reads, response evidence ledger queries, executive briefings, and asset/technology stack lookups that give the Agentic SOC and human analysts situational awareness at case time.
Business problem: Security leadership at a regulated financial institution needs continuous visibility into SOC performance and risk posture without waiting for manual reporting cycles. Blink provides on-demand and agent-invocable access to the command center, risk register, and evidence ledger.
Key integrations: Blink Tables, Blink Case Management
Category: GRC | Subcategories: Security metrics & reporting
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Read SOC Command Metrics | 0 | Reporting |
| Read Recent Response Evidence | 0 | Reporting |
| Read Risk Register | 0 | Reporting |
| Save Executive Briefing | 0 | Reporting |
| Agent Ability — Get Org Technological Stack | 0 | Agent Ability |
| Agent Ability — Get Org Assets | 0 | Agent Ability |
| Agent Ability — Get VIP Users | 0 | Agent Ability |
| Agent Ability — Get Vendor Logo List | 0 | Agent Ability |
| Agent Ability — Get Core Agent Questions | 0 | Agent Ability |
| Agent Ability — Get Closing Questions | 0 | Agent Ability |
| Agent Ability — Get Case Types From Case Management Settings | 0 | Agent Ability |
| Agent Ability — Get Malware Questions | 0 | Agent Ability |
| Agent Ability - Get Org Assets | 263 | Agent Ability |
| Agent Ability - Get Vendor Logo List | 0 | Agent Ability |
| Agent Ability - Get VIP Users | 53 | Agent Ability |
| Agent Ability - Get Org Technological Stack | 36 | Agent Ability |
9. Employee Onboarding
Description: Automated new-employee provisioning in Okta triggered by HR system webhooks, covering user creation, credential generation, and onboarding flow orchestration.
Business problem: Manual provisioning creates lag between a hire's start date and their day-one access, and increases the risk of configuration errors. Blink automates Okta account creation and onboarding steps from the moment an HR record is created.
Key integrations: Okta, HR webhook (custom webhook trigger)
Category: IAM | Subcategories: Employee onboarding, Identity lifecycle automation
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| 1. Employee Onboarding — Ignition | 0 | Provisioning |
| 2. Employee Onboarding — Lift Off | 0 | Provisioning |
| 2. Employee Onboarding — Orbit | 0 | Event-Triggered |
| Employee Onboarding Orbit — Trigger | 0 | Utility |
10. Vulnerability Scanning & Reporting
Description: On-demand Shodan-based vulnerability scanning that searches for exposed, vulnerable assets and summarizes the top findings for review.
Business problem: Security teams need a fast way to surface externally visible vulnerable assets without manually querying Shodan and sifting through raw results. Blink automates the search, extraction, and formatting of the highest-priority findings into a readable summary.
Key integrations: Shodan
Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Threat hunting & detection
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| SUCCESS HALLELUJAH | 0 | On-Demand |
11. Platform Administration & DevOps Automation
Description: Platform-level administrative automations for data onboarding and workflow release management — generic CSV-to-Blink-Table import utilities (including an auto-create-table variant) and a Teams-approval-gated pipeline for promoting workflows and agent packs from a dev workspace to production.
Business problem: As the Blink footprint grows, teams need standardized, low-code ways to bulk-load reference data into Blink Tables and to safely promote workflow changes from dev to production without manual, unaudited copy/paste. Blink provides reusable import utilities and an approval-gated promotion pipeline — with optional destination-workspace backup — so platform changes stay consistent, auditable, and reversible.
Key integrations: Blink Tables, Microsoft Teams, Blink Platform (workspace/workflow promotion)
Category: Other | Subcategories: SaaS / IT administration, DevOps & release automation
| Playbook | Executions (12 mo) | Type |
|---|---|---|
| Generic CSV To Blink Table | 0 | Utility |
| Generic CSV to Blink Table Import (Auto-Create Table) | 0 | Utility |
| Promote Dev to Prod (Teams Approval) | 0 | Release Mgmt |
Key Observations
Strengths
1. Phishing is the primary production workload. Five ingestion playbooks are running at scale — Google Workspace (reclassification + user-reported), Microsoft Defender XDR, Abnormal Security, and a Microsoft Graph Security API poller running on a 5-minute cycle — collectively ingesting over 49,000 alerts per year. This is a mature, multi-source phishing pipeline covering every major email security tool in the WAB stack, now including a second, independently deployed Microsoft Graph-based alert poller.
2. Deep Agentic SOC investment. Western Alliance Bank has built a full agentic investigation layer: a Decision Layer, Expert Agents, and a Close Case flow, all wired into a rich library of 47 enrichment abilities. The architecture is production-ready and represents one of the more complete Agentic SOC deployments — early production usage has begun (9 AI investigations processed via the main investigation flow, backed by new case-sanitization and truncation utilities), though volume remains well below the pipeline's full capacity.
3. Broad integration ecosystem. The playbook library spans 20+ distinct security tools: CrowdStrike Falcon (EDR, RTR, Identity Protection, Falcon Surface), Microsoft Defender for Endpoint/XDR/Cloud, Microsoft Graph Security API, Google Workspace, Okta, Proofpoint TAP/TRAP, Abnormal, Recorded Future, VirusTotal, Elasticsearch, URLScan, AbuseIPDB, WHOIS, DNS Dumpster, Slack, GitHub, SentinelOne, Shodan, and ServiceNow. This breadth positions Blink as the connective tissue across WAB's entire security stack.
4. WAB-native self-service and copilot layer. The WAB-branded self-service flows (phishing campaign investigation, endpoint malware containment drill, identity lateral movement response, cloud risk remediation) and the WAB SOC Copilot abilities represent a purpose-built, bank-specific automation layer — a strong signal of deep product adoption and customization.
5. Analyst approval gating throughout. Destructive actions (endpoint isolation, email quarantine, session revocation) are consistently gated behind approval_decision inputs, reflecting a security-appropriate human-in-the-loop design for a regulated financial institution.
Gaps & Opportunities
1. Agentic SOC and enrichment library are still mostly unexercised. The Agentic SOC pipeline has begun processing cases in production (9 AI investigations recorded), but the bulk of the 47-playbook enrichment library, identity and cloud response flows, and the employee onboarding suite still show no executions in the trailing 12 months. Fully enabling and routing production alerts through the Agentic SOC pipeline would multiply measurable automation value.
2. Process Alert volume (147) is low relative to ingestion volume (46,080+). The four ingestion playbooks are running at full scale, but only 147 alerts have been processed through the end-to-end pipeline. This gap suggests the Process Alert workflow is either connected to a different alert source than the four ingestion playbooks, or is underutilized relative to potential.
3. SentinelOne and Okta ingestion connectors are dormant. Both the SentinelOne webhook ingest and the Okta webhook ingest show 0 executions, while WAB has Okta deployed (used in enrichment playbooks). Activating these would expand log coverage without additional development work.
4. Employee onboarding not yet in production. The IAM onboarding workspace has 0 executions. With Okta already integrated and the provisioning logic built, activating the HR webhook trigger would deliver measurable time-to-access reduction for new hires.
5. Cloud security coverage is thin. Three playbooks cover cloud exposure and remediation, all with 0 executions and no ingestion trigger for cloud-native alert sources. Given WAB's Azure footprint (Microsoft Defender for Cloud is connected), adding scheduled or event-triggered cloud alert ingestion would expand the use case without significant new build effort.
6. Duplicate agent abilities. Agent_Ability_Enrich_domain and Agent_Ability_Enrich_domain copy are identical. Consolidating these would reduce maintenance overhead.
7. A second, separately deployed alert-polling pipeline has emerged. The Microsoft Graph Security Alert Poller Workflow, its lookback-time subflow, and the Microsoft Defender for Office 365 / Check SM list processing steps live in a distinct workspace from the primary SOC pipeline, yet are already running at high volume (3,210 executions). Consolidating this into the main workspace would reduce duplicated maintenance and give a single pane of glass over phishing ingestion.
8. Vulnerability scanning is a single, isolated, unexercised playbook. The new Shodan-based vulnerability search-and-summarize workflow has 0 executions and no scheduled trigger or ticketing integration. Wiring it to a recurring schedule and a downstream ticket/case creation step would turn it into a repeatable vulnerability management workflow rather than a one-off utility.
Integration Ecosystem Summary
| Category | Tools |
|---|---|
| EDR / Endpoint | CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne |
| Email Security | Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph Security API, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook |
| Identity | Microsoft Entra ID, Okta, CrowdStrike Identity Protection |
| Cloud Security | Microsoft Defender for Cloud, Azure Monitor, AWS CloudTrail |
| Threat Intelligence | VirusTotal, Recorded Future, CrowdStrike ThreatGraph, AbuseIPDB, DNS Dumpster |
| Vulnerability Management | Shodan |
| SIEM / Logging | Elasticsearch |
| URL / Domain | URLScan, WHOIS |
| Collaboration | Slack, Microsoft Teams |
| ITSM | ServiceNow |
| Developer | GitHub |
| Case Management | Blink native (case management, tables, agents) |
E New Integrations (detail) 7 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| westernalliancebank | servicenow | servicenow_connection | 2026-08-21 |
| westernalliancebank | elasticsearch | elasticsearch_connection | 2026-08-18 |
| westernalliancebank | microsoft-graph | microsoft_graph_migration_connection | 2026-08-12 |
| westernalliancebank | crowdstrike | crowdstrike_dev_connection | 2026-08-12 |
| westernalliancebank | recorded-future | recorded_future_connection | 2026-08-11 |
| westernalliancebank | crowdstrike | crowdstrike_connection | 2026-08-11 |
| westernalliancebank | microsoft-graph | microsoft_graph_connection_security | 2026-08-11 |