Blink Security Automation — Confidential

zeus — Customer Success Report

Generated 2026-08-31 | zeus-value-report.md
2026-08-31Report Date
15Total Playbooks
3Unique Workflows (12m)
2,047Actions Automated (12m)
$526Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

15
Total playbooks built
all non-deleted workflows
3
Active playbooks
currently enabled
3
Unique workflows executed (12m)
distinct workflows that ran
2,047
Actions automated (12m)
completed action steps
11.4h
Hours saved (12m)
@ 20s per action
$526
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 21 CrowdStrike security alerts triaged and escalated to analyst via Teams - 3 management reports generated, formatted, and emailed automatically - 3 scheduled data record normalization runs executed without manual intervention

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
CrowdStrike Alert Response
  • 21Security alerts routed to analyst with automated triage
97.8%
1
1 active
Security Reporting & Data Management
  • 3Management reports generated and distributed automatically
  • 3Record sets updated and normalized on automated schedule
2.2%
2
2 active
Total182 executions100%
3
3 active

Use Case Growth Over Time

9 unique playbooks  |  2 operational use cases  |  182 total executions (12m)  |  2025-11 to 2026-06
Toggle:
Toggle:

03Integration Ecosystem

CrowdStrike Alert Response
Microsoft Teams CrowdStrike
Security Reporting & Data Management
Microsoft Outlook

04Key Observations

✓  Strengths

Strengths

  • Human-in-the-loop SOC response is live. The CrowdStrike → Teams pipeline is actively running (21 executions), meaning analysts are receiving structured, actionable alerts through their collaboration tool rather than triaging raw detections manually.
  • Reporting cadence is fully automated. The bi-monthly manager report pipeline demonstrates that Zeus has eliminated recurring manual reporting work — data is pulled, transformed, and distributed without any human touch.

###

△  Gaps & Growth Opportunities

Gaps

  • Narrow automation footprint. With only 3 active workflows, Blink is deployed at the earliest stage of adoption. There is significant untapped surface area across IAM, cloud security, vulnerability management, and broader SOC use cases.
  • No response actions in the CrowdStrike workflow. The current detection workflow stops at analyst notification. Adding containment steps (host isolation, credential reset) would move Zeus from "alert routing" to "automated response."
  • No offboarding, access review, or identity lifecycle automation. IAM workflows are entirely absent — a common high-ROI area given the volume of identity-related work most security teams handle.
  • Reporting pipeline is fragile. Email_Mangers relies on Bash, two separate Python steps, and an HTTP table fetch in a sequential chain — a good candidate for simplification and error handling to ensure reliability.

Integration Ecosystem

Integration Used In
CrowdStrike Crowdstrike Detection
Microsoft Teams Crowdstrike Detection
Microsoft Outlook Email_Mangers
Blink Tables Title Update, Email_Mangers
Python / Bash Email_Mangers
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 New Agent Nick.Zeigler@zeusinc.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Nick.Zeigler@zeusinc.com0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 2 use cases | 182 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts routed to analyst with automated triage 21 Crowdstrike Detection
Management reports generated and distributed automatically 3 Email_Mangers
Record sets updated and normalized on automated schedule 3 Title Update
In the last 12 months, Blink automated: - 21 CrowdStrike security alerts triaged and escalated to analyst via Teams - 3 management reports generated, formatted, and emailed automatically - 3 scheduled data record normalization runs executed without manual intervention

Use Case Summary

Use Case Category Subcategory Playbooks Total Executions
CrowdStrike Alert Response SOC EDR containment & response, Case mgmt & SOAR 1 21
Security Reporting & Data Management GRC Security metrics & reporting 2 6

Use Cases

1. CrowdStrike Alert Response

Description: Automates the intake and analyst handoff of CrowdStrike endpoint detections. When a webhook fires, the workflow extracts key variables and routes the alert to an analyst via a Microsoft Teams interactive prompt, enabling a human-in-the-loop decision before further action.

Business problem solved: Reduces mean time to triage for endpoint detections by eliminating manual alert review queues — analysts receive structured, contextualized prompts directly in Teams rather than raw SIEM noise.

Category: SOC

Subcategories: EDR containment & response, Case mgmt & SOAR, Agentic SOC

Integrations: CrowdStrike (webhook trigger), Microsoft Teams

Playbook Executions (12 mo.)
Crowdstrike Detection 21

2. Security Reporting & Data Management

Description: A pair of bi-monthly scheduled workflows that prepare and distribute operational security data to management. Title Update normalizes record titles in a data table on the 1st and 15th; Email_Mangers then pulls those records, processes timestamps, renders an HTML report, and sends it to managers via Outlook.

Business problem solved: Eliminates manual reporting effort for recurring management updates — data retrieval, transformation, and distribution are fully automated on a predictable cadence, ensuring stakeholders receive consistent, up-to-date operational data without analyst involvement.

Category: GRC

Subcategories: Security metrics & reporting

Integrations: Blink Tables, Microsoft Outlook, Python, Bash

Playbook Executions (12 mo.)
Title Update 3
Email_Mangers 3

Key Observations

Strengths

  • Human-in-the-loop SOC response is live. The CrowdStrike → Teams pipeline is actively running (21 executions), meaning analysts are receiving structured, actionable alerts through their collaboration tool rather than triaging raw detections manually.
  • Reporting cadence is fully automated. The bi-monthly manager report pipeline demonstrates that Zeus has eliminated recurring manual reporting work — data is pulled, transformed, and distributed without any human touch.

Gaps

  • Narrow automation footprint. With only 3 active workflows, Blink is deployed at the earliest stage of adoption. There is significant untapped surface area across IAM, cloud security, vulnerability management, and broader SOC use cases.
  • No response actions in the CrowdStrike workflow. The current detection workflow stops at analyst notification. Adding containment steps (host isolation, credential reset) would move Zeus from "alert routing" to "automated response."
  • No offboarding, access review, or identity lifecycle automation. IAM workflows are entirely absent — a common high-ROI area given the volume of identity-related work most security teams handle.
  • Reporting pipeline is fragile. Email_Mangers relies on Bash, two separate Python steps, and an HTTP table fetch in a sequential chain — a good candidate for simplification and error handling to ensure reliability.

Integration Ecosystem

Integration Used In
CrowdStrike Crowdstrike Detection
Microsoft Teams Crowdstrike Detection
Microsoft Outlook Email_Mangers
Blink Tables Title Update, Email_Mangers
Python / Bash Email_Mangers
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.