01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| CrowdStrike Alert Response |
| 97.8% | 1 1 active |
| Security Reporting & Data Management |
| 2.2% | 2 2 active |
| Total | 182 executions | 100% | 3 3 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Human-in-the-loop SOC response is live. The CrowdStrike → Teams pipeline is actively running (21 executions), meaning analysts are receiving structured, actionable alerts through their collaboration tool rather than triaging raw detections manually.
- Reporting cadence is fully automated. The bi-monthly manager report pipeline demonstrates that Zeus has eliminated recurring manual reporting work — data is pulled, transformed, and distributed without any human touch.
###
Gaps
- Narrow automation footprint. With only 3 active workflows, Blink is deployed at the earliest stage of adoption. There is significant untapped surface area across IAM, cloud security, vulnerability management, and broader SOC use cases.
- No response actions in the CrowdStrike workflow. The current detection workflow stops at analyst notification. Adding containment steps (host isolation, credential reset) would move Zeus from "alert routing" to "automated response."
- No offboarding, access review, or identity lifecycle automation. IAM workflows are entirely absent — a common high-ROI area given the volume of identity-related work most security teams handle.
- Reporting pipeline is fragile.
Email_Mangersrelies on Bash, two separate Python steps, and an HTTP table fetch in a sequential chain — a good candidate for simplification and error handling to ensure reliability.
Integration Ecosystem
| Integration | Used In |
|---|---|
| CrowdStrike | Crowdstrike Detection |
| Microsoft Teams | Crowdstrike Detection |
| Microsoft Outlook | Email_Mangers |
| Blink Tables | Title Update, Email_Mangers |
| Python / Bash | Email_Mangers |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | New Agent | Nick.Zeigler@zeusinc.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Nick.Zeigler@zeusinc.com | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 2 use cases | 182 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts routed to analyst with automated triage | 21 | Crowdstrike Detection |
| Management reports generated and distributed automatically | 3 | Email_Mangers |
| Record sets updated and normalized on automated schedule | 3 | Title Update |
Use Case Summary
| Use Case | Category | Subcategory | Playbooks | Total Executions |
|---|---|---|---|---|
| CrowdStrike Alert Response | SOC | EDR containment & response, Case mgmt & SOAR | 1 | 21 |
| Security Reporting & Data Management | GRC | Security metrics & reporting | 2 | 6 |
Use Cases
1. CrowdStrike Alert Response
Description: Automates the intake and analyst handoff of CrowdStrike endpoint detections. When a webhook fires, the workflow extracts key variables and routes the alert to an analyst via a Microsoft Teams interactive prompt, enabling a human-in-the-loop decision before further action.
Business problem solved: Reduces mean time to triage for endpoint detections by eliminating manual alert review queues — analysts receive structured, contextualized prompts directly in Teams rather than raw SIEM noise.
Category: SOC
Subcategories: EDR containment & response, Case mgmt & SOAR, Agentic SOC
Integrations: CrowdStrike (webhook trigger), Microsoft Teams
| Playbook | Executions (12 mo.) |
|---|---|
| Crowdstrike Detection | 21 |
2. Security Reporting & Data Management
Description: A pair of bi-monthly scheduled workflows that prepare and distribute operational security data to management. Title Update normalizes record titles in a data table on the 1st and 15th; Email_Mangers then pulls those records, processes timestamps, renders an HTML report, and sends it to managers via Outlook.
Business problem solved: Eliminates manual reporting effort for recurring management updates — data retrieval, transformation, and distribution are fully automated on a predictable cadence, ensuring stakeholders receive consistent, up-to-date operational data without analyst involvement.
Category: GRC
Subcategories: Security metrics & reporting
Integrations: Blink Tables, Microsoft Outlook, Python, Bash
| Playbook | Executions (12 mo.) |
|---|---|
| Title Update | 3 |
| Email_Mangers | 3 |
Key Observations
Strengths
- Human-in-the-loop SOC response is live. The CrowdStrike → Teams pipeline is actively running (21 executions), meaning analysts are receiving structured, actionable alerts through their collaboration tool rather than triaging raw detections manually.
- Reporting cadence is fully automated. The bi-monthly manager report pipeline demonstrates that Zeus has eliminated recurring manual reporting work — data is pulled, transformed, and distributed without any human touch.
Gaps
- Narrow automation footprint. With only 3 active workflows, Blink is deployed at the earliest stage of adoption. There is significant untapped surface area across IAM, cloud security, vulnerability management, and broader SOC use cases.
- No response actions in the CrowdStrike workflow. The current detection workflow stops at analyst notification. Adding containment steps (host isolation, credential reset) would move Zeus from "alert routing" to "automated response."
- No offboarding, access review, or identity lifecycle automation. IAM workflows are entirely absent — a common high-ROI area given the volume of identity-related work most security teams handle.
- Reporting pipeline is fragile.
Email_Mangersrelies on Bash, two separate Python steps, and an HTTP table fetch in a sequential chain — a good candidate for simplification and error handling to ensure reliability.
Integration Ecosystem
| Integration | Used In |
|---|---|
| CrowdStrike | Crowdstrike Detection |
| Microsoft Teams | Crowdstrike Detection |
| Microsoft Outlook | Email_Mangers |
| Blink Tables | Title Update, Email_Mangers |
| Python / Bash | Email_Mangers |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.