01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Identity Threat Detection & Response |
| 0.0% | 17 17 active |
| Case Management & Alert Routing |
| 0.0% | 6 6 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 3 3 active |
| Threat Intelligence & Watchlist Management | 0 executions | 0.0% | 3 3 active |
| Privileged Access Management |
| 0.0% | 1 1 active |
| SaaS Administration | 0 executions | 0.0% | 1 1 active |
| Infrastructure & Shared Subflows | 0 executions | 0.0% | 7 7 active |
| Total | 0 executions | 100% | 38 38 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Deep Okta coverage. The workspace contains 11 distinct Okta threat-response playbooks covering the most common identity attack patterns: MFA bypass, session impersonation, account takeover, TOR-IP activity, proxy authentication, policy modification, API token creation, and admin portal access. This is production-ready identity threat response automation.
- Cohesive SOAR architecture. monday.com serves a dual role as both a SIEM-adjacent alert source (via webhooks) and as the case management backbone. The shared subflow pattern (Assign Security Automation Bot → Get Monday Sub-Items → Create Comment → Change Status) is consistent and reusable across all 17 identity threat playbooks.
- Multi-source identity context. Investigation playbooks routinely pull context from Splunk (historical search), Okta (user profile, group membership), and VirusTotal (IP reputation) before deciding whether to escalate or auto-close. This enrichment depth reduces false-positive analyst interruptions.
- User watchlist capability. The add/check watchlist pattern creates a persistent risk memory across unrelated alert investigations — a differentiating capability that most SOAR deployments lack.
- Feedback loop for severity. Dedicated raise/decrease severity playbooks with audit comments create an auditable severity lifecycle, critical for compliance-conscious security programs.
###
Gaps
- Zero recorded executions. All 39 workflows show 0 runs in the last 12 months. This suggests either the alert pipeline has not been fully connected to the Blink trigger layer, or execution logging was not enabled during the capture window. The highest-priority next step is confirming webhook connectivity from the monday.com alert board to the Main Alert Switch.
- No EDR coverage. The workspace has no endpoint detection or response workflows. Given the depth of identity coverage, adding CrowdStrike or SentinelOne containment playbooks is the natural extension.
- No cloud/SaaS misconfiguration coverage. Despite monday.com being a cloud-native company, there are no CSPM, cloud config audit, or SaaS policy workflows. AWS/GCP/Azure and Salesforce/Google Workspace posture automation would add a second major use-case pillar.
- LastPass coverage is thin. Only two LastPass playbooks exist (TOR IP and Master Password Changed by Admin). LastPass is a high-value target; expanding to cover credential breach events and suspicious export activity would be valuable.
- No phishing response. There is no email/phishing triage or response automation. Phishing is typically the highest-volume alert category in a corporate SOC and is absent here.
Integration Ecosystem
| Integration | Usage |
|---|---|
| monday.com | Webhook trigger, board read/write, column update, comment creation, user lookup — central SOAR platform |
| Okta | User lookup, session revocation, user attribute enrichment — identity source of truth across all IR playbooks |
| Splunk | Historical search for IP lists, user activity correlation — used in 4 playbooks |
| VirusTotal | IP reputation lookup — used in 4 TOR/proxy detection playbooks |
| Slack | Human-in-the-loop decision gates (AskQuestionViaSlack) — used across 9 playbooks |
| PagerDuty | Incident creation for critical escalations — 1 dedicated playbook |
| LastPass | Alert source (inferred from playbook names) — 2 playbooks |
| Blink internal tables | Alert template registry, watchlist storage — 3 playbooks |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| monday.com - SecOps | 3 | 0 | 0 | N/A |
B AI Agents 3 active | 117 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | MDR automation agent | monday.com - SecOps | 65 | 15 | 5,389,057 |
| 2 | Secops on-demand agent | monday.com - SecOps | 37 | 27 | 12,240,825 |
| 3 | Static monday domain Agent | monday.com - GRC | 15 | 0 | 722,918 |
| 4 | Agent Blink | monday.com - SecOps | 0 | 0 | 0 |
| 5 | IT assistant | monday.com - SecOps | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| monday.com - SecOps | 102 |
| monday.com - GRC | 15 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | working workflows runs | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Monday domain checker | 0 | 0 |
D Full Use Case Analysis 7 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Okta identity threat alerts investigated & responded to | 0 | Okta - Account Takeover Attempt Detected, Okta - Attempted Bypass of Okta MFA, Okta - User Session Impersonation, Okta - Admin Portal Accessed Via Proxy, Okta - Successful Authentication Via Proxy, Okta - Activity from TOR IP - Allowed, Okta - Create API Token, Okta - User Rejected Multiple Push Verifications, Okta - Multiple Admin users disabled, Okta - Policy Modified or Deleted, Threat - Okta - Admin User Connected to New Device for the First Time - Rule |
| Slack threat alerts auto-triaged | 0 | Threat - Slack - CLI Login Detected - Rule |
| LastPass threat alerts investigated | 0 | LastPass - Activity from TOR IP, LastPass - Master Password Changed by Admin |
| monday.com platform threat alerts handled | 0 | monday - Activity from TOR IP, Monday.com - Transfer All Board Ownerships |
| Privilege-grant requests reviewed & actioned | 0 | Granting User Privileges to Non-IT Team Members, Okta - Grant User Privilege |
| Security alerts auto-routed via case management | 0 | Main Alert Switch, check alert for watchlist user |
| PagerDuty incidents auto-created from alert escalations | 0 | Create pager duty alert |
Use Case Summary
| Use Case | Category | Subcategory | Playbook Count |
|---|---|---|---|
| Identity Threat Detection & Response | SOC | Identity threat response | 17 |
| Case Management & Alert Routing | SOC | Case mgmt & SOAR | 6 |
| Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 3 |
| Threat Intelligence & Watchlist Management | SOC | Threat intel ingest & curation | 3 |
| Privileged Access Management | IAM | Privileged account mgmt | 2 |
| SaaS Administration | Other | SaaS / IT administration | 2 |
| Infrastructure & Subflows | — | (Internal utilities) | 6 |
Use Cases
1. Identity Threat Detection & Response
Description: Automated investigation and response to identity-based threats across Okta, LastPass, and Slack. Each playbook handles a specific alert type — enriching context, querying threat intelligence, asking the analyst a single scoped question via Slack, and closing or escalating the case.
Business problem solved: Security analysts are overwhelmed with identity alerts that are individually low-effort but collectively high-volume. This suite eliminates manual triage for common Okta/SaaS identity threat patterns, routing only true positives requiring human judgment.
Integrations: Okta, Splunk, VirusTotal, Slack, PagerDuty, monday.com (case mgmt)
Category: SOC | Subcategory: Identity threat response
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Okta - Account Takeover Attempt Detected | 63e6cfaa-ac28-4c50-aad1-02089b8ae901 | 0 |
| Okta - Attempted Bypass of Okta MFA | 70233d17-dec9-4384-b057-9342f495473d | 0 |
| Okta - User Session Impersonation | 6dc2b22f-ae72-42c0-9c70-3683d9368b38 | 0 |
| Okta - Admin Portal Accessed Via Proxy | e27e09ea-9ebe-45a4-9db1-d4f548bc2e32 | 0 |
| Okta - Successful Authentication Via Proxy | 38322420-0502-4ae9-aa00-2f74964465ac | 0 |
| Okta - Activity from TOR IP - Allowed | 83eccfa7-e63d-4c64-a546-ab502c91ee49 | 0 |
| Okta - Create API Token | e2d14640-7de3-4f61-a759-2cf56ef33bcc | 0 |
| Okta - User Rejected Multiple Push Verifications | e4f624a5-77b7-43f2-85d4-036fdb27b55f | 0 |
| Okta - Multiple Admin users disabled | 80c3183d-f6ae-4470-8982-7ae389282c79 | 0 |
| Okta - Policy Modified or Deleted | 29652fd8-6688-4ce1-aab8-34d7760f063f | 0 |
| Threat - Okta - Admin User Connected to New Device for the First Time - Rule | a8c5ba8d-2c50-4dac-8639-f84a7c1fc29d | 0 |
| Okta Automation - User report suspicious Activity - Rule | 321f3d74-2800-4d08-a96e-7c8d195a8477 | 0 |
| LastPass - Activity from TOR IP | eaa7a29b-1c31-4494-861b-0d7e12dc67a6 | 0 |
| LastPass - Master Password Changed by Admin | 5e5c444e-410a-44d3-813f-8806ddf14ecf | 0 |
| Threat - Slack - CLI Login Detected - Rule | 1288328d-0593-48a1-8cde-c7c7429f3158 | 0 |
| monday - Activity from TOR IP | 39c70da3-86db-4508-85ea-850c5f2c2148 | 0 |
| Okta - Grant User Privilege | f9097a7c-ca29-4c19-9a24-93258f323afb | 0 |
2. Case Management & Alert Routing
Description: Orchestrates the full lifecycle of a security alert inside monday.com as the case management platform — routing alerts to the correct handler, managing severity escalation and de-escalation, creating comments, assigning ownership, and raising PagerDuty incidents for critical cases.
Business problem solved: Security alerts arriving via monday.com webhooks need to be triaged, assigned, and tracked without manual ticket management. This use case replaces analyst toil with an automated dispatch layer that mirrors what a Tier-1 SOC analyst does in the first 10 minutes of alert triage.
Integrations: monday.com, PagerDuty, Slack
Category: SOC | Subcategory: Case mgmt & SOAR
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Main Alert Switch | 4b15e0b8-ef3d-4957-abba-8741cde585e9 | 0 |
| check alert for watchlist user | 82c53668-650d-4ffe-b557-201bf9806680 | 0 |
| Raise alert severity | 8ba2e56b-af73-48d3-b963-ae56063e1f1d | 0 |
| Decrease alert severity | e6ede9e4-6c25-4cab-a602-d18811073055 | 0 |
| Create pager duty alert | 7e68b372-aab6-4ec6-83d2-9d938ca5d1b2 | 0 |
| Monday.com integration | 5b228714-85e5-43b0-a964-9582f14f7350 | 0 |
3. Alert Enrichment & IOC Lookup
Description: Supporting workflows that extract observables (IPs, users, devices) from raw alert payloads, check IPs against known internal address ranges, and process alerts that lack a matching detection template.
Business problem solved: Reduces the time analysts spend manually extracting indicators from raw log data and normalising them for downstream workflows.
Integrations: Blink internal tables, Splunk, Python
Category: SOC | Subcategory: Alert enrichment / IOC lookup
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Subflow - Extract Observables | ae985347-12db-4852-a6e0-1834727371db | 0 |
| Check IP for monday Addresses | 9220751b-a27d-4152-ba63-1d7eb4ca5feb | 0 |
| Utility - Process Alerts With Missing Templates | 85c5a8b6-7a57-4be6-93e5-ef1a149f675f | 0 |
4. Threat Intelligence & Watchlist Management
Description: Maintains an internal watchlist of high-risk users, checks each incoming alert against that list, and automatically elevates handling priority when a watchlisted user appears. New users can be added to the watchlist as an outcome of other investigation workflows.
Business problem solved: Analysts lose track of users who appeared in prior investigations. This use case creates a persistent, automated risk memory — ensuring repeat offenders or known-bad actors are flagged on every subsequent alert, without manual cross-referencing.
Integrations: Blink internal tables, monday.com (case mgmt)
Category: SOC | Subcategory: Threat intel ingest & curation
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Add user to watchlist table | c15b152c-a5ec-4f82-99f0-653e84fd7173 | 0 |
| Check Watchlist for user alert | 629862df-a389-4e7c-bb48-f63c615d74f9 | 0 |
| Search for users open IT tickets - by name | 58421846-6a23-4acc-8553-772d3b3bbca8 | 0 |
5. Privileged Access Management
Description: Detects and investigates privilege-grant events for users outside the IT department. Validates whether a grant is legitimate by cross-referencing HR ticket data and Okta user attributes, then requests analyst approval or auto-closes depending on context.
Business problem solved: Privilege creep is a top IAM risk. This use case ensures that every privilege elevation for a non-IT user receives at minimum automated scrutiny, and that suspicious grants surface to a human before becoming a standing access risk.
Integrations: Okta, Slack, Blink internal tables
Category: IAM | Subcategory: Privileged account mgmt
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Granting User Privileges to Non-IT Team Members | 13be5e38-d758-45a6-be08-b8cca4f568c1 | 0 |
6. SaaS Administration
Description: Automates ownership and governance operations within the monday.com platform itself — specifically transferring all board ownerships from one user to another, an operation typically triggered by offboarding or role changes.
Business problem solved: Manually reassigning board ownership during employee transitions is time-consuming and error-prone. This workflow automates the end-to-end transfer, validating both source and destination users via Okta and monday.com before executing the change.
Integrations: monday.com, Okta
Category: Other | Subcategory: SaaS / IT administration
| Playbook | Workflow ID | Executions (12 mo) |
|---|---|---|
| Monday.com - Transfer All Board Ownerships | 7b2080a4-d28b-4065-bf31-e3f086b299b9 | 0 |
Infrastructure & Shared Subflows
These are internal building blocks called by the use-case workflows above. They are excluded from KPI counts.
Category: SOC | Subcategory: Case mgmt & SOAR (internal utilities)
| Playbook | Role | Workflow ID |
|---|---|---|
| Assign Security Automation Bot | Assigns the bot user to every alert ticket on intake | 66a06075-8ae4-411d-be41-918ef736520f |
| Get Monday Sub-Items | Retrieves sub-items from a monday.com board item | 67d9c8f4-4db2-4c39-9d6c-74d05e102fa1 |
| change monday status column value | Updates a status column value via GraphQL | 7486f730-68b3-4e03-85dd-8d89e84af971 |
| Create Monday Update (Comment) | Adds an audit comment to a monday.com board item | f008c26e-8da6-458e-97ba-aa8f47007d9b |
| Get User By monday.com ID | Resolves a monday.com internal user ID to a user object | 21b7e6e9-cb7e-4d92-b176-51a2d63016f0 |
| Inform IT on Action | Sends a Slack notification to the IT team after an automated action | 7b8adda4-fdd1-4ac2-8a0e-56779a5e75b3 |
| Assign Item to User | Assigns a board item to a named analyst | ba4f8785-52dc-49f8-9f38-e694cad7e0f2 |
Key Observations
Strengths
- Deep Okta coverage. The workspace contains 11 distinct Okta threat-response playbooks covering the most common identity attack patterns: MFA bypass, session impersonation, account takeover, TOR-IP activity, proxy authentication, policy modification, API token creation, and admin portal access. This is production-ready identity threat response automation.
- Cohesive SOAR architecture. monday.com serves a dual role as both a SIEM-adjacent alert source (via webhooks) and as the case management backbone. The shared subflow pattern (Assign Security Automation Bot → Get Monday Sub-Items → Create Comment → Change Status) is consistent and reusable across all 17 identity threat playbooks.
- Multi-source identity context. Investigation playbooks routinely pull context from Splunk (historical search), Okta (user profile, group membership), and VirusTotal (IP reputation) before deciding whether to escalate or auto-close. This enrichment depth reduces false-positive analyst interruptions.
- User watchlist capability. The add/check watchlist pattern creates a persistent risk memory across unrelated alert investigations — a differentiating capability that most SOAR deployments lack.
- Feedback loop for severity. Dedicated raise/decrease severity playbooks with audit comments create an auditable severity lifecycle, critical for compliance-conscious security programs.
Gaps
- Zero recorded executions. All 39 workflows show 0 runs in the last 12 months. This suggests either the alert pipeline has not been fully connected to the Blink trigger layer, or execution logging was not enabled during the capture window. The highest-priority next step is confirming webhook connectivity from the monday.com alert board to the Main Alert Switch.
- No EDR coverage. The workspace has no endpoint detection or response workflows. Given the depth of identity coverage, adding CrowdStrike or SentinelOne containment playbooks is the natural extension.
- No cloud/SaaS misconfiguration coverage. Despite monday.com being a cloud-native company, there are no CSPM, cloud config audit, or SaaS policy workflows. AWS/GCP/Azure and Salesforce/Google Workspace posture automation would add a second major use-case pillar.
- LastPass coverage is thin. Only two LastPass playbooks exist (TOR IP and Master Password Changed by Admin). LastPass is a high-value target; expanding to cover credential breach events and suspicious export activity would be valuable.
- No phishing response. There is no email/phishing triage or response automation. Phishing is typically the highest-volume alert category in a corporate SOC and is absent here.
Integration Ecosystem
| Integration | Usage |
|---|---|
| monday.com | Webhook trigger, board read/write, column update, comment creation, user lookup — central SOAR platform |
| Okta | User lookup, session revocation, user attribute enrichment — identity source of truth across all IR playbooks |
| Splunk | Historical search for IP lists, user activity correlation — used in 4 playbooks |
| VirusTotal | IP reputation lookup — used in 4 TOR/proxy detection playbooks |
| Slack | Human-in-the-loop decision gates (AskQuestionViaSlack) — used across 9 playbooks |
| PagerDuty | Incident creation for critical escalations — 1 dedicated playbook |
| LastPass | Alert source (inferred from playbook names) — 2 playbooks |
| Blink internal tables | Alert template registry, watchlist storage — 3 playbooks |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| monday | salesforce | my_salesforce_connection | 2026-07-05 |
| monday | gemini | new_api_key_test_connection | 2026-06-30 |