Blink Security Automation — Confidential

monday.com — Customer Success Report

Generated 2026-07-16 | monday.com-value-report.md
2026-07-16Report Date
69Total Playbooks
182Unique Workflows (12m)
912,009Actions Automated (12m)
$234,570Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

69
Total playbooks built
all non-deleted workflows
39
Active playbooks
currently enabled
182
Unique workflows executed (12m)
distinct workflows that ran
912,009
Actions automated (12m)
completed action steps
5,066.7h
Hours saved (12m)
@ 20s per action
$234,570
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
3
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
3
Active AI agents
of 6 total
117
AI agent tasks executed (12m)
42 in last 30d
Note: All workflows in this workspace show 0 recorded executions over the last 12 months. The automation library is fully built and deployed — the KPI table below reflects the scope and scale of what is automated, ready to generate impact as the workflows are activated and execution data flows in.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Identity Threat Detection & Response
  • 0Okta identity threat alerts investigated & responded to
  • 0Slack threat alerts auto-triaged
  • 0LastPass threat alerts investigated
0.0%
17
17 active
Case Management & Alert Routing
  • 0Security alerts auto-routed via case management
  • 0PagerDuty incidents auto-created from alert escalations
0.0%
6
6 active
Alert Enrichment & IOC Lookup0 executions
0.0%
3
3 active
Threat Intelligence & Watchlist Management0 executions
0.0%
3
3 active
Privileged Access Management
  • 0Privilege-grant requests reviewed & actioned
0.0%
1
1 active
SaaS Administration0 executions
0.0%
1
1 active
Infrastructure & Shared Subflows0 executions
0.0%
7
7 active
Total0 executions100%
38
38 active

Use Case Growth Over Time

60 unique playbooks  |  7 operational use cases  |  0 total executions (12m)  |  2024-09 to 2025-02
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
String Utilities Splunk
Identity Threat Detection & Response
Monday Slack Okta Splunk String Utilities PagerDuty VirusTotal
Case Management & Alert Routing
Monday PagerDuty
Infrastructure & Shared Subflows
Monday Slack
Privileged Access Management
Okta Slack Monday
SaaS Administration
Okta Slack

04Key Observations

✓  Strengths

Strengths

  • Deep Okta coverage. The workspace contains 11 distinct Okta threat-response playbooks covering the most common identity attack patterns: MFA bypass, session impersonation, account takeover, TOR-IP activity, proxy authentication, policy modification, API token creation, and admin portal access. This is production-ready identity threat response automation.
  • Cohesive SOAR architecture. monday.com serves a dual role as both a SIEM-adjacent alert source (via webhooks) and as the case management backbone. The shared subflow pattern (Assign Security Automation Bot → Get Monday Sub-Items → Create Comment → Change Status) is consistent and reusable across all 17 identity threat playbooks.
  • Multi-source identity context. Investigation playbooks routinely pull context from Splunk (historical search), Okta (user profile, group membership), and VirusTotal (IP reputation) before deciding whether to escalate or auto-close. This enrichment depth reduces false-positive analyst interruptions.
  • User watchlist capability. The add/check watchlist pattern creates a persistent risk memory across unrelated alert investigations — a differentiating capability that most SOAR deployments lack.
  • Feedback loop for severity. Dedicated raise/decrease severity playbooks with audit comments create an auditable severity lifecycle, critical for compliance-conscious security programs.

###

△  Gaps & Growth Opportunities

Gaps

  • Zero recorded executions. All 39 workflows show 0 runs in the last 12 months. This suggests either the alert pipeline has not been fully connected to the Blink trigger layer, or execution logging was not enabled during the capture window. The highest-priority next step is confirming webhook connectivity from the monday.com alert board to the Main Alert Switch.
  • No EDR coverage. The workspace has no endpoint detection or response workflows. Given the depth of identity coverage, adding CrowdStrike or SentinelOne containment playbooks is the natural extension.
  • No cloud/SaaS misconfiguration coverage. Despite monday.com being a cloud-native company, there are no CSPM, cloud config audit, or SaaS policy workflows. AWS/GCP/Azure and Salesforce/Google Workspace posture automation would add a second major use-case pillar.
  • LastPass coverage is thin. Only two LastPass playbooks exist (TOR IP and Master Password Changed by Admin). LastPass is a high-value target; expanding to cover credential breach events and suspicious export activity would be valuable.
  • No phishing response. There is no email/phishing triage or response automation. Phishing is typically the highest-volume alert category in a corporate SOC and is absent here.

Integration Ecosystem

Integration Usage
monday.com Webhook trigger, board read/write, column update, comment creation, user lookup — central SOAR platform
Okta User lookup, session revocation, user attribute enrichment — identity source of truth across all IR playbooks
Splunk Historical search for IP lists, user activity correlation — used in 4 playbooks
VirusTotal IP reputation lookup — used in 4 TOR/proxy detection playbooks
Slack Human-in-the-loop decision gates (AskQuestionViaSlack) — used across 9 playbooks
PagerDuty Incident creation for critical escalations — 1 dedicated playbook
LastPass Alert source (inferred from playbook names) — 2 playbooks
Blink internal tables Alert template registry, watchlist storage — 3 playbooks
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
3
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
monday.com - SecOps 3 0 0 N/A
B AI Agents 3 active | 117 tasks (12m)

AI Agents

Active Agents
3
of 6 total
Tasks Executed (12m)
117
42 in last 30d
Data Usage (12m)
18,352,800
12,404,613 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 MDR automation agent monday.com - SecOps 65 15 5,389,057
2 Secops on-demand agent monday.com - SecOps 37 27 12,240,825
3 Static monday domain Agent monday.com - GRC 15 0 722,918
4 Agent Blink monday.com - SecOps 0 0 0
5 IT assistant monday.com - SecOps 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
monday.com - SecOps102
monday.com - GRC15
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 working workflows runs 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Monday domain checker 00
D Full Use Case Analysis 7 use cases | 0 executions (12m)

Business KPIs

Note: All workflows in this workspace show 0 recorded executions over the last 12 months. The automation library is fully built and deployed — the KPI table below reflects the scope and scale of what is automated, ready to generate impact as the workflows are activated and execution data flows in.
Metric Count Playbook
Okta identity threat alerts investigated & responded to 0 Okta - Account Takeover Attempt Detected, Okta - Attempted Bypass of Okta MFA, Okta - User Session Impersonation, Okta - Admin Portal Accessed Via Proxy, Okta - Successful Authentication Via Proxy, Okta - Activity from TOR IP - Allowed, Okta - Create API Token, Okta - User Rejected Multiple Push Verifications, Okta - Multiple Admin users disabled, Okta - Policy Modified or Deleted, Threat - Okta - Admin User Connected to New Device for the First Time - Rule
Slack threat alerts auto-triaged 0 Threat - Slack - CLI Login Detected - Rule
LastPass threat alerts investigated 0 LastPass - Activity from TOR IP, LastPass - Master Password Changed by Admin
monday.com platform threat alerts handled 0 monday - Activity from TOR IP, Monday.com - Transfer All Board Ownerships
Privilege-grant requests reviewed & actioned 0 Granting User Privileges to Non-IT Team Members, Okta - Grant User Privilege
Security alerts auto-routed via case management 0 Main Alert Switch, check alert for watchlist user
PagerDuty incidents auto-created from alert escalations 0 Create pager duty alert
In the last 12 months, Blink automated: - 0 Okta identity threat alerts investigated & responded to - 0 privilege-grant requests reviewed & actioned - 0 security alerts auto-routed via case management - 0 LastPass threat alerts investigated - 0 monday.com platform threat alerts handled *All workflows are deployed and configured. Execution counts will populate as the automation program scales.*

Use Case Summary

Use Case Category Subcategory Playbook Count
Identity Threat Detection & Response SOC Identity threat response 17
Case Management & Alert Routing SOC Case mgmt & SOAR 6
Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 3
Threat Intelligence & Watchlist Management SOC Threat intel ingest & curation 3
Privileged Access Management IAM Privileged account mgmt 2
SaaS Administration Other SaaS / IT administration 2
Infrastructure & Subflows — (Internal utilities) 6

Use Cases

1. Identity Threat Detection & Response

Description: Automated investigation and response to identity-based threats across Okta, LastPass, and Slack. Each playbook handles a specific alert type — enriching context, querying threat intelligence, asking the analyst a single scoped question via Slack, and closing or escalating the case.

Business problem solved: Security analysts are overwhelmed with identity alerts that are individually low-effort but collectively high-volume. This suite eliminates manual triage for common Okta/SaaS identity threat patterns, routing only true positives requiring human judgment.

Integrations: Okta, Splunk, VirusTotal, Slack, PagerDuty, monday.com (case mgmt)

Category: SOC | Subcategory: Identity threat response

Playbook Workflow ID Executions (12 mo)
Okta - Account Takeover Attempt Detected 63e6cfaa-ac28-4c50-aad1-02089b8ae901 0
Okta - Attempted Bypass of Okta MFA 70233d17-dec9-4384-b057-9342f495473d 0
Okta - User Session Impersonation 6dc2b22f-ae72-42c0-9c70-3683d9368b38 0
Okta - Admin Portal Accessed Via Proxy e27e09ea-9ebe-45a4-9db1-d4f548bc2e32 0
Okta - Successful Authentication Via Proxy 38322420-0502-4ae9-aa00-2f74964465ac 0
Okta - Activity from TOR IP - Allowed 83eccfa7-e63d-4c64-a546-ab502c91ee49 0
Okta - Create API Token e2d14640-7de3-4f61-a759-2cf56ef33bcc 0
Okta - User Rejected Multiple Push Verifications e4f624a5-77b7-43f2-85d4-036fdb27b55f 0
Okta - Multiple Admin users disabled 80c3183d-f6ae-4470-8982-7ae389282c79 0
Okta - Policy Modified or Deleted 29652fd8-6688-4ce1-aab8-34d7760f063f 0
Threat - Okta - Admin User Connected to New Device for the First Time - Rule a8c5ba8d-2c50-4dac-8639-f84a7c1fc29d 0
Okta Automation - User report suspicious Activity - Rule 321f3d74-2800-4d08-a96e-7c8d195a8477 0
LastPass - Activity from TOR IP eaa7a29b-1c31-4494-861b-0d7e12dc67a6 0
LastPass - Master Password Changed by Admin 5e5c444e-410a-44d3-813f-8806ddf14ecf 0
Threat - Slack - CLI Login Detected - Rule 1288328d-0593-48a1-8cde-c7c7429f3158 0
monday - Activity from TOR IP 39c70da3-86db-4508-85ea-850c5f2c2148 0
Okta - Grant User Privilege f9097a7c-ca29-4c19-9a24-93258f323afb 0

2. Case Management & Alert Routing

Description: Orchestrates the full lifecycle of a security alert inside monday.com as the case management platform — routing alerts to the correct handler, managing severity escalation and de-escalation, creating comments, assigning ownership, and raising PagerDuty incidents for critical cases.

Business problem solved: Security alerts arriving via monday.com webhooks need to be triaged, assigned, and tracked without manual ticket management. This use case replaces analyst toil with an automated dispatch layer that mirrors what a Tier-1 SOC analyst does in the first 10 minutes of alert triage.

Integrations: monday.com, PagerDuty, Slack

Category: SOC | Subcategory: Case mgmt & SOAR

Playbook Workflow ID Executions (12 mo)
Main Alert Switch 4b15e0b8-ef3d-4957-abba-8741cde585e9 0
check alert for watchlist user 82c53668-650d-4ffe-b557-201bf9806680 0
Raise alert severity 8ba2e56b-af73-48d3-b963-ae56063e1f1d 0
Decrease alert severity e6ede9e4-6c25-4cab-a602-d18811073055 0
Create pager duty alert 7e68b372-aab6-4ec6-83d2-9d938ca5d1b2 0
Monday.com integration 5b228714-85e5-43b0-a964-9582f14f7350 0

3. Alert Enrichment & IOC Lookup

Description: Supporting workflows that extract observables (IPs, users, devices) from raw alert payloads, check IPs against known internal address ranges, and process alerts that lack a matching detection template.

Business problem solved: Reduces the time analysts spend manually extracting indicators from raw log data and normalising them for downstream workflows.

Integrations: Blink internal tables, Splunk, Python

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Playbook Workflow ID Executions (12 mo)
Subflow - Extract Observables ae985347-12db-4852-a6e0-1834727371db 0
Check IP for monday Addresses 9220751b-a27d-4152-ba63-1d7eb4ca5feb 0
Utility - Process Alerts With Missing Templates 85c5a8b6-7a57-4be6-93e5-ef1a149f675f 0

4. Threat Intelligence & Watchlist Management

Description: Maintains an internal watchlist of high-risk users, checks each incoming alert against that list, and automatically elevates handling priority when a watchlisted user appears. New users can be added to the watchlist as an outcome of other investigation workflows.

Business problem solved: Analysts lose track of users who appeared in prior investigations. This use case creates a persistent, automated risk memory — ensuring repeat offenders or known-bad actors are flagged on every subsequent alert, without manual cross-referencing.

Integrations: Blink internal tables, monday.com (case mgmt)

Category: SOC | Subcategory: Threat intel ingest & curation

Playbook Workflow ID Executions (12 mo)
Add user to watchlist table c15b152c-a5ec-4f82-99f0-653e84fd7173 0
Check Watchlist for user alert 629862df-a389-4e7c-bb48-f63c615d74f9 0
Search for users open IT tickets - by name 58421846-6a23-4acc-8553-772d3b3bbca8 0

5. Privileged Access Management

Description: Detects and investigates privilege-grant events for users outside the IT department. Validates whether a grant is legitimate by cross-referencing HR ticket data and Okta user attributes, then requests analyst approval or auto-closes depending on context.

Business problem solved: Privilege creep is a top IAM risk. This use case ensures that every privilege elevation for a non-IT user receives at minimum automated scrutiny, and that suspicious grants surface to a human before becoming a standing access risk.

Integrations: Okta, Slack, Blink internal tables

Category: IAM | Subcategory: Privileged account mgmt

Playbook Workflow ID Executions (12 mo)
Granting User Privileges to Non-IT Team Members 13be5e38-d758-45a6-be08-b8cca4f568c1 0

6. SaaS Administration

Description: Automates ownership and governance operations within the monday.com platform itself — specifically transferring all board ownerships from one user to another, an operation typically triggered by offboarding or role changes.

Business problem solved: Manually reassigning board ownership during employee transitions is time-consuming and error-prone. This workflow automates the end-to-end transfer, validating both source and destination users via Okta and monday.com before executing the change.

Integrations: monday.com, Okta

Category: Other | Subcategory: SaaS / IT administration

Playbook Workflow ID Executions (12 mo)
Monday.com - Transfer All Board Ownerships 7b2080a4-d28b-4065-bf31-e3f086b299b9 0

Infrastructure & Shared Subflows

These are internal building blocks called by the use-case workflows above. They are excluded from KPI counts.

Category: SOC | Subcategory: Case mgmt & SOAR (internal utilities)

Playbook Role Workflow ID
Assign Security Automation Bot Assigns the bot user to every alert ticket on intake 66a06075-8ae4-411d-be41-918ef736520f
Get Monday Sub-Items Retrieves sub-items from a monday.com board item 67d9c8f4-4db2-4c39-9d6c-74d05e102fa1
change monday status column value Updates a status column value via GraphQL 7486f730-68b3-4e03-85dd-8d89e84af971
Create Monday Update (Comment) Adds an audit comment to a monday.com board item f008c26e-8da6-458e-97ba-aa8f47007d9b
Get User By monday.com ID Resolves a monday.com internal user ID to a user object 21b7e6e9-cb7e-4d92-b176-51a2d63016f0
Inform IT on Action Sends a Slack notification to the IT team after an automated action 7b8adda4-fdd1-4ac2-8a0e-56779a5e75b3
Assign Item to User Assigns a board item to a named analyst ba4f8785-52dc-49f8-9f38-e694cad7e0f2

Key Observations

Strengths

  • Deep Okta coverage. The workspace contains 11 distinct Okta threat-response playbooks covering the most common identity attack patterns: MFA bypass, session impersonation, account takeover, TOR-IP activity, proxy authentication, policy modification, API token creation, and admin portal access. This is production-ready identity threat response automation.
  • Cohesive SOAR architecture. monday.com serves a dual role as both a SIEM-adjacent alert source (via webhooks) and as the case management backbone. The shared subflow pattern (Assign Security Automation Bot → Get Monday Sub-Items → Create Comment → Change Status) is consistent and reusable across all 17 identity threat playbooks.
  • Multi-source identity context. Investigation playbooks routinely pull context from Splunk (historical search), Okta (user profile, group membership), and VirusTotal (IP reputation) before deciding whether to escalate or auto-close. This enrichment depth reduces false-positive analyst interruptions.
  • User watchlist capability. The add/check watchlist pattern creates a persistent risk memory across unrelated alert investigations — a differentiating capability that most SOAR deployments lack.
  • Feedback loop for severity. Dedicated raise/decrease severity playbooks with audit comments create an auditable severity lifecycle, critical for compliance-conscious security programs.

Gaps

  • Zero recorded executions. All 39 workflows show 0 runs in the last 12 months. This suggests either the alert pipeline has not been fully connected to the Blink trigger layer, or execution logging was not enabled during the capture window. The highest-priority next step is confirming webhook connectivity from the monday.com alert board to the Main Alert Switch.
  • No EDR coverage. The workspace has no endpoint detection or response workflows. Given the depth of identity coverage, adding CrowdStrike or SentinelOne containment playbooks is the natural extension.
  • No cloud/SaaS misconfiguration coverage. Despite monday.com being a cloud-native company, there are no CSPM, cloud config audit, or SaaS policy workflows. AWS/GCP/Azure and Salesforce/Google Workspace posture automation would add a second major use-case pillar.
  • LastPass coverage is thin. Only two LastPass playbooks exist (TOR IP and Master Password Changed by Admin). LastPass is a high-value target; expanding to cover credential breach events and suspicious export activity would be valuable.
  • No phishing response. There is no email/phishing triage or response automation. Phishing is typically the highest-volume alert category in a corporate SOC and is absent here.

Integration Ecosystem

Integration Usage
monday.com Webhook trigger, board read/write, column update, comment creation, user lookup — central SOAR platform
Okta User lookup, session revocation, user attribute enrichment — identity source of truth across all IR playbooks
Splunk Historical search for IP lists, user activity correlation — used in 4 playbooks
VirusTotal IP reputation lookup — used in 4 TOR/proxy detection playbooks
Slack Human-in-the-loop decision gates (AskQuestionViaSlack) — used across 9 playbooks
PagerDuty Incident creation for critical escalations — 1 dedicated playbook
LastPass Alert source (inferred from playbook names) — 2 playbooks
Blink internal tables Alert template registry, watchlist storage — 3 playbooks
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
monday salesforce my_salesforce_connection 2026-07-05
monday gemini new_api_key_test_connection 2026-06-30