BRIEFING
BLINKOPS / AI MANAGEMENT CERTIFICATION ANNOUNCED AUG 2026COTERIE / REPORTS ABOUT 600 VULNERABILITY ALERTS TRIAGED WEEKLY

COMPANY / SECURITY AUTOMATION

BlinkOps and the art of giving security teams their time back

A failed workflow could cost Coterie Insurance another two hours. BlinkOps bets that security teams need smaller AI agents, clearer controls, and fewer chores between an alert and an answer.

At Coterie Insurance, the frustrating part of automation was the wait. An engineer could assemble a workflow, discover that a late step had failed, and have to run the whole thing again. Each attempt could take two hours to produce an answer. Automation had acquired a peculiar habit: keeping its owners busy.

THE STORY IN THREE POINTS
  • Blink combines specialized AI agents with repeatable security workflows.
  • Its customers want investigation, approvals and action connected across existing tools.
  • The useful lesson: give an agent a bounded chore before giving it a department.

That is a revealing place to begin with BlinkOps. The company sells software to security teams whose work stretches between systems: an alert here, an identity record there, a ticket waiting somewhere else. Its product, Blink, brings those steps together. The appeal lies in the distance between knowing something deserves attention and doing something useful about it.

The two-hour retry

Coterie had used in-house tools, including Azure Logic Apps. Its engineers wanted integrations with their existing systems, a mixture of fixed workflows and agents, and the ability to work quickly while retaining control. BlinkOps became the place to build that combination.

In the published customer account, an agent gathers logs, adds historical context and prepares notes before a human reviews the case. Coterie reports approximately 50% lower mean time to resolve SOC incidents and about 600 vulnerability alerts automatically triaged weekly. Those are customer-reported results. Their significance is the mechanism: an analyst starts with evidence assembled rather than a fresh scavenger hunt.

“The biggest benefit I’ve seen from working with BlinkOps comes down to control with speed.”

Brandon Kern, Coterie Insurance

An agent with a job description

BlinkOps was founded in 2021 by Gil Barak and Zion Zatlavi. They had previously co-founded Secdo, later acquired by Palo Alto Networks. They came to this problem with experience of security operations, where a useful discovery must eventually become an intervention.

Blink’s Agentic Studio lets teams construct specialized micro-agents. Give one a role, grant it particular abilities, and supply the procedures and reference material it needs. A phishing investigator and a compliance auditor need different knowledge. Asking one general-purpose assistant to do both would be an ambitious hiring decision.

The accompanying Workflow Studio provides a fixed sequence of steps. Agents can enter where judgment helps; predictable tasks can follow prescribed logic. Case management keeps investigations and response together. This division of labour matters: deciding whether evidence is suspicious and opening the correct ticket are different kinds of work.

Blink workflow builder showing connected automation steps
01 / The choreography behind the answer. Blink’s published workflow-builder screenshot turns a succession of chores into a visible sequence.

Start with the chore everybody hates

BDO Israel’s managed detection and response service had another version of the same problem. It handled more than 20,000 alerts monthly. Its previous SOAR tools demanded coding effort and offered interfaces too complicated for customers to use comfortably. Collaboration still travelled through scattered systems.

The team began with repetitive tasks, including known false positives and malicious IPs. Workshops helped analysts build workflows; deployment then expanded to more than 40 clients. The published study reports a 40% reduction in manual tasks. The sequence is worth copying: choose work people understand, demonstrate a result, and expand after the pilot earns confidence.

At Larry H. Miller Company, the chores included exporting reports, comparing spreadsheets and checking endpoint compliance. BlinkOps worked with the team during a three-month trial to build dashboards and workflows. Its account describes automated licence reviews, patch reminders and endpoint checks, with 40 to 50 hours saved weekly across cybersecurity and operations.

A licence audit lacks the glamour of a cyberattack. It also arrives reliably. That makes it a respectable candidate for automation: a recurring job with identifiable inputs, an owner and a result somebody can check.

40%
LESS MANUAL WORK

Reported in BDO Israel’s BlinkOps case study. One deployment’s result, rather than a forecast for every buyer.

Buying back the handoff

BlinkOps competes in the territory occupied by SOAR platforms and security workflow builders. Buyers can also consider Cortex XSOAR, Splunk SOAR, Tines and Torq. BlinkOps’s proposition combines custom agents, workflow execution and case management across security functions, extending beyond alert triage into identity, vulnerability management and compliance.

That breadth offers a practical route for an enterprise: begin with one troublesome process, then reuse connections elsewhere. Identity workflows can coordinate access requests or employee departures. Vulnerability workflows can prioritize findings and route fixes. Compliance workflows can collect evidence. These are connected administrative responsibilities with security consequences.

The commercial arrangement is enterprise SaaS, with subscription scope and usage limits established through contracts. Support and deployment expertise are part of the offering, and marketplace procurement is available. The buying decision should account for the engineers’ setup time, ongoing usage and the effort needed to maintain a workflow alongside the subscription itself.

Capital has followed the pitch. BlinkOps announced a $50 million Series B in July 2025, led by O.G. Venture Partners, reporting $90 million invested overall. By November, Barak wrote that funding exceeded $100 million. Funding buys room to develop and deploy; the customer still needs a useful working process.

BlinkOps team gathered outdoors in matching company shirts
02 / The humans behind the digital colleagues. Matching shirts are easy; agreeing which actions require approval takes considerably more work.

Permission is part of the product

BlinkOps lets teams constrain access at workspace and task levels and place human approvals before consequential actions. Its August 2026 ISO/IEC 42001 announcement concerns an audited AI management system. That is evidence of governance processes, rather than a guarantee that every investigation will reach the right conclusion.

The same month, it introduced support for customers’ own Microsoft Foundry subscriptions, addressing data boundaries, logging and allocation of cloud spending. These details matter to the people who must explain an automated action after it happens.

A sensible pilot would measure human minutes saved, exceptions, approval delays and incorrect actions. It would begin with limited permissions and reviewable outputs. Poor inputs, unclear policy or untested access can spoil the arrangement. The attractive outcome is straightforward: an analyst opens a case and can spend attention on the decision, because the gathering, copying and chasing have already happened.