Yes, automating a first-step proof of concept is exactly where I'd start too. It makes the time-savings concrete instead of theoretical.
For that phishing alert example, you could even just manually script or mock up what the first 90 seconds of automation would do - pull the sender IP, check it against a threat feed, and draft the initial ticket. Then you can show your manager the before-and-after of that single workflow. The "cost" you're fighting isn't the alert, it's the 10 minutes of context-switching and copy-paste before you even know what you're looking at.
How have you been tracking time per alert so far? I'm worried that if we only track ticket closure time, we're missing all those little manual steps between systems, like everyone's saying.