All templates

Automated AppSheet App Access Audit

Every Monday, WebRun opens AppSheet, reads the sharing settings and deployment status on every app, records who has access at what level and which data sources each app reads, builds the access table in Notion, and drafts a revoke request in Gmail for your approval.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 AppSheet read sharing on every app
2 Notion build the access table
3 Gmail draft the revoke request
In short

How do I audit who has access to my AppSheet apps?

Every Monday WebRun opens AppSheet, reads the sharing settings on every app, and records who has access at what level alongside the data sources each app reads. It builds the access table in Notion and drafts a revoke request in Gmail, flagging leavers and outside addresses.

  • One table shows every app, every user, and every access level
  • Leavers and outside addresses are flagged the week they appear
  • Access changes are proposed for approval, never made automatically

Built for app owners · IT administrators · operations teams · compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.appsheet.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    AppSheet - read sharing on every app
    appsheet.com
    WebRun in AppSheet: read sharing on every app
    WebRun opens AppSheet to read sharing on every app.
    • Open AppSheet and list every app you own, with its deployment status
    • Read the sharing settings on each one and capture every user and their access level
    • Note the data sources each app reads, so the sensitivity of the access is clear

    Done when Every app has its full user list, access levels, and data sources recorded.

  3. 2
    Notion - build the access table
    notion.so
    WebRun in Notion: build the access table
    WebRun opens Notion to build the access table.
    • Update your access register with one row per app and user
    • Flag rows where the address is outside your company domain, and rows for people on your leavers list
    • Show what changed since last week: new access granted, access removed, apps newly deployed

    Done when The Notion register shows the current app-by-user access picture with changes marked.

  4. 3
    Gmail - draft the revoke request
    gmail.com
    WebRun in Gmail: draft the revoke request
    WebRun opens Gmail to draft the revoke request.
    • Draft an email to the app owner listing the access that looks wrong, riskiest first
    • Explain each flag: leaver, outside domain, or editor rights on an app reading sensitive data
    • Leave the email unsent and remove nobody. Every revoke is a human decision

    Done when A revoke proposal is drafted in Gmail and waiting for the owner to approve.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.appsheet.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access register · Notion
OutputWhat each run produces - One table of app by user by access level, with leavers, outside addresses, and week-on-week changes flagged, plus a drafted revoke list.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove anyone's access?

No. WebRun reads sharing settings and proposes. The revoke list is left as an unsent Gmail draft for the app owner, and no user, app, or permission is ever changed by the run.

How does it spot someone who has left?

It checks each address against the leavers list you point it at, and separately flags any address outside your company domain, so both cases surface even if the lists disagree.

Does it open the underlying data?

No. It records which data sources an app reads so you can judge sensitivity, but it never opens, exports, or copies the records inside them.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.