All templates

Automated Appsmith App Access Reviews

Every Monday, WebRun opens Appsmith, walks every workspace and app, records who holds each role, notes which apps are shared publicly and which datasources they reach, opens a Trello card per access risk, and messages you on WhatsApp with the ones worth acting on today.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Appsmith review sharing and roles
2 Trello open a card per access risk
3 WhatsApp flag the public shares
In short

How do I review who can access my internal tools each week?

Every Monday WebRun signs into Appsmith and reviews access rather than build state: who holds which role in each workspace, which apps are shared publicly, and which datasources those apps reach. It opens a Trello card per risk and messages the platform owner on WhatsApp, so rights get pulled back the same week.

  • Publicly shared internal tools are caught within a week
  • Leavers holding edit rights surface with a card and an owner
  • Every access risk has a named next step rather than a note in someone's head

Built for platform teams · internal tools owners · IT security · engineering managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.appsmith.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Appsmith - review sharing and roles
    appsmith.com
    WebRun in Appsmith: review sharing and roles
    WebRun opens Appsmith to review sharing and roles.
    • Sign in to Appsmith and list every workspace you own
    • For each workspace, record the members and the role each one holds
    • Open each app's share settings and note whether it is shared publicly or invite only
    • Note which datasources each publicly shared app can reach
    • Compare the member list against your current staff roster and mark anyone who has left

    Done when Every app and workspace has its sharing state and role list recorded.

  3. 2
    Trello - open a card per access risk
    trello.com
    WebRun in Trello: open a card per access risk
    WebRun opens Trello to open a card per access risk.
    • Open a card for each access risk found: a public share, a leaver with edit rights, or an app nobody owns
    • Put the workspace, the app and the current setting in the card description
    • Label the cards holding a public share on a live datasource as the ones to do first
    • Skip risks that already have an open card from an earlier week

    Done when Every access risk has a Trello card with an owner and a label.

  4. 3
    WhatsApp - flag the public shares
    whatsapp.com
    WebRun in WhatsApp: flag the public shares
    WebRun opens WhatsApp to flag the public shares.
    • Message the platform owner with the count of apps shared publicly and leavers still holding rights
    • Name the highest risk items first, with a link to the Trello card
    • Note when the review found nothing new, so a quiet week is still reported

    Done when The platform owner has this week's access summary on WhatsApp.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.appsmith.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access review · WhatsApp
OutputWhat each run produces - A weekly access picture: who holds which role in each workspace, which apps are public, and which leavers still have edit rights.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it revoke anyone's access on its own?

No. WebRun only reads sharing settings and role lists, then opens Trello cards describing what it found. Removing a member or turning off a public share stays a human decision.

What does it treat as a risk?

An app shared publicly, a former staff member who still holds edit rights, and any app with no named owner. Public shares that reach a live datasource are labelled as the ones to fix first.

Does it look inside the apps themselves?

No. This review ignores build state entirely and reads only sharing settings, workspace membership and the datasources a shared app can reach.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.