All templates

Automated BeyondTrust Session Review

Every morning, WebRun signs in to BeyondTrust, pulls the privileged sessions completed since yesterday, records who connected, to which endpoint, with which managed account and for how long, logs every session in Airtable, and sends your security lead a Telegram review list with the unusual ones first.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 BeyondTrust pull completed sessions
2 Airtable log each session
3 Telegram send the review list
In short

How do I review who used privileged access overnight?

WebRun opens BeyondTrust every morning, pulls the privileged sessions that ran overnight, and records who connected, to which endpoint, with which managed account, and for how long. It logs each session in Airtable and sends the review list to your security lead in Telegram.

  • Yesterday's privileged access is reviewed before the working day starts
  • Out-of-hours and first-time connections are surfaced, not buried
  • Every session carries a dated audit row with a reviewer sign-off

Built for security leads · IT operations · compliance teams · internal auditors

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.beyondtrust.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    BeyondTrust - pull completed sessions
    beyondtrust.com
    WebRun in BeyondTrust: pull completed sessions
    WebRun opens BeyondTrust to pull completed sessions.
    • Sign in to BeyondTrust and list the privileged sessions completed since the last run
    • For each session, capture the user, the endpoint, the managed account used, the start time, and the duration
    • Note whether a session recording exists and flag sessions outside normal working hours
    • Read only. Never terminate a session, revoke access, or change an account

    Done when Every completed session since yesterday is captured with its user, endpoint, and duration.

  3. 2
    Airtable - log each session
    airtable.com
    WebRun in Airtable: log each session
    WebRun opens Airtable to log each session.
    • Open your access audit base in Airtable and add a row per completed session
    • Write the user, endpoint, managed account, start time, duration, and whether a recording exists
    • Leave a reviewed column empty for the security lead to sign off against each row

    Done when Every session has an audit row waiting for a reviewer's sign-off.

  4. 3
    Telegram - send the review list
    telegram.org
    WebRun in Telegram: send the review list
    WebRun opens Telegram to send the review list.
    • Send your security channel the overnight review list with a count and the highlights
    • Put out-of-hours sessions, unusually long sessions, and first-time user and endpoint pairs at the top
    • Link the Airtable rows so sign-off happens in one place

    Done when Your security lead has the review list before the working day starts.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.beyondtrust.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Session review · Telegram
OutputWhat each run produces - A daily audit list of completed privileged sessions with user, endpoint, managed account, start time, duration, and any unusual pattern flagged.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Can it revoke access or kill a session?

No. WebRun reads completed session records and writes an audit list. Terminating a session, revoking access, or changing a managed account stays with your security team.

What makes a session get flagged?

Three checkable patterns: it ran outside your normal working hours, it lasted far longer than that user's usual session, or it is the first time that user connected to that endpoint.

Does this satisfy an auditor?

It produces the evidence auditors ask for: a dated record of who connected to which system, with which account, for how long, and a named reviewer sign-off against each session in Airtable.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.