Automated BeyondTrust Session Review
Every morning, WebRun signs in to BeyondTrust, pulls the privileged sessions completed since yesterday, records who connected, to which endpoint, with which managed account and for how long, logs every session in Airtable, and sends your security lead a Telegram review list with the unusual ones first.
How do I review who used privileged access overnight?
WebRun opens BeyondTrust every morning, pulls the privileged sessions that ran overnight, and records who connected, to which endpoint, with which managed account, and for how long. It logs each session in Airtable and sends the review list to your security lead in Telegram.
- Yesterday's privileged access is reviewed before the working day starts
- Out-of-hours and first-time connections are surfaced, not buried
- Every session carries a dated audit row with a reviewer sign-off
Built for security leads · IT operations · compliance teams · internal auditors
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.beyondtrust.comin a real browser with your saved login - no setup, no API keys. -
1
BeyondTrust - pull completed sessions
WebRun opens BeyondTrust to pull completed sessions. - Sign in to BeyondTrust and list the privileged sessions completed since the last run
- For each session, capture the user, the endpoint, the managed account used, the start time, and the duration
- Note whether a session recording exists and flag sessions outside normal working hours
- Read only. Never terminate a session, revoke access, or change an account
Done when Every completed session since yesterday is captured with its user, endpoint, and duration.
-
2
Airtable - log each session
WebRun opens Airtable to log each session. - Open your access audit base in Airtable and add a row per completed session
- Write the user, endpoint, managed account, start time, duration, and whether a recording exists
- Leave a reviewed column empty for the security lead to sign off against each row
Done when Every session has an audit row waiting for a reviewer's sign-off.
-
3
Telegram - send the review list
WebRun opens Telegram to send the review list. - Send your security channel the overnight review list with a count and the highlights
- Put out-of-hours sessions, unusually long sessions, and first-time user and endpoint pairs at the top
- Link the Airtable rows so sign-off happens in one place
Done when Your security lead has the review list before the working day starts.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it revoke access or kill a session?
No. WebRun reads completed session records and writes an audit list. Terminating a session, revoking access, or changing a managed account stays with your security team.
What makes a session get flagged?
Three checkable patterns: it ran outside your normal working hours, it lasted far longer than that user's usual session, or it is the first time that user connected to that endpoint.
Does this satisfy an auditor?
It produces the evidence auditors ask for: a dated record of who connected to which system, with which account, for how long, and a named reviewer sign-off against each session in Airtable.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.