All templates

Automated Bluescape Workspace Access Review

Every Monday, WebRun opens Bluescape, reads the member list of each workspace with everyone's role and guest status, posts the full roster to Slack, and sends the workspace owner a Telegram flag for guests and members who look like leftovers from a finished project.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Bluescape read members and roles
2 Slack post the access roster
3 Telegram flag leftover access
In short

How do I review who still has access to each workspace?

Every Monday WebRun opens Bluescape and reads the member list of each workspace, recording every person, their role, and whether they are a guest. It posts the full roster to Slack and flags on Telegram anyone who has not opened the workspace recently, so contractors lose access when a project ends.

  • Leftover contractor access is named every week, not discovered at audit time
  • New members added since last week are marked in the roster
  • Every removal is left to a person, so nobody loses access by accident

Built for workspace owners · IT administrators · project leads · agencies working with contractors

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.bluescape.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Bluescape - read members and roles
    bluescape.com
    WebRun in Bluescape: read members and roles
    WebRun opens Bluescape to read members and roles.
    • Open Bluescape and list every workspace you own or administer
    • For each workspace, capture the members, their roles, and which of them are guests or external accounts
    • Note the last activity date you can see for each person
    • Compare against last week's roster and mark anyone newly added

    Done when Every workspace has a current list of members, roles, and guest status.

  3. 2
    Slack - post the access roster
    slack.com
    WebRun in Slack: post the access roster
    WebRun opens Slack to post the access roster.
    • Post one roster per workspace to your internal admin channel
    • Group people by role so owners, editors, and viewers are separated
    • Mark anyone added since last week so new access is visible at a glance

    Done when The admin channel holds this week's roster for every workspace.

  4. 3
    Telegram - flag leftover access
    telegram.org
    WebRun in Telegram: flag leftover access
    WebRun opens Telegram to flag leftover access.
    • Message the workspace owner the shorter list of access worth reviewing: guests, external accounts, and anyone with no recent activity
    • Say which workspace each person can still open and at what role
    • Leave every removal to the owner. WebRun never revokes access or changes a role

    Done when The owner has a short review list of leftover access on Telegram.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.bluescape.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access review · Slack
OutputWhat each run produces - A weekly roster per workspace with each member's role and guest status, plus a short list of access that looks like a leftover.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove anyone's access?

No. WebRun reads membership and reports it. Removing a member, downgrading a role, or revoking a guest invite stays a decision the workspace owner makes by hand.

How does it decide access is leftover?

It flags guests, external accounts, and members with no recent activity in a workspace. You set the inactivity window, and everyone else stays off the review list.

Does it cover every workspace?

Yes, every workspace you own or administer is read on each run, and new people added since last week are marked so unexpected access is obvious.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.