Automated CyberArk Account Onboarding Queue
Every Monday, WebRun signs in to CyberArk, lists the discovered accounts still sitting outside a safe, records each one in Notion with its host and likely owner, and emails you a drafted request per owner so onboarding is a decision rather than a hunt.
How do I track privileged accounts that were discovered but never onboarded?
WebRun reviews your CyberArk discovered accounts every Monday and lists the privileged accounts still sitting outside a safe. It records each one in Notion with its host, type and days outstanding, then drafts an email to the likely owner in Gmail, so onboarding gaps get chased instead of quietly ageing.
- No discovered account ages quietly outside a safe
- Every outstanding account carries a named owner to ask
- The backlog is ordered by days outstanding, oldest first
Built for privileged access administrators · security operations · IT compliance · identity teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.cyberark.comin a real browser with your saved login - no setup, no API keys. -
1
CyberArk - list unonboarded discovered accounts
WebRun opens CyberArk to list unonboarded discovered accounts. - Open CyberArk and review the discovered accounts list
- Keep the accounts not yet onboarded into a safe
- Capture the account name, host or directory, account type, and when it was first discovered
- Note the platform and onboarding rule each account would match if it were onboarded
Done when Every discovered account outside a safe is listed with its host and type.
-
2
Notion - record the onboarding backlog
WebRun opens Notion to record the onboarding backlog. - Add a row per account to your privileged access backlog page
- Fill in the host, account type, discovery date, and days outstanding
- Record the likely owner from the host inventory or the last known administrator
- Update rows already on the page rather than duplicating them, and close out anything now onboarded
Done when The Notion backlog matches the accounts still outside a safe.
-
3
Gmail - draft the owner requests
WebRun opens Gmail to draft the owner requests. - Draft one email per owner listing the accounts on their systems awaiting onboarding
- Ask which are still in use, which can be disabled, and who should own each safe
- Leave every message as a draft. You read it and press send yourself
- Send yourself a summary of the whole backlog ordered by days outstanding
Done when An owner request is drafted for every account, and your summary is waiting.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it onboard accounts or change credentials itself?
No. WebRun only reads the discovered accounts list and reports what is outstanding. Onboarding an account into a safe, changing a password, or altering a platform stays entirely with your administrators.
Does it email the account owners on its own?
No. Every owner request is left as an unsent draft in your Gmail. You read the wording, adjust it, and send it yourself.
What stops the same account being chased twice?
The Notion backlog carries one row per account, so WebRun updates the existing row and its days outstanding instead of creating a duplicate, and closes out accounts once they are onboarded.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.