Automated CyberArk Rotation Planning
Every Monday, WebRun opens CyberArk, lists privileged accounts whose managed credentials are due for rotation in the next fourteen days or whose last rotation failed, places a maintenance-window hold on your team calendar in Google Calendar for each batch, and posts the plan with owners and risk order to Microsoft Teams.
How do I keep track of privileged credential rotations that are coming due?
WebRun plans your CyberArk credential rotations every Monday. It lists privileged accounts due for rotation within fourteen days plus any whose last rotation failed, holds a maintenance window for each batch in Google Calendar, and posts the ordered plan with owners to Microsoft Teams, so no credential expires unnoticed.
- Failed rotations stay visible until they succeed
- Every rotation batch has a booked window and a named owner
- Expiring privileged credentials are seen two weeks out
Built for security operations teams · IAM administrators · IT compliance leads · infrastructure engineers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.cyberark.comin a real browser with your saved login - no setup, no API keys. -
1
CyberArk - list rotations due and failed
WebRun opens CyberArk to list rotations due and failed. - Open CyberArk and review managed privileged accounts by safe and platform
- Capture accounts whose credential rotation falls due in the next 14 days
- Add any account whose last rotation attempt failed, with its owner and the reported reason
Done when Every due or failed rotation is listed with its safe, owner, and target date.
-
2
Google Calendar - hold the maintenance window
WebRun opens Google Calendar to hold the maintenance window. - Open Google Calendar and place a maintenance-window hold on your team calendar for each rotation batch
- Put the safe names and account count in the event description so the window is self-explanatory
- Leave the hold without guests. WebRun never sends a calendar invitation on your behalf
Done when Each rotation batch has a dated maintenance hold on the team calendar.
-
3
Microsoft Teams - post the rotation plan
WebRun opens Microsoft Teams to post the rotation plan. - Post the rotation plan to your security operations Teams channel
- Put failed rotations at the top, then accounts due soonest, each with its owner and window
- Note any account with no assigned owner so it can be claimed
Done when The security channel has this week's rotation plan with owners and windows.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun rotate the credentials itself?
No. WebRun reads CyberArk, plans the work, and reports it. Every rotation is performed by your own engineers in the booked window, and nothing in the vault is changed by the run.
Will it invite people to the maintenance window?
No. WebRun places the hold on your team calendar with no guests attached, so you decide who gets invited and when the invitation goes out.
What happens to a rotation that failed twice?
It stays at the top of the Teams post every week until it succeeds, with the reported failure reason attached, so a repeatedly failing account cannot quietly drop off the list.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.