All templates

Automated Google Cloud IAM Access Audit

Every Monday, WebRun opens the Google Cloud console, reads the IAM policy on each project, lists every principal and service account holding a broad role, compares it with last week, opens a Trello card for each thing worth revoking, and sends you the summary on WhatsApp.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Google Cloud read the IAM policy
2 Trello file each revocation
3 WhatsApp send you the diff
In short

How do I audit who has access to my Google Cloud projects each week?

Every Monday WebRun opens the Google Cloud console, reads the IAM policy on each project, and lists every person and service account holding a broad role. It compares the result with last week, opens a Trello card for each change worth revoking, and sends the summary to WhatsApp.

  • Access creep is caught weekly instead of at audit time
  • Every ageing service account key gets a card before it is a finding
  • New owner and editor grants are visible the Monday after they happen

Built for platform teams · cloud engineers · DevOps · security and compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens console.cloud.google.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Google Cloud - read the IAM policy
    cloud.google.com
    WebRun in Google Cloud: read the IAM policy
    WebRun opens Google Cloud to read the IAM policy.
    • Open the Google Cloud console and go to IAM and admin for each project on your list
    • Record every principal, the roles they hold, and whether the role is a broad or primitive one
    • List the service accounts, who can impersonate them, and the age of each service account key
    • Read only. Never change or remove a binding, and never create a key

    Done when Every project has its full list of principals, roles, service accounts and key ages captured.

  3. 2
    Trello - file each revocation
    trello.com
    WebRun in Trello: file each revocation
    WebRun opens Trello to file each revocation.
    • Compare this week's list with the one from last week and isolate what changed
    • Open a card on your access review board for each new broad role, each dormant principal and each key past your age limit
    • Put the project, the principal, the role and the reason on the card so it can be actioned without opening the console
    • Move any card that was resolved during the week to Done

    Done when Every access change worth reviewing has a card with the project, principal and reason on it.

  4. 3
    WhatsApp - send you the diff
    whatsapp.com
    WebRun in WhatsApp: send you the diff
    WebRun opens WhatsApp to send you the diff.
    • Send the platform group a short summary of the week
    • Lead with anything newly granted at owner or editor level, then the ageing service account keys
    • Include the count of principals per project and a link to the board

    Done when The platform group has this week's access diff with the new grants at the top.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
console.cloud.google.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Access diff · WhatsApp
OutputWhat each run produces - A weekly diff of who gained or kept broad roles on each project, which service accounts are dormant, and which keys are ageing.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove anyone's access on its own?

No. WebRun reads the IAM policy and never edits a binding, deletes a key or removes a principal. Everything it thinks should go becomes a Trello card for a human to action.

How does it know what changed?

It keeps last week's list of principals, roles and key ages, then diffs this week against it, so you see the new grants rather than re-reading the whole policy.

Can it cover more than one project?

Yes. Give WebRun the list of projects during setup and each run walks all of them, reporting per project so the cards and the WhatsApp summary stay grouped.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.