All templates
For backend leads, platform engineers & security reviewers

Audit which roles can touch each table

Every Monday, WebRun opens Hasura Cloud, walks every tracked table and reads the select, insert, update, and delete rules attached to each role, writes a role by table matrix into Airtable, and posts anything unusually broad to Notion for the backend team to review.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every Monday at 9:00 AM WebRun
1 Hasura read role permissions
2 Airtable write the permission matrix
3 Notion post what needs review
Run a sample
In short

How do I audit which roles can read and write each table?

WebRun audits your Hasura project every Monday, reading the select, insert, update, and delete rules attached to every role on every tracked table. It writes the role by table matrix into Airtable, marks what changed since last week, and posts the broadest rules to Notion for review.

  • An over permissive role is caught before it reaches production
  • Every table and role pair in one readable matrix
  • Permission drift since last week marked automatically

Built for backend leads · platform engineers · security reviewers · data teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens cloud.hasura.io in a real browser with your saved login - no setup, no API keys.

  2. 1
    Hasura - read role permissions
    hasura.io
    WebRun in Hasura: read role permissions
    WebRun opens Hasura to read role permissions.
    • Open Hasura Cloud and select the project to audit
    • List every tracked table exposed through the GraphQL API
    • For each table, read the select, insert, update, and delete permissions per role
    • Note where a role has no row filter, where all columns are exposed, and where a delete rule exists

    Done when Every table has its per role rules recorded across all four operations.

  3. 2
    Airtable - write the permission matrix
    airtable.com How to Automate Airtable
    WebRun in Airtable: write the permission matrix
    WebRun opens Airtable to write the permission matrix.
    • Open your engineering base and write one row per table and role pair
    • Record select, insert, update, and delete as separate columns
    • Add whether a row filter is set and how many columns are exposed
    • Compare against last week's rows and mark anything that changed

    Done when The role by table matrix is written with changes since last week marked.

  4. 3
    Notion - post what needs review
    notion.so How to Automate Notion
    WebRun in Notion: post what needs review
    WebRun opens Notion to post what needs review.
    • Post a review note listing rules with no row filter or with delete granted
    • Call out any permission added or widened since the previous audit
    • Group by role so an over permissive role is obvious at a glance
    • Leave every change to your engineers. WebRun never edits a permission or deploys metadata

    Done when The backend team has this week's review list grouped by role.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
cloud.hasura.io
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Permission matrix · Airtable
OutputWhat each run produces - A row per table and role showing select, insert, update, and delete rules, row filters, and exposed column counts.
Table
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change a permission or deploy anything?

No. WebRun reads the console and reports what it finds. It never edits a role, tightens a rule, applies metadata, or deploys a project. Every change stays with your engineers and your review process.

Does it read any of my actual data?

No. It reads permission configuration only: which roles hold which operations on which tables. It does not run queries against your data or read table contents.

How does it flag an over permissive rule?

It flags rules with no row filter, rules exposing every column, and any role granted delete. It also marks permissions added or widened since the previous week, so drift is visible.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.