Audit which roles can touch each table
Every Monday, WebRun opens Hasura Cloud, walks every tracked table and reads the select, insert, update, and delete rules attached to each role, writes a role by table matrix into Airtable, and posts anything unusually broad to Notion for the backend team to review.
- No credit card
- Under $0.01 per run
- Cancel anytime
How do I audit which roles can read and write each table?
WebRun audits your Hasura project every Monday, reading the select, insert, update, and delete rules attached to every role on every tracked table. It writes the role by table matrix into Airtable, marks what changed since last week, and posts the broadest rules to Notion for review.
- An over permissive role is caught before it reaches production
- Every table and role pair in one readable matrix
- Permission drift since last week marked automatically
Built for backend leads · platform engineers · security reviewers · data teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
cloud.hasura.ioin a real browser with your saved login - no setup, no API keys. -
1
Hasura - read role permissions
WebRun opens Hasura to read role permissions. - Open Hasura Cloud and select the project to audit
- List every tracked table exposed through the GraphQL API
- For each table, read the select, insert, update, and delete permissions per role
- Note where a role has no row filter, where all columns are exposed, and where a delete rule exists
Done when Every table has its per role rules recorded across all four operations.
-
2
Airtable - write the permission matrix
WebRun opens Airtable to write the permission matrix. - Open your engineering base and write one row per table and role pair
- Record select, insert, update, and delete as separate columns
- Add whether a row filter is set and how many columns are exposed
- Compare against last week's rows and mark anything that changed
Done when The role by table matrix is written with changes since last week marked.
-
3
Notion - post what needs review
WebRun opens Notion to post what needs review. - Post a review note listing rules with no row filter or with delete granted
- Call out any permission added or widened since the previous audit
- Group by role so an over permissive role is obvious at a glance
- Leave every change to your engineers. WebRun never edits a permission or deploys metadata
Done when The backend team has this week's review list grouped by role.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change a permission or deploy anything?
No. WebRun reads the console and reports what it finds. It never edits a role, tightens a rule, applies metadata, or deploys a project. Every change stays with your engineers and your review process.
Does it read any of my actual data?
No. It reads permission configuration only: which roles hold which operations on which tables. It does not run queries against your data or read table contents.
How does it flag an over permissive rule?
It flags rules with no row filter, rules exposing every column, and any role granted delete. It also marks permissions added or widened since the previous week, so drift is visible.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.