All templates

Automated Keybase Device and Key Audit

Every Monday, WebRun signs into Keybase, lists the devices and paper keys attached to your account, checks the identity proofs still published, reviews who is a member of each team, posts the audit to Microsoft Teams, and blocks review time in Google Calendar to confirm or revoke.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Keybase list devices, keys, and members
2 Microsoft Teams post the security audit
3 Google Calendar hold time to confirm or revoke
In short

How do I review which devices still have access to my Keybase teams?

Every Monday, WebRun signs into Keybase, lists the devices and paper keys attached to your account, and checks who is still a member of each team. It posts the audit to Microsoft Teams and blocks review time in Google Calendar, so an old laptop never keeps access to a private team.

  • An old laptop stops keeping quiet access to a private team
  • New devices and members surface the Monday after they appear
  • The audit format never changes, so a difference is obvious in seconds

Built for security-conscious teams · team admins · open source projects · distributed engineering teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens keybase.io in a real browser with your saved login - no setup, no API keys.

  2. 1
    Keybase - list devices, keys, and members
    keybase.io
    WebRun in Keybase: list devices, keys, and members
    WebRun opens Keybase to list devices, keys, and members.
    • Sign into Keybase and list every device attached to the account with its name and type
    • List the paper keys that exist and when each was created
    • Open each team and record the current members and their roles
    • Read the identity proofs still published on the account
    • Compare against last week and mark anything new or unfamiliar

    Done when Every device, paper key, team member, and proof is listed with what changed since last week.

  3. 2
    Microsoft Teams - post the security audit
    microsoft.com
    WebRun in Microsoft Teams: post the security audit
    WebRun opens Microsoft Teams to post the security audit.
    • Post the audit to your security channel in Microsoft Teams
    • Put anything new since last week at the top: a new device, a new paper key, a new team member
    • List devices you have not confirmed in previous audits as candidates to revoke
    • Keep the format identical each week so a change stands out immediately

    Done when The security channel has this week's audit with the changes at the top.

  4. 3
    Google Calendar - hold time to confirm or revoke
    calendar.google.com
    WebRun in Google Calendar: hold time to confirm or revoke
    WebRun opens Google Calendar to hold time to confirm or revoke.
    • Add a short private review block to your own Google Calendar when anything changed
    • Name the change in the event title so it is clear before you open it
    • Leave the event with no attendees. WebRun never sends a calendar invite
    • Leave revoking a device, deleting a paper key, or removing a member to a person. WebRun never revokes anything

    Done when A private review block exists for any week where something changed.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
keybase.io
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Security audit · Microsoft Teams
OutputWhat each run produces - A weekly audit of Keybase devices, paper keys, identity proofs, and team members, with everything that changed since the last run at the top.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it revoke a device or remove a team member?

No. WebRun only reads and reports. Revoking a device, deleting a paper key, or removing someone from a team stays a human decision, so nobody is locked out of a team by an automated run.

Does it read the contents of my chats?

No. The audit covers account structure only: devices, paper keys, identity proofs, and team membership. Message contents are never read, copied, or posted anywhere.

How does it know what changed?

It compares this week's list against the previous audit and puts anything new or missing at the top, so a device added on Wednesday is visible the following Monday rather than months later.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.