Automated Kintone App Permission Audits
Every Monday, WebRun opens Kintone, reads the app permissions across your spaces, flags apps where everyone can view or edit records, lists users who still hold rights but have stopped signing in, posts the findings to Microsoft Teams, and pings you in Telegram when a customer data app is wide open.
How do I review who can see and edit each app in my workspace?
WebRun audits your Kintone access every Monday. It reads the permission settings on every app in your spaces, flags apps where everyone can view or edit records, and lists users who still hold rights but stopped signing in. It posts the review to Microsoft Teams and pings Telegram when a customer data app is wide open.
- Wide-open apps surface weekly instead of at audit time
- Leavers stop holding live rights on customer data
- Every finding names the exact right granted and to whom
Built for Kintone admins · IT and security teams · operations managers · compliance owners
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
kintone.comin a real browser with your saved login - no setup, no API keys. -
1
Kintone - read permissions on every app
WebRun opens Kintone to read permissions on every app. - Open Kintone and list the apps in every space you administer
- Read each app's permission settings and note where Everyone holds view, edit, or delete rights
- List the users and groups with rights on each app and note who has not signed in recently
Done when Every app has a recorded permission setting and access list.
-
2
Microsoft Teams - post the access review
WebRun opens Microsoft Teams to post the access review. - Post the review to your admin channel with wide-open apps at the top
- Under each app name the rights granted and to whom
- List stale accounts separately with the apps they still hold rights on
Done when This week's access review is in Teams.
-
3
Telegram - ping on wide-open apps
WebRun opens Telegram to ping on wide-open apps. - Send a short ping only when an app you tagged as holding customer data is open to everyone
- Name the app, the space, and the right that is too broad
- Stay quiet in weeks where nothing sensitive is over-shared
Done when You have been pinged about any wide-open sensitive app.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change permissions or remove a user?
No. WebRun reads permissions and reports them. Narrowing an app's access or deactivating a user stays a human action, because revoking the wrong right can stop a team working.
Does it read the records inside the apps?
No. It reads app names, spaces, permission settings, and the user and group lists. The record data inside each app is never opened or copied into the report.
How does it decide an account is stale?
By last sign-in against the window you set, commonly 60 or 90 days. Each stale account is listed with the apps it still holds rights on, so the offboarding gap is obvious.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.