All templates

Automated Kintone App Permission Audits

Every Monday, WebRun opens Kintone, reads the app permissions across your spaces, flags apps where everyone can view or edit records, lists users who still hold rights but have stopped signing in, posts the findings to Microsoft Teams, and pings you in Telegram when a customer data app is wide open.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Kintone read permissions on every app
2 Microsoft Teams post the access review
3 Telegram ping on wide-open apps
In short

How do I review who can see and edit each app in my workspace?

WebRun audits your Kintone access every Monday. It reads the permission settings on every app in your spaces, flags apps where everyone can view or edit records, and lists users who still hold rights but stopped signing in. It posts the review to Microsoft Teams and pings Telegram when a customer data app is wide open.

  • Wide-open apps surface weekly instead of at audit time
  • Leavers stop holding live rights on customer data
  • Every finding names the exact right granted and to whom

Built for Kintone admins · IT and security teams · operations managers · compliance owners

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens kintone.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Kintone - read permissions on every app
    kintone.com
    WebRun in Kintone: read permissions on every app
    WebRun opens Kintone to read permissions on every app.
    • Open Kintone and list the apps in every space you administer
    • Read each app's permission settings and note where Everyone holds view, edit, or delete rights
    • List the users and groups with rights on each app and note who has not signed in recently

    Done when Every app has a recorded permission setting and access list.

  3. 2
    Microsoft Teams - post the access review
    microsoft.com
    WebRun in Microsoft Teams: post the access review
    WebRun opens Microsoft Teams to post the access review.
    • Post the review to your admin channel with wide-open apps at the top
    • Under each app name the rights granted and to whom
    • List stale accounts separately with the apps they still hold rights on

    Done when This week's access review is in Teams.

  4. 3
    Telegram - ping on wide-open apps
    telegram.org
    WebRun in Telegram: ping on wide-open apps
    WebRun opens Telegram to ping on wide-open apps.
    • Send a short ping only when an app you tagged as holding customer data is open to everyone
    • Name the app, the space, and the right that is too broad
    • Stay quiet in weeks where nothing sensitive is over-shared

    Done when You have been pinged about any wide-open sensitive app.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
kintone.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access review · Microsoft Teams
OutputWhat each run produces - A ranked list of over-permissive apps and stale accounts, with the exact rights held on each.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change permissions or remove a user?

No. WebRun reads permissions and reports them. Narrowing an app's access or deactivating a user stays a human action, because revoking the wrong right can stop a team working.

Does it read the records inside the apps?

No. It reads app names, spaces, permission settings, and the user and group lists. The record data inside each app is never opened or copied into the report.

How does it decide an account is stale?

By last sign-in against the window you set, commonly 60 or 90 days. Each stale account is listed with the apps it still holds rights on, so the offboarding gap is obvious.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.