All templates

Automated Lucidchart Sharing Audits

Every Monday, WebRun opens Lucidchart, walks the documents in your team folders, reads the sharing setting on each one, and flags anything shared with anyone who has the link or shared outside your domain, posting the list to Slack and briefing the security owner in Microsoft Teams.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Lucidchart check sharing on every document
2 Slack post the exposure list
3 Microsoft Teams brief the security owner
In short

How do I find Lucidchart diagrams that are shared publicly?

WebRun opens Lucidchart every Monday, walks the documents in your team folders, and reads the sharing setting on each one. It posts anything shared by link, published to the web, or shared outside your domain to Slack with the owner named, then briefs the security owner in Microsoft Teams.

  • Publicly shared diagrams are found weekly, not during an incident
  • Every finding carries the document owner's name
  • Sharing changes stay in human hands

Built for IT administrators · security teams · operations managers · compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens lucidchart.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Lucidchart - check sharing on every document
    lucidchart.com
    WebRun in Lucidchart: check sharing on every document
    WebRun opens Lucidchart to check sharing on every document.
    • Open Lucidchart and walk the documents in your team folders
    • Read the sharing setting on each document and note who has access
    • Flag anything set to anyone with the link, published to the web, or shared with an address outside your domain, and record the document owner and last edit date

    Done when Every document has been checked and each externally reachable one is recorded with its owner.

  3. 2
    Slack - post the exposure list
    slack.com
    WebRun in Slack: post the exposure list
    WebRun opens Slack to post the exposure list.
    • Post the exposure list to your workspace operations channel
    • Show the document name, its sharing setting, the owner, and when it was last edited
    • Separate documents that are genuinely meant to be public from the ones that look accidental

    Done when The exposure list is in the operations channel with owners named.

  4. 3
    Microsoft Teams - brief the security owner
    microsoft.com
    WebRun in Microsoft Teams: brief the security owner
    WebRun opens Microsoft Teams to brief the security owner.
    • Brief the security owner with the count of newly exposed documents and what changed since last week
    • Highlight anything containing architecture, credentials, or customer names in the title
    • Leave every sharing change to a human. WebRun never revokes access or edits a permission

    Done when The security owner has this week's brief with the week-on-week change.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
lucidchart.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Exposure list · Slack
OutputWhat each run produces - A weekly list of Lucidchart documents reachable outside your team, with the sharing setting, owner, and what changed since last week.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change sharing settings itself?

No. WebRun reads permissions and reports them. Revoking a link, removing a collaborator, or unpublishing a document stays with a human, so no colleague loses access because an audit ran.

What counts as exposed?

Three settings: shared with anyone who has the link, published to the web, and shared with an email address outside your domain. Documents you have marked as intentionally public are listed separately.

Does it read the contents of my diagrams?

It reads document titles, owners, and sharing settings. It flags titles mentioning architecture, credentials, or customer names as higher priority, but the audit is about access, not content.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.