All templates

Automated Mattermost Channel Access Audits

Every Monday, WebRun opens Mattermost, reads the member list of each sensitive channel, checks every member against who still works here, flags guests and deactivated accounts still holding access, files the audit in Airtable, and messages the admin the exceptions on WhatsApp.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Mattermost read channel membership
2 Airtable file the access audit
3 WhatsApp message the exceptions
In short

How do I audit who has access to private Mattermost channels?

WebRun opens Mattermost every Monday and reads the member list of each sensitive channel, checking every account against who still works here. It files the audit in Airtable and messages the workspace admin the exceptions on WhatsApp: guests, deactivated accounts, and new additions, so offboarding gaps close before an audit finds them.

  • Leavers still holding channel access are found within a week
  • Guests on sensitive channels are named, not assumed
  • Every week's membership is kept, so a change is traceable

Built for workspace admins · IT security teams · compliance leads · engineering managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens mattermost.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Mattermost - read channel membership
    mattermost.com
    WebRun in Mattermost: read channel membership
    WebRun opens Mattermost to read channel membership.
    • Sign in to Mattermost and open the teams and channels on your sensitive list
    • Read the member list of each channel and record every account on it
    • Mark which members are guest accounts and which are full team members
    • Check each account against the active user list and flag deactivated accounts
    • Note anyone who has had no activity in the channel for a long stretch

    Done when Every sensitive channel has a full member list with guests and leavers marked.

  3. 2
    Airtable - file the access audit
    airtable.com
    WebRun in Airtable: file the access audit
    WebRun opens Airtable to file the access audit.
    • Write one row per channel member with the channel, the account, and the account type
    • Mark each row as expected, guest, deactivated, or dormant
    • Keep prior weeks so an access change can be traced to the week it happened
    • Highlight any account added to a sensitive channel since last week

    Done when This week's access audit is stored in Airtable with exceptions marked.

  4. 3
    WhatsApp - message the exceptions
    whatsapp.com
    WebRun in WhatsApp: message the exceptions
    WebRun opens WhatsApp to message the exceptions.
    • Message the workspace admin the exceptions only, not the full list
    • Lead with deactivated accounts still holding channel access
    • Follow with guests on sensitive channels and anyone newly added this week

    Done when The admin has this week's access exceptions on WhatsApp.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
mattermost.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Access exceptions · WhatsApp
OutputWhat each run produces - A weekly membership audit of sensitive channels, with guests, deactivated accounts, dormant members, and new additions marked.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove people from channels?

No. WebRun never removes a member, deactivates an account, or changes a permission. It reads membership and reports exceptions to Airtable and WhatsApp, and the admin makes every removal deliberately.

How does it know someone has left the company?

It checks each channel member against the active user list in your workspace, so a deactivated account still sitting in a private channel is flagged as an offboarding gap.

Does it read any messages?

No. It reads channel membership and account status only. The content of the conversations in those channels is never opened, captured, or posted anywhere.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.