All templates

Automated Quip External Sharing Audits

Every Monday, WebRun opens Quip, walks your documents and folders reading only who each is shared with and which links are open, lists the ones reachable outside your company, pings the list to Telegram, and books a short review slot in Google Calendar.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Quip read who can open each document
2 Telegram ping the externally shared list
3 Google Calendar book the review slot
In short

How do I audit which documents are shared outside my company?

WebRun opens Quip every Monday and reads the sharing settings on your documents and folders, never their content. It lists the documents reachable outside your company with who has access and how long, pings that list to Telegram, and books a review slot in Google Calendar.

  • A link opened for one client review does not stay open a year
  • Every external share names who can open it and since when
  • Document content is never read, only who can reach it

Built for IT and security teams · operations managers · compliance officers · consulting firms

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens quip.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Quip - read who can open each document
    quip.com
    WebRun in Quip: read who can open each document
    WebRun opens Quip to read who can open each document.
    • Open Quip and walk your documents and folders
    • For each one read the members and the sharing setting, including any open share link
    • Flag documents with members outside your company domain or a link anyone can open
    • Read sharing settings only. Never open or copy document content

    Done when Every document has a sharing status and its external members listed.

  3. 2
    Telegram - ping the externally shared list
    telegram.org
    WebRun in Telegram: ping the externally shared list
    WebRun opens Telegram to ping the externally shared list.
    • Ping the list of externally shared documents with who has access to each
    • Show how long each has been shared so a link opened for one review a year ago stands out
    • Keep the ping to document titles and access, never content

    Done when The externally shared list has been pinged to Telegram.

  4. 3
    Google Calendar - book the review slot
    calendar.google.com
    WebRun in Google Calendar: book the review slot
    WebRun opens Google Calendar to book the review slot.
    • Book a short review slot in your own calendar when anything new appears on the list
    • Put the count of documents to review in the event title
    • Skip the booking in a week where nothing changed

    Done when A review slot is on the calendar whenever new external sharing appears.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
quip.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
External sharing list · Telegram
OutputWhat each run produces - A list of Quip documents reachable outside the company, each with the external members, the link setting, and how long it has been shared.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change sharing settings or remove access?

No. Removing access can cut off a client mid project, so WebRun only lists what is shared and with whom. Closing a link or removing a member stays your decision in Quip.

Does it read what is inside the documents?

No. This run reads sharing settings, members, and link states only. Document content is never opened, quoted, or copied into the Telegram list.

How does it decide a share is external?

Any member outside your company domain, or any share link that anyone with the address can open, is flagged. Each entry shows how long that access has been in place.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.