All templates

Automated Retool Access Reviews

Every Monday, WebRun signs in to Retool, reads every user, group and permission along with which apps and resources each group can reach, builds a per group access list in Airtable, and writes the week's review into Notion with leavers, unused accounts, and over-broad grants called out for you to action.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Retool read users, groups and permissions
2 Airtable build the per group access list
3 Notion write the review with the exceptions
In short

How do I review who has access to our internal tools?

WebRun runs your Retool access review every Monday. It reads every user, group and permission along with the apps and resources each can reach, rebuilds the access list in Airtable, and writes a Notion review calling out leavers and over-broad grants, so an audit question takes minutes.

  • Access is recertified every week instead of once a quarter
  • Dormant accounts and production edit rights are named automatically
  • An auditor question is answered from a dated Notion page

Built for Retool admins · IT and security teams · compliance managers · engineering leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens login.retool.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Retool - read users, groups and permissions
    retool.com
    WebRun in Retool: read users, groups and permissions
    WebRun opens Retool to read users, groups and permissions.
    • Sign in to Retool as an admin and open the user and group settings for your organisation
    • Capture every user with their groups, their role, and their last sign in date
    • For each group, capture which apps it can open and which resources those apps query, noting edit rights separately from view rights

    Done when Every user, group, app, and resource permission has been captured.

  3. 2
    Airtable - build the per group access list
    airtable.com
    WebRun in Airtable: build the per group access list
    WebRun opens Airtable to build the per group access list.
    • Rebuild the access list in Airtable: one row per user showing their groups, the apps they can reach, and the resources behind them
    • Keep last week's version so a permission added mid-week is visible as a change
    • Flag rows where a user has edit rights on a production resource or has not signed in for the period you set

    Done when The access list reflects today's permissions with the changes since last week flagged.

  4. 3
    Notion - write the review with the exceptions
    notion.so
    WebRun in Notion: write the review with the exceptions
    WebRun opens Notion to write the review with the exceptions.
    • Write this week's access review page in Notion with the group by group summary and the total user count
    • Call out the exceptions in their own section: dormant accounts, people whose access looks broader than their role, and any group that can reach a production database
    • Leave removing access to your admin. WebRun never deletes a user, edits a group, or changes a permission

    Done when The review page is written and every exception is named with its owner.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
login.retool.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Access review · Notion
OutputWhat each run produces - A weekly access review: every user and group with the apps and resources they reach, plus the exceptions to action.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove users or change permissions?

No. WebRun reads permissions and reports the exceptions. Removing a user or narrowing a group stays with your admin, because revoking the wrong access breaks someone's day.

What counts as an over-broad grant?

Two things WebRun always flags: edit rights on a production resource, and an account with no sign in during the period you set. You can add your own rules on top.

Is the review enough for an auditor?

It gives the auditor the direct answer: who can open which app, which resource sits behind it, and when each person last signed in, dated and kept week by week in Notion.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.