All templates

Automated SentinelOne Endpoint Coverage Audit

Every Monday, WebRun signs in to the SentinelOne console, lists every managed endpoint with its agent version and last seen date, flags devices offline for too long or running an old agent, updates an Airtable device inventory, and posts the coverage picture to your IT channel in Microsoft Teams.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 SentinelOne list endpoints and agent versions
2 Airtable update the device inventory
3 Microsoft Teams post the coverage picture
In short

How do I check that every device still has a working security agent?

WebRun signs in to the SentinelOne console every Monday and lists every managed endpoint with its agent version and last seen date. It flags devices offline too long, running an old agent, or with protection disabled, updates an Airtable inventory, and posts the coverage picture to Microsoft Teams.

  • Endpoints that stopped reporting are named every Monday
  • Agent version drift is caught before an audit does it for you
  • A dated Airtable inventory shows coverage improving week over week

Built for IT administrators · security operations teams · managed service providers · compliance managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.sentinelone.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    SentinelOne - list endpoints and agent versions
    sentinelone.com
    WebRun in SentinelOne: list endpoints and agent versions
    WebRun opens SentinelOne to list endpoints and agent versions.
    • Sign in to the SentinelOne console and open the endpoint list
    • Capture each device with its hostname, owner, operating system, agent version, and last seen date
    • Flag devices not seen for more than seven days, devices on an agent version behind your standard, and any endpoint whose protection is disabled

    Done when Every managed endpoint has an agent version, a last seen date, and a coverage flag.

  3. 2
    Airtable - update the device inventory
    airtable.com
    WebRun in Airtable: update the device inventory
    WebRun opens Airtable to update the device inventory.
    • Update your Airtable device inventory with one row per endpoint
    • Fill in agent version, last seen, owner, and the coverage flag, and add rows for devices seen for the first time
    • Mark rows as resolved once a device comes back online or updates its agent, keeping a dated history of each week's gaps

    Done when The Airtable inventory matches the SentinelOne console with this week's flags set.

  4. 3
    Microsoft Teams - post the coverage picture
    microsoft.com
    WebRun in Microsoft Teams: post the coverage picture
    WebRun opens Microsoft Teams to post the coverage picture.
    • Post the coverage picture to your IT channel in Microsoft Teams
    • Lead with the count of endpoints offline, out of date, or unprotected, and name the owners
    • Show the change against last week so the team can see whether coverage is improving

    Done when IT has this week's coverage numbers and the named devices behind them.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.sentinelone.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Endpoint coverage report · Microsoft Teams
OutputWhat each run produces - A weekly endpoint coverage report naming devices offline, out of date, or unprotected, backed by a dated Airtable inventory.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change anything in the SentinelOne console?

No. WebRun only reads the endpoint list. It never pushes an agent update, isolates a device, changes a policy, decommissions an endpoint, or resolves a threat.

How does it tell a decommissioned laptop from a missing one?

It compares each endpoint against your Airtable inventory. A device you have already marked as retired is reported separately, so the offline count reflects machines that should be reporting in.

Why track coverage weekly rather than only reading alerts?

Because an endpoint that stopped reporting raises no alerts at all. Counting devices by last seen date and agent version each Monday is what surfaces the quiet gaps in protection.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.