Automated SentinelOne Endpoint Coverage Audit
Every Monday, WebRun signs in to the SentinelOne console, lists every managed endpoint with its agent version and last seen date, flags devices offline for too long or running an old agent, updates an Airtable device inventory, and posts the coverage picture to your IT channel in Microsoft Teams.
How do I check that every device still has a working security agent?
WebRun signs in to the SentinelOne console every Monday and lists every managed endpoint with its agent version and last seen date. It flags devices offline too long, running an old agent, or with protection disabled, updates an Airtable inventory, and posts the coverage picture to Microsoft Teams.
- Endpoints that stopped reporting are named every Monday
- Agent version drift is caught before an audit does it for you
- A dated Airtable inventory shows coverage improving week over week
Built for IT administrators · security operations teams · managed service providers · compliance managers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.sentinelone.comin a real browser with your saved login - no setup, no API keys. -
1
SentinelOne - list endpoints and agent versions
WebRun opens SentinelOne to list endpoints and agent versions. - Sign in to the SentinelOne console and open the endpoint list
- Capture each device with its hostname, owner, operating system, agent version, and last seen date
- Flag devices not seen for more than seven days, devices on an agent version behind your standard, and any endpoint whose protection is disabled
Done when Every managed endpoint has an agent version, a last seen date, and a coverage flag.
-
2
Airtable - update the device inventory
WebRun opens Airtable to update the device inventory. - Update your Airtable device inventory with one row per endpoint
- Fill in agent version, last seen, owner, and the coverage flag, and add rows for devices seen for the first time
- Mark rows as resolved once a device comes back online or updates its agent, keeping a dated history of each week's gaps
Done when The Airtable inventory matches the SentinelOne console with this week's flags set.
-
3
Microsoft Teams - post the coverage picture
WebRun opens Microsoft Teams to post the coverage picture. - Post the coverage picture to your IT channel in Microsoft Teams
- Lead with the count of endpoints offline, out of date, or unprotected, and name the owners
- Show the change against last week so the team can see whether coverage is improving
Done when IT has this week's coverage numbers and the named devices behind them.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change anything in the SentinelOne console?
No. WebRun only reads the endpoint list. It never pushes an agent update, isolates a device, changes a policy, decommissions an endpoint, or resolves a threat.
How does it tell a decommissioned laptop from a missing one?
It compares each endpoint against your Airtable inventory. A device you have already marked as retired is reported separately, so the offline count reflects machines that should be reporting in.
Why track coverage weekly rather than only reading alerts?
Because an endpoint that stopped reporting raises no alerts at all. Counting devices by last seen date and agent version each Monday is what surfaces the quiet gaps in protection.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.