All templates

Automated Supabase Security Warning Reviews

Every Monday, WebRun signs in to Supabase, opens each project in your organisation, and reads the security warnings the dashboard raises, including tables exposed without row level security and policies that leave data readable. It records every warning in Airtable with the project and table, and writes a dated review page in Notion with the highest risk findings first.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Supabase collect each project's security warnings
2 Airtable log every warning by project and table
3 Notion write the weekly security review
In short

How do I review Supabase security warnings across all my projects?

WebRun opens every Supabase project each Monday and collects the security warnings the dashboard raises, including tables exposed without row level security. It logs each finding in Airtable with its project and table, then writes a dated review page in Notion showing what is new, ageing, and fixed.

  • Tables left without row level security are named within a week
  • Warnings open for more than two weeks are escalated by name
  • The security review is written every Monday without anyone opening a dashboard

Built for backend engineers · platform teams · startup CTOs · security engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.supabase.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Supabase - collect each project's security warnings
    supabase.com
    WebRun in Supabase: collect each project's security warnings
    WebRun opens Supabase to collect each project's security warnings.
    • Sign in to Supabase and open each project in your organisation
    • Open the advisor warnings for the project and read the security findings
    • Capture tables exposed without row level security, along with any other warning raised
    • Record the project, the table or object, the warning, and its severity. Never change a policy or run SQL

    Done when Every project has been checked and its security warnings captured.

  3. 2
    Airtable - log every warning by project and table
    airtable.com
    WebRun in Airtable: log every warning by project and table
    WebRun opens Airtable to log every warning by project and table.
    • Open the platform review base in Airtable and add this week's rows
    • Record project, table or object, warning, severity, and the date first seen
    • Mark warnings that have persisted for more than two weeks as ageing
    • Close rows for warnings that no longer appear

    Done when Every current warning has an up to date row in Airtable.

  4. 3
    Notion - write the weekly security review
    notion.so
    WebRun in Notion: write the weekly security review
    WebRun opens Notion to write the weekly security review.
    • Add this week's section to the engineering security page in Notion
    • Lead with the highest severity findings and the projects they belong to
    • Show how many warnings were fixed and how many are new since last week
    • Name anything that has been open for more than two weeks so it gets an owner

    Done when The Notion security page carries this week's review with new and fixed counts.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.supabase.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Security review · Notion
OutputWhat each run produces - A weekly security review across your Supabase projects: open warnings by project and table, with new, ageing, and fixed counts.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change my database or enable policies itself?

No. WebRun reads the dashboard warnings and reports them. It never runs SQL, enables row level security, edits a policy, rotates a key, or pauses a project. Every fix is made by an engineer.

Does it read any of my data?

No. It reads project level warnings and object names such as tables and schemas. It never opens table contents, runs a query, or exports rows.

Can it cover several projects at once?

Yes. It walks every project in the organisation you point it at and keeps the findings separate by project, so a shared warning across projects is easy to spot in the Notion review.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.