Automated Surfshark Device Access Audit
Once a month, WebRun signs in to your Surfshark account, reviews the devices and sessions showing on it, checks the security settings and the subscription state, compares everything against the approved list you keep, posts a plain audit to Microsoft Teams, and pings your Telegram straight away if a device or setting does not match.
How do I audit the devices on my Surfshark account?
WebRun signs in to your Surfshark account once a month, reviews the devices and sessions on it, and checks the security settings and plan state. It posts the audit to your IT channel in Microsoft Teams and pings Telegram immediately if a device or setting does not match your approved list.
- An unfamiliar device is reported the day it appears
- Security settings are reviewed monthly instead of never
- A clean month still leaves a written audit record
Built for IT administrators · small business owners · remote teams · security leads
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
my.surfshark.comin a real browser with your saved login - no setup, no API keys. -
1
Surfshark - review devices and settings
WebRun opens Surfshark to review devices and settings. - Sign in to your Surfshark account area and open the devices and account sections
- List the devices and active sessions the account shows
- Read the security settings and note anything switched off that your policy says should be on
- Record the plan state and the next renewal date so billing and access are reviewed together
Done when Every device, session, and setting on the account is captured for this month.
-
2
Microsoft Teams - post the monthly audit
WebRun opens Microsoft Teams to post the monthly audit. - Post the monthly audit to your IT channel in Microsoft Teams
- List the devices seen, marking each as recognised or unrecognised against your approved list
- Note any security setting that is off and the plan state underneath
- Say plainly when everything matches, so a clean month still leaves a record
Done when The IT channel has this month's Surfshark audit.
-
3
Telegram - ping on anything unfamiliar
WebRun opens Telegram to ping on anything unfamiliar. - Send an immediate Telegram ping if a device or session is not on your approved list
- Ping too if a security setting your policy requires has been switched off
- Lead with what changed so it reads on a lock screen
- Never remove a device or change a setting. Report it and let a person decide
Done when Anything unfamiliar has been reported to you the moment it was found.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it remove a device or change my settings?
No. WebRun only reads what your Surfshark account shows and reports it. It never signs a device out, deletes a session, changes a security setting, or cancels a plan. Every change stays a human decision.
Does it handle my password?
No. WebRun uses the session you connect once and never types, copies, or stores your password. Credentials are never written into a message, a channel, or a file.
What counts as unfamiliar?
Anything not on the approved device list you keep. WebRun compares the account against that list each month and pings Telegram only when something appears that you have not approved.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.