All templates

Automated Wiz Critical Exposure Alerts

Every hour, WebRun checks Wiz for newly discovered critical severity findings, such as toxic combinations of exposure, permissions, and vulnerability, sends a Telegram alert naming the affected resource, and escalates by Twilio text if the same finding is still open at the next check.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Wiz check for new critical findings
2 Telegram alert the cloud security team
3 Twilio escalate if still open
In short

How do I get alerted immediately when Wiz finds a critical cloud exposure?

WebRun checks Wiz every hour for newly discovered critical severity cloud findings, including toxic combinations, sends a Telegram alert naming the resource and account, and escalates by Twilio text if the finding is still open an hour later. It never changes a cloud configuration itself, only detects and alerts on it.

  • Critical cloud findings reach the team within the hour they're discovered
  • Unresolved findings escalate automatically instead of aging quietly
  • Low and medium severity noise never triggers an alert

Built for cloud security teams · DevSecOps teams · platform engineers · CISOs

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.wiz.io in a real browser with your saved login - no setup, no API keys.

  2. 1
    Wiz - check for new critical findings
    wiz.io
    WebRun in Wiz: check for new critical findings
    WebRun opens Wiz to check for new critical findings.
    • Open Wiz and check for findings discovered in the last hour
    • Filter to critical severity, including toxic combinations
    • Note the affected resource, cloud account, and finding type

    Done when Any new critical finding this hour is listed with resource and account.

  3. 2
    Telegram - alert the cloud security team
    telegram.org
    WebRun in Telegram: alert the cloud security team
    WebRun opens Telegram to alert the cloud security team.
    • Send a Telegram alert naming the resource, account, and finding type
    • Include a link to the finding in Wiz
    • Send nothing when no new critical finding this hour

    Done when Every new critical finding has a Telegram alert.

  4. 3
    Twilio - escalate if still open
    twilio.com
    WebRun in Twilio: escalate if still open
    WebRun opens Twilio to escalate if still open.
    • Send a text through Twilio only if the same finding is still open at the next hourly check
    • Name the resource and how long it has been open
    • Stop escalating once the finding is resolved

    Done when Any finding still open after an hour has triggered a Twilio escalation.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.wiz.io
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Critical exposure alert · Telegram
OutputWhat each run produces - An hourly check for new critical cloud findings, with a Telegram alert and a Twilio escalation if unresolved.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun fix the misconfiguration itself?

No. WebRun only detects and alerts on the finding. Changing a cloud configuration or permission is a manual step your engineering team takes.

Will I get an alert for every low severity finding?

No. It only alerts on critical severity findings, including toxic combinations Wiz flags as most urgent, not routine low or medium findings.

Who receives the escalation text?

Only your configured cloud security on-call number. WebRun never contacts anyone outside your security team.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.