All templates

Automated AML Alert Email Ingestion into Unit21

Every morning, WebRun reads the compliance Gmail inbox for emails flagged as external AML alerts, law enforcement referrals, or 314a requests, extracts the subject entity details and alert type from each email, creates or updates the matching entity record in Unit21, and posts a summary of what was ingested to the compliance Slack channel for analyst follow-up.

Runs on WebRun · Strict Lockdown policy
Every day at 8:00 AM WebRunorchestrates each step
1 Gmail read and parse external AML alert emails
2 Unit21 create or update entity record from email data
3 Slack post ingestion summary for analyst follow-up
In short

How do I automatically log external AML alerts and referrals from email into Unit21?

WebRun reads the compliance Gmail inbox every morning for external AML alert emails, law enforcement referrals, and 314a requests, extracts the entity details from each, and creates or updates the matching record in Unit21 without manual re-keying. A Slack summary lists what was ingested and flags any emails that need an analyst to review directly.

  • External AML alerts are in Unit21 the same morning they arrive with no manual re-keying
  • Existing entity records are enriched rather than duplicated when a repeat alert arrives
  • Analysts see a clear list of what was auto-ingested and what still needs their attention

Built for AML compliance teams · BSA officers · compliance analysts · fintechs · banks

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens mail.google.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Gmail - read and parse external AML alert emails
    gmail.com
    WebRun in Gmail: read and parse external AML alert emails
    WebRun opens Gmail to read and parse external AML alert emails.
    • Open the compliance Gmail inbox and filter for emails labelled External AML Alert or 314a Request received since the last run
    • For each email, extract the subject entity name, ID or account number, alert type, source institution, and date of the reported activity
    • Flag emails where the required details are missing or ambiguous for manual review

    Done when All qualifying alert emails are parsed and their key fields extracted or flagged.

  3. 2
    Unit21 - create or update entity record from email data
    unit21.ai
    WebRun in Unit21: create or update entity record from email data
    WebRun opens Unit21 to create or update entity record from email data.
    • Open Unit21 and search for an existing entity matching the name and ID from each parsed email
    • If a match is found, add the external alert as a note on the existing entity record
    • If no match exists, create a new entity record with the extracted details and set the source as External Referral
    • Tag the record with the alert type: 314a, Law Enforcement Referral, or External SAR

    Done when Every parsed alert email has a corresponding record or update in Unit21.

  4. 3
    Slack - post ingestion summary for analyst follow-up
    slack.com
    WebRun in Slack: post ingestion summary for analyst follow-up
    WebRun opens Slack to post ingestion summary for analyst follow-up.
    • Post an ingestion summary to the compliance analyst channel listing how many alerts were processed and how many need manual review
    • Include entity names and Unit21 record links for the processed alerts
    • Flag any emails that could not be fully parsed so an analyst can handle them today

    Done when Analysts know exactly which external alerts were ingested and which need manual attention.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
mail.google.com
ScheduleRuns automatically on this cadence
Every day at 8:00 AM
DeliveryHow each run's result reaches you
Ingestion summary · Slack
OutputWhat each run produces - New or updated Unit21 entity records for each parsed external AML alert email, plus a Slack ingestion summary with links and a list of emails needing manual review.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it reply to the external sender automatically?

No. WebRun only reads the inbound email and logs the data into Unit21. Any response to a law enforcement referral or 314a inquiry is always drafted and sent manually by your compliance team.

How does it identify which emails are AML alerts?

It reads emails with a label you define in Gmail, such as External AML Alert or 314a Request. Apply the label manually or set up a Gmail filter for specific senders, and WebRun handles the rest.

What happens if an entity already exists in Unit21?

It matches on entity name and account ID. If a record already exists, the new alert is added as a note on that record rather than creating a duplicate entity.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.