All templates

Unit21 Automated Transaction Anomaly Flagging

Every hour, WebRun opens Unit21, reads alerts triggered by anomaly detection rules, groups them by customer entity and pattern type, logs the exceptions to a running Google Sheets register, and posts a structured summary to the compliance Slack channel for same-day review.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Unit21 read new anomaly rule alerts
2 Google Sheets log exception register
3 Slack post anomaly digest
In short

How do I automatically flag and digest AML transaction anomalies from Unit21?

WebRun checks Unit21 every hour for newly triggered anomaly and velocity-rule alerts, groups exceptions by customer entity and pattern type, and logs every exception to a Google Sheets register. It then posts a structured digest to the compliance Slack channel so your team can review and escalate high-risk patterns the same day they appear.

  • High-risk anomalies surface within an hour instead of sitting in an unread queue
  • Entities triggering multiple rules at once are highlighted for faster escalation
  • A running Google Sheets register gives auditors a complete exception log

Built for AML compliance teams · transaction monitoring analysts · BSA officers · fintechs · banks

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.unit21.ai in a real browser with your saved login - no setup, no API keys.

  2. 1
    Unit21 - read new anomaly rule alerts
    unit21.ai
    WebRun in Unit21: read new anomaly rule alerts
    WebRun opens Unit21 to read new anomaly rule alerts.
    • Open Unit21 and filter alerts to those created in the last hour
    • Identify alerts triggered by behavioral anomaly or velocity rules
    • Group alerts by entity and capture rule name, transaction volume, and alert severity

    Done when All new anomaly alerts from the past hour are grouped by entity and rule type.

  3. 2
    Google Sheets - log exception register
    google.com
    WebRun in Google Sheets: log exception register
    WebRun opens Google Sheets to log exception register.
    • Open the Anomaly Exception Register sheet
    • Append each exception: entity, rule name, severity, transaction count, and timestamp
    • Highlight rows where the same entity triggered more than one rule in the same hour

    Done when Each new exception is logged with full context in the register.

  4. 3
    Slack - post anomaly digest
    slack.com
    WebRun in Slack: post anomaly digest
    WebRun opens Slack to post anomaly digest.
    • Post a grouped digest to the compliance channel: entity name, rules triggered, and severity
    • Lead with entities that triggered multiple rules, as these carry the highest escalation risk
    • Include a count of total new exceptions and a link to the register

    Done when The compliance team has an hourly anomaly digest in Slack.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.unit21.ai
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Anomaly digest · Slack
OutputWhat each run produces - An hourly grouped digest of new Unit21 anomaly exceptions, sorted by entity and escalation risk, logged to Google Sheets and posted to Slack.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it create cases from anomalies automatically?

No. WebRun reports anomalies for human review. Creating a case or escalating an alert is always a deliberate analyst action inside Unit21.

Which rules does it cover?

It reads whatever rules are active in your Unit21 environment, including velocity checks, structuring patterns, and geographic anomalies. You control the rules in Unit21, and WebRun surfaces whatever fires.

What if no new anomalies fired in the last hour?

WebRun skips the Slack post and sheet update when there is nothing new to report, keeping the channel free of empty noise.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.