How to Automate Unit21

Unit21 detects and documents the risk it is fed. Rules and models raise the alerts, Case Management works them, and Regulatory Filing sends SARs and CTRs to FinCEN. The registries, processor consoles and vendor portals holding the rest of the evidence are where an agent like WebRun does the fetching.

Every alert in the queue is a live customer account

Fintechs, sponsor banks and crypto businesses run their fraud and anti-money-laundering operations on Unit21. Payments, customer attributes, device signals and behaviour feed into it, models and rules turn a small share of that into alerts, and analysts work the alerts as cases until each is dismissed, escalated or reported.

What sits inside is the whole risk record. The transaction that tripped a rule and the fourteen around it. The entity behind the account, with its linked parties and its risk rating. Every alert, its disposition, and the analyst who set it. The narratives, the filings already made, and the ones whose window is still open.

Fraud analysts work it through the day, AML investigators take the older cases, and a BSA officer signs what goes to the regulator. All of them know one thing about that record: an examiner will read it years from now, with the outcome already known.

The evidence for an alert lives outside the alert

An alert names a customer and a pattern. It cannot tell you whether the pattern is a business quietly doing business.

So the analyst goes looking. The company's registration on a secretary of state search page, to see whether the entity still exists and who signs for it. The identity vendor's dashboard, to see whether the re-verification came back. The processor's console, for the chargeback that landed the same week. The support desk, where this customer already explained the wire to somebody in chat. The documents promised by email eleven days ago and still not sent, so a third reminder gets written. On the crypto side, a block explorer and the counterparty address's history.

None of that is analysis. It is twenty minutes of opening tabs and copying what they say into a case, done by someone hired to recognise structuring, and it starts again at the next line.

The unit21.ai homepage, the app these three jobs run in. Unit21
The queue sorted by the clock Open alerts ordered by how long they have been sitting against the deadline a filing runs on, so the oldest exposure is the first thing anyone sees.
Entities checked against the register that made them The business behind an account looked up on the state's own filing search: still active, dissolved last spring, or trading under officers nobody recorded.
Documents chased until they turn up Customers who still owe paperwork for enhanced due diligence, listed with how many times they have been asked and a follow-up drafted for each.

Detection fires on the data that reached the platform

Unit21 does the core of this properly, and a team not using all of it should start there rather than here.

Transaction Monitoring takes in transactions, device data and customer attributes in real time, and runs both prebuilt detection models and rules a compliance analyst can deploy without waiting on an engineer. Case Management gives the alerts somewhere to live: queues, enrichment, prioritisation, dispositions and an audit trail behind every decision. Sanction Screening handles the list checks. Regulatory Filing drafts the narrative, then submits SARs and CTRs to FinCEN, STRs to FINTRAC and reports to further regimes through goAML. Unit21's own AI agents take a share of the research and the summary writing, and the company is explicit that the final decision stays with the compliance team.

The ceiling is the pipeline. Every one of those acts on what was sent to Unit21, or on the sources its agents are pointed at. The rest of your operation is not in that set. The processor console, the ticket queue, the identity vendor's portal, the state register and the drive holding a customer's signed documents each sit behind their own login, with no feed into the case.

The background work on an alert can happen overnight

Work starts in Unit21 and immediately needs somewhere else. Something that can open both ends changes what the queue looks like by morning.

Every open alert in one worklist, ordered by how long it has been sitting against the deadline the filing clock runs to, so the oldest exposure is at the top rather than buried. Each business entity on that list checked against the register that incorporated it: active, dissolved, or renamed without telling anyone. The dispute console read for chargebacks on the same accounts, so a fraud pattern and a payments pattern are seen together rather than a fortnight apart.

Then the chasing, which is most of the week. Customers who owe a document for enhanced due diligence, listed with the number of times they have been asked and a follow-up drafted for each. Remediation actions assigned a month ago and never closed, with the owner named next to them. Sanctions and PEP hits grouped so the true matches sit apart from the people who merely share a name.

And the alerts a partner bank sends by email, read, matched to the right customer and written up as a case an analyst can pick up.

An analyst still decides what the alert means

That split is the whole thing, and a regulated function cannot afford to blur it. Collecting evidence and judging it are separate jobs, and only the first can be handed over.

WebRun is an AI agent that works a real Chrome browser, signed in as you. It opens Unit21 the way your team does, reads the open alerts and the dates they are running against, then opens the state register, the dispute console and the identity vendor's portal beside it, and brings back what it found, attached to the case.

It reads and it prepares. No SAR is filed, no alert is dispositioned, no account is restricted and nothing reaches a customer until someone qualified to make that call has said so.

The workflows below are already built, and each one names what it opens.

Questions people ask

Is a SAR ever filed without a person signing it?

No. Reading, gathering and drafting run unattended; the decisions do not. A filing is a signed statement to a regulator and a restriction is felt by a customer, so both wait for someone with the authority to make that call. The agent assembles the evidence and stops there.

We already run detection models in Unit21. Is this a second one?

No, it works the other end of the job. Detection decides which activity deserves attention, and that stays inside Unit21's own pipeline. This is the outside legwork once an alert exists: the state register, the processor console, the identity vendor's dashboard and the document nobody sent.

A partner bank emails us alerts. Can those get into Unit21?

Yes, as prepared work. It reads the mailbox, matches each alert to the customer and writes it up as a case with the mail and its attachments kept, ready for an analyst to work. What it never does is set a disposition or close anything out.

12 ready-made Unit21 workflows

Each one names the apps it touches and the exact steps it takes. Open one to read what it will do, then turn it on.

Unit21 Automated Sanctions and PEP Review Routing
WebRun checks Unit21 each morning for customer risk ratings and sanctions screening records due for periodic review, builds an expiry-sorted worklist, and routes each review to the correct analyst in Slack based on customer type.
Unit21SlackGoogle Sheets
Automated AML Regulatory Filing Deadline Reminders
When a regulatory reporting deadline approaches in your compliance calendar, WebRun reads the filing requirements, drafts a reminder notice for the responsible officer, and queues it for review in Gmail so nothing is filed late.
Unit21GmailGoogle Calendar
Unit21 Automated AML Remediation Action Chaser
WebRun checks Unit21 each morning for customers with open remediation actions that have passed their due date, ranks them by risk tier, and posts a prioritized chase list to the compliance Slack channel so nothing stays unresolved.
Unit21SlackGoogle Sheets
Unit21 Automated KYC Onboarding Kickoff
When a new entity is created in Unit21, WebRun reads the profile, creates the KYC onboarding checklist in Google Sheets, and posts an internal kickoff notice to the compliance Slack channel so the team can start CDD without delay.
Unit21Google SheetsSlack
Unit21 Automated Transaction Anomaly Flagging
WebRun scans Unit21 for newly triggered anomaly rules each hour, groups exceptions by customer and pattern type, and posts a structured digest to your compliance Slack channel for immediate review.
Unit21SlackGoogle Sheets
Automated KYC Document Collection Chaser
WebRun checks Unit21 and your document tracker each morning for customers with incomplete KYC document sets, identifies what is still missing, and drafts collection request emails for your compliance team to review and send.
Unit21GmailGoogle Sheets
Unit21 Automated AML Alert Triage Worklist
WebRun opens Unit21 each morning, reads new and unassigned alerts, scores them by risk level, and posts a prioritized worklist to Slack so your analysts know exactly where to start.
Unit21SlackGoogle Sheets
Automated AML Alert Email Ingestion into Unit21
When an external AML alert, law enforcement referral, or 314a inquiry arrives in your compliance inbox, WebRun reads the email, extracts the key details, and creates a structured entity record or case in Unit21 so nothing is manually re-keyed.
GmailUnit21Slack
Unit21 Automated EDD Monitoring Condition Tracker
WebRun checks Unit21 each week for customers under enhanced due diligence or ongoing monitoring conditions, verifies that required review actions have been completed, and posts a condition tracker digest to your compliance team in Slack.
Unit21Google SheetsSlack
Unit21 Automated SAR Deadline Tracking
WebRun reads open cases in Unit21 each morning, calculates the days remaining to file each SAR, and posts a prioritized deadline list to Slack so your compliance team never misses a regulatory window.
Unit21SlackGoogle Sheets
Unit21 Automated AML Case Escalation Routing
When a Unit21 case is escalated, WebRun reads the case details, matches it to the correct senior compliance officer based on your routing rules, and drafts an escalation notification for your review before sending.
Unit21GmailSlack
Unit21 Automated AML Case Status Digest
Every morning, WebRun reads all open AML cases in Unit21, summarises their current status and age, and posts a structured digest to your compliance Slack channel so the team has a single view of every live investigation.
Unit21Slack

Want one of these running on your own Unit21?

Show WebRun the process once and it will run it on schedule, in your own private browser environment.