How to Automate Unit21
Unit21 detects and documents the risk it is fed. Rules and models raise the alerts, Case Management works them, and Regulatory Filing sends SARs and CTRs to FinCEN. The registries, processor consoles and vendor portals holding the rest of the evidence are where an agent like WebRun does the fetching.
Every alert in the queue is a live customer account
Fintechs, sponsor banks and crypto businesses run their fraud and anti-money-laundering operations on Unit21. Payments, customer attributes, device signals and behaviour feed into it, models and rules turn a small share of that into alerts, and analysts work the alerts as cases until each is dismissed, escalated or reported.
What sits inside is the whole risk record. The transaction that tripped a rule and the fourteen around it. The entity behind the account, with its linked parties and its risk rating. Every alert, its disposition, and the analyst who set it. The narratives, the filings already made, and the ones whose window is still open.
Fraud analysts work it through the day, AML investigators take the older cases, and a BSA officer signs what goes to the regulator. All of them know one thing about that record: an examiner will read it years from now, with the outcome already known.
The evidence for an alert lives outside the alert
An alert names a customer and a pattern. It cannot tell you whether the pattern is a business quietly doing business.
So the analyst goes looking. The company's registration on a secretary of state search page, to see whether the entity still exists and who signs for it. The identity vendor's dashboard, to see whether the re-verification came back. The processor's console, for the chargeback that landed the same week. The support desk, where this customer already explained the wire to somebody in chat. The documents promised by email eleven days ago and still not sent, so a third reminder gets written. On the crypto side, a block explorer and the counterparty address's history.
None of that is analysis. It is twenty minutes of opening tabs and copying what they say into a case, done by someone hired to recognise structuring, and it starts again at the next line.
Detection fires on the data that reached the platform
Unit21 does the core of this properly, and a team not using all of it should start there rather than here.
Transaction Monitoring takes in transactions, device data and customer attributes in real time, and runs both prebuilt detection models and rules a compliance analyst can deploy without waiting on an engineer. Case Management gives the alerts somewhere to live: queues, enrichment, prioritisation, dispositions and an audit trail behind every decision. Sanction Screening handles the list checks. Regulatory Filing drafts the narrative, then submits SARs and CTRs to FinCEN, STRs to FINTRAC and reports to further regimes through goAML. Unit21's own AI agents take a share of the research and the summary writing, and the company is explicit that the final decision stays with the compliance team.
The ceiling is the pipeline. Every one of those acts on what was sent to Unit21, or on the sources its agents are pointed at. The rest of your operation is not in that set. The processor console, the ticket queue, the identity vendor's portal, the state register and the drive holding a customer's signed documents each sit behind their own login, with no feed into the case.
The background work on an alert can happen overnight
Work starts in Unit21 and immediately needs somewhere else. Something that can open both ends changes what the queue looks like by morning.
Every open alert in one worklist, ordered by how long it has been sitting against the deadline the filing clock runs to, so the oldest exposure is at the top rather than buried. Each business entity on that list checked against the register that incorporated it: active, dissolved, or renamed without telling anyone. The dispute console read for chargebacks on the same accounts, so a fraud pattern and a payments pattern are seen together rather than a fortnight apart.
Then the chasing, which is most of the week. Customers who owe a document for enhanced due diligence, listed with the number of times they have been asked and a follow-up drafted for each. Remediation actions assigned a month ago and never closed, with the owner named next to them. Sanctions and PEP hits grouped so the true matches sit apart from the people who merely share a name.
And the alerts a partner bank sends by email, read, matched to the right customer and written up as a case an analyst can pick up.
An analyst still decides what the alert means
That split is the whole thing, and a regulated function cannot afford to blur it. Collecting evidence and judging it are separate jobs, and only the first can be handed over.
WebRun is an AI agent that works a real Chrome browser, signed in as you. It opens Unit21 the way your team does, reads the open alerts and the dates they are running against, then opens the state register, the dispute console and the identity vendor's portal beside it, and brings back what it found, attached to the case.
It reads and it prepares. No SAR is filed, no alert is dispositioned, no account is restricted and nothing reaches a customer until someone qualified to make that call has said so.
The workflows below are already built, and each one names what it opens.
Questions people ask
Is a SAR ever filed without a person signing it?
No. Reading, gathering and drafting run unattended; the decisions do not. A filing is a signed statement to a regulator and a restriction is felt by a customer, so both wait for someone with the authority to make that call. The agent assembles the evidence and stops there.
We already run detection models in Unit21. Is this a second one?
No, it works the other end of the job. Detection decides which activity deserves attention, and that stays inside Unit21's own pipeline. This is the outside legwork once an alert exists: the state register, the processor console, the identity vendor's dashboard and the document nobody sent.
A partner bank emails us alerts. Can those get into Unit21?
Yes, as prepared work. It reads the mailbox, matches each alert to the customer and writes it up as a case with the mail and its attachments kept, ready for an analyst to work. What it never does is set a disposition or close anything out.
12 ready-made Unit21 workflows
Each one names the apps it touches and the exact steps it takes. Open one to read what it will do, then turn it on.
Want one of these running on your own Unit21?
Show WebRun the process once and it will run it on schedule, in your own private browser environment.


