Automated Expel Critical Incident Alerts
Every hour, WebRun opens Expel, checks for new incidents rated critical or high severity, logs each one in an Airtable register with the affected system and Expel's recommended action, and emails your on-call lead the moment one is found so response starts immediately.
How do I get alerted the moment Expel flags a critical incident?
WebRun checks Expel every hour for incidents rated critical or high severity, logs each one in an Airtable register with the affected system and Expel's recommended action, and emails your on-call lead the moment one is found. It never remediates the incident itself, so your team decides how to respond.
- Critical incidents trigger an email alert within the hour they are raised
- Every incident has a logged record with the recommended action
- Low severity findings stay logged without adding alert noise
Built for security teams · SOC analysts · IT admins · on-call engineers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
expel.ioin a real browser with your saved login - no setup, no API keys. -
1
Expel - check for critical incidents
WebRun opens Expel to check for critical incidents. - Open Expel and check incidents raised in the past hour
- Note the severity, affected system, and Expel's recommended action
- Flag anything rated critical or high
Done when This hour's incidents have been checked for critical or high severity.
-
2
Airtable - log the incident
WebRun opens Airtable to log the incident. - Open the incident register in Airtable
- Add a row for each critical or high severity incident with recommended action
- Mark any incident Expel shows as resolved as closed
Done when This hour's critical incidents, if any, are logged in Airtable.
-
3
Gmail - email your on-call lead
WebRun opens Gmail to email your on-call lead. - Email your on-call lead the moment a critical or high severity incident is found
- Include the affected system and Expel's recommended action
- Stay quiet when nothing critical is found this hour
Done when Any critical incident this hour has triggered an email to the on-call lead.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun remediate the incident itself?
No. WebRun only reads and reports what Expel already found. Taking Expel's recommended action, such as isolating a host, is left for your on-call team to do.
Will I get an email for every low severity finding?
No. It only emails for incidents rated critical or high. Lower severity findings are still logged in Airtable but do not trigger an email.
What if Expel already resolved the incident?
It checks Expel's live status each hour, so an incident marked resolved is closed in Airtable and does not trigger a repeat alert.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.