All templates

Automated Expel Critical Incident Alerts

Every hour, WebRun opens Expel, checks for new incidents rated critical or high severity, logs each one in an Airtable register with the affected system and Expel's recommended action, and emails your on-call lead the moment one is found so response starts immediately.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Expel check for critical incidents
2 Airtable log the incident
3 Gmail email your on-call lead
In short

How do I get alerted the moment Expel flags a critical incident?

WebRun checks Expel every hour for incidents rated critical or high severity, logs each one in an Airtable register with the affected system and Expel's recommended action, and emails your on-call lead the moment one is found. It never remediates the incident itself, so your team decides how to respond.

  • Critical incidents trigger an email alert within the hour they are raised
  • Every incident has a logged record with the recommended action
  • Low severity findings stay logged without adding alert noise

Built for security teams · SOC analysts · IT admins · on-call engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens expel.io in a real browser with your saved login - no setup, no API keys.

  2. 1
    Expel - check for critical incidents
    expel.io
    WebRun in Expel: check for critical incidents
    WebRun opens Expel to check for critical incidents.
    • Open Expel and check incidents raised in the past hour
    • Note the severity, affected system, and Expel's recommended action
    • Flag anything rated critical or high

    Done when This hour's incidents have been checked for critical or high severity.

  3. 2
    Airtable - log the incident
    airtable.com
    WebRun in Airtable: log the incident
    WebRun opens Airtable to log the incident.
    • Open the incident register in Airtable
    • Add a row for each critical or high severity incident with recommended action
    • Mark any incident Expel shows as resolved as closed

    Done when This hour's critical incidents, if any, are logged in Airtable.

  4. 3
    Gmail - email your on-call lead
    gmail.com
    WebRun in Gmail: email your on-call lead
    WebRun opens Gmail to email your on-call lead.
    • Email your on-call lead the moment a critical or high severity incident is found
    • Include the affected system and Expel's recommended action
    • Stay quiet when nothing critical is found this hour

    Done when Any critical incident this hour has triggered an email to the on-call lead.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
expel.io
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Incident alert · Gmail
OutputWhat each run produces - An hourly check of Expel incidents, with a logged record and an email alert only for critical or high severity.
Alert
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun remediate the incident itself?

No. WebRun only reads and reports what Expel already found. Taking Expel's recommended action, such as isolating a host, is left for your on-call team to do.

Will I get an email for every low severity finding?

No. It only emails for incidents rated critical or high. Lower severity findings are still logged in Airtable but do not trigger an email.

What if Expel already resolved the incident?

It checks Expel's live status each hour, so an incident marked resolved is closed in Airtable and does not trigger a repeat alert.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.