Deepfake Vendor Payment Change Triage
Cross-check urgent vendor payment change emails, require human review, and block social engineering signals before money moves.
The full canvas, before you import it
Click any node to see its config.
Click a node to select it — same as the Heym editor; the panel shows its settings.
11 nodes · Free & source-available
Deepfake Vendor Payment Change Triage
Protect accounts payable from business email compromise and deepfake-assisted payment fraud. The workflow watches a dedicated mailbox, looks up the vendor record through an internal API, and pauses for human review before classifying the request.
What this workflow does
- PaymentChangeMailbox receives vendor bank detail change requests
- BuildPaymentReviewPacket extracts sender, subject, and message context
- LookupVendorRecord retrieves approved contacts and current payment metadata
- ReviewPaymentChangeRisk assesses urgency, channel mismatch, impersonation, and verification gaps
- RoutePaymentDecision separates blocked, verified, and callback-required requests
- Blocked requests alert the fraud team in Slack
- Verified decisions are archived in DataTable
- Ambiguous requests email an internal callback owner
Use cases
- Deepfake payment fraud prevention
- Vendor bank account change verification
- Business email compromise triage
- Accounts payable human approval workflows
Setup
Connect the monitored IMAP inbox, your internal vendor master API, an LLM credential, Slack, DataTable, and email. The agent must request human review. Never use contact details from the inbound message for verification, and never let this workflow move money.
How to import this template
- 1Click Import → Copy JSON on this page.
- 2Open your Heym and navigate to a workflow canvas.
- 3PressCmd+V/Ctrl+V— nodes appear instantly.
- 4Add your API keys in the node config panels and click Run.
Discover more automations
- Finance OpsPayment Webhook HandlerReceive a Stripe-style webhook payload, parse the event, send a receipt email on success, and Slack-alert your team on failure.
- Finance OpsBinance WebSocket BTC Price AlertSubscribe to the Binance public WebSocket ticker stream and trigger a price alert when BTC/USDT crosses your target threshold — no API key required.
- Finance OpsInvoice Data Extraction from PDFAn AI agent calls LlamaParse to parse a PDF invoice, then returns structured JSON with vendor, amount, line items, and totals.
- Finance OpsQuickBooks Sales Receipts from StripeReceive Stripe payment webhooks, create or find the QuickBooks customer, and generate a sales receipt automatically.
- Finance OpsPortfolio Diversification Slack BriefRead portfolio holdings from Google Sheets, analyze concentration risk with AI, and alert Slack when exposure needs review.
- Finance OpsInvoice Total Calculator (Agent Skill)An agent runs a bundled Python skill that computes line totals, discount, tax, and the grand total from invoice items.
- Finance OpsFinance Evidence S3 ArchiveUpload a finance evidence note to a structured Amazon S3 path and return the stored object key.
- Finance OpsOrder-to-Cash Exception AgentInspect order, fulfillment, invoice, and payment events, then route revenue exceptions before they become customer-facing issues.
- Finance OpsFreight Invoice Audit AgentAudit carrier invoices against shipment milestones, contracts, and accessorial rules before overcharges hit finance.
- Finance OpsGPU Inference Cost per Token Anomaly MonitorCalculate GPU inference cost per million tokens, detect efficiency regressions, and send a FinOps investigation brief.
- Dev & IT OpsHTML Status PageCheck an upstream service and answer a browser GET with a rendered status page instead of JSON.
- Dev & IT OpsWorkflow Change Audit LogCapture every workflow create, update, and delete on your Heym instance and post a batched summary to Slack.