Install and configure
The page provides instructions on installing and configuring Evan (formerly Evelyn AMM). For data on the WorkFusion platform compatibility, refer to the release notes.
Meet requirements
Hardware
Evan runs on the standard Work.AI hardware configuration as documented in the Hardware and OS guide.
| Server | Recommended OS | CPU (cores) | RAM (GB) | HDD (GB) |
|---|---|---|---|---|
| Master | RHEL 8.5 | 8 | 32 | 750 |
| BEP Agent | RHEL 8.5 | 4 | 16 | 150 |
| Analytics | Windows Server 2016 | 16 | 32 | 150 |
| MS SQL | Windows Server 2016 | 2/4 | 8/16 | 500 |
- RPA bots are not required for Adverse Media Monitoring.
- High-availability environments require a Proxy server.
For the architecture deployment, refer to Install AI Agents | View architecture deployment.
Software
| AMM version | Environment topology | Platform version | AutoML Worker configuration | Control Tower Worker configuration | Java Native Worker configuration |
|---|---|---|---|---|---|
| 4.2.x | standard-6 topology (6/1 BEP Agents) | 10.2.9+ | 1 CPU / 8 GB memory | 0.4 CPU / 2 GB memory | 0.4 CPU / 2 GB memory |
Before installing AMM, make sure that your environment meets the following requirements:
- You have installed Work.AI v10.2.9+ and have the Control Tower and Analytics components enabled. ODF 2 is installed automatically along with the system.
- You have a bundle with the AMM Business Processes and ML models.
- You have received the credentials for the required watchlists or licenses for the external screening software to be integrated with AMM.
- You have the Advanced Package Import and Import/Export permissions in Control Tower.
To check that ODF 2 is installed, do as follows:
Log in to Control Tower, and click Advanced > Data Stores in the menu.
In the list, find the Data Stores with the_odf_transactions and _odf_transactions_status names. ODF is installed on your instance if they are on the list.

If the Data Stores are missing, download ODF and save odf-install-package-yourversion.zip to your local workstation. To find a proper ODF installation package for your Work.AI version, refer to the Compatibility matrix guide.
Review performance data
Adverse Media Monitoring leverages BEP servers that can be horizontally scaled for higher volumes.
The following table shows sample volumes that can be expected when using the corresponding versions and configurations. These tests were performed with AMM 4.0 using Google API as the search provider. Note that throughputs may vary slightly, depending on the provider.
Test input: 280 entities file, with 1 entity = 20 articles
| Number of BEP Agents | Throughput | Execution time |
|---|---|---|
| 1 | 2,036 articles/hour | 165 min |
| 2 | 6,340 articles/hour | 53 min |
| 3 | 8,000 articles/hour | 42 min |
| 4 | 10,500 articles/hour | 32 min |
| 5 | 10,800 articles/hour | 31 min |
| 6 | 12,923 articles/hour | 26 min |
Performance is measured per article across the total run to calculate throughput at the specific scaling level. Tests are run using the CSV upload method, and the system is monitored to identify long-running processes or performance bottlenecks.
Install Evan
You can install Evan from the Solution Catalog or as a bundle. For details, see the Install AI Agents guide.
Configure Evan
Once Evan is installed, you need to configure it before running for the first time:
Set the API credentials for data providers.
Configure the SMTP credentials.
Set the proxy.
Configure the options on the AMM configuration screen. To open the configuration screen, log in to Control Tower, navigate to Digital Workers, find your newly installed AMM variation, and click the Prepare button. The configuration screen includes the following steps:
You can configure multiple variations, or sets of parameters, for Evan. For example, you can set up a different data provider or a set of keywords per variation. For details, refer to Manage AI Agent variations.
API credentials for providers
The following search providers are supported:
- Google Custom Search API
- Dow Jones Factiva Headlines
- LexisNexis L&P Media
- World-Check One
- Thomson Reuters CLEAR Adverse Media
You must acquire licenses and credentials for all providers, except for Google API. WorkFusion’s AMM solution includes access to Google API at no additional cost.
If you use Google API, your first step is to provide credentials. To do that, in a GCP-hosted environment, complete the instructions under the expand below.
Provide credentials for Google API
The Google API used for the AMM AI Agent is the Custom Search JSON API. You must provide credentials from the WorkFusion’s Developer account owned by the Cloud Ops team.
GCP requires unique credentials for each customer environment (for example, pre-production and production).
If you are not using Google Cloud, notify the WorkFusion Engineering and Product teams so that they can perform an audit to ensure there are no gaps for enablement.
To generate credentials, do the following:
Log in to https://cloud.console.google.com.
Ensure that the Custom Search JSON API is enabled.

Navigate to the environment where you will use the API, for example, companyname-preprod.
Click Create Credentials.

In the Name field, specify a name for the API Key.
In the Application restrictions group, select HTTP referrers and click Save.

Navigate to OAuth consent screen. In the User Type group, select Internal and click Create.

Navigate to Enabled APIs & services to view the key and copy the credentials.
Add the key value in the Key field when setting a Secrets Vault entry as described in Manage secret entries in Secrets Vault. The Value field is static.
To use providers other than Google API, the first step is to add the credentials to Secrets Vault. For step-by-step instructions, refer to the Manage secret entries in Secrets Vault guide.
SMTP credentials
Evan emails analysts when results are ready and the final report is available. To enable the email notification, configure the SMTP credentials. Provide your own SMTP to ensure the respective security protocols are followed.
The sub-sections below describe how to configure the credentials and enable the email notification.
Update configuration in Data Store
To update the configuration in the Data Store, do the following:
- Log in to Control Tower.
- On the main menu, navigate to Advanced and select Data Stores.
- Select amm_configuration and specify the following:
| Name | Value | Example | Notes |
|---|---|---|---|
smtp.protocol | SMTP_OVER_TLS/SMTP_OVER_SSL/SMTP | SMTP_OVER_TLS | To be confirmed with WorkFusion. |
smtp.host | smtp.office365.com | Set your host. | |
smtp.port | 123 | ||
smtp.replyTo | replyTo@domain.com | Set the email address to be shown as the sender. | |
smtp.authEnabled | true/false | true | Set to true if the SMTP server requires authentication. Otherwise, set to false. |
smtp.credentialsAlias | amm_smtp_credentials | Configure only if smtp.authEnabled is set to true. Specify the alias for the Secrets Vault entry that contains the access credentials to the SMTP server. | |
smtp.from | report@workfusion.com | Enter the email address to be shown as the sender. |
Set entry for SMTP credentials in Secrets Vault
The step is needed only if smtp.authEnabled is set to true.
The key is the email address, and the value is the password. For detailed instructions, see Manage secret entries in Secrets Vault.
Use a descriptive name, such as amm_smtp_credentials.
Proxy settings
To configure a proxy, do the following:
Log in to Control Tower.
On the main menu, navigate to Advanced and select Data Stores.
Select amm_configuration and specify the following:
Name Example Notes proxy.hostproxy.customerdomain.comUse your proxy host. proxy.port9473 Use your proxy port. proxy.credentialsAliasamm_proxy_credentialsSpecify the alias for the Secrets Vault entry containing the proxy credentials. Configure only if the proxy requires authentication. If the proxy requires authentication, add the proxy credentials to Secrets Vault.
The key is the username address, and the value is the password. For detailed instructions, see the Manage secret entries in Secrets Vault guide.
Input
To set up the input for the installed AI Agent, do the following:
Indicate whether you want Evan to generate Entity ID automatically if the latter is not provided in the input data.
When you select Yes, Evan looks for an Entity ID in the input data and, if it finds none, generates it automatically based on such details as search request, date of birth, or location. Read also about Automatic Entity ID generation and decision reapplication.
When you select No, you will need to specify the Entity ID manually if it is not contained in the input data.

Choose how you want entities to be screened.

The following options are available:
Retrospectively using a risk-based approach if you want the screening to be executed upon request. For further instructions, read Retrospective screening.
Proactively using event-based monitoring if you want screening to be automatically executed based on monitored events. For further instructions, read Proactive screening.
Retrospective screening
To configure AMM to screen retrospectively, select one or more data providers in the Search provider field. You can configure the AI Agent to return search results from up to four providers at a time.

The following providers are supported out of the box:
- Google API
- Dow Jones Factiva Headlines
- LexisNexis L&P Media v1
- World-Check One
- Thomson Reuters CLEAR Adverse Media
- External Source
The settings for each selected provider appear as a separate collapsible section below the Search provider field.

Review each section carefully to ensure all required parameters are configured correctly. Available parameters vary by provider. For detailed instructions, read the sections below.
Google API

Google API Key alias: specify the alias for the Secrets Vault entry containing the Google API credentials. Choose an existing alias or click Create Secrets Vault entry to set up one.
Use Scrape.do to download the articles that could not be retrieved: when enabled, Scrape.do will parse any website that your internal APIs failed to parse.

Scrape.do Secret Vault alias: if you choose to utilize Scrape.do, specify the alias for the Secrets Vault entry containing the credentials for its licence. You can create a Secrets Vault entry on the go by clicking Create Secrets Vault entry.
Use browser rendering if a standard Scrape.do download attempt fails: when enabled, Scrape.do API will use different techniques to bypass the paywalls from some websites.
Article language: select the language in which Evan is to search for articles. The Any language setting is applied by default.

For the default Any option, you can specify the following additional settings:
Translation Option: configure the translation settings as described in the section.
Screening keywords options:
- Shared: the same set of keywords is to be used in articles across all languages.
- Defined by keyword language: depending on the Keyword language setting, each language will have a specific set of keywords.
Keyword language: select the language of the keywords for the search.
Screening keywords: specify the keywords for the search or upload a CSV file with keywords. You can add a maximum of 28 words.
The following keywords are added by default based on the article languages you select:
English:
ACCUSE, ARREST, BRIBE, CONVICT, CORRUPT, COUNTERFEIT, CRIME, EMBEZZLEMENT, FRAUD, GUILT, ILLEGAL, INDICTMENT, INVESTIGATION, KICKBACK, MONEY LAUNDERING, NARCOTIC, PENALTY, SANCTION, SENTENCED, EVASION, TERRORIST, THEFT, TRAFFICKING, VIOLATIONSpanish:
ACUSAR, ARRESTAR, SOBORNO, CORRUPTO, FALSIFICACIÓN, CRIMEN, MALVERSACIÓN, FRAUDE, CULPA, ILEGAL, ACUSACIÓN, INVESTIGACIÓN, CONTRAGOLPE, LAVADO DE DINERO, NARCÓTICO, MULTA, SANCIÓN, SENTENCIADO, EVASIÓN, TERRORISTA, ROBO, TRÁFICO, VIOLACIÓN
Enable keywords thesaurus: activate to look not only for exact keywords but also for their synonyms. By default, the feature is on. Disable it if your organization requires only exact matches on all keywords.
Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
Search period: select a time frame to specifically search for information published within it.
File types to exclude from results: select the file types that you want to exclude from Google results:
- HTML is included by default.
- Non-HTML file types do not have the same metadata and tagging. Excluding them reduces the number of articles to review and false hits by 50% without increasing the risk of missing a true hit.
Enable partial name search?: select to dynamically substitute names if no results were found for their full variants.
Use dynamic location search?: select to dynamically broaden the search location for an entity if no results are found for the initial location setting.
Ignore articles with errors?: exclude those articles that failed to be downloaded.
Exclude articles where the searched entity was not found?: if enabled, articles where Evan failed to detect the entity’s name in the text are excluded.
Automatically escalate articles that are too small?: if the setting is enabled, Evan automatically escalates small articles for manual review by default. A small article is one with fewer than 50 words.
Factiva

Factiva Headlines API URL: select one of the options below as the Factiva API address.
Factiva Headlines API Key alias: specify the alias for the Secrets Vault entry containing the Factiva credentials. Choose an existing alias or click Create Secrets Vault entry to set up one.
Article language: select the language in which Evan is to search for articles. The English language is the default option.
Screening keywords: specify the keywords for the search or upload them as a CSV file. You can add a maximum of 28 words.
The following keywords are added by default based on the article languages you select:
English:
ACCUSE, ARREST, BRIBE, CONVICT, CORRUPT, COUNTERFEIT, CRIME, EMBEZZLEMENT, FRAUD, GUILT, ILLEGAL, INDICTMENT, INVESTIGATION, KICKBACK, MONEY LAUNDERING, NARCOTIC, PENALTY, SANCTION, SENTENCED, EVASION, TERRORIST, THEFT, TRAFFICKING, VIOLATIONSpanish:
ACUSAR, ARRESTAR, SOBORNO, CORRUPTO, FALSIFICACIÓN, CRIMEN, MALVERSACIÓN, FRAUDE, CULPA, ILEGAL, ACUSACIÓN, INVESTIGACIÓN, CONTRAGOLPE, LAVADO DE DINERO, NARCÓTICO, MULTA, SANCIÓN, SENTENCIADO, EVASIÓN, TERRORISTA, ROBO, TRÁFICO, VIOLACIÓN
Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
Search period: select a time frame to specifically search for information published within it.
LexisNexis

LexisNexis L&P Media API URL: select the address of the LexisNexis API. By default, it is https://services-api.lexisnexis.com.
LexisNexis L&P Media authorization URL: specify the Authentication URL for the LexisNexis News. By default, it is https://auth-api.lexisnexis.com.
LexisNexis L&P Media API Key alias: specify the alias for the Secrets Vault entry containing the credentials for the LexisNexis News system. Choose an existing alias or click Create Secrets Vault entry to set up one.
Article language: select the language in which Evan is to search for articles. The English language is used by default.
Screening keywords: specify the keywords for the search or upload them as a CSV file. You can add a maximum of 28 words.
The following keywords are added by default based on the article languages you select:
English:
ACCUSE, ARREST, BRIBE, CONVICT, CORRUPT, COUNTERFEIT, CRIME, EMBEZZLEMENT, FRAUD, GUILT, ILLEGAL, INDICTMENT, INVESTIGATION, KICKBACK, MONEY LAUNDERING, NARCOTIC, PENALTY, SANCTION, SENTENCED, EVASION, TERRORIST, THEFT, TRAFFICKING, VIOLATIONSpanish:
ACUSAR, ARRESTAR, SOBORNO, CORRUPTO, FALSIFICACIÓN, CRIMEN, MALVERSACIÓN, FRAUDE, CULPA, ILEGAL, ACUSACIÓN, INVESTIGACIÓN, CONTRAGOLPE, LAVADO DE DINERO, NARCÓTICO, MULTA, SANCIÓN, SENTENCIADO, EVASIÓN, TERRORISTA, ROBO, TRÁFICO, VIOLACIÓN
Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
Search period: select a time frame to specifically search for information published within it.
World-Check One

World-Check One API URL: select the address of the World-Check One API. The default one is https://api-worldcheck.refinitiv.com.
World-Check One groupID: specify the Group Id for the World-Check One system.
World-Check One API Key alias: specify the alias for the Secrets Vault entry containing the credentials for the World-Check One system. Choose an existing alias or click Create Secrets Vault entry to set up one.
Article language: select the language in which Evan is to search for articles. The English language is used by default.
Screening keywords: specify the keywords for the search or upload them as a CSV file. You can add a maximum of 28 words.
The following keywords are added by default based on the article languages you select:
English:
ACCUSE, ARREST, BRIBE, CONVICT, CORRUPT, COUNTERFEIT, CRIME, EMBEZZLEMENT, FRAUD, GUILT, ILLEGAL, INDICTMENT, INVESTIGATION, KICKBACK, MONEY LAUNDERING, NARCOTIC, PENALTY, SANCTION, SENTENCED, EVASION, TERRORIST, THEFT, TRAFFICKING, VIOLATIONSpanish:
ACUSAR, ARRESTAR, SOBORNO, CORRUPTO, FALSIFICACIÓN, CRIMEN, MALVERSACIÓN, FRAUDE, CULPA, ILEGAL, ACUSACIÓN, INVESTIGACIÓN, CONTRAGOLPE, LAVADO DE DINERO, NARCÓTICO, MULTA, SANCIÓN, SENTENCIADO, EVASIÓN, TERRORISTA, ROBO, TRÁFICO, VIOLACIÓN
Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
Search period: select a time frame to specifically search for information published within it.
For the World-Check One provider, keywords highlight important sections within each article returned by the search, but not for the API call. Configure the keywords for your search at the World-Check One's website.
Thomson Reuters CLEAR Adverse Media
To start using the Thomson Reuters CLEAR Adverse Media to source input data for Evan, comply with the following requirements:
Install the Thomson Reuters CLEAR API connector.
Add all public IP addresses of Agent servers to Thomson Reuters Whitelist. For that, contact the Thomson Reuters team.
Install a Thomson Reuters keystore to
/opt/workfusion/sslon the Master node. Once it is installed, create the tr.clear.api.keystore Secrets Vault entry, where the key is the path to the keystore file, and the value is the certificate password. For instructions on creating a Secrets Vault entry, see the guide.On the Input step of the configuration screen, configure the settings described below:

Use Scrape.do to download the articles that could not be retrieved: when enabled, Scrape.do will parse any website that your internal APIs failed to parse.
Scrape.do Secret Vault alias: if you choose to utilize Scrape.do, specify the alias for the Secrets Vault entry containing the credentials for its licence. You can create a Secrets Vault entry on the go by clicking Create Secrets Vault entry.
Use browser rendering if a standard Scrape.do download attempt fails: when enabled, Scrape.do API will use different techniques to bypass the paywalls from some websites.
Article language: select the language in which Evan is to search for articles. The English language is used by default. For the Any option, configure the translation settings.

Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
Search period: select a time frame to specifically search for information published within it.
File types to exclude from search results: select the file types that you want to exclude from the provider's results:
- HTML is included by default.
- Non-HTML file types do not have the same metadata and tagging. Excluding them reduces the number of articles to review and false hits by 50% without increasing the risk of missing a true hit.
External Source
When the option is selected, AMM doesn't search in a news provider. Instead, the AI Agent uses the article links provided in the input CSV data file.

To enable sourcing data from a CSV file, do as follows:
Make sure your CSV file has the correct format. To do that, open the CSV file monitoring settings section and click the Template link to download a CSV file template. Files that do not comply with the format requirements are not ingested.
In the Content Source Priority section, define how Evan should prioritize the content fields when both input data and downloaded content (from a link) are available.
Specify the following general screening settings:
Select Use Scrape.do to download the articles that could not be retrieved if you want Scrape.do to parse any website that your internal APIs failed to parse.
In the Scrape.do Secret Vault alias field, specify the alias for the Secrets Vault entry containing the credentials for the Scrape.do licence. You can also create a Secrets Vault entry on the go by clicking the Create Secrets Vault entry button.
Select Use browser rendering if a standard Scrape.do download attempt fails if you want Scrape.do API to use different techniques to bypass the paywalls from some websites.
Configure the translation settings as described in the section.
Set Do you want to ignore dead links? to Yes if you want Evan to exclude invalid links from the final result.
Set Do you want to ignore articles that redirect? to Yes if you want Evan to exclude the links that return 30X statuses in the final result.
In the CSV file monitoring settings section, configure the following:
- Input file bucket: specify the S3 bucket name where you need to upload the CSV file.
- Input file location: specify the path to the directory where you need to upload the CSV file.
- Monitoring frequency and Time Unit: configure the interval of monitoring for CSV files.
Proactive screening
If you indicate that you want the entities to be screened Proactively using event-based monitoring, you are requested to choose a search provider.

For now, ongoing monitoring is available only with the Thomson Reuters provider.

To start using the Thomson Reuters CLEAR Adverse Media for proactive screening, comply with the following requirements:
Install the Thomson Reuters CLEAR API connector.
Add all public IP addresses of your Agent servers to Thomson Reuters Whitelist. For that, contact Thomson Reuters team.
Install a Thomson Reuters keystore to
/opt/workfusion/sslon the Master node. Once it is installed, create thetr.clear.api.keystoreSecrets Vault entry, where key is the path to the keystore file and value is the certificate password. For instructions on creating a Secrets Vault entry, see the guide.On the Input step of the configuration screen, configure the settings described below:
Use Scrape.do to download the articles that could not be retrieved: when enabled, Scrape.do will parse any website that your internal APIs failed to parse.
ScrapeDo Secret Vault alias: specify the alias for the Secrets Vault entry containing the credentials for its licence. You can create a Secrets Vault entry on the go by clicking Create Secrets Vault entry.
Use browser rendering if a standard Scrape.do download attempt fails: when enabled, Scrape.do API will use different techniques to bypass the paywalls from some websites.

Article language: select the language in which Evan is to search for articles. The English language is used by default. For the Any option, configure the translation settings.
Maximum extracted articles per entity screening: specify the maximum number (from 1 to 30) of articles to fetch. By default, up to 20 articles are retrieved.
File types to exclude from search results: select the file types that you want to exclude from the provider's results:
- HTML is included by default.
- Non-HTML file types do not have the same metadata and tagging. Excluding them reduces the number of articles to review and false hits by 50% without increasing the risk of missing a true hit.
To start using Thomson Reuters Clear API for ongoing monitoring, comply with the following requirements:
Validation settings
In the section, you can select the options to validate the following input data entities:
- Country of residence or operating country
- Country of citizenship or incorporation
- Subdivision
- City
All validations are enabled by default. For details on validation rules, requirements, and errors, see Learn about input and output data | Input data validation.
Translation settings
The feature enables the translation of article content, title, and summary. It is available only for the following providers:
Mind the following translation feature limitations:
- Translation is done after Evan downloads and parses the article content. Large or media-heavy pages may take longer to process.
- The rate limits or quota constraints on the Google Translation API side can impact throughput. Monitor your usage and adjust quotas as needed.
- For optimal results, ensure the Target translation language setting matches your analysts’ working language and the final report and manual review task language configured in the output settings.
The general configuration sequence for the translation feature is as outlined below. See also Provider-specific details.
In the Translation Option section, select a rule:
The Do not translate articles rule skips the translation. The Target translation language and Google Translate API Key alias fields are hidden if this option is selected.
The Translate only articles that are not in English or Spanish rule translates articles if their original language is neither English nor Spanish.
The Translate all articles that are not in the target language rule translates articles where the original language is different from the configured target language.

If you select Do not translate articles above, skip this step. Otherwise, proceed to configure the following settings:
Target translation language: select the supported language into which articles should be translated.
Google Translate API Key alias: specify the alias for the Secrets Vault entry containing the Google Translate API credentials.
To create a Secrets Vault entry, if you don't have one, click Create Secrets Vault entry and follow the instructions in the Manage secret entries in Secrets Vault guide.
Provider-specific details
Google
- Translation supports the article fields retrieved from Google: title, snippet or summary, and the content downloaded by Evan.
- To allow searching across all languages, set the provider’s Article language parameter to Any. If a specific language is selected, translation is typically unnecessary.
- The translation engine uses the key provided in the Google Translate API Key alias field.
- If the translation for a particular article fails due to an API error, quota exceeded, or unsupported language, Evan keeps the original text and marks the article with an internal error code. The article still appears in the search results unless excluded by other settings.
Thomson Reuters CLEAR Adverse Media
- Translation supports the provider’s returned title, summary, and content downloaded by Evan for the linked articles.
- To enable cross-language retrieval, set the Article language parameter to Any. The translation feature will then be applied according to the configured Translation Option settings.
- The translation feature uses the same Google Translate API Key alias as for the Google provider.
- If translation is not possible, for instance, due to the provider content inaccessible or language unsupported, Evan keeps the original text and continues processing. Articles are not dropped only due to the translation issues.
External Source
- Translation applies to the content downloaded from the provided links, along with any provided titles or summaries in the input file, when available.
- There is no provider-side Article language selector for External Source. Translation is applied purely based on the detected language and the configured Translation Option settings.
- The translation feature uses the same Google Translate API Key alias as for the Google provider.
- If a link is dead or content cannot be retrieved, translation is skipped for that item and Evan's behavior is according to the External Source settings (for instance, the Ignore dead links option).
Investigation
After setting the Input parameters, click Next to go to the following step of the wizard.

General settings
Do you want the Digital Worker to identify and group duplicate content?: set to Yes for AMM to identify and group articles by the specified similarity threshold. By default, the threshold is set to 50%. However, you can configure it in the field below.
Do you want to use available meta data to adjudicate articles first?: applicable only for the External Source input. Set to Yes for AMM to use the metadata from the input file and process it with the NSS model before running the investigation. To start using it, you also need to configure Signal ID on the Execute NSS step in the Adverse Media Monitoring File Ingestion BP.

Remove legal endings: select Yes to remove legal endings from the names of the company type entities. Entities with common names or small businesses (LLCs, S corps) can receive more tailored results when the option is set to No.
Preferred date format: select the date format to use for input and output data.
Ad-hoc investigation settings
Fields to include in the ad-hoc investigation task: configure what fields should be visible on the Ad Hoc search screen.
Number of investigation tasks to be created in Workspace: configure how many investigation tasks you want to create when running the Ad hoc investigation BP. The recommended setting is one task per 2-3 analysts.
Always assign human-in-the-loop tasks to the person who initiates the investigation: if selected, all manual review tasks created by the user are automatically assigned to them.
Article classification settings
Classification model for article processing: select the version of the model you want to use. The latest model is selected by default.
Do you want to use GenAI to help disposition articles? Specify if you want a Large Language Model (LLM) to back up the dispositioning of articles in case the selected AMM model fails to take a decision.

As you select Yes, you are prompted to specify the following:
Select an LLM provider. Available options include OpenAI, Google, Anthropic, and xAI.
Choose the provider's LLM model and its version.
When you choose the Other option in the model list, a free-text input field is shown for you to type in a custom model name.
Choose a screening approach. The available options are as follows:
Entity extraction and age disposition only: the LLM model helps to match the name and age of the screened entity. The AMM OOTB model age-matching functionality is not used.
Entity and crime extraction, age disposition: the LLM model helps to match the name and age of the screened entity. Additionally, it identifies the crime mentioned in articles and generates a decision comment. The AMM OOTB model age-matching and article disposition functionality is not used.
Specify the alias for the Secrets Vault entry contaning the credentials to access the selected LLM provider.
To create a Secrets Vault entry on the go, if you don't have one, click Create Secrets Vault entry and follow the instructions in the Manage secret entries in Secrets Vault guide.
Date of birth matching threshold: articles are marked as False Positive if the difference between the age of the screened entity and the age of the entity in the article is greater than the value configured here. The default setting is 2 years.
High-risk countries: select countries from the drop-down box or type them in. The configured high-risk countries are highlighted in articles returned from each investigation.
Advanced article classification settings
In the section, configure custom investigation statuses and comments for various ML decisions.

Human in the Loop

Configure whether and how you want to send the search results to Workspace by selecting one of the following options:
Send in all cases: the AI Agent creates manual review steps for every search run.
Do not send when there are no new articles to review: the AI Agent skips the manual review step when all retrieved articles are evaluated as False Positive or have been previously reviewed1 with the False Positive status.
Do not send when all new articles are false positive: the AI Agent skips the manual review step when all retrieved articles are evaluated as False Positive or have been previously reviewed1 with any status.
Do not send in all cases: the AI Agent skips the manual review step in all cases, sticking to the model's decisions.
Depending on the selected option, configure the settings below:
Decision reapplication matching conditions: set the rules for applying decision reapplication.
Required matching decisions: how many times an article with the same status needs to be reviewed for a decision to be reapplied.
Required distinct users: how many unique users need to review an article with the same status before a decision is reapplied.
Enable Auto QC?: if enabled, the specified percentage of false positive articles are flagged for manual review for quality control purposes. Set the percentage in the Percentage of articles to sample for Auto QC field.
Require users to disposition all articles?: set to Yes if you want users to disposition all articles prior to closing an investigation in Workspace.
Require users to manually disposition “False Positive” articles?: configure if users must manually select an investigation status for False Positive articles and provide a comment.
Restricts the analyst from closing an investigation with True Positive status on the initial review? Specify whether you want to allow users to submit an investigation with the True positive status when it's opened for the first time. When the option is set to Yes, one more review is required to close the task with the True Positive status.
Automatically route users to the next task after closing the investigation?: choose whether you want users to be routed to the next task in the queue. If disabled, users are always taken back to the main queue list after closing or saving an assignment.
Generate report if a manual assignment expires: if the parameter is set to Yes, when a manual review assignment in Workspace expires, it is considered submitted. The transaction is processed as usual, and a report is generated.
Allow users to add websites to ignore list?:

If set to Yes, users are allowed to add websites or articles to the ignore list directly from Evan's manual assignment in Workspace. Associated URLs and metadata are saved to the content_relevance_feedback Data Store with the
enabledparameter set totrue. In future search requests, AMM will automatically ignore these articles and websites, and they will not be displayed in manual review assignments.If set to Yes, with additional approval, added websites or articles will require approval before being ignored. Associated URLs and metadata are also saved to the content_relevance_feedback Data Store, but the
enabledparameter is set tofalse. The approving person must review the blocked URLs in the Data Store and approve them by changing theenabledparameter value totrue. Otherwise, the articles and websites will still be displayed in the search results during manual review.If set to No, users are not allowed to add websites to the ignore list.
Note: adding a website to the ignore list will only impact new Manual Tasks submitted after applying the configuration. Any existing Manual Tasks are not updated.
Assignment status customization: the setting allows you to view and customize the labels shown for investigation statuses in a Manual Task. The default values are as follows:
- New: the assignment has been just created.
- Draft: someone had been working on the assignment, and it was updated.
- Reopened: the investigation has been reopened.
To add or edit a custom label to indicate an assignment status, enter your preferred label text in the right column next to the corresponding description. The status description is not editable.
Shorthand list of predefined reasons: allows you to specify additional shorthand reasons that can be used by analysts during the manual review.
How would you like to arrange the article details layout?: choose a layout for displaying manual review assignment components in Workspace:
Display the article controls to the right of the navigation panel, and the article content to the right of the controls: article controls are moved to the left side, towards the article list, and the article content is moved to the right.
Center the article content: with the article controls shown on the right, the article content is displayed in the middle.
Number of articles displayed on one page: number of articles displayed per page on the Articles to Review and Dispositioned Articles lists within a manual review assignment page.
Output

This is the last configuration step where you specify the following output parameters:
Final report and manual review task language: select the language of the final report and Manual Task.
Enable report generation: when this option is deselected, Evan skips the report generation entirely.
Report preferences
Generate combined report: select to generate a combined report. The option is not available for requests through REST API.
Generate batch report: select to generate a batch report. The option is not available for requests through REST API.
Generate quality control report: select to generate a quality control report if you enabled the quality control on the Human in the Loop step. The option is not available for requests through REST API.
Report format: select the format of the report for screening requests. Available options are HTML or PDF.
Remove article details for the report?: if set to Yes, AMM generates only the short version of the report without the full article text.
Send quality control report to: once a batch of records is processed and a quality control report is generated, the latter is sent to the email specified in the field. Note that the quality report is not generated when screening starts with REST API.
Use webhook to enable notification about investigations sent to Workspace for manual review: if the checkbox is selected, a webhook callback is sent every time when a manual review task is created.
- URL for investigations sent to manual review: specify a URL to be triggered with the webhook callback. For the webhook payload structure, see the AMM API reference.
Use webhook to enable notification when an investigation is completed: if the checkbox is selected, a webhook callback is sent every time when an investigation is completed.
- URL for completed investigations: specify the URL to be triggered with the webhook callback. For the webhook payload structure, see the AMM API reference.
Use webhook to enable notifications for error events: if the checkbox is selected, a webhook callback is sent every time when an error occurs.
URL for error events: specify the URL to be triggered with the webhook callback. For the webhook payload structure, see the AMM API reference.
Encrypt the webhook payload: select if you want the webhook payload to be encrypted. For details on how the encryption works and what you need to do, see the Webhook payload encryption section.
- Encryption key alias: specify the name of the alias in Secrets Vault containing the encryption key. If you do not have one, click Create Secrets Vault entry and set one up in accordance with the guide.
Webhook payload encryption
Webhook payload encryption ensures that sensitive investigation results sent from AMM to your external systems are protected in transit. When enabled, Evan does not send the webhook body as plain JSON. Instead, the AI Agent encrypts it using Google Tink’s AEAD encryption with the key provided by you.
Encryption flag: when the Encrypt the webhook payload configuration property is enabled for final results or for manual review alerts, Evan automatically encrypts the webhook payload.
Encryption key alias: Evan fetches the encryption key from the Secrets Vault using the alias defined in Encryption key alias field. The value stored in Secrets Vault must be a valid Tink JSON keyset.
Below is a sample keyset that can be stored in Secrets Vault:
{
"primaryKeyId": 123456789,
"key": [{
"keyData": {
"typeUrl": "type.googleapis.com/google.crypto.tink.AesGcmKey",
"value": "EhA1mwq3dU45s3lMquF8H0m7gQ==",
"keyMaterialType": "SYMMETRIC"
},
"status": "ENABLED",
"keyId": 123456789,
"outputPrefixType": "TINK"
}]
}
The encryption sequence is as follows:
Evan serializes the webhook payload into JSON using the provided key from the Secrets Vault to encrypt the payload.
The webhook request is sent with the following Content-Type setting:
application/octet-stream. The request body contains only the encrypted byte array (not JSON).The webhook is decrypted on the customer side. To consume the encrypted payloads, your system must use the same Tink keyset to decrypt the data.
Below is an example in Java:
import com.google.crypto.tink.Aead;
import com.google.crypto.tink.CleartextKeysetHandle;
import com.google.crypto.tink.JsonKeysetReader;
import com.google.crypto.tink.KeysetHandle;
byte[] encryptedPayload = ...; // webhook request body
String keysetJson = ...; // same JSON keyset you uploaded to Secrets Vault
KeysetHandle handle = CleartextKeysetHandle.read(JsonKeysetReader.withString(keysetJson));
Aead aead = handle.getPrimitive(Aead.class);
byte[] decrypted = aead.decrypt(encryptedPayload, new byte[0]);
String payloadJson = new String(decrypted, StandardCharsets.UTF_8);
After the decryption, payloadJson will contain the original AMM webhook JSON.
To enable the webhook encryption, do the following:
Generate an encryption keyset. Use Tink key generation tools or WorkFusion’s guidance to create a JSON keyset. Recommended: AES-256-GCM key type.
Add the generated JSON keyset as a new secret entry to Secrets Vault. Use a descriptive alias, for instance, amm_webhook_encryption_key.
Update the AMM configuration. On the Output step, select the Encrypt the webhook payload checkbox and specify the key alias.
Update your webhook consumer to make sure the system receiving AMM webhooks has access to the same JSON keyset.
Implement a decryption logic similar to the one shown above before processing the payload.
Review configuration
Once you complete the required fields, review the configuration. You can return to any step to change previous settings before finalizing. If everything is correct, click Finish. You are now ready to use AMM to run an investigation.
Configure advanced settings
Data Purge
The Adverse Media Monitoring Data Purge Business Process enables periodic data cleanup based on internal retention policies, either on a set schedule or on demand.
Configure Data Purge settings
To configure Data Purge settings, do the following:
Log in to Control Tower.
Click the Advanced tab and select Data Stores.
Select amm_configuration and set the following parameters:
Name Value type Example Description dataPurge.storagePeriodInDaysInteger 30Specify how many days after the completion of a transaction its data should be stored. dataPurge.historyStoragePeriodInDaysInteger 30Specify how many after the completion of a transaction its history data should be stored (used in decision reapplication). dataPurge.userActivityStoragePeriodInDaysInteger 30Specify how many days after the completion of a transaction user activity data should be stored. dataPurge.deleteReportstrue/falsefalseSet to trueto delete generated reports.dataPurge.deleteAnalyticsDatatrue/falsefalseSet to trueto delete analytics data.dataPurge.deleteArticleAndInvestigationHistorytrue/falsefalseSet to trueto delete the historical data for previous investigations (used in decision reapplication).dataPurge.deleteUserActivitytrue/falsefalseSet to trueto delete the user activity data.dataPurge.deleteArticleContenttrue/falsefalseSet to trueif you need to delete the article content.
Configure Data Purge scheduling
You can run the Data Purge BP manually or on a schedule. To configure the schedule, do the following:
Log in to Control Tower.
Go to the Advanced tab and select Schedules.
Click Create.
In the Create Schedule window, set the following parameters:
- In Process Definition, select Adverse Media Monitoring Data Purge vX.X.X | AMM | X.X.X.
- In Input Data, select Empty.
- Specify Schedule Period to run Data Purge only for some period. Otherwise, leave it empty.
- In Schedule Name, set the operation's name, for example, Adverse Media Monitoring Data Purge.
- In Schedule Frequency, specify days and times when Data Purge must be started. It is recommended to set the time when the environment is least loaded, for example, nightly hours on weekends.

Click Save.
After that, the purge operation runs automatically on a specified day and time.
To learn more about data purging in Work.AI, see the following guides:
REST API endpoints
To configure REST endpoints for Adverse Media Monitoring, perform the following steps:
In Control Tower, open the core BP definition Adverse Media Monitoring vX.X.X. On the Data tab, select Streaming Records from External Sources. Here, you can also specify a custom Signal ID if needed:

On the Run tab, click Run This Process.
After the BP starts, return to the Run tab and click Show API to find all available generated endpoints:

For Adverse Media Monitoring, only asynchronous invocation is supported, in particular, the following endpoints:
/start-record-raw/to start a BP/check-record-status/to check the status of a running transaction/get-record-result/to get the result data of a finished transaction
For detailed information on invoking transactions and getting access to a token, see Running AI Agents via REST API.
Sample JSON request
{
search_request: String (required),
entity_type: String (COMPANY/INDIVIDUAL),
year_of_birth: Integer,
citizenship_country: String (2 letter ISO Country code),
residence_country: String (2 letter ISO Country code),
subdivision: String (ISO 3166-2 code of the subdivision),
city: String (Full City name. Used only by Thomson Reuters provider),
search_period: Integer (search period in days),
entity_id: String (Used for decision reapplication),
batch_id: String (Used to group search entities for combined reports generation)
}
Sample JSON response
{
"transactionUUID" : String,
"runUUID" : String,
"variationUUID" : String,
"startTime" : UTC-date,
"endTime" : UTC-date,
"searchRequest" : String,
"investigationStatus" : String (FALSE_POSITIVE/TRUE_POSITIVE/NEEDS_INVESTIGATION/NO_RESULTS_FOUND),
"newsProvider" : String,
"manualTaskExecuted" : boolean,
"reviewerUUID" : String,
"reviewerName" : String,
"reviewComment" : String,
"reportLink" : String,
"articles" : [
{
"articleUUID" : String,
"tile" : String,
"summary" : String,
"investigationStatus" : String (FALSE_POSITIVE/TRUE_POSITIVE/NEEDS_INVESTIGATION),
"adjudicationReason" : String,
"publishingDate" : UTC-date,
"author" : String,
"language" : String,
"wordCount" : int,
"source" : String,
"articleLink" : String,
"originalArticleLink" : String,
"score" : Decimal,
"isReviewed" : boolean,
"reviewerUUID" : String,
"reviewerName" : String,
"reviewComment" : String,
"errorCode" : String
},
...
]
}
Ad Hoc search
To configure the Ad Hoc search settings, follow the steps below:
Log in to Control Tower.
On the main menu, navigate to Advanced > Data Stores.
In the Data Store list, select amm_configuration and enter the values for the following parameter:
| Name | Value type | Example | Notes |
|---|---|---|---|
adHoc.investigationBatchMaxSize | Integer | 100 | Defines how many entity names can be in one investigation batch. |
- Articles are marked as reviewed if the status or comment was updated manually.↩