ScreenshotNeo

BlogHow-to

How to Set Up SEC Form 4 Alerts with Slack, Visualping, and n8n

Build a Form 4 alert workflow with Visualping, n8n, and Slack. Learn how to retrieve filings, deduplicate alerts, and read transaction codes carefully.

By the ScreenshotNeo team4 October 20269 min read

Direct answer: Create a Visualping monitor for the SEC ownership filings page of each company you want to follow, send its page-change webhook to an n8n workflow, retrieve and parse the new Form 4, then post a concise alert with the filing link to Slack. Deduplicate by accession number and preserve transaction codes and footnotes: a Form 4 can report grants, gifts, exercises, and other events, not just open-market purchases or sales.

Form 4 is the Statement of Changes in Beneficial Ownership. Section 16 applies to directors and officers of SEC reporting companies and holders of more than 10% of a registered equity class. A reportable transaction is generally due before the end of the second business day after execution; that deadline does not set your workflow’s polling or delivery time. SEC Form 4 instructions · SEC investor overview · SEC Section 16 overview.

1. Choose how to detect new filings

This guide uses Visualping for page-change detection, n8n for orchestration and filing retrieval, and Slack for team notifications. Treat it as a reference design: product screens and interface labels can change, so check current product documentation when configuring a live workflow.

Detection method Good fit Trade-offs
Visualping page monitor You want a visual change trigger for an issuer’s recent ownership filings page. Depends on the page and selected region remaining recognizable; the change event is a trigger, so the workflow still has to find and parse the filing.
SEC filing-search RSS You want EDGAR filing search subscriptions filtered by company, CIK, and form type. You need to manage feed polling and downstream processing; confirm the feed’s current filters and behavior.
SEC company submissions API You want company submission data from an SEC REST API as a retrieval foundation. Your workflow must detect new submissions, track state, retrieve filing documents, and handle retries.

The SEC provides company submissions and extracted XBRL data through REST APIs, and EDGAR filing searches can provide RSS feeds filtered by company, CIK, and form type, including ownership reports. These are official alternatives to a page monitor; they can still feed n8n and Slack. Consult the SEC developer resources and SEC RSS instructions for current details. The available sources establish the options, not a latency or cost benchmark between them.

2. Prepare the company list and Slack destination

  1. Identify each issuer by its SEC Central Index Key (CIK), and open its SEC ownership-filings page. Use the filing page as the target for a separate Visualping monitor per CIK.
  2. In Visualping, select the recent-filings table or relevant region if the current interface permits it. Configure the monitor to notify a webhook and point it at an n8n webhook trigger URL. A monitor per company makes routing and troubleshooting easier; send all events to a shared workflow if you want one processing path.
  3. Create a Slack app and enable an incoming webhook for the destination channel. Store the resulting unique webhook URL as a secret in n8n credentials or an equivalent secret store. Do not expose it in a public workflow export or source repository.
  4. In n8n, create a workflow with a Webhook trigger, filing retrieval and parsing steps, deduplication, and a Slack notification step. Activate the workflow and configure the Visualping monitor to call its production webhook URL.

Slack incoming webhooks accept a JSON payload at a unique app-specific URL and support message formatting blocks. See Slack’s incoming webhook documentation.

3. Build the n8n detection-to-alert workflow

  1. Receive the event. Accept the Visualping webhook and inspect the actual event payload. Extract the filing link or accession number if provided. Payload fields can vary; do not assume field names without checking a real event sample.
  2. Resolve the filing. If the event only identifies a changed page, fetch the issuer’s ownership-filings page, find the newest Form 4 row, and extract its filing link or accession. If you have an accession, resolve the filing index page and retrieve the full submission text or XML. Prefer filing data from SEC sources, and retain the original filing link.
  3. Use a descriptive SEC User-Agent. Include an application name and contact email on SEC requests. Keep request traffic reasonable, and use backoff for retries. Check the SEC’s current fair-access guidance before production deployment; a third-party workflow example is not a substitute for SEC policy.
  4. Parse the form. Extract the issuer, reporting person, relationship, transaction date, transaction code and description, shares and price when present, direct or indirect ownership details, and footnotes. Form 4 XML is structured, but the transaction tables and footnotes need to be retained in context rather than reduced to one label.
  5. Deduplicate. Store the last alerted accession for each CIK, or maintain a set of processed accessions. Before posting to Slack, skip any accession already recorded. Persist the new accession only after the alert is accepted, so a transient Slack error can be retried safely.
  6. Post and record. Send a concise Slack message with the key fields, cautious summary, and direct SEC filing link. Record success and enough event metadata to diagnose retries or parsing issues.

For multiple companies, use a shared n8n workflow and route each event using its CIK. Keep deduplication state keyed by CIK plus accession number. This avoids duplicate messages when a page monitor fires more than once or a workflow retries.

4. Format a useful Slack alert

Include enough detail for a reader to decide whether to open the filing, without implying that a code alone explains the insider’s intent.

Form 4 filed: Example Company (CIK 0000000000)
Reporting person: Jane Doe — Director
Transaction: P — purchase
Transaction date: 2026-09-30
Shares / price: 1,000 / $25.00 (if reported)
Ownership: Direct (see filing for details)
Footnotes: 1, 2
Summary: The filing reports a coded transaction. Review the filing and footnotes for context; this alert is not an investment recommendation.
SEC filing: https://www.sec.gov/Archives/edgar/data/...

Common codes include P for a purchase, S for a sale, A for a grant or award, F for securities used to pay an exercise price or tax liability, M for exercise or conversion, and G for a gift. The form instructions cover additional codes. Preserve the code as filed and link readers to the primary document. A Form 4 alert is a filing notification, not proof of motive or a recommendation to trade. See the complete SEC instructions.

5. Do-it-yourself code: post a parsed filing to Slack

The following runnable Python example posts a prepared alert to an incoming webhook. It assumes the upstream n8n steps have already retrieved and parsed a filing and applied accession-based deduplication. Store the webhook URL in an environment variable; never commit it to a repository.

import json
import os
import urllib.request

webhook_url = os.environ["SLACK_WEBHOOK_URL"]
message = {
    "text": (
        "Form 4 filed: Example Company\\n"
        "Reporting person: Jane Doe — Director\\n"
        "Transaction: P — purchase; review the filing and footnotes for context.\\n"
        "SEC filing: https://www.sec.gov/Archives/edgar/data/..."
    )
}
request = urllib.request.Request(
    webhook_url,
    data=json.dumps(message).encode("utf-8"),
    headers={"Content-Type": "application/json"},
    method="POST",
)
with urllib.request.urlopen(request, timeout=20) as response:
    print(response.status, response.read().decode("utf-8"))

In n8n, use its Webhook, HTTP Request, data transformation, storage, and Slack or HTTP Request nodes to implement the same stages. Configure retries with backoff for transient network or service errors, and ensure retries pass through the accession deduplication check.

6. Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. It can capture a public filing page or issuer page if a visual record is useful alongside the structured filing alert. Its API accepts one GET request with a URL and returns an image or PDF; see the ScreenshotNeo API documentation. For this SEC Form 4 workflow, use the SEC filing itself as the authoritative data source and treat a screenshot as a visual snapshot, not a replacement for parsing the filing.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.sec.gov/Archives/edgar/data/... -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://www.sec.gov/Archives/edgar/data/..."}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://www.sec.gov/Archives/edgar/data/...' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);

Cookie banners, popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed; responses include page-verdict and billing headers. An MCP server lets AI agents use screenshot tools. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, with no card.

7. Reliability, performance, and operating cost

  • Alert timing: The filing deadline is generally before the end of the second business day after execution; it does not promise an alert at that time. Your monitor’s check frequency, workflow queueing, SEC response, parsing, and Slack delivery determine when a notification arrives. No measured end-to-end latency is established here.
  • Request load: Avoid aggressive polling. Reuse a filing already retrieved during a workflow run, identify records by accession, and back off after transient failures. Follow current SEC fair-access guidance.
  • Retries: Retry timeouts and temporary server failures with increasing delays and a limit. Do not retry permanent parse errors indefinitely. Make Slack delivery and state updates idempotent to avoid duplicate alerts.
  • Page changes: A page layout change or unrelated page update can produce a monitor event. Have the workflow confirm that a new Form 4 accession exists before alerting.
  • Cost: This research does not establish comparative operating prices for Visualping, n8n, or Slack, or a cost benchmark against SEC-native feeds. Check current service plans and estimate usage from your chosen monitor frequency, number of CIKs, workflow executions, and retention needs.
  • Data quality: Preserve the raw filing link and relevant XML/text alongside parsed fields. If a field is absent, label it unavailable rather than filling it from inference.

8. Troubleshooting

Symptom Likely cause Fix
No n8n execution appears The monitor is using a test webhook URL, workflow is inactive, or webhook delivery failed. Use the active production webhook URL, activate the workflow, and inspect Visualping delivery history and n8n execution logs.
Workflow runs but finds no filing The page changed for another reason, the event contains no filing URL, or the wrong company page was monitored. Resolve the CIK, fetch the current filings table, and require a new Form 4 accession before continuing.
SEC request fails or is throttled Request volume is too high, the request lacks a descriptive User-Agent, or a temporary network/server problem occurred. Set a descriptive User-Agent with contact information, reduce request frequency, and retry transient failures with backoff. Recheck current SEC access guidance.
Duplicate Slack messages The monitor fires repeatedly or workflow retries lack persistent idempotency. Store processed accession numbers and check the store immediately before posting.
Alert says “purchase” for an award or exercise The parser collapsed transaction codes into a broad label. Retain the SEC transaction code, map only codes you understand, include footnotes, and link the filing.
Slack returns an error The webhook URL is invalid or revoked, the payload is malformed, or the destination configuration changed. Check the HTTP response and Slack app webhook configuration; rotate the secret if it was exposed.
Key fields are missing That field may not apply, may be in a footnote, or the parser did not handle the filing’s XML structure. Keep fields optional, preserve source context, and test parser handling against the primary filing before enabling alerts.

9. Frequently asked questions

Can I monitor only one company?

Yes. Set up a monitor or SEC feed for that company’s CIK and retain the CIK in the workflow so filing resolution and deduplication stay scoped correctly.

Can I use the SEC RSS feed instead of Visualping?

Yes. SEC filing-search RSS can be filtered by company, CIK, and form type. It can replace page-change detection while n8n still retrieves, parses, deduplicates, and routes filings.

Does every Form 4 mean an insider bought or sold shares?

No. Forms can report awards, gifts, exercises, tax-related dispositions, and other changes. Read the transaction code, ownership details, and footnotes in the filing.

When will Slack send the alert?

There is no guaranteed delivery time in the sources for this design. Check frequency and workflow processing affect alert timing; the SEC filing deadline is a separate requirement.

Should an alert include an AI interpretation?

If you add one, label it as an automated summary, keep the primary filing link and codes visible, and do not present the summary as an SEC conclusion or investment advice.