jump to content

Webhook Event Types

Reference for each type of platform webhook event and the form of the useful data load, covering third parties, users, obligations and document life cycle.

Show as Markdown

This reference maps each event name to the exact object delivered in data. Events cover third parties, users, obligations, rights claims and the entire document life cycle. Frameworks, controls, measures, risks, access reviews, devices and cookie consent do not emit webhook events - useGraphQL, CLI,MCPsaun8for these areas. What webhooks cover.

Webhook organizations and the X-Probo-Webhook-Event header use lower source names, such as third-party:created. The console nodeAPI, CLI and CLI8nutrices higher entity names, such as THIRD_PARTY_CREATED.

Each delivery wraps the useful load of resources into a root package (eventId, subscriptionId, organizationId, createdAt, data, and optional updatedFrom) and the setting of corresponding HTTP titles. Webhooks Overview The following sections describe only embedded resource forms data / updatedFrom.

Event Description
third-party:created A third party was created
third-party:updated A third party was updated
third-party:deleted A third party was deleted
Event Description
user:created A user was created
user:updated A user was updated
user:deleted A user was deleted
Event Description
obligation:created An obligation was created
obligation:updated An obligation was updated
obligation:deleted An obligation was deleted
Event Description
right-request:created A data subject rights request was created
right-request:updated A data subject rights request was updated
right-request:deleted A data subject rights request was deleted
Event Description
document:created A document was created
document:updated A document was updated
document:archived A document was archived
document:unarchived A document was unarchived
document:deleted A document was deleted
Event Description
document-version:created A document version was created
document-version:updated A document version was updated
document-version:published A document version was published
document-version:rejected A document version was rejected
document-version:deleted A document version was deleted
Event Description
document-version-signature:requested A signature was requested
document-version-signature:signed A signature was completed
document-version-signature:cancelled A signature request was cancelled
Event Description
document-version-approval-quorum:requested An approval quorum was requested
document-version-approval-quorum:updated An approval quorum was updated
document-version-approval-quorum:approved An approval quorum was approved
document-version-approval-quorum:rejected An approval quorum was rejected
document-version-approval-quorum:voided An approval quorum was voided

Update events and updatedFrom

“Update events and updatedFrom”

For any event *:updated, the useful load includes:

  • data – entity after change
  • updatedFrom – a complete instant picture of the same entity shape before change

Non-update events omit updatedFrom.

The two objects have the same scheme, which makes field-level comparisons secure:

if (event.eventType === "user:updated") {
const oldRole = event.updatedFrom.membership?.role;
const newRole = event.data.membership?.role;
if (oldRole !== newRole) {
await syncAccess(event.data.id, newRole);
}
}

Deleted events carry the last instant image of the resources captured before deletion. Life cycle events such as archiving, publishing, signing and approval carry the resources after that transition.

  • Timestamps are RFC 3339 strings.
  • Resetable values appear as null; fields are not omitted from resource objects.
  • The enum values are uppercase strings such as ACTIVE, PUBLISHED or PENDING.
  • Marks are present even when they are empty.
  • Receptors should ignore the fields they do not recognize so that additive scheme changes remain compatible.

The field data (and updatedFrom when present) contains the resource that triggered the event.

Submitted for events third-party:created, third-party:updated and third-party:deleted.

{
"id": "thp_01DEF456",
"name": "Acme Cloud",
"category": "CLOUD_INFRASTRUCTURE",
"description": "Cloud hosting provider",
"statusPageUrl": "https://status.acme.cloud",
"termsOfServiceUrl": "https://acme.cloud/tos",
"privacyPolicyUrl": "https://acme.cloud/privacy",
"serviceLevelAgreementUrl": "https://acme.cloud/sla",
"dataProcessingAgreementUrl": null,
"businessAssociateAgreementUrl": null,
"subprocessorsListUrl": "https://acme.cloud/subprocessors",
"certifications": ["SOC2", "ISO27001"],
"countries": ["US", "DE"],
"securityPageUrl": "https://acme.cloud/security",
"trustPageUrl": "https://acme.cloud/trust",
"headquarterAddress": "123 Cloud St, San Francisco, CA",
"legalName": "Acme Cloud Inc.",
"websiteUrl": "https://acme.cloud",
"administratorIds": ["usr_01GHI789", "usr_01JKL012"],
"createdAt": "2026-01-05T10:00:00Z",
"updatedAt": "2026-01-05T10:00:00Z"
}
Field Type Description
id string Third party identifier
name string Third party name
category string Category
description string | null Description
statusPageUrl string | null Status page URL
termsOfServiceUrl string | null Terms of service URL
privacyPolicyUrl string | null Privacy policy URL
serviceLevelAgreementUrl string | null SLA URL
dataProcessingAgreementUrl string | null DPA URL
businessAssociateAgreementUrl string | null BAA URL
subprocessorsListUrl string | null Subprocessors list URL
certifications string[] List of certifications
countries string[] Country codes in which the third party operates
securityPageUrl string | null Security page URL
trustPageUrl string | null Trust page URL
headquarterAddress string | null Headquarters address
legalName string | null Legal entity name
websiteUrl string | null Website URL
administratorIds string[] User IDs of third-party administrators
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)

Submitted for events user:created, user:updated and user:deleted.

{
"id": "usr_01GHI789",
"organizationId": "org_01MNO345",
"emailAddress": "jane@example.com",
"fullName": "Jane Doe",
"kind": "EMPLOYEE",
"source": "MANUAL",
"additionalEmailAddresses": ["jane.doe@example.com"],
"position": "Security Engineer",
"contractStartDate": "2024-01-15T00:00:00Z",
"contractEndDate": null,
"createdAt": "2024-01-15T09:00:00Z",
"updatedAt": "2026-02-01T11:00:00Z",
"membership": {
"id": "mem_01ABC123",
"role": "ADMIN",
"state": "ACTIVE"
}
}
Field Type Description
id string User identifier
organizationId string Organization identifier
emailAddress string Primary email address
fullName string Full name
kind string | null User kind (e.g. EMPLOYEE)
source string Profile source (e.g. MANUAL)
additionalEmailAddresses string[] Additional email addresses
position string | null Job position
contractStartDate string | null Contract start date (RFC 3339)
contractEndDate string | null Contract end date (RFC 3339)
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)
membership object | null Membership details when present
membership.id string Membership identifier
membership.role string Membership role
membership.state string Profile/membership state (e.g. ACTIVE)

Submitted for events obligation:created, obligation:updated and obligation:deleted.

{
"id": "obl_01PQR678",
"organizationId": "org_01MNO345",
"area": "Data Protection",
"source": "GDPR",
"requirement": "Maintain records of processing activities",
"actionsToBeImplemented": "Implement ROPA template and quarterly review",
"regulator": "CNIL",
"ownerId": "usr_01GHI789",
"lastReviewDate": "2026-01-01T00:00:00Z",
"dueDate": "2026-06-30T00:00:00Z",
"status": "IN_PROGRESS",
"type": "LEGAL",
"createdAt": "2024-06-01T10:00:00Z",
"updatedAt": "2026-01-15T14:00:00Z"
}
Field Type Description
id string Obligation identifier
organizationId string Organization identifier
area string | null Compliance area
source string | null Regulatory source
requirement string | null Requirement description
actionsToBeImplemented string | null Required actions
regulator string | null Regulatory body
ownerId string Owner user ID
lastReviewDate string | null Last review date (RFC 3339)
dueDate string | null Due date (RFC 3339)
status string Obligation status
type string Obligation type
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)

Submitted for events right-request:created, right-request:updated and right-request:deleted.

{
"id": "rr_01STU901",
"organizationId": "org_01MNO345",
"requestType": "ACCESS",
"requestState": "OPEN",
"dataSubject": "Jane Doe",
"contact": "jane@example.com",
"details": "Please provide a copy of my personal data.",
"deadline": "2026-08-15T00:00:00Z",
"actionTaken": null,
"createdAt": "2026-07-20T10:00:00Z",
"updatedAt": "2026-07-20T10:00:00Z"
}
Field Type Description
id string Rights request identifier
organizationId string Organization identifier
requestType string Type of request (for example ACCESS)
requestState string Current state (e.g. OPEN)
dataSubject string | null Data subject name
contact string | null Contact details
details string | null Request details
deadline string | null Response deadline (RFC 3339)
actionTaken string | null Actions taken
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)

Submitted to document:created, document:updated, document:archived, document:unarchived and document:deleted events.

{
"id": "doc_01VWX234",
"organizationId": "org_01MNO345",
"title": "Information Security Policy",
"documentType": "POLICY",
"status": "ACTIVE",
"compliancePortalVisibility": "PRIVATE",
"currentPublishedMajor": 1,
"currentPublishedMinor": 0,
"archivedAt": null,
"createdAt": "2026-01-10T09:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z"
}
Field Type Description
id string Document identifier
organizationId string Organization identifier
title string Document title
documentType string Document type
status string Document status
compliancePortalVisibility string Visibility on the compliance portal
currentPublishedMajor number | null Current published major version
currentPublishedMinor number | null Current published minor version
archivedAt string | null Archive timestamp (RFC 3339)
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)

Submitted for events ___ZBT_I18N_RUNTIME_BLOCK_343__. Includes the embedded parent ___ZBT_I18N_RUNTIME_BLOCK_344__.

{
"id": "docv_01YZA567",
"documentId": "doc_01VWX234",
"title": "Information Security Policy",
"major": 1,
"minor": 1,
"classification": "INTERNAL",
"documentType": "POLICY",
"changelog": "Updated remote work section",
"status": "DRAFT",
"publishedAt": null,
"createdAt": "2026-07-02T11:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z",
"document": {
"id": "doc_01VWX234",
"organizationId": "org_01MNO345",
"title": "Information Security Policy",
"documentType": "POLICY",
"status": "ACTIVE",
"compliancePortalVisibility": "PRIVATE",
"currentPublishedMajor": 1,
"currentPublishedMinor": 0,
"archivedAt": null,
"createdAt": "2026-01-10T09:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z"
}
}
Field Type Description
id string Document version identifier
documentId string Parent document identifier
title string Version title
major number Major version number
minor number Minor version number
classification string Document classification enum
documentType string Document type enum
changelog string Description of changes
status string Version status enum
publishedAt string | null Publication timestamp (RFC 3339)
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)
document object Parent document snapshot

Reference for events document-version-signature:*. Includes embedded version (with document).

{
"id": "docs_01BCD890",
"documentVersionId": "docv_01YZA567",
"state": "REQUESTED",
"signedBy": "usr_01GHI789",
"signedAt": null,
"requestedAt": "2026-07-02T12:00:00Z",
"createdAt": "2026-07-02T12:00:00Z",
"updatedAt": "2026-07-02T12:00:00Z",
"version": {
"id": "docv_01YZA567",
"documentId": "doc_01VWX234",
"title": "Information Security Policy",
"major": 1,
"minor": 1,
"classification": "INTERNAL",
"documentType": "POLICY",
"changelog": "Updated remote work section",
"status": "DRAFT",
"publishedAt": null,
"createdAt": "2026-07-02T11:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z",
"document": {
"id": "doc_01VWX234",
"organizationId": "org_01MNO345",
"title": "Information Security Policy",
"documentType": "POLICY",
"status": "ACTIVE",
"compliancePortalVisibility": "PRIVATE",
"currentPublishedMajor": 1,
"currentPublishedMinor": 0,
"archivedAt": null,
"createdAt": "2026-01-10T09:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z"
}
}
}
Field Type Description
id string Signature identifier
documentVersionId string Document version identifier
state string Signature state
signedBy string ID-ul utilizatorului semnatarului
signedAt string | null When the document was signed
requestedAt string When the signature was requested
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)
version object Nested document version snapshot

Reference for events document-version-approval-quorum:*. Includes decisions and embedded version.

{
"id": "daq_01EFG123",
"versionId": "docv_01YZA567",
"status": "PENDING",
"createdAt": "2026-07-02T13:00:00Z",
"updatedAt": "2026-07-02T13:00:00Z",
"decisions": [
{
"id": "dad_01HIJ456",
"approverId": "usr_01GHI789",
"state": "PENDING",
"comment": null,
"decidedAt": null,
"createdAt": "2026-07-02T13:00:00Z",
"updatedAt": "2026-07-02T13:00:00Z"
}
],
"version": {
"id": "docv_01YZA567",
"documentId": "doc_01VWX234",
"title": "Information Security Policy",
"major": 1,
"minor": 1,
"classification": "INTERNAL",
"documentType": "POLICY",
"changelog": "Updated remote work section",
"status": "DRAFT",
"publishedAt": null,
"createdAt": "2026-07-02T11:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z",
"document": {
"id": "doc_01VWX234",
"organizationId": "org_01MNO345",
"title": "Information Security Policy",
"documentType": "POLICY",
"status": "ACTIVE",
"compliancePortalVisibility": "PRIVATE",
"currentPublishedMajor": 1,
"currentPublishedMinor": 0,
"archivedAt": null,
"createdAt": "2026-01-10T09:00:00Z",
"updatedAt": "2026-07-02T11:00:00Z"
}
}
}
Field Type Description
id string Approval quorum identifier
versionId string Document version identifier
status string Quorum status
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)
decisions object[] One decision object per approver
version object Nested document version snapshot

Each element in decisions has this shape:

Field Type Description
id string Approval decision identifier
approverId string Approver user identifier
state string Decision state enum
comment string | null Comentariu furnizat de aprobat
decidedAt string | null Decision timestamp (RFC 3339)
createdAt string Creation timestamp (RFC 3339)
updatedAt string Last update timestamp (RFC 3339)

Ultima actualizare: