Webhook Event Types
Reference for each type of platform webhook event and the form of the useful data load, covering third parties, users, obligations and document life cycle.
This reference maps each event name to the exact object delivered in data. Events cover third parties, users, obligations, rights claims and the entire document life cycle. Frameworks, controls, measures, risks, access reviews, devices and cookie consent do not emit webhook events - useGraphQL, CLI,MCPsaun8for these areas. What webhooks cover.
Webhook organizations and the X-Probo-Webhook-Event header use lower source names, such as third-party:created. The console nodeAPI, CLI and CLI8nutrices higher entity names, such as THIRD_PARTY_CREATED.
Each delivery wraps the useful load of resources into a root package (eventId, subscriptionId, organizationId, createdAt, data, and optional updatedFrom) and the setting of corresponding HTTP titles. Webhooks Overview The following sections describe only embedded resource forms data / updatedFrom.
Available events
Section entitled “Available events”Third party
Section entitled “Third Party”| Event | Description |
|---|---|
third-party:created |
A third party was created |
third-party:updated |
A third party was updated |
third-party:deleted |
A third party was deleted |
| Event | Description |
|---|---|
user:created |
A user was created |
user:updated |
A user was updated |
user:deleted |
A user was deleted |
Obligation
Section entitled ‘Obligation’| Event | Description |
|---|---|
obligation:created |
An obligation was created |
obligation:updated |
An obligation was updated |
obligation:deleted |
An obligation was deleted |
Rights request
Section entitled “Rights request”| Event | Description |
|---|---|
right-request:created |
A data subject rights request was created |
right-request:updated |
A data subject rights request was updated |
right-request:deleted |
A data subject rights request was deleted |
Document
Section entitled ‘Document’| Event | Description |
|---|---|
document:created |
A document was created |
document:updated |
A document was updated |
document:archived |
A document was archived |
document:unarchived |
A document was unarchived |
document:deleted |
A document was deleted |
Document version
Section entitled “Document version”| Event | Description |
|---|---|
document-version:created |
A document version was created |
document-version:updated |
A document version was updated |
document-version:published |
A document version was published |
document-version:rejected |
A document version was rejected |
document-version:deleted |
A document version was deleted |
Document version signature
Section entitled “Document version signature”| Event | Description |
|---|---|
document-version-signature:requested |
A signature was requested |
document-version-signature:signed |
A signature was completed |
document-version-signature:cancelled |
A signature request was cancelled |
Document version approval quorum
Section entitled ‘Document version approval quorum’| Event | Description |
|---|---|
document-version-approval-quorum:requested |
An approval quorum was requested |
document-version-approval-quorum:updated |
An approval quorum was updated |
document-version-approval-quorum:approved |
An approval quorum was approved |
document-version-approval-quorum:rejected |
An approval quorum was rejected |
document-version-approval-quorum:voided |
An approval quorum was voided |
Update events and updatedFrom
“Update events and updatedFrom”For any event *:updated, the useful load includes:
data– entity after changeupdatedFrom– a complete instant picture of the same entity shape before change
Non-update events omit updatedFrom.
The two objects have the same scheme, which makes field-level comparisons secure:
if (event.eventType === "user:updated") { const oldRole = event.updatedFrom.membership?.role; const newRole = event.data.membership?.role;
if (oldRole !== newRole) { await syncAccess(event.data.id, newRole); }}Deleted events carry the last instant image of the resources captured before deletion. Life cycle events such as archiving, publishing, signing and approval carry the resources after that transition.
Compatibility
Section entitled ‘Compatibility’- Timestamps are RFC 3339 strings.
- Resetable values appear as
null; fields are not omitted from resource objects. - The enum values are uppercase strings such as
ACTIVE,PUBLISHEDorPENDING. - Marks are present even when they are empty.
- Receptors should ignore the fields they do not recognize so that additive scheme changes remain compatible.
Payload structures
Section entitled ‘Payload structures’The field data (and updatedFrom when present) contains the resource that triggered the event.
Third party
Section entitled “Third Party”Submitted for events third-party:created, third-party:updated and third-party:deleted.
{ "id": "thp_01DEF456", "name": "Acme Cloud", "category": "CLOUD_INFRASTRUCTURE", "description": "Cloud hosting provider", "statusPageUrl": "https://status.acme.cloud", "termsOfServiceUrl": "https://acme.cloud/tos", "privacyPolicyUrl": "https://acme.cloud/privacy", "serviceLevelAgreementUrl": "https://acme.cloud/sla", "dataProcessingAgreementUrl": null, "businessAssociateAgreementUrl": null, "subprocessorsListUrl": "https://acme.cloud/subprocessors", "certifications": ["SOC2", "ISO27001"], "countries": ["US", "DE"], "securityPageUrl": "https://acme.cloud/security", "trustPageUrl": "https://acme.cloud/trust", "headquarterAddress": "123 Cloud St, San Francisco, CA", "legalName": "Acme Cloud Inc.", "websiteUrl": "https://acme.cloud", "administratorIds": ["usr_01GHI789", "usr_01JKL012"], "createdAt": "2026-01-05T10:00:00Z", "updatedAt": "2026-01-05T10:00:00Z"}| Field | Type | Description |
|---|---|---|
id |
string | Third party identifier |
name |
string | Third party name |
category |
string | Category |
description |
string | null | Description |
statusPageUrl |
string | null | Status page URL |
termsOfServiceUrl |
string | null | Terms of service URL |
privacyPolicyUrl |
string | null | Privacy policy URL |
serviceLevelAgreementUrl |
string | null | SLA URL |
dataProcessingAgreementUrl |
string | null | DPA URL |
businessAssociateAgreementUrl |
string | null | BAA URL |
subprocessorsListUrl |
string | null | Subprocessors list URL |
certifications |
string[] | List of certifications |
countries |
string[] | Country codes in which the third party operates |
securityPageUrl |
string | null | Security page URL |
trustPageUrl |
string | null | Trust page URL |
headquarterAddress |
string | null | Headquarters address |
legalName |
string | null | Legal entity name |
websiteUrl |
string | null | Website URL |
administratorIds |
string[] | User IDs of third-party administrators |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
Submitted for events user:created, user:updated and user:deleted.
{ "id": "usr_01GHI789", "organizationId": "org_01MNO345", "emailAddress": "jane@example.com", "fullName": "Jane Doe", "kind": "EMPLOYEE", "source": "MANUAL", "additionalEmailAddresses": ["jane.doe@example.com"], "position": "Security Engineer", "contractStartDate": "2024-01-15T00:00:00Z", "contractEndDate": null, "createdAt": "2024-01-15T09:00:00Z", "updatedAt": "2026-02-01T11:00:00Z", "membership": { "id": "mem_01ABC123", "role": "ADMIN", "state": "ACTIVE" }}| Field | Type | Description |
|---|---|---|
id |
string | User identifier |
organizationId |
string | Organization identifier |
emailAddress |
string | Primary email address |
fullName |
string | Full name |
kind |
string | null | User kind (e.g. EMPLOYEE) |
source |
string | Profile source (e.g. MANUAL) |
additionalEmailAddresses |
string[] | Additional email addresses |
position |
string | null | Job position |
contractStartDate |
string | null | Contract start date (RFC 3339) |
contractEndDate |
string | null | Contract end date (RFC 3339) |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
membership |
object | null | Membership details when present |
membership.id |
string | Membership identifier |
membership.role |
string | Membership role |
membership.state |
string | Profile/membership state (e.g. ACTIVE) |
Obligation
Section entitled ‘Obligation’Submitted for events obligation:created, obligation:updated and obligation:deleted.
{ "id": "obl_01PQR678", "organizationId": "org_01MNO345", "area": "Data Protection", "source": "GDPR", "requirement": "Maintain records of processing activities", "actionsToBeImplemented": "Implement ROPA template and quarterly review", "regulator": "CNIL", "ownerId": "usr_01GHI789", "lastReviewDate": "2026-01-01T00:00:00Z", "dueDate": "2026-06-30T00:00:00Z", "status": "IN_PROGRESS", "type": "LEGAL", "createdAt": "2024-06-01T10:00:00Z", "updatedAt": "2026-01-15T14:00:00Z"}| Field | Type | Description |
|---|---|---|
id |
string | Obligation identifier |
organizationId |
string | Organization identifier |
area |
string | null | Compliance area |
source |
string | null | Regulatory source |
requirement |
string | null | Requirement description |
actionsToBeImplemented |
string | null | Required actions |
regulator |
string | null | Regulatory body |
ownerId |
string | Owner user ID |
lastReviewDate |
string | null | Last review date (RFC 3339) |
dueDate |
string | null | Due date (RFC 3339) |
status |
string | Obligation status |
type |
string | Obligation type |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
Rights request
Section entitled “Rights request”Submitted for events right-request:created, right-request:updated and right-request:deleted.
{ "id": "rr_01STU901", "organizationId": "org_01MNO345", "requestType": "ACCESS", "requestState": "OPEN", "dataSubject": "Jane Doe", "contact": "jane@example.com", "details": "Please provide a copy of my personal data.", "deadline": "2026-08-15T00:00:00Z", "actionTaken": null, "createdAt": "2026-07-20T10:00:00Z", "updatedAt": "2026-07-20T10:00:00Z"}| Field | Type | Description |
|---|---|---|
id |
string | Rights request identifier |
organizationId |
string | Organization identifier |
requestType |
string | Type of request (for example ACCESS) |
requestState |
string | Current state (e.g. OPEN) |
dataSubject |
string | null | Data subject name |
contact |
string | null | Contact details |
details |
string | null | Request details |
deadline |
string | null | Response deadline (RFC 3339) |
actionTaken |
string | null | Actions taken |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
Document
Section entitled ‘Document’Submitted to document:created, document:updated, document:archived, document:unarchived and document:deleted events.
{ "id": "doc_01VWX234", "organizationId": "org_01MNO345", "title": "Information Security Policy", "documentType": "POLICY", "status": "ACTIVE", "compliancePortalVisibility": "PRIVATE", "currentPublishedMajor": 1, "currentPublishedMinor": 0, "archivedAt": null, "createdAt": "2026-01-10T09:00:00Z", "updatedAt": "2026-07-02T11:00:00Z"}| Field | Type | Description |
|---|---|---|
id |
string | Document identifier |
organizationId |
string | Organization identifier |
title |
string | Document title |
documentType |
string | Document type |
status |
string | Document status |
compliancePortalVisibility |
string | Visibility on the compliance portal |
currentPublishedMajor |
number | null | Current published major version |
currentPublishedMinor |
number | null | Current published minor version |
archivedAt |
string | null | Archive timestamp (RFC 3339) |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
Document version
Section entitled “Document version”Submitted for events ___ZBT_I18N_RUNTIME_BLOCK_343__. Includes the embedded parent ___ZBT_I18N_RUNTIME_BLOCK_344__.
{ "id": "docv_01YZA567", "documentId": "doc_01VWX234", "title": "Information Security Policy", "major": 1, "minor": 1, "classification": "INTERNAL", "documentType": "POLICY", "changelog": "Updated remote work section", "status": "DRAFT", "publishedAt": null, "createdAt": "2026-07-02T11:00:00Z", "updatedAt": "2026-07-02T11:00:00Z", "document": { "id": "doc_01VWX234", "organizationId": "org_01MNO345", "title": "Information Security Policy", "documentType": "POLICY", "status": "ACTIVE", "compliancePortalVisibility": "PRIVATE", "currentPublishedMajor": 1, "currentPublishedMinor": 0, "archivedAt": null, "createdAt": "2026-01-10T09:00:00Z", "updatedAt": "2026-07-02T11:00:00Z" }}| Field | Type | Description |
|---|---|---|
id |
string | Document version identifier |
documentId |
string | Parent document identifier |
title |
string | Version title |
major |
number | Major version number |
minor |
number | Minor version number |
classification |
string | Document classification enum |
documentType |
string | Document type enum |
changelog |
string | Description of changes |
status |
string | Version status enum |
publishedAt |
string | null | Publication timestamp (RFC 3339) |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
document |
object | Parent document snapshot |
Document version signature
Section entitled “Document version signature”Reference for events document-version-signature:*. Includes embedded version (with document).
{ "id": "docs_01BCD890", "documentVersionId": "docv_01YZA567", "state": "REQUESTED", "signedBy": "usr_01GHI789", "signedAt": null, "requestedAt": "2026-07-02T12:00:00Z", "createdAt": "2026-07-02T12:00:00Z", "updatedAt": "2026-07-02T12:00:00Z", "version": { "id": "docv_01YZA567", "documentId": "doc_01VWX234", "title": "Information Security Policy", "major": 1, "minor": 1, "classification": "INTERNAL", "documentType": "POLICY", "changelog": "Updated remote work section", "status": "DRAFT", "publishedAt": null, "createdAt": "2026-07-02T11:00:00Z", "updatedAt": "2026-07-02T11:00:00Z", "document": { "id": "doc_01VWX234", "organizationId": "org_01MNO345", "title": "Information Security Policy", "documentType": "POLICY", "status": "ACTIVE", "compliancePortalVisibility": "PRIVATE", "currentPublishedMajor": 1, "currentPublishedMinor": 0, "archivedAt": null, "createdAt": "2026-01-10T09:00:00Z", "updatedAt": "2026-07-02T11:00:00Z" } }}| Field | Type | Description |
|---|---|---|
id |
string | Signature identifier |
documentVersionId |
string | Document version identifier |
state |
string | Signature state |
signedBy |
string | ID-ul utilizatorului semnatarului |
signedAt |
string | null | When the document was signed |
requestedAt |
string | When the signature was requested |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
version |
object | Nested document version snapshot |
Document version approval quorum
Section entitled ‘Document version approval quorum’Reference for events document-version-approval-quorum:*. Includes decisions and embedded version.
{ "id": "daq_01EFG123", "versionId": "docv_01YZA567", "status": "PENDING", "createdAt": "2026-07-02T13:00:00Z", "updatedAt": "2026-07-02T13:00:00Z", "decisions": [ { "id": "dad_01HIJ456", "approverId": "usr_01GHI789", "state": "PENDING", "comment": null, "decidedAt": null, "createdAt": "2026-07-02T13:00:00Z", "updatedAt": "2026-07-02T13:00:00Z" } ], "version": { "id": "docv_01YZA567", "documentId": "doc_01VWX234", "title": "Information Security Policy", "major": 1, "minor": 1, "classification": "INTERNAL", "documentType": "POLICY", "changelog": "Updated remote work section", "status": "DRAFT", "publishedAt": null, "createdAt": "2026-07-02T11:00:00Z", "updatedAt": "2026-07-02T11:00:00Z", "document": { "id": "doc_01VWX234", "organizationId": "org_01MNO345", "title": "Information Security Policy", "documentType": "POLICY", "status": "ACTIVE", "compliancePortalVisibility": "PRIVATE", "currentPublishedMajor": 1, "currentPublishedMinor": 0, "archivedAt": null, "createdAt": "2026-01-10T09:00:00Z", "updatedAt": "2026-07-02T11:00:00Z" } }}| Field | Type | Description |
|---|---|---|
id |
string | Approval quorum identifier |
versionId |
string | Document version identifier |
status |
string | Quorum status |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |
decisions |
object[] | One decision object per approver |
version |
object | Nested document version snapshot |
Each element in decisions has this shape:
| Field | Type | Description |
|---|---|---|
id |
string | Approval decision identifier |
approverId |
string | Approver user identifier |
state |
string | Decision state enum |
comment |
string | null | Comentariu furnizat de aprobat |
decidedAt |
string | null | Decision timestamp (RFC 3339) |
createdAt |
string | Creation timestamp (RFC 3339) |
updatedAt |
string | Last update timestamp (RFC 3339) |