Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Start your demo
Log in Start your demo
← Docs
← All documentation

Webhook events

Every event your endpoint can subscribe to. Backsplice POSTs a signed JSON body ({ event, timestamp, payload }) for each subscribed event; verify the X-Backsplice-Signature header (HMAC-SHA256 of the raw body with your secret). For 24 hours after you rotate a secret, each delivery also carries X-Backsplice-Signature-Previous, the same body signed with the superseded secret — accept either during that window, then drop the old one. Failed deliveries retry with backoff and can be replayed from Settings → Webhooks.

AI governance

EventFires when
ai_system.proposed An AI system was proposed for the registry (from the page, the API or MCP).
approval.decided A review of an AI system closed with its outcome (approved, approved with conditions, rejected, sent back or withdrawn).
approval.expiring An AI system's approval reaches its review date within 30 days, when a re-review opens (ai-rereview cron; once per approval).
model_version.registered A new version of an AI model was recorded (from the page or the API).
metric.threshold_breached A deployed system's reported metric crossed its breach threshold (once per crossing, from POST /api/v1/metrics).

Assessments

EventFires when
assessment.completed An assessment was marked complete.
assessment.archived An assessment was archived.

Findings

EventFires when
finding.status_changed A finding moved between statuses (open → resolved, etc.).
finding.risk_changed A finding's risk level changed.

Incidents

EventFires when
incident.created An incident was created.
incident.escalated An incident was escalated.
incident.closed An incident was closed.

Policies

EventFires when
policy.published A policy was published.
policy.reviewed A policy was reviewed.

Members

EventFires when
member.invited A team member was invited.
member.removed A team member was removed.

Evidence

EventFires when
evidence.uploaded Evidence was uploaded.
evidence.deleted Evidence was deleted.

Remediation

EventFires when
remediation.completed A remediation task was completed.
remediation.approval_pending A remediation task has been awaiting approval past its SLA.

Deadlines

EventFires when
risk.overdue A risk treatment passed its due date (risk-sla cron).
evidence.review_due Evidence reached its review date (evidence-review cron).
access_review.overdue An access review passed its due date (access-review-sla cron).
vendor.questionnaire_overdue A vendor questionnaire passed its due date unanswered (questionnaire-sla cron).
Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile)

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.