Webhooks & Event Streaming

When payroll finalizes or a permit's about to expire, your other systems hear about it — automatically

HumanR pushes its own events out to wherever your operation already watches — a Slack channel, a Teams connector, or your own systems over signed webhooks. A payroll run finalizes, an approval is decided, a permit is weeks from expiring: the notification lands in the channel your team lives in, with nobody logging in to check and nothing polling on a timer.

See it live — demo in minutes →

Sound familiar?

The finance channel finds out payroll was finalized when someone remembers to mention it

Permit and visa expiries sit in HumanR, but the group chat where work actually gets chased never hears them

Wiring HumanR to an internal system means someone building a poller — or, in practice, nothing at all

Every 'has the run finalized yet?' is a message to the payroll officer instead of an automatic ping

Capabilities

What you get

7 capabilities

Slack and Teams out of the box

Point an endpoint at a Slack or Microsoft Teams incoming webhook and events arrive as readable cards. The URL is the only credential and there is no code to write — paste it, tick the events, done.

Subscribe to the events that matter

Payroll runs finalizing and reopening, approval decisions, and document, permit, contract and probation expiries. Subscribe to one event, a whole family like approval.*, or everything — per company in a multi-company install.

Signed webhooks for your own systems

The generic format POSTs a canonical JSON envelope signed with HMAC-SHA256, so your receiver can prove the event came from HumanR and wasn't spoofed. Works with Zapier, Make, n8n or anything that accepts an HTTP POST.

At-least-once, safe to dedupe

Every event carries a stable id that survives retries, so a consumer can recognise and drop a duplicate. Failed deliveries retry on a backoff ladder — 1m, 5m, 30m, then hours — instead of hammering your endpoint.

A delivery log you can actually debug

Every attempt is recorded with the HTTP status it got back and the error when it failed. Fix the far end, then retry a specific delivery by hand — dead deliveries are kept 30 days with their error rather than vanishing.

Rotate secrets without dropping events

Rotate an endpoint's signing secret and the previous one keeps verifying through an overlap window, so a consumer rolls over on its own schedule without losing a single delivery.

Locked down because it points outward

Endpoints are HTTPS-only and re-checked against a private-network blocklist at send time, not just at save. Configuring one needs a dedicated permission withheld from the HR and demo roles, and events carrying pay data are a sensitive, logged read — an endpoint aims payroll data at the outside world, and it's treated that way.

Delivered wherever your team already watches

Slack and Teams take an incoming-webhook URL and render events as cards — no code. Anything else receives a signed JSON POST, which is what makes Zapier, Make, n8n or your own service a receiver without a purpose-built connector.

Slack
Chat app
Microsoft Teams
Chat app
Any HTTPS endpoint
Signed HTTP

Everything HumanR connects to, in and out →

Straight from the product

Real screens from the demo company — the same system your login opens.

HumanR webhook endpoints — a Slack, a Teams and a signed Generic endpoint, each subscribed to its own events with delivery health
Point HumanR at as many endpoints as you like — Slack and Teams get a formatted card, Generic sends signed JSON that Zapier, Make, n8n or your own code can read. Each one subscribes to just the events it cares about, and every endpoint shows its own delivery health at a glance.
HumanR webhook delivery log — one row per event with status, HTTP code, retry count and last error, including a parked failure with a Retry button
The delivery log is the receipt: every event, the HTTP response it got, and how many tries it took. A failure retries on a 1m→5m→30m→2h→6h ladder and parks after five attempts — nothing is silently dropped, and you can replay any row by hand.

Questions

Do we need a developer to use this?

For Slack or Teams, no — paste the incoming-webhook URL, choose the events, and cards start arriving. Signed webhooks into your own systems are for teams with a developer or a Zapier/Make/n8n account; the payload is documented and version-stamped so a consumer isn't guessing.

What events can we subscribe to?

Payroll runs finalizing and reopening, approval decisions, and document, permit, contract and probation expiries. Subscribe to a single event, a family like approval.* , or everything with a wildcard — and scope an endpoint to one company if you run several.

What happens if our endpoint is down?

Deliveries retry on a backoff ladder — a minute, then five, then thirty, then hours — and park with their error for 30 days rather than disappearing. An endpoint that fails 20 times in a row is disabled automatically, with a log entry saying so, so a decommissioned URL doesn't quietly burn the queue.

Is the payroll data in these events secure?

Endpoints are HTTPS-only and re-validated against a private-range blocklist at send time, the body is signed with a rotatable HMAC secret that is encrypted at rest, and the permission to add an endpoint is kept away from the HR and demo roles. Payloads that carry pay figures are a sensitive read, logged like any other.

Jionee mwenyewe kwa data inayofanana na yako

Omba demo na tutakutumia kwa barua pepe akaunti yako binafsi ya kuingia katika kampuni ya mfano iliyojaa data — chunguza skrini halisi zenye data ya kweli ndani ya dakika chache.

Hakuna kadi ya mkopo. Hakuna simu ya mauzo. Akaunti halisi ya kuingia, inayotumwa kwa barua pepe.