CloudSignLab

Help centerTeam, packages and account

Connect Slack, Teams, webhooks and the API

Send events to Slack, Microsoft Teams or your own systems, and read your registers with read-only API keys.

Updated September 29, 2026

In this section: Team, packages and account

Integrations brings CloudSignLab events to the tools your team already uses, and lets your own systems read your registers. It is for owners and admins and is included from the Professional package.

Messages and webhooks

  1. Open Integrations in the organization menu.
  2. Under Messages and webhooks, choose Where:
  3. Enter a Name and paste the Address (https).
  4. Tick the Events: Incident reported, Risk added, Policy published, Audit finding recorded, Task created, Supplier check answered, Supplier check decided.
  5. Click Add, then Send test to check it arrives.

Addresses are stored encrypted. Only https addresses of the chosen service are accepted, without IP addresses or ports. You can switch each integration on or off. After 20 failed deliveries in a row it stops until you switch it on again.

Checking webhook signatures

Every webhook is signed. The signing secret is shown once, right after saving. Each request has the headers X-CloudSignLab-Timestamp and X-CloudSignLab-Signature: a sha256 HMAC of "timestamp.body" with your secret. The body holds ids and a link, no personal data.

API keys

  1. Under API keys, enter a name, for example Power BI, and click Create key.
  2. Copy the key now. It is shown only once; afterwards you only see when it was last used.
  3. Click Revoke when a key is no longer needed.

Keys are read-only and belong to the organization. You can have up to 10 active keys, and up to 300 requests per 10 minutes. The API reads the organization, risks, controls, incidents, suppliers (without contact details) and published policies. The full documentation is on the public page /developers.

Tips

  • Give each system its own key, so you can revoke one without breaking the others.

The events also include Automatic check failing. Under Where you can also choose Jira or ServiceNow. An organization can have at most 10 integrations.

See also