event_types: [] (none) — explicit per-event opt-in
is required. See Create a webhook endpoint.
Integrity (AIP)
Fired from the gateway’s per-turn integrity analysis.integrity.checkpoint
Fired on every AIP analysis run, regardless of verdict. Subscribe here for a complete audit
trail; subscribe to integrity.violation instead if you only want to page on violations.
integrity.violation
Fired when AIP analysis returns a boundary_violation verdict. A companion integrity.checkpoint
always fires for the same checkpoint — this event is a filtered subset of it.
conscience.escalation
Fired when AIP analysis detects a conscience-value conflict in agent reasoning beyond a routine
boundary check.
conscience.values_updated
Fired when an org owner/admin creates, updates, or removes an org-level conscience value.
Alignment traces (AAP)
Fired when an AAP alignment trace is verified.trace.created
trace.verified
Fired when a trace passes verification (signature, chain, and boundary checks).
trace.failed
Fired when a trace fails verification — signature mismatch, chain break, or boundary violation.
trace.escalation_required
policy.violation
Fired when policy evaluation flags a violation in agent behavior.
Drift & team coherence
Cross-turn and cross-team detector firings. These are operator-actionable signals — the agent itself never sees them.sideband.drift.fired
Fired when N consecutive non-clear AIP verdicts in a session cross the configured drift threshold.
drift.resolved
Fired when an org owner/admin acknowledges a previously-fired drift alert. Companion to sideband.drift.fired.
sideband.coherence.fired
Fired when a team’s pairwise governance floor drops below threshold, conflict edges exceed
threshold, or specific agents’ declared values diverge from the rest of the team.
sideband.fault_line.fired
Fired when team fault-line analysis detects a minority of agents whose alignment cards diverge
from the team majority.
sideband.fleet.fired
Fired when team-topology analysis detects outlier agents, a cluster partition, or a pair score
below threshold across a team.
Safe House
Fired by the Safe House front door and the review workflow. See Safe House Threat Model for what each verdict means. Ansh.evaluation.* event is emitted per screened surface, not per turn — one request can
emit several (the inbound message, plus each tool result screened before the model sees it).
sh.evaluation.warn
sh.evaluation.quarantine
sh.evaluation.block
sh.canary.triggered
Fired when a planted canary credential appears in agent output or input — a strong signal of
active exploitation.
sh.session.escalated
Fired when a session’s accumulated risk score crosses an escalation threshold.
sh.campaign.detected
Fired when cross-session correlation detects a coordinated attack targeting your agents.
sh.review.triggered
Fired when a quarantine-band verdict raises a review hold — the conversation is held pending
adjudication.
sh.review.approved
Fired when a reviewer releases a held item — it proceeds.
sh.review.denied
Fired when a reviewer denies a held item — a transparent refusal is applied in its place.
sh.review.expired
Fired when a review hold reaches its SLA deadline unresolved. The card’s configured
on_timeout default applies (fail-closed reject unless configured otherwise).
Detection reports
recipe.candidate.created
Fired when your org submits a false-negative/false-positive report on a detection recipe (or
Mnemom’s own arena tooling proposes one). Delivered to your org’s own webhook endpoints when
you’re the reporting org, alongside Mnemom’s internal review queue.
The recipe lifecycle events that follow a candidate’s triage —
recipe.promoted, recipe.retired, advisory.published, ioc.added,
network.campaign.closed, and reviewer-mode.changed — are internal Mnemom
operations events today (delivered only to Mnemom’s own account, never to a
customer org), so they aren’t in this catalog. Poll
Intelligence Overview for advisories
and indicators instead.Agent lifecycle
agent.paused / agent.resumed / agent.killed
Fired when an org owner/admin (or auto-containment) changes an agent’s containment status.
killed is stronger than paused — reactivation requires explicit operator action.
agent.exemption.granted / agent.exemption.revoked
Fired when an org admin grants or revokes a temporary exemption from a Safe House section for
a specific agent.
Governance (cards & templates)
alignment_card.updated / protection_card.updated
Fired when an agent’s alignment or protection card is updated.
org_alignment_template.updated / org_alignment_template.deleted
Fired when an org-scope alignment template is set, updated, or cleared — this triggers a
recompose for every agent inheriting from the template.
org_protection_template.updated / org_protection_template.deleted
Same shape as the alignment-template events above, for the protection template.
Teams
team.created / team.archived
team.member_added / team.member_removed
team.card_updated
Fired when a team’s alignment- or protection-template card is set, updated, or cleared.
Reputation
reputation.score_changed
Fired when an agent’s reputation score crosses a meaningful threshold.
reputation.grade_changed
Fired when an agent crosses a reputation-grade boundary.
Quota & billing
quota.warning / quota.exceeded
Fired once per billing period when integrity-check usage crosses 80% / 100% of your usage
budget.
quota.risk_warning / quota.risk_exceeded
Same shape, for risk-assessment usage.
quota.team_reputation_warning / quota.team_reputation_exceeded
Same shape, for team-reputation computation usage.
quota.sh_warning
Fired when Safe House usage cost for the period crosses your configured budget alert threshold.
subscription.status_changed
Fired when your billing subscription transitions state (e.g. active → past_due).
transaction.completed
Fired when a billed autonomous-operation transaction completes.
See also
- Webhook Notifications — creating endpoints, signature verification, retries, and the CLI.
- Safe House Threat Model — what each Safe House verdict means.
- Intelligence Overview — the pull-side threat-intelligence feed (advisories and indicators aren’t delivered as customer webhooks today; poll the feed endpoints instead).