Workhuman Change Ingestion and Event Governance
Overview
Choose the least risky supported delivery mode and make authenticity, duplicates, ordering, replay, privacy, reconciliation, and fallback explicit.
Prerequisites
- A defined business transition, source of truth, freshness target, expected volume, and downstream owner
- Current tenant documentation for managed integrations, events, APIs, reports, or exports
- Data classification, retention, capacity, incident, and recovery requirements
Tool Discipline
Use Read, Glob, and Grep to inspect consumers and schemas, WebFetch for current first-party and tenant contracts, and Write or Edit for ingestion code, fixtures, mappings, and redacted receipts.
Current Contract
Workhuman publicly confirms managed integrations and an open API but does not publish a universal webhook registration route, event catalogue, signature header, or retry schedule on the cited pages. Treat webhook delivery as unavailable until customer-authorized documentation defines it.
Authentication
For documented push delivery, use the exact authenticity mechanism and secret lifecycle in the customer contract. For polling, reports, exports, or connectors, use a least-privilege authorized principal. Never invent an HMAC header or accept unauthenticated events.
Instructions
- Define transition, required fields, allowed delay, source authority, privacy class, and downstream mutation.
- Inventory supported modes: managed connector, documented event delivery, incremental read, scheduled report or export, and approved manual handoff.
- Select by supportability, authenticity, freshness, replay, observability, capacity, privacy, and cost—not a preference for webhooks.
- Freeze schemas and define stable identity, deduplication, ordering assumptions, checkpoints, effective dates, and deletion behavior.
- Implement validate-before-acknowledge, quarantine, bounded retry, dead-letter handling, and authoritative reconciliation.
- Test valid, invalid, duplicate, late, out-of-order, missing-field, replay, revoked-auth, outage, and partial cases with synthetic fixtures.
- Present endpoint, schedule, connector, or subscription changes with exposure, owner, rollback, secret plan, and approval.
- Canary the approved mode, reconcile it to the authority, and retain only redacted operational evidence.
Approval Boundaries
Do not expose an endpoint, create a subscription, enable a connector, poll production, replay messages, or mutate downstream records without named owners.
Output
Return the selected mode and evidence, frozen schema, auth plan, deduplication and ordering policy, failure tests, mutation preview, canary reconciliation, and fallback.
Error Handling
| Condition | Response |
|---|---|
| Webhook contract is not documented | Use an approved connector, polling, report, export, or manual pattern; do not fabricate one. |
| Authenticity validation fails | Reject and quarantine without downstream mutation. |
| Checkpoint and source disagree | Stop advancement, reconcile the window, and preserve replay evidence. |
Example
A redacted completion receipt might look like this:
use-case=award-to-payroll; mode=managed-workday; freshness=scheduled; dedupe=source-id-plus-version; failure-fixtures=10-pass; reconciliation=exact
Resources
Next Steps
Review the selected delivery mode whenever tenant capabilities, downstream authority, or freshness requirements change.