Record real security incidents that occur outside of Whalemate simulations (received phishing, compromised credentials, suspicious clicks, etc.).
Keep the Human Risk Score updated with what happens in the real world, not just in training exercises.
Centralize each employee's security history in one place within the platform.
Integrate external tools (SIEM, EDR, detection systems) with Whalemate's risk data.
Events are recorded through the Whalemate API. For each event you need to indicate:
Title — short description of the incident
Employee email — must belong to your organization
Severity — low (counted as a click) or high (counted as credential compromise)
Description — optional, to add additional context
Once recorded, the event immediately impacts the employee's Human Risk Score. Viewing the event on the individual profile will be available soon. If this feature is a priority for your organization, you can request it at roadmap.whalemate.com/roadmap
The employee's email must belong to your organization. It is not possible to record events for employees of other companies.
Impact on the Human Risk Score:
Severity | How it impacts |
|---|---|
| Processed as a click on a simulation |
| Processed as credential compromise |
For the technical integration documentation (authentication, endpoint, code examples), see the Integration Guide: Custom Events API.
When do I use severity low and when high?
Use low for low-impact incidents (clicking a suspicious link, opening a dubious email). Use high for critical incidents (compromised credentials, malware download, unauthorized access).
Do custom events affect the score the same way as simulation events?
Yes. The system processes them with the same logic: low is equivalent to a click and high is equivalent to a credential compromise.
Can I record events in bulk for several employees at once?
The current endpoint processes one event per call. Batch registration will be available soon. If this is a priority for your organization, you can request it at roadmap.whalemate.com/roadmap
Do I need special permissions to use this feature?
Yes, you need a company API Key. You can generate it from Settings → General → API Keys → Active Keys.
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap