Normalize risk event
Risk Signals
Normalize Identity Event
Submit a raw identity event for automatic normalization into a risk signal. The normalization layer maps platform events to standardized signal types with pre-calibrated risk scores.
POST
Normalize risk event
How Normalization Works
When you submit an identity event, the platform:- Records the raw event in the audit trail
- Maps the
event_typeto a canonical signal type and base risk score - Enriches the signal with available metadata (issuer trust tier, geo, device)
- Stores a
risk_signalrecord ready for policy evaluation
Built-in Event Mappings
Unknown event types are accepted with a base score of 10 and signal type
behavior.
Request
string
required
The system that generated this event:
attestation, verification, login, consumer_portalstring
required
The raw event name (e.g.
login.failed, verification.failed, attestation.deepfake_suspect)string
required
Identifier of the entity involved in the event.
string
External reference ID (attestation_id, session_id, etc.) for cross-referencing.
string
Source IP address.
object
Raw event payload for enrichment context.
Response
string
UUID of the recorded raw event source.
string
UUID of the normalized risk signal created from this event.
string
The normalized signal type derived from the event.
integer
The base risk score assigned during normalization.
boolean
true if the event matched a known mapping; false if it used the generic fallback.
