Returns a paginated list of workplace incident summaries for an organisation. By default only open (non-closed) incidents are returned; pass show_closed_reports=true to include closed ones. Use the query parameter to filter by affected person name, incident type, or submitter name.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidentsPath Parameters
The ID of the organisation.
Query Parameters
Filter incidents by affected person name, incident type, or submitter name.
Include closed incidents in the results. Defaults to false.
Include incidents for members who have left the organisation. Defaults to false.
Page number (1-based). Defaults to 1.
Number of results per page. Defaults to 20, maximum 100.
Response Body
Returns a paginated list of workplace incidents for the organisation.
Paginated list of workplace incidents.
Array of incident summary objects.
Current page number.
Total number of matching incidents.
Total number of pages.
Example
curl -X GET \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ"Response
{ "data": { "items": [ { "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "incident_type": "Near Miss", "date_and_time": "2025-06-15T09:30:00.000Z", "submitter_name": "Jane Smith", "name": "John Doe", "location": "Warehouse A", "approval_status": "Pending", "last_editor": "Jane Smith", "last_edited_at": "2025-06-15T10:00:00.000Z", "created_at": "2025-06-15T09:45:00.000Z", "closed_by": null, "closed_at": null, "is_anonymous": false, "raised_by": "employee" } ], "page_index": 1, "total_items": 1, "total_pages": 1 }}Upload attachment files for workplace incidents. Uploaded files are not linked to any incident until you pass the returned id values in the file_ids field of Create Workplace Incident or Update Workplace Incident.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/file_uploadsPath Parameters
The ID of the organisation.
Request Body
Files to upload via multipart/form-data.
Note
Allowed formats: JPG, JPEG, PNG, PDF, DOC, DOCX.
Response Body
Returns a list of successfully uploaded file details on HTTP 201.
List of uploaded file details.
Example
curl -X POST \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/file_uploads" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ" \ -F "files=/path/to/incident-photo.png"Response
{ "data": { "files": [ { "id": "c580adfd-c0f6-4544-85a8-b366c4c79251", "url": "https://cdn.employmenthero.com/files/incident-photo.png", "name": "incident-photo.png" } ] }}Submits a new workplace incident report on behalf of an internal employee, internal contractor, or external person. For internal employees and contractors, supply the member_id and the affected person's personal details (name, date of birth, phone number, position, address, manager) are automatically populated from their member record. For external persons, supply the name field directly. Attached files are returned as short-lived presigned download URLs in file_urls — do not cache these URLs; re-fetch on each request.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidentsPath Parameters
The ID of the organisation.
Request Body
Whether the affected person is an internal employee, contractor, or external person.
UUID of the affected member. Required when affectedpersontype is internalemployee or internalcontractor.
Name of the affected person. Required when affectedpersontype is external_person.
Date of birth of the affected person (YYYY-MM-DD).
Phone number of the affected person.
Job position of the affected person.
Home address of the affected person.
Name of the affected person's manager.
Category of the incident. AU organisations support all values except "Harassment" and "Sexual harassment". UK organisations support all values except "Psychosocial hazard".
Street address where the incident occurred.
Date and time the incident occurred.
State or territory where the incident occurred.
Location where the incident occurred.
Detailed description of the incident.
Body parts affected by the injury.
Additional description of the injury.
Whether the affected person received medical treatment.
Location where treatment was received.
Name of the medical treatment provider.
Whether to submit the incident anonymously.
UUIDs of files to attach. Returned as short-lived presigned URLs in file_urls.
Witnesses to the incident.
Answers to organisation-defined custom fields.
Response Body
Returns the full details of the newly created workplace incident.
Unique identifier for the workplace incident.
Category of the incident. AU organisations support all values except "Harassment" and "Sexual harassment". UK organisations support all values except "Psychosocial hazard".
Date and time the incident occurred.
Full name of the person who submitted the incident report. Returns "Anonymous" when the incident was submitted anonymously.
Full name of the affected person.
Location where the incident occurred.
Current status of the incident.
Full name of the member who last edited the incident.
Timestamp of the most recent edit.
Timestamp when the incident report was created.
Full name of the member who closed the incident.
Timestamp when the incident was closed.
Whether the incident was submitted anonymously.
Indicates who raised the incident. Null when the incident is anonymous.
Whether the affected person is an internal employee, internal contractor, or external person.
UUID of the affected member. Null when the affected person is external.
Phone number of the affected person.
Job position of the affected person.
Date of birth of the affected person (YYYY-MM-DD).
Home address of the affected person.
Name of the affected person's manager.
Street address where the incident occurred.
State or territory where the incident occurred.
Detailed description of the incident.
Outcome or consequence of the incident.
Nature of injury sustained.
Body parts affected by the injury.
Additional description of the injury.
Whether the affected person received medical treatment.
Location where treatment was received.
Name of the medical treatment provider.
Short-lived presigned download URLs for attached files. Do not cache — re-fetch on each request.
Title of the Worksafe Authority reviewer.
First name of the Worksafe Authority reviewer.
Last name of the Worksafe Authority reviewer.
Position of the Worksafe Authority reviewer.
Contact number of the Worksafe Authority reviewer.
Email address of the Worksafe Authority reviewer.
Whether the incident was deemed notifiable to the Worksafe Authority.
Short-term actions taken to prevent recurrence. Required when notifiable_incident is true.
Long-term actions planned to prevent recurrence.
Display hints for the caller. Not a server-side access control gate.
Witnesses to the incident.
Answers to organisation-defined custom fields.
Example
curl -X POST \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ" \ -H "Content-Type: application/json" \ -d '{ "affected_person_type": "internal_employee", "member_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "incident_type": "Near Miss", "date_and_time": "2025-06-15T09:30:00.000Z", "location": "Warehouse A", "description": "Forklift passed within 50 cm of pedestrian walkway without warning.", "witnesses": [ { "name": "Alice Witness", "contact_details": "alice@example.com" } ], "custom_field_answers": [ { "custom_field_id": "cf-001", "value": "Warehouse A" } ] }'Response
{ "data": { "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "incident_type": "Near Miss", "date_and_time": "2025-06-15T09:30:00.000Z", "submitter_name": "Jane Smith", "name": "John Doe", "location": "Warehouse A", "approval_status": "Pending", "last_editor": "Jane Smith", "last_edited_at": "2025-06-15T10:00:00.000Z", "created_at": "2025-06-15T09:45:00.000Z", "closed_by": null, "closed_at": null, "is_anonymous": false, "raised_by": "employee", "affected_person_type": "internal_employee", "member_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "phone_number": "+61 400 000 001", "position": "Warehouse Operator", "date_of_birth": "1990-03-22", "worker_address": "42 Example Street, Brisbane QLD 4000", "manager": "Sarah Manager", "incident_address": "1 Work Site Road, Brisbane QLD 4000", "state": "QLD", "description": "Forklift passed within 50 cm of pedestrian walkway without warning.", "outcome": "Near miss", "nature_of_injury": null, "injured_body_parts": null, "injury_description": null, "has_treatment": false, "treatment_location": null, "treatment_provider": null, "file_urls": [], "wsa_title": null, "wsa_first_name": null, "wsa_last_name": null, "wsa_position": null, "wsa_contact_number": null, "wsa_email": null, "notifiable_incident": null, "short_term_recurrence_prevention": null, "long_term_recurrence_prevention": null, "permissions": { "show_affected_person_details": true }, "witnesses": [ { "name": "Alice Witness", "contact_details": "alice@example.com" } ], "custom_field_answers": [ { "custom_field_id": "cf-001", "custom_field_name": "Location", "value": "Warehouse A", "display_value": "Warehouse A" } ] }}Returns the full details of a specific workplace incident, including all personal details, Worksafe Authority review fields, witnesses, and custom field answers. When the incident was submitted anonymously, submitter_name always returns "Anonymous" regardless of the caller's permissions. The permissions.show_affected_person_details flag is a display hint for the caller — it does not gate which fields the server returns.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_idPath Parameters
The ID of the organisation.
The ID of the workplace incident.
Response Body
Returns the full details of the specified workplace incident.
Unique identifier for the workplace incident.
Category of the incident. AU organisations support all values except "Harassment" and "Sexual harassment". UK organisations support all values except "Psychosocial hazard".
Date and time the incident occurred.
Full name of the person who submitted the incident report. Returns "Anonymous" when the incident was submitted anonymously.
Full name of the affected person.
Location where the incident occurred.
Current status of the incident.
Full name of the member who last edited the incident.
Timestamp of the most recent edit.
Timestamp when the incident report was created.
Full name of the member who closed the incident.
Timestamp when the incident was closed.
Whether the incident was submitted anonymously.
Indicates who raised the incident. Null when the incident is anonymous.
Whether the affected person is an internal employee, internal contractor, or external person.
UUID of the affected member. Null when the affected person is external.
Phone number of the affected person.
Job position of the affected person.
Date of birth of the affected person (YYYY-MM-DD).
Home address of the affected person.
Name of the affected person's manager.
Street address where the incident occurred.
State or territory where the incident occurred.
Detailed description of the incident.
Outcome or consequence of the incident.
Nature of injury sustained.
Body parts affected by the injury.
Additional description of the injury.
Whether the affected person received medical treatment.
Location where treatment was received.
Name of the medical treatment provider.
Short-lived presigned download URLs for attached files. Do not cache — re-fetch on each request.
Title of the Worksafe Authority reviewer.
First name of the Worksafe Authority reviewer.
Last name of the Worksafe Authority reviewer.
Position of the Worksafe Authority reviewer.
Contact number of the Worksafe Authority reviewer.
Email address of the Worksafe Authority reviewer.
Whether the incident was deemed notifiable to the Worksafe Authority.
Short-term actions taken to prevent recurrence. Required when notifiable_incident is true.
Long-term actions planned to prevent recurrence.
Display hints for the caller. Not a server-side access control gate.
Witnesses to the incident.
Answers to organisation-defined custom fields.
Example
curl -X GET \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_id" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ"Response
{ "data": { "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "incident_type": "Near Miss", "date_and_time": "2025-06-15T09:30:00.000Z", "submitter_name": "Jane Smith", "name": "John Doe", "location": "Warehouse A", "approval_status": "Pending", "last_editor": "Jane Smith", "last_edited_at": "2025-06-15T10:00:00.000Z", "created_at": "2025-06-15T09:45:00.000Z", "closed_by": null, "closed_at": null, "is_anonymous": false, "raised_by": "employee", "affected_person_type": "internal_employee", "member_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "phone_number": "+61 400 000 001", "position": "Warehouse Operator", "date_of_birth": "1990-03-22", "worker_address": "42 Example Street, Brisbane QLD 4000", "manager": "Sarah Manager", "incident_address": "1 Work Site Road, Brisbane QLD 4000", "state": "QLD", "description": "Forklift passed within 50 cm of pedestrian walkway without warning.", "outcome": "Near miss", "nature_of_injury": null, "injured_body_parts": null, "injury_description": null, "has_treatment": false, "treatment_location": null, "treatment_provider": null, "file_urls": [], "wsa_title": null, "wsa_first_name": null, "wsa_last_name": null, "wsa_position": null, "wsa_contact_number": null, "wsa_email": null, "notifiable_incident": null, "short_term_recurrence_prevention": null, "long_term_recurrence_prevention": null, "permissions": { "show_affected_person_details": true }, "witnesses": [ { "name": "Alice Witness", "contact_details": "alice@example.com" } ], "custom_field_answers": [ { "custom_field_id": "cf-001", "custom_field_name": "Location", "value": "Warehouse A", "display_value": "Warehouse A" } ] }}Partially updates an open workplace incident. Only the fields supplied in the request body are changed; omitted fields retain their existing values. The witnesses array is fully replaced on every request — any previously saved witnesses not included in the array are permanently removed. Always include the full list of desired witnesses. Submitting both file_urls and file_ids combines both sets in the response. Closed incidents (approval_status: "Closed") cannot be updated.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_idPath Parameters
The ID of the organisation.
The ID of the workplace incident to update.
Request Body
Whether the affected person is an internal employee, contractor, or external person.
UUID of the affected member. Required when affectedpersontype is internalemployee or internalcontractor.
Name of the affected person.
Date of birth of the affected person (YYYY-MM-DD).
Phone number of the affected person.
Job position of the affected person.
Home address of the affected person.
Name of the affected person's manager.
Category of the incident. AU organisations support all values except "Harassment" and "Sexual harassment". UK organisations support all values except "Psychosocial hazard".
Street address where the incident occurred.
Date and time the incident occurred.
State or territory where the incident occurred.
Location where the incident occurred.
Detailed description of the incident.
Body parts affected by the injury.
Additional description of the injury.
Whether the affected person received medical treatment.
Location where treatment was received.
Name of the medical treatment provider.
External file URLs to attach. Merged with URLs resolved from file_ids.
UUIDs of files to attach. Resolved URLs are merged with file_urls.
Full replacement of all witnesses. Any previously saved witnesses not in this array are permanently removed.
Answers to organisation-defined custom fields.
Response Body
Returns the full details of the updated workplace incident.
Unique identifier for the workplace incident.
Category of the incident. AU organisations support all values except "Harassment" and "Sexual harassment". UK organisations support all values except "Psychosocial hazard".
Date and time the incident occurred.
Full name of the person who submitted the incident report. Returns "Anonymous" when the incident was submitted anonymously.
Full name of the affected person.
Location where the incident occurred.
Current status of the incident.
Full name of the member who last edited the incident.
Timestamp of the most recent edit.
Timestamp when the incident report was created.
Full name of the member who closed the incident.
Timestamp when the incident was closed.
Whether the incident was submitted anonymously.
Indicates who raised the incident. Null when the incident is anonymous.
Whether the affected person is an internal employee, internal contractor, or external person.
UUID of the affected member. Null when the affected person is external.
Phone number of the affected person.
Job position of the affected person.
Date of birth of the affected person (YYYY-MM-DD).
Home address of the affected person.
Name of the affected person's manager.
Street address where the incident occurred.
State or territory where the incident occurred.
Detailed description of the incident.
Outcome or consequence of the incident.
Nature of injury sustained.
Body parts affected by the injury.
Additional description of the injury.
Whether the affected person received medical treatment.
Location where treatment was received.
Name of the medical treatment provider.
Short-lived presigned download URLs for attached files. Do not cache — re-fetch on each request.
Title of the Worksafe Authority reviewer.
First name of the Worksafe Authority reviewer.
Last name of the Worksafe Authority reviewer.
Position of the Worksafe Authority reviewer.
Contact number of the Worksafe Authority reviewer.
Email address of the Worksafe Authority reviewer.
Whether the incident was deemed notifiable to the Worksafe Authority.
Short-term actions taken to prevent recurrence. Required when notifiable_incident is true.
Long-term actions planned to prevent recurrence.
Display hints for the caller. Not a server-side access control gate.
Witnesses to the incident.
Answers to organisation-defined custom fields.
Example
curl -X PATCH \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_id" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ" \ -H "Content-Type: application/json" \ -d '{ "description": "Forklift passed within 50 cm of pedestrian walkway without warning. Updated with additional details.", "witnesses": [ { "name": "Alice Witness", "contact_details": "alice@example.com" } ] }'Response
{ "data": { "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "incident_type": "Near Miss", "date_and_time": "2025-06-15T09:30:00.000Z", "submitter_name": "Jane Smith", "name": "John Doe", "location": "Warehouse A", "approval_status": "Pending", "last_editor": "Jane Smith", "last_edited_at": "2025-06-15T10:00:00.000Z", "created_at": "2025-06-15T09:45:00.000Z", "closed_by": null, "closed_at": null, "is_anonymous": false, "raised_by": "employee", "affected_person_type": "internal_employee", "member_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901", "phone_number": "+61 400 000 001", "position": "Warehouse Operator", "date_of_birth": "1990-03-22", "worker_address": "42 Example Street, Brisbane QLD 4000", "manager": "Sarah Manager", "incident_address": "1 Work Site Road, Brisbane QLD 4000", "state": "QLD", "description": "Forklift passed within 50 cm of pedestrian walkway without warning.", "outcome": "Near miss", "nature_of_injury": null, "injured_body_parts": null, "injury_description": null, "has_treatment": false, "treatment_location": null, "treatment_provider": null, "file_urls": [], "wsa_title": null, "wsa_first_name": null, "wsa_last_name": null, "wsa_position": null, "wsa_contact_number": null, "wsa_email": null, "notifiable_incident": null, "short_term_recurrence_prevention": null, "long_term_recurrence_prevention": null, "permissions": { "show_affected_person_details": true }, "witnesses": [ { "name": "Alice Witness", "contact_details": "alice@example.com" } ], "custom_field_answers": [ { "custom_field_id": "cf-001", "custom_field_name": "Location", "value": "Warehouse A", "display_value": "Warehouse A" } ] }}Closes a reviewed workplace incident. The incident must have approval_status: "Reviewed" — incidents in "Pending" status (Worksafe Authority review not yet completed) cannot be closed. Attempting to close an already-closed incident returns 422. This endpoint requires the Incident - Create OAuth scope and the Safety Incident Management — write CSS permission.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_id/closePath Parameters
The ID of the organisation.
The ID of the workplace incident to close.
Response Body
Returns HTTP 200 OK on success. The incident approval_status changes to "Closed". No response body is included.
Example
curl -X POST \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_id/close" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ"Response
This endpoint does not return a response body.
Permanently deletes a workplace incident, including all associated witnesses and custom field answers. This action cannot be undone. Open incidents can be deleted by any caller with the Safety Incident Management — remove permission scoped to the affected member. Closed incidents can only be deleted by worksafe officers or admins/owners.
https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_idPath Parameters
The ID of the organisation.
The ID of the workplace incident to permanently delete.
Response Body
Returns HTTP 204 No Content on success. The incident, its witnesses, and custom field answers are permanently deleted.
Example
curl -X DELETE \ "https://api.employmenthero.com/api/v1/organisations/:organisation_id/incidents/:incident_id" \ -H "Authorization: Bearer AUXJ3123xyrj123fdsjkl124aAJKQ"Response
This endpoint does not return a response body.