document.generatedA RAMS, CPP, induction, emergency plan, toolbox talk or COSHH PDF finishes generating.
Written by Nicola Dobbie, Founder, The Site BookLast reviewed
Site Control · enterprise integrations
The Site Book's Site Control tier connects construction compliance to your own systems: SAML single sign-on with Okta or Microsoft Entra ID, a read-only REST API, signed webhooks for real-time site events, and Microsoft 365 publishing to SharePoint.
curl "https://thesitebook.co.uk/api/v1/certifications?expiring_before=2026-08-01" \
-H "Authorization: Bearer sb_live_..."
{
"data": [
{
"id": "cm9x…",
"worker_id": "cm7k…",
"worker_name": "D. Kowalski",
"name": "CSCS Card",
"issued_at": "2024-08-14T00:00:00.000Z",
"expires_at": "2026-07-28T00:00:00.000Z",
"created_at": "2025-11-03T09:12:44.000Z"
}
],
"next_cursor": null
}01Single sign-on
Your IT team manages joiners and leavers in Okta or Microsoft Entra ID — Site Control plugs into that instead of adding another password to police. Connect your company domain over SAML, and optionally require SSO so sign-ins on your domain always go through your IdP.
Procurement asking about SSO? Point them at this page and the principal-contractor overview.
02Read-only REST API
Feed your BI dashboard, data warehouse or in-house tools from the same records the site gate captures. The API is read-only by design — write scopes will arrive as separate, opt-in scopes so a key you issued today never silently gains abilities.
Full reference at /docs/api, machine-readable spec at /api/v1/openapi.json.
03Signed webhooks
Push real-time events into your own systems instead of polling: notify the compliance team, update a dashboard, or open a ticket the moment something on site changes.
document.generatedA RAMS, CPP, induction, emergency plan, toolbox talk or COSHH PDF finishes generating.
document.signedA worker signs a document from their phone via a sign-off link.
certificate.expiringA worker certification enters its expiry warning window.
worker.checked_inSomeone checks in to a site — portal, QR, kiosk or dashboard.
induction.acknowledgedA worker acknowledges the site induction.
document.approval_requestedA named approver was asked to review a specific document version.
document.approvedThe named approver approved a document version.
document.published_to_sharepointAn approved document was published to the account's configured SharePoint destination.
04Microsoft 365 publishing
On Site Control, connect your Microsoft tenant and The Site Book copies each approved, issue-confirmed document into one SharePoint site, library and folder you choose — automatically after approval, or on demand. Teams notifications post to a channel when an approval is requested or a document is published, through your own Power Automate flow.
Your tenant is bound by our support team, and your IT admin grants consent for the single SharePoint site. The approval record, sign-off history and audit trail always stay in The Site Book — SharePoint receives a copy.
The API is read-only today — write scopes will be added as separate, opt-in scopes. Requiring SSO is an access-policy gate on the app for team members on your domain (the account owner keeps a break-glass sign-in); it is not a session-revocation tool. And the SSO connection itself is set up with our team during onboarding, not self-serve.
Running live sites with subcontractors? Site Control is the per-site enterprise tier above Business — entrance QR sign-in, CSCS checks, induction gating, live attendance and audit-grade exports. From £675/site per month, plus £5,000 setup.
Yes, by design. Every /api/v1 endpoint is read-only today, and write scopes will be added as separate, opt-in scopes so existing keys never gain abilities silently. It covers projects, documents, workers, certifications and site attendance.
Okta, Microsoft Entra ID, or any SAML 2.0 identity provider. The connection is based on your company email domain, so workers and guests on other domains are unaffected.
Team members on your company email domain must sign in to The Site Book through your identity provider to use the app. It is an access-policy gate on the application, not a session-revocation tool — and the account owner always keeps a direct sign-in as a break-glass, so an identity-provider outage can never lock your company out.
Eight events: document.generated, document.signed, certificate.expiring, worker.checked_in, induction.acknowledged, document.approval_requested, document.approved and document.published_to_sharepoint. Each delivery is HMAC-SHA256 signed, retried automatically with increasing backoff (up to six attempts over roughly ten hours), and recorded in a delivery log.
120 requests per minute per API key. List endpoints use cursor pagination with up to 100 records per page. The OpenAPI 3.1 spec at /api/v1/openapi.json documents every endpoint, parameter and response shape.
SSO, the API and webhooks are part of the Site Control tier. API keys and webhook endpoints are self-serve in Settings → Integrations once you are on Site Control; the SSO connection to your identity provider is set up with our team during onboarding. Book a walkthrough to get started.
Yes — on Site Control, the Microsoft 365 integration copies approved, issue-confirmed documents into one SharePoint site, library and folder you choose, automatically after approval or on demand, and posts Teams notifications through your own Power Automate flow. Your Microsoft tenant is connected by our support team, and your IT admin grants consent for the single site.
No. Google Drive, Xero and Zapier are included on Pro and above, while Slack Site Ready is Business and Site Control. SAML SSO, the public REST API and signed webhooks are Site Control only.
SSO · read-only API · signed webhooks
Comparing options first? See how Site Control stacks up as the best construction site access software in the UK, or read the head-to-heads against MSite and Donseed.