Admin guide
Everything an IT Admin does day to day. All of this lives under Settings and the main navigation.
Managing people
- Users — invite, import via CSV, deactivate, and organise people into groups (including smart groups with rule-based membership).
- Access & Roles (Settings → Access & Roles) — grant admin access to colleagues, change roles inline, and revoke access. Guardrails stop you from locking your organisation out. See Roles & access.
Running programmes
- Phishing — one-off campaigns or recurring series. Edit drafts, preview victim landing pages, and track the full funnel. See Phishing & training.
- Training — assign modules (slides + narrated video + graded quiz), set due dates, and auto-enrol anyone caught by a simulation.
- Interventions / coaching — nudge users in-app and by email, and auto-assign remedial training, based on behaviour or incoming security signals. See Coaching & interventions.
- Policies — publish and collect versioned e-signature attestations, with a live signature roster and "remind unsigned". See Policies & attestation.
Configuration (Settings tabs)
| Tab | What it does |
|---|---|
| Profile / Organisation | Your details and company info |
| Plan & Billing | Your current plan, seat usage, trial status, and upgrade options |
| Branding | Upload your org logo and toggle it on policy pages — see Branding |
| Email Integration | Per-tenant SMTP for sending, plus a test-send — see Email & deliverability |
| Deliverability | Dedicated sending domains with SPF/DKIM/DMARC records (Pro+) |
| Access & Roles | Admin access management |
| Single Sign-On | SAML SSO configuration (Enterprise) |
| Telemetry | SecurityCoach signal ingestion (Enterprise) |
| LMS | xAPI / SCORM connectors (Pro+) |
Features marked with a tier require that plan or higher — the UI shows an upgrade prompt, and the API enforces the same gate. See Plans & entitlements.
Individual users can also add two-factor authentication to their own accounts; the platform-wide security policy (session timeout, lockout, password rules, IP allowlist, enforce-MFA) is managed by the vendor. See MFA & account security.
Notifications & reminders
Configure campaign, training-due, weekly-digest, and risk-alert notifications under Settings → Notifications. Time-based reminders and digests fire through a scheduler — see Automation & scheduling.
Reports & evidence
The Reports section provides catalogue reports (caught users, repeat offenders, threat reporters, credential submissions, training completion) with CSV, JSON, PDF and HTML export — plus a bundled CSV zip and an executive PDF, deliverable by email, all carrying your org logo. See Reports & compliance.
Next: Roles & access (RBAC).