Core concepts
A quick tour of the objects you'll work with.
Organisation (tenant)
Your company. AfriPhish is multi-tenant: every user, campaign, training record and report belongs to exactly one organisation, and data is isolated per tenant. An organisation has a plan, a seat cap, and (on a trial) a trial expiry.
Users & roles
People in your organisation. Each has a role that determines what they can do:
| Role | Console access | Can do |
|---|---|---|
| IT Admin | Full | Manage users & admins, campaigns, training, integrations, settings |
| Campaign Manager | Yes | Run simulations & training, view results |
| Viewer | Read-only | Dashboards & reports |
| Employee | None | Receives simulations, completes assigned training |
See Roles & access for how admins grant and revoke access safely.
Phishing campaigns
A simulated attack sent to a set of recipients. Campaigns draw on a library of 17 template families / 337 localized variants (EN/FR/AR), each built around one of five attack types (link, credential page, attachment, reply-to, QR), and record a per-recipient funnel. A series runs campaigns automatically on a recurring schedule. See Phishing & training.
Training
Micro-courses combining slides, a narrated video, and a graded quiz (you must pass to complete), available in EN/FR/AR. Modules can be assigned manually or auto-assigned to anyone caught by a simulation, and can be taken from a no-login signed link. Progress can be pushed to your own LMS via xAPI or SCORM.
Risk score
A living score per user and per department. It's a weighted blend of training (40%), phishing behaviour (45%), and reporting (15%), optionally informed by external security telemetry. It's how you measure whether human risk is actually going down.
Coaching & interventions
Rule-based actions that fire when someone behaves riskily — a nudge (shown in-app and emailed) or an auto-assigned remedial course. See Coaching & interventions.
Policies
Publish security policies and collect versioned e-signature attestations — audit-ready evidence for ISO 27001 (A.5.1) and SOC 2 (CC2.2). See Policies & attestation.
Branding
Upload an org logo that appears on report headers and, optionally, on policy sign pages and emails. See Branding.
Next: the Admin guide.