Core concepts

A quick tour of the objects you'll work with.

Organisation (tenant)

Your company. AfriPhish is multi-tenant: every user, campaign, training record and report belongs to exactly one organisation, and data is isolated per tenant. An organisation has a plan, a seat cap, and (on a trial) a trial expiry.

Users & roles

People in your organisation. Each has a role that determines what they can do:

RoleConsole accessCan do
IT AdminFullManage users & admins, campaigns, training, integrations, settings
Campaign ManagerYesRun simulations & training, view results
ViewerRead-onlyDashboards & reports
EmployeeNoneReceives simulations, completes assigned training

See Roles & access for how admins grant and revoke access safely.

Phishing campaigns

A simulated attack sent to a set of recipients. Campaigns draw on a library of 17 template families / 337 localized variants (EN/FR/AR), each built around one of five attack types (link, credential page, attachment, reply-to, QR), and record a per-recipient funnel. A series runs campaigns automatically on a recurring schedule. See Phishing & training.

Training

Micro-courses combining slides, a narrated video, and a graded quiz (you must pass to complete), available in EN/FR/AR. Modules can be assigned manually or auto-assigned to anyone caught by a simulation, and can be taken from a no-login signed link. Progress can be pushed to your own LMS via xAPI or SCORM.

Risk score

A living score per user and per department. It's a weighted blend of training (40%), phishing behaviour (45%), and reporting (15%), optionally informed by external security telemetry. It's how you measure whether human risk is actually going down.

Coaching & interventions

Rule-based actions that fire when someone behaves riskily — a nudge (shown in-app and emailed) or an auto-assigned remedial course. See Coaching & interventions.

Policies

Publish security policies and collect versioned e-signature attestations — audit-ready evidence for ISO 27001 (A.5.1) and SOC 2 (CC2.2). See Policies & attestation.

Branding

Upload an org logo that appears on report headers and, optionally, on policy sign pages and emails. See Branding.


Next: the Admin guide.