---
language: "en"
---
# For Admins: Effective Product Setup and Use

## For Admins: Effective Product Setup and Use

This Knowledge Base focuses on helping you get the most out of using SoSafe products once they are set up. If you need help with the setup, check the [Technical Implementation space](https://support.sosafe.de/ADOC/). If you're a learner, you will find helpful information by going back and picking the [User Documentation space](https://support.sosafe.de/UserDoc/).

### Recommended articles

*

  #### [Human Risk Management](https://support.sosafe.de/ProductDoc/human-risk-management.md)

  Preview the next iteration of cyber security risk awareness - the Human Risk OS™
*

  #### [Analytics](https://support.sosafe.de/ProductDoc/analytics.md)

  In this section, you can find out how the numbers in your Analytics are calculcated, what they mean exactly and how you can get the data that you want.

### Documentation

*

  #### [E-Learning](https://support.sosafe.de/ProductDoc/e-learning.md)

  * [Policy-to-Lesson](https://support.sosafe.de/ProductDoc/policy-to-lesson.md)
  * [E-Learning course setup](https://support.sosafe.de/ProductDoc/e-learning-course-setup.md)
  * [E-Learning course management](https://support.sosafe.de/ProductDoc/e-learning-course-management.md)
  * [Follow-up campaigns](https://support.sosafe.de/ProductDoc/follow-up-campaigns.md)
*

  #### [Sofie - Instant Alerts \& Level Zero Support](https://support.sosafe.de/ProductDoc/sofie-instant-alerts-level-zero-support.md)

  * [Instant Alerts](https://support.sosafe.de/ProductDoc/instant-alerts.md)
  * [Level Zero Support](https://support.sosafe.de/ProductDoc/level-zero-support.md)
  * [Sofie customization](https://support.sosafe.de/ProductDoc/sofie-customization.md)
  * [Sofie Policy Management](https://support.sosafe.de/ProductDoc/sofie-policy-management.md)
*

  #### [Phishing Simulation](https://support.sosafe.de/ProductDoc/create-your-own-phishing-simulations.md)

  * [Create a Basic Simulation](https://support.sosafe.de/ProductDoc/create-a-basic-simulation.md)
  * [Create a Targeted Simulation](https://support.sosafe.de/ProductDoc/create-a-targeted-simulation.md)
  * [Create a Behavior-based Simulation](https://support.sosafe.de/ProductDoc/create-a-behavior-based-simulation.md)
  * [Template Studio](https://support.sosafe.de/ProductDoc/simulation-studio-how-to-guide.md)
  * [QuickEdit - Template customization](https://support.sosafe.de/ProductDoc/quickedit-template-customization.md)
  * [3 more pages](https://support.sosafe.de/ProductDoc/create-your-own-phishing-simulations.md)
*

  #### [Analytics](https://support.sosafe.de/ProductDoc/analytics.md)

  * [E-Learning metrics](https://support.sosafe.de/ProductDoc/e-learning-overview-metrics.md)
  * [Simulation metrics](https://support.sosafe.de/ProductDoc/simulation-base-metrics.md)
  * [ISO Analytics](https://support.sosafe.de/ProductDoc/iso-analytics.md)
  * [Reporting \& data exports](https://support.sosafe.de/ProductDoc/reporting.md)

---
language: "en"
---
# Analytics

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/analytics), [**Deutsch**](https://de.support.sosafe.de/pdok/analytics)

In this section, you can find out how the numbers in your Analytics are calculcated, what they mean exactly and how you can get the data that you want.  
Note: Analytics data are refreshed twice a day. This happens usually early in the morning and on evenings (CET). The exact timing can vary.

* [E-Learning metrics](https://support.sosafe.de/ProductDoc/e-learning-overview-metrics.md)

  * [E-Learning registration metrics](https://support.sosafe.de/ProductDoc/e-learning-registration-metrics.md)

  * [E-Learning on track metrics](https://support.sosafe.de/ProductDoc/e-learning-on-track-metrics.md)

  * [E-Learning starting rate metrics](https://support.sosafe.de/ProductDoc/e-learning-starting-rate-metrics.md)

  * [E-Learning completion score metrics](https://support.sosafe.de/ProductDoc/e-learning-completion-score-metrics.md)

  * [E-Learning completion rate metrics](https://support.sosafe.de/ProductDoc/e-learning-completion-rate-metrics.md)

  * [E-Learning user rating metrics](https://support.sosafe.de/ProductDoc/e-learning-user-rating-metrics.md)

  * [E-Learning user overview](https://support.sosafe.de/ProductDoc/e-learning-user-overview.md)

* [Simulation metrics](https://support.sosafe.de/ProductDoc/simulation-base-metrics.md)

  * [Simulation overview metrics](https://support.sosafe.de/ProductDoc/simulation-overview-metrics.md)

  * [Simulation overview over time metrics](https://support.sosafe.de/ProductDoc/simulation-overview-over-time-metrics.md)

  * [Simulation click rate metrics](https://support.sosafe.de/ProductDoc/simulation-click-rate-metrics.md)

  * [Simulation user metrics](https://support.sosafe.de/ProductDoc/simulation-user-metrics.md)

* [ISO Analytics](https://support.sosafe.de/ProductDoc/iso-analytics.md)

  * [ISO Simulation Analytics](https://support.sosafe.de/ProductDoc/iso-simulation-analytics.md)

  * [ISO E-Learning Analytics](https://support.sosafe.de/ProductDoc/iso-e-learning-analytics.md)

---
language: "en"
---
# Communication templates

To effectively communicate the introduction of Sofie to the company's employees, a structured communication plan is essential. This plan will ensure that all employees are informed, engaged, and prepared to integrate Sofie into their daily operations for security-related inquiries. Here's a plan to achieve that:

## Pre-Launch Announcement

**Objective** : To generate curiosity and inform employees about the upcoming introduction of Sofie.

**Timeline** : A week before the installation date.

**Method** : Email from the IT or Security department head.

**Content**: Brief introduction of Sofie, its purpose, and the benefits it brings to the company's security posture. Mention the installation date and tease upcoming detailed instructions.

**Template:**  
**Subject: Introducing Sofie: Your New Security Assistant in MS Teams**

"Dear Team,

As part of our ongoing commitment to enhancing our cybersecurity posture, we are excited to announce the upcoming introduction of Sofie, a smart conversational support bot designed to assist you with all your security-related queries directly within Microsoft Teams.

What makes Sofie stand out? It's your go-to resource for immediate, 24/7 assistance with any cybersecurity questions you might have, from identifying potential phishing attempts to setting up strong passwords. Sofie is specifically trained to handle a wide array of security concerns, ensuring you have expert guidance at your fingertips.

Mark your calendars! We will be welcoming Sofie to our Teams environment on **\[ENTER DATE/PERIOD\]**. Look forward to detailed guidance on how to interact with Sofie and how this tool can play a pivotal role in our security strategy.

Stay tuned for more information on how you can leverage Sofie to enhance your daily security practices. This is just the beginning of our journey towards a safer, more secure digital workplace."

## Announcement Template -- Launch Day

**Objective** : To announce the availability of Sofie and guide employees on how to start using it.

**Timeline** : On the installation day.

**Method** : Company-wide email and a post on the internal company platform/portal.

**Content**: Detailed information on Sofie, including:

* What Sofie is and the scope of questions it can answer.

* Instructions on where to find Sofie in MS Teams.

* Steps on what to do for the first interaction.

* Encouragement to use Sofie for any security-related questions.

* Contact information for further assistance.

**Template:**  
**Subject: Sofie is Here - Your New Cybersecurity Assistant in MS Teams**

Dear **\[COMPANY NAME\]** Family,

We are thrilled to announce that Sofie, our conversational AI support bot, has officially launched and is now available in our Microsoft Teams environment. Designed to be your first line of support for all cybersecurity queries, Sofie stands ready to assist you, 24/7.

**What is Sofie?**

Sofie is a conversational AI support bot, developed to provide you with instant, expert advice on a wide range of security issues. Whether you're concerned about a potential phishing attack, have a security question websites, or are unsure about the company's policies, Sofie is here to assist, 24/7.

**Where to find Sofie:**

Sofie has taken its place on the left side menu in MS Teams, making it easily accessible for everyone. If you haven't already, you will soon receive a direct message from Sofie, welcoming you to this new feature.

**Why use Sofie?**

* **Immediate Assistance**: Get quick answers to your security questions, anytime.

* **Empowerment**: Enhance your knowledge and confidence in handling security issues.

* **Support**: If Sofie doesn't have the answer, your query will be escalated to our IT personnel for further assistance.

Let's embrace this innovative step towards a more secure and informed digital environment at **\[COMPANY NAME\].** Start your conversation with Sofie today and see how easy it is to enhance your cybersecurity awareness.

## First-Week Follow-Up

**Objective:** To gather initial feedback and encourage continuous use.

**Timeline:** One week after installation.

**Method:** Short survey via email and reminder posts on the internal company platform/portal.

**Content:**

* Ask for feedback on their initial experience.

* Remind employees of Sofie's availability 24/7 for security questions.

* Highlight any success stories or interesting interactions with Sofie.

**Template:**  
**Subject: 🚀 One Week with Sofie: How's It Going?**

**Dear \[COMPANY NAME\] Team,**

As we conclude our first week with Sofie, our new AI support bot in Microsoft Teams, we want to take a moment to reflect on this initial phase of our cybersecurity enhancement journey. Sofie was introduced to provide immediate, expert assistance with your security-related inquiries, and we hope you have found this new resource to be both useful and informative.

**Engagement with Sofie**

If you have not yet had the opportunity to interact with Sofie, we encourage you to do so. Sofie is available to assist you with a wide range of security questions, offering support 24/7 directly within our Teams environment.

**Highlights from the First Week**

In just one week, we have seen:

* A significant number of queries resolved by Sofie, indicating a strong start to our engagement with the bot.

* A diverse range of questions, reflecting the varied cybersecurity needs within our organization.

* Positive initial feedback on the speed and accuracy of Sofie's responses.

We appreciate your active participation in this initiative and look forward to your continued engagement with Sofie. Please do not hesitate to reach out to the IT department with your feedback or any questions you may have about using Sofie.

Thank you for your commitment to maintaining a secure digital environment at **\[COMPANY NAME\].**

## Monthly Follow-Up

**Objective:**To maintain engagement and inform about updates or improvements.

**Timeline:** Monthly after the launch**.**

**Method:**Email newsletter and posts on the internal company platform.

**Content:**

* Updates or new features added to Sofie

* Tips on how to make the most out of Sofie.

* Highlight frequently asked questions of the month and their answers.

**Template:**  
**Subject: Monthly Check-In: Sofie's Progress and Your Insights**

Dear \[COMPANY NAME\] Team,

As we wrap up another month with Sofie at our side, this brief note serves to share updates and seek your continuous feedback on our cybersecurity companion, Sofie, in Microsoft Teams.

Sofie's Milestones

* Sofie has now addressed over \[X\] security inquiries, helping us navigate through a myriad of cybersecurity concerns.

* Continuous improvements have been made to enhance Sofie's responsiveness and accuracy, thanks to your valuable feedback.

We Value Your Feedback

Your insights are pivotal for Sofie's growth and effectiveness. Have you encountered new challenges, or do you have suggestions for new features? Please share your thoughts with us.

Stay Engaged

Remember, Sofie is here to assist 24/7 with any security questions. We encourage you to keep leveraging this tool to support your cybersecurity needs.

Thank you for your continued support and engagement with Sofie. Together, we're making our digital workspace safer and more secure.

---
language: "en"
---
# Create a Basic Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/create-a-basic-simulation), [**Deutsch**](https://de.support.sosafe.de/pdok/basic-simulation-erstellen)  
Reach out to your Customer Success Team if you're interested in what you see here.

Basic Simulations can serve as a good starting point if you want to collect baseline data for future, more targeted simulations. They also require very little setup. However, while we've selected the templates to be used based on years of experience with our customers, more advanced and targeted simulations usually lead to better results.

---
language: "en"
---
# Create a Behavior-based Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/create-a-behavior-based-simulation), [**Deutsch**](https://de.support.sosafe.de/pdok/verhaltensbasierte-simulation-erstellen)

Behavior-based Simulations adapt to user behavior. The assignment of template difficulty is based on the individual Behavior Awareness Score (BAS). The system adjusts the frequency and difficulty level based on user interactions to provide targeted training.

You can choose which templates are included. Make sure they **fit your organization** well and try to select **as many as possible**. If you select only a few templates for each difficulty, at some point the simulated phishing mails will include repetitions, which lowers the learning effect.

Unlike Basic and Targeted Simulations, Behavior-based Simulations have no specified end date.

## Setup demo

## Details

Each user is assigned a score that develops throughout a campaign based on their interaction with simulated phishing emails. **The better users perform, the harder the templates they receive are.**

* Users with a**low score** receive **2 emails per month**, based on easy templates.

* Users with a **medium or high score** receive **1 email per month**, with a corresponding difficulty.

The system tries to avoid repeating templates where possible and will only use a template again if there are no unused templates left in the given difficulty level. **We therefore recommend selecting as many templates as possible for behavior-based simulations - provided that they suit your organization.**

---
language: "en"
---
# Create a Smishing Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/create-a-smishing-simulation)**,** [**German**](https://de.support.sosafe.de/pdok/smishing-sms-simulation)

Smishing, short for SMS phishing, is a cyber attack vector that uses text messages instead of emails to target individuals. Thanks to SoSafe, you can now also raise awareness about these types of attacks. If you've set up your own SoSafe Phishing Simulation before, setting up your own Smishing Simulation works pretty much exactly the same. And if you haven't, don't worry, it'll only take a few minutes!

You can either watch our walkthrough demo or continue to the step-by-step guide below.

## Walkthrough demo

## Step-by-step guide

### Overview

Navigate to **Phishing Simulation / SMS Simulation** in the Manager to get started!

This is your starting point. If you already have created Smishing Simulations, these will show up here. Since we haven't done so yet, let's select **Create smishing simulation**.  
![smishing_overview.png](https://support.sosafe.de/__attachments/a_f0be5085842d4d47f3babdd3841353791d6c0418f6c97e82b5f81e56db971e64/smishing_overview.png?cb=412bad025883c5638442e1950231935d)  
![smishing_overview2.png](https://support.sosafe.de/__attachments/a_68eecb93c88af3375682f0aa65cbf9dbcd28d583ba02eb94289f6292e1b6c378/smishing_overview2.png?cb=8ad263d2a598ee034c5035f1943f2213)

### 1. Templates

In our first step, we select which templates we want our simulation to use. Select the eye icon to get a preview of the content. The more relevant these templates are to your employees' work context, the better they will work.  
![smishing_templates.png](https://support.sosafe.de/__attachments/a_58f02b00a0f155ee3531ea4639b4fd347c95e477c57f6d67712d9bd894b7a26f/smishing_templates.png?cb=4dc5ea5bba502e972a53abdc1cd3d8a8)  
![smishing_templatepreview.png](https://support.sosafe.de/__attachments/a_8ace2664a2924d126f406695db2072098108a9d7462dcd4572dde31afbe026ff/smishing_templatepreview.png?cb=7917578976f582094e54cdc02d0ac10f)

### 2. Targets

Next we'll decide who will receive these SMS messages throughout the Simulation. Simply pick from your existing user groups.  
![smishing_targets.png](https://support.sosafe.de/__attachments/a_c5a856cf2574572b7bf9e29389e6dcc846dd15768aa49b3e66d101fb4c6e1072/smishing_targets.png?cb=e09d3e9f079badf573048d6ffdedb1ef)

### 3. Schedule

All you need to do here is set an end and a start date. If you're just experimenting with a small campaign, we recommend a short schedule. For proper training, longer timeframes are recommended for both convenience and effectiveness.  
![smishing_schedule.png](https://support.sosafe.de/__attachments/a_b01a71f7a580dc3d25b15694ad4ff39fed4a127cc4bc97c2bd65bb05226c7318/smishing_schedule.png?cb=f275d40d2c575d44446138fde4dabc48)

### 4. Analytics

Here you can choose between aggredated, anonymous and person-specific reporting in your Analytics.

### 5. Review

In this step you'll get a brief recap of the settings you just chose. You can make changes in the corresponding sections by selecting **Edit** . We also recommend naming your Simulation. Once you're done, select **Add simulation**. That's it! On your chosen start date, we'll start sending out SMS to keep your employees on their toes.  
![smishing_review.png](https://support.sosafe.de/__attachments/a_79a0bc2bc83632d1e58f58b4769f7684bc97f18e566e5af671cce6bb015ed6c3/smishing_review.png?cb=da3384f36521a84b3a4d75ce2e080168)

---
language: "en"
---
# Create a Targeted Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/create-a-targeted-simulation), [**Deutsch**](https://de.support.sosafe.de/pdok/gezielte-simulation-erstellen)  
Reach out to your Customer Success Team if you're interested in what you see here.

Targeted Simulations allow you to use more specific templates for certain departments at your organization. For instance, you can send templates specifically tailored to fit the work context of IT professionals to your company's IT team. This makes the simulated phishing emails a lot more realistic, leading to improved learning and behavior. Thankfully, creating a targeted simulation is very easy!

---
language: "en"
---
# Phishing Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/create-your-own-phishing-simulations), [**Deutsch**](https://de.support.sosafe.de/pdok/eigene-phishing-simulationen-erstellen)  
Reach out to your Customer Success Team if you're interested in what you see here.

Learn all about creating your own Phishing Simulations as well as creating and editing templates!

* [Create a Basic Simulation](https://support.sosafe.de/ProductDoc/create-a-basic-simulation.md)
* [Create a Targeted Simulation](https://support.sosafe.de/ProductDoc/create-a-targeted-simulation.md)
* [Create a Behavior-based Simulation](https://support.sosafe.de/ProductDoc/create-a-behavior-based-simulation.md)
* [Template Studio](https://support.sosafe.de/ProductDoc/simulation-studio-how-to-guide.md)
* [QuickEdit - Template customization](https://support.sosafe.de/ProductDoc/quickedit-template-customization.md)
* [Recreate Attack (Beta)](https://support.sosafe.de/ProductDoc/simulation-recreate-attack.md)
* [Classic Phishing Simulation](https://support.sosafe.de/ProductDoc/phishing-simulation.md)
* [Create a Smishing Simulation](https://support.sosafe.de/ProductDoc/create-a-smishing-simulation.md)

---
language: "en"
---
# E-Learning

We're currently improving the self-service capabilities of our E-Learning and are adding new features for you to make training for your employees even more personal and effective!

* [Policy-to-Lesson](https://support.sosafe.de/ProductDoc/policy-to-lesson.md)
* [E-Learning course setup](https://support.sosafe.de/ProductDoc/e-learning-course-setup.md)
* [E-Learning course management](https://support.sosafe.de/ProductDoc/e-learning-course-management.md)
* [Follow-up campaigns](https://support.sosafe.de/ProductDoc/follow-up-campaigns.md)

---
language: "en"
---
# E-Learning completion rate metrics

## Passed modules by user group

![elearning-completionrate-passedmodules.png](https://support.sosafe.de/__attachments/a_3233a09168348c7c600bf2383f3d374105278622f76793c8b15b1d0217327a82/elearning-completionrate-passedmodules.png?cb=092101eeb80b22b2fb68ca903818db17)

### **Definition**

This shows the percentage of all completed modules in a user group compared to the sum count of all modules assigned to users in that user group.

Module names are only available for languages where at least one user in the campaign has completed a module in that language. This chart will first attempt to show modules in the language set for the current Manager user. If not available, the chart will show the names in English.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** Users are assigned modules per campaign, so for multiple campaigns, assignments within a single user group are simply added together.

Since user groups exist within a single tenant, multiple tenants will simply show the union of all user group completion rates in each tenant.

**Personalized Learning:** (multiple tenants only) Since user groups exist within a single tenant, multiple tenants will simply show the union of all user group completion rates in each tenant.

### Module split filter behavior

Only individual completion instances according to the filter setting are included in the average.  

### **Impact**

This metric provides a good overview of the learning progress across user groups. Useful for identifying user groups that are outperforming the average in your company or ones that do worse.

## Completion rate by module

![elearning-completionrate-bymodule.png](https://support.sosafe.de/__attachments/a_655e85a72734630fb4206154b9b9f0d43f47da6f98d86023b0e75cc5348e378a/elearning-completionrate-bymodule.png?cb=fa7fb7938760476adf84cebda0c06ca8)

### **Definition**

This shows the percentage of users who have completed a module compared to the total number of users to whom the module was assigned, broken down by module.

**Note:**Module names are only available for languages where at least one user in the campaign has completed a module in that language. This chart will first attempt to show modules in the language set for the current Manager user. If not available, the chart will show the names in English.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** Users are assigned modules per campaign, so module assignments and completions across all included campaigns and tenants are simply added together.

**Personalized Learning:** (multiple tenants only) Total number of user completion instances is compared to the total number of module assignments for each module.

### Module split filter behavior

Only individual completion instances according to the filter setting are included in the average.  

### **Impact**

This metric can help identify unpopular modules. You might want to stress their relevance in your internal communication - or consider removing them if they are not relevant.

---
language: "en"
---
# E-Learning completion score metrics

## Overall completion score

![elearning-completionscore.png](https://support.sosafe.de/__attachments/a_49211af5103619cb2d807235263e484f9c503eadcca708807a6492f505b3b65b/elearning-completionscore.png?cb=a5c989757650ff65b0850d3f9fed3447)

### **Definition**

This shows the arithmetic mean of module score for all completed modules in a campaign. This metric does not include incomplete or failed modules.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** Individual completed module scores from all included campaigns and tenants are averaged.

**Personalized Learning:** (multiple tenants only) Individual completed module scores from all included tenants are averaged.

## Completion results by user group

![elearning_completion_group.png](https://support.sosafe.de/__attachments/a_7d495f9494e608e46569be275d4e42883808819089beac0fc351bd1a98d8236b/elearning_completion_group.png?cb=2c01f4c6bc33d84d144405b24920c78c)

### **Definition**

This shows the arithmetic mean of module score for all completed modules in a campaign, broken down by user group. This metric does not include incomplete or failed modules.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** Users need to complete each assigned module for every campaign where it is assigned to them. If a user completes the same module for multiple campaigns, each score is included in the overall average.

Since user groups exist within a single tenant, multiple tenants will simply show the union of all user group scores in each tenant.

**Personalized Learning:** (multiple tenants only) Since user groups exist within a single tenant, multiple tenants will simply show the union of all user group scores in each tenant.

## Completion results by module

![elearning-completionmodule.png](https://support.sosafe.de/__attachments/a_7bd29e785a2737ac311026124897eb38f6bec5af21ab6524198138725109e267/elearning-completionmodule.png?cb=0f3abc092e652bd7dfbde200aebb683b)

### **Definition**

This shows the arithmetic mean of completed module score broken down by module for all users in a campaign. This metric does not include incomplete or failed modules.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** Users need to complete each assigned module for every campaign where it is assigned to them. If a user completes the same module for multiple campaigns, each score is included in the overall average.

For multiple tenants, the individual completed module scores from all included tenants are averaged.

**Personalized Learning:** (multiple tenants only) Individual completed module scores from all included tenants are averaged.

### Module split filter behavior

Only individual completion instances according to the filter setting are included in the average.

---
language: "en"
---
# E-Learning course management

**Read this article in:** [++**German**++](https://de.support.sosafe.de/pdok/e-learning-kursverwaltung)  
This article introduces the **Course Management** page. Here, you will learn how to create new E-Learning courses as well as how to manage, edit, or duplicate existing courses.

The Course Management page provides a clear overview of all your created E-Learning courses and their settings. Let's take a look at the various functions in detail.

## Overview

In the SoSafe Manager, navigate to **E-Learning / Course Management**. There, you will find the overview of your created courses.  
![image-20260625-062716.png](https://support.sosafe.de/__attachments/a_ec58dbfccbd4d1fdacfee8e5336629b0a07005aa6f896fa8b1f14a5910549643/image-20260625-062716.png?cb=049eb76715cdc79d88ea2e6e978c4a71)

*** ** * ** ***

## Creating new E-Learning courses

Select **+ Create new course** to begin. This opens the guided 6-step process for creating a course. Complete these steps one after the other.  
For a detailed step-by-step guide with further information, please refer to this [support article](https://support.sosafe.de/ProductDoc/e-learning-course-setup).

## Managing and editing created E-Learning courses

Course Management also allows you to review and edit created E-Learning courses. The available editing options and processes depend on the current status of the E-Learning course.

Here is an overview of the E-Learning course statuses:

* **Running** = running E-Learning course

* **Scheduled** = the 6-step course creation process is complete and the course has been scheduled to launch at a future date

* **Draft** = the creation of a new E-Learning course has begun, but it is incomplete or has not been confirmed yet

* **Finished** = a finished and inactive course

To view or edit the settings of a course, select the **pencil icon** in the **Actions** column. Depending on the current status of your course, different options will be available to you.  
![image-20260625-062836.png](https://support.sosafe.de/__attachments/a_75a6bc046a8b9b8968a49a2f55a2c2dc6d947b8e8f13770e79010dd7b5e285eb/image-20260625-062836.png?cb=4ea0c198ffcd618d99118c7363500508)

The following sections show you which adjustments you can make in each case:

### a) Editing a course in "Draft" status

After selecting the **pencil icon**, you will land on the first page of the guided 6-step process.  
![image-20260624-142616.png](https://support.sosafe.de/__attachments/a_4ad373aeef83b673beb51d249e31acb60ccee9d2a212e1b40acbee0b436ae8d3/image-20260624-142616.png?cb=e00aaed3b22f0b4445faa41c4d92281a)

1. Make your adjustments in the desired steps.

2. Select **Continue** to move through the subsequent steps until you reach the course overview.

3. Select **Launch course** to save your changes and officially activate the E-Learning.

![image-20260624-142650.png](https://support.sosafe.de/__attachments/a_f8fb25d14bbe66f65a67a29757cfa840c7ff800c59ab3c7b7ef86b684df929c8/image-20260624-142650.png?cb=c40cae840ddbc39128aa1a9cde779933)

Note: The status of the course will now change from **Draft** to **Scheduled**. If you wish to make further changes to this course at a later time, you can do so at any time. The procedure for this can be found in the following section.

### b) Editing a course in "Scheduled" status

After selecting the **pencil icon** , you will be directed to the **Course overview**.  
![image-20260624-142738.png](https://support.sosafe.de/__attachments/a_df52b1295d292d153bad4db14b220184480e11a6ae626029940baf093178f518/image-20260624-142738.png?cb=0c4c012ea9ff687f7f3ab6877c75573a)

1. Within the listed **completed step section**, select the respective pencil icon of the step to make specific changes to that step.

2. Select **Continue** to move through the subsequent steps until you are back at the course overview.

3. Select **Update course** to save your changes. You will then be automatically redirected back to the Course Management page.

### c) Editing a course in "Running" status

After selecting the **pencil icon** , you will also land on the **Course overview**.  
![image-20260624-142833.png](https://support.sosafe.de/__attachments/a_0711931f872ecad6dac02003dc98fe70b12415cd8986536553507e12e80e36b0/image-20260624-142833.png?cb=3660c58c071c899d9a6c2258c392d69c)

**Changing settings:**

1. Select the **pencil icon** next to the desired step in the completed **step section** to make adjustments.

2. Select **Continue** to move through the subsequent steps until you are back at the course overview.

3. Select **Update course** at the end to apply the changes.

Note: The start date of courses that are already running cannot be changed retroactively.

**Ending a course prematurely:**

If you want to stop the course, select the red **End course now** button and confirm the action.  
Attention: This action is irreversible. A completed course cannot be restored.

### d) Viewing a course in "Finished" status

Courses with the **Finished** status cannot be edited retroactively. However, you can check the applied settings at any time by selecting the **eye icon** in the **Actions** column.  
![image-20260625-063217.png](https://support.sosafe.de/__attachments/a_d437b31e2cb3eca15e1aa453509cad972330242c1ab05c132677dac667b58f46/image-20260625-063217.png?cb=d9618ba7649b9b0bfa9d24a4f22e84a0)

You will then be redirected to the course overview to review the settings.

## Duplicating E-Learning courses

You can easily reuse already created courses as templates by duplicating them.  
Duplicating a course is particularly useful for your second-year campaign, for instance.

1. In the **Actions** column, select the **double rectangle icon (Duplicate)** next to the desired course.

![image-20260625-062932.png](https://support.sosafe.de/__attachments/a_a15d21e098c1e99966b11e14d1bbe1ae4ab9d91e869c72aadbe02a2b2b833560/image-20260625-062932.png?cb=1bdb28b837d915b2980211ee7ff4c8d9)

2. The duplicated course will immediately appear as a new **Draft** in your course overview.

3. The title of the original course will be adopted and appended with **(Copy)** for better recognition. You can now freely edit and customize this draft.

---
language: "en"
---
# E-Learning course setup

**Read this article in:** [++**German**++](https://de.support.sosafe.de/pdok/e-learning-kurs-erstellen)  
This article covers creating a campaign for Premium customers. If you're on the Professional plan, some options might be limited.

Setting up your own E-Learning course is an easy 6-step process that will only take a few minutes to complete. Let's go!

1. **Course details**

Give your course a **name** and select the **start** and **end date**. We recommend a 2-week window before the course start date to give you time to communicate the upcoming e-learning to employees.

In addition, you can **limit lesson visibility**. This means that learners will only be shown lessons that are due within the next 90 days. The purpose of this setting is to focus learner efforts on what is most critical and to support continuous, sustainable engagement instead of a one-time learning rush.

You also have the option to activate a **pre-course assessment**. Pre-course assessments are short knowledge checks on the contents of selected lessons. These are designed within our system to allow lessons to be skipped if learners successfully complete the corresponding pre-course assessment.

Several options are available for this setting:

* **On -- for returning learners**: This option is suitable if you are launching a second or a follow-up E-Learning course and some lessons from the previous course are repeated. Learners who have already participated in the previous course can test their existing knowledge of the familiar content via the pre-course assessment and skip the lesson if applicable.

* **On -- for all learners**: All learners are given the opportunity to complete the pre-course assessment in advance to skip lessons directly if they possess the relevant prior knowledge.

* **Off**: No pre-course assessment will be presented, and all learners proceed directly to the lesson.

![image-20260624-135435.png](https://support.sosafe.de/__attachments/a_948f18018cec3845a1ffb404ed004b0f25c2286f63d1548efc65ebf5812469d2/image-20260624-135435.png?cb=7374c42d2190e57844108824930962c2)

2. **Audience**

The course can include either **all users** or only the **user groups of your choice** . Either way, this screen will show you how many employees will be part of the course. Select **Save changes** to proceed.  
![Screenshot 2026-06-16 at 12.45.19.png](https://support.sosafe.de/__attachments/a_5da6d1837d23a7dd46f31f6eed273b6f02805ec7954765043a57c4f29de37989/Screenshot%202026-06-16%20at%2012.45.19.png?cb=b9a8e112f4cd55ff952f6efafdb0cc4e)
All users  
![Screenshot 2026-06-16 at 12.45.30.png](https://support.sosafe.de/__attachments/a_3b61c3a1187d9666caf904af0ee92919ba328ff18f15236ddc5f3bbc7b842734/Screenshot%202026-06-16%20at%2012.45.30.png?cb=492855f596050b643639cd3481fdc694)
User group selection

3. **Lesson assignment**

Here you can choose from all lessons available to you. The default selection will be our **starter pack**, consisting of 19 lessons, as well as up to 6 survey-based lessons. The starter pack covers the most important basics of secure behavior. The survey-based lessons, meanwhile, provide additional content based on relevancy. When employees first log in, they will see a brief survey asking them if they work from home or use a company phone, for instance. If they answer 'Yes' to some of these questions, the corresponding lessons will be added to their learning path.

Note that you can add further mandatory modules from our lesson library by selection **Add lesson** . Note that any lessons you deselect in the dialog window that opens will also be removed from your mandatory lesson selection.

You can also preview individual lessons or set specific due dates by selecting the 3 dots (**...)** next to the corresponding lesson.  
![Screenshot 2026-06-16 at 12.45.45.png](https://support.sosafe.de/__attachments/a_7ad40475e67569963e13c35879989562267ccd07a9d01ff6a35512c1e2da0c6b/Screenshot%202026-06-16%20at%2012.45.45.png?cb=3af12aae36be0b5ca71a4b8fc2e1164d)
Lesson assignment  
![Screenshot 2026-06-16 at 12.45.55.png](https://support.sosafe.de/__attachments/a_e838dc8d8b141b4f68d34e24adedfc8633f32f0b73878368d33fe13da4990ef5/Screenshot%202026-06-16%20at%2012.45.55.png?cb=1232f50123aeafd695c676cd2ffdebcd)
Add lesson dialog window

4. **Email notifications**

Here you can set which type of email notifications should be sent to employees. Select the toggle to activate or deactive individual reminders or select **Preview** to see how they will look.  
![Screenshot 2026-06-16 at 12.46.19.png](https://support.sosafe.de/__attachments/a_2f511bc0940b4b1f8e30e5a326d8317f2c3aceb1c92d917bad8e4743f6ed26b9/Screenshot%202026-06-16%20at%2012.46.19.png?cb=3707b2db24cce49eaf0ebba20f26636f)

5. **Reporting method**

**Individual** reporting allows deeper insights into individual employee learning success. **Anonymous** reporting still allows you to track completion across your company. Note that this setting has data privacy implications.  
![Screenshot 2026-06-16 at 12.46.40.png](https://support.sosafe.de/__attachments/a_8cd478b7974e1172fb43bf72af1f228f42da1f16b96b783b9ac9b6e10aa283f9/Screenshot%202026-06-16%20at%2012.46.40.png?cb=5316e2b8b2245ef5ee3fdf833d6f6cbf)

6. **Employee login**

By default, employees will be using their **email address to log in**. If you aren't using single sign-on (SSO), your users will have to register an account. If you're using SSO, they only have to enter their email address.  
If you're still using SSO through a SCIM/SAML connection: In this step you will be asked whether you want to enable SSO logins for this course.

You can also enable access to the course using a **code** that you can specify. To do so, select **Yes** and enter a code. This is a great solution for employees without a dedicated email address. See <https://support.sosafe.de/ADOC/access-code-users> for more details.  
![Screenshot 2026-07-28 at 11.23.21.png](https://support.sosafe.de/__attachments/a_bf4e0373bb71d5d2f04fe5261b69f767c3f5b8852a0156c7abc56f5fb99d7efa/Screenshot%202026-07-28%20at%2011.23.21.png?cb=063f583b88ee5d34841aa3222660b381)

7. **Overview \& launch**

On this final screen, you will see an overview of your settings. You can go back to any of the steps and make edits as you wish. If you're happy with your settings, select **Launch course. Congrats!**  
You can update your settings at any time, even after your course launches.  
![Screenshot 2026-06-16 at 12.46.57.png](https://support.sosafe.de/__attachments/a_bfbd1c6e709636f0c7f8aef8e06465093abbf265326b902bf19de892bfa1ea5c/Screenshot%202026-06-16%20at%2012.46.57.png?cb=f6b23bbbfa80a5bab0d9af2f00a28826)

---
language: "en"
---
# E-Learning on track metrics

## On track

Percentage of users in various E-Learning module completion states, with respect to the module assignment due dates:

* **On schedule**: Users who have completed all mandatory modules due before today.

* **Less than 30 days behind**: Users who have outstanding overdue modules, but no module is more than 30 days overdue.

* **Less than 90 days behind**: Users who have outstanding overdue modules, but no module is more than 90 days overdue.

* **More than 90 days behind**: Users who have outstanding modules more than 90 days overdue.

The "doing well" percentage shown inside the pie chart is the sum of users On schedule + Less than 30 days behind.

This chart is only available for Personalized Learning campaigns.  
![Bildschirmfoto 2025-02-14 um 08.55.11.png](https://support.sosafe.de/__attachments/a_c534e9cb64727295d5f345029eab858628da685511b1f9a662204d64719c87b3/Bildschirmfoto%202025-02-14%20um%2008.55.11.png?cb=fd88f089532bf2cf6831277d7b90b3c2)  
**Impact**

With Personalized Learning, the idea is to encourage long-term sustainable learning spread out in chunks over time. Thus, the traditional completion rate here fails to adequately address the question of which users are currently in the desired completion state. The on track metric fills this gap by displaying the percentage of users who have completed the share of modules already due.

### Multiple campaigns / Multiple tenants behavior

Metric is not available.

### Module split filter behavior

No impact

---
language: "en"
---
# E-Learning metrics

## Overview metrics

These metrics aim to give you the most important KPIs at a glance.

### Registration rate

**Definition**

The registration rate shows percent of invited users to a campaign who have registered on the E-Learning platform.

**Calculation**

`Registration count / Potential user count`

**Impact**

Only registered users can actually participate in the e-learning. The higher the registration rate, the better.  
![Screenshot 2024-06-26 at 10.52.22.png](https://support.sosafe.de/__attachments/a_582cd4073797ae187db8cd99b5e7797690674edf34da3687c7ab9a36e90159d6/Screenshot%202024-06-26%20at%2010.52.22.png?cb=3ea1e5854292be54a994d335ce08b7b9)

### Starting rate

The starting rate shows percent of potential users in a campaign who have completed at least one module as defined in the base definitions.

**Calculation**

`Started user count / Potential user count`

**Impact**

Completing a lesson is the next step in terms of engagement after registering. The higher the starting rate, the better.  
![startingrate.png](https://support.sosafe.de/__attachments/a_745e061a07a86e312260011ef5110a998f66a0c0820c0ea9ad444ceaed248c06/startingrate.png?cb=ca53cc81e7f27a359b40fa2630ceeeea)

### Completion rate

**Definition**

The completion rate shows percent of potential users in a campaign who have completed all modules as defined by in the base definitions. **Note:** At the top of the e-learning Analytics page, you can select whether all lessons should be taken into account, or whether you only want to consider either mandatory or optional lessons. When you're using Personalized Learning, the completion rate will by default only factor in mandatory lessons.

**Calculation**

`Completion count / Potential user count`

**Impact**

This metric can vary substantially depending on how many lessons are included in your e-learning and how much time has passed. While a high completion rate is desirable, it is normal for it to take a while. Steady learning over time instead of forcing your users to complete the e-learning as quickly as possible leads to better outcomes.  

![completionrate.png](https://support.sosafe.de/__attachments/a_0c5e7fb54fabd3631bb2cb296b3f4fc9651008c8d5557c75ea6dcfd1bf5fa384/completionrate.png?cb=39af3eeef72592098040e38b38a2495d)

### Module Split Filter Behavior

Completion count follows the module split filter logic, and shows completion for the selected module set.

## Multiple campaigns / Multiple tenants behavior

**Classic Learning:** For all overview metrics, the calculation for multiple campaigns and multiple tenants uses simple addition on each metric component. This means that if the same registered user is invited to multiple campaigns, they will be included in the registration count for each campaign being considered in the calculation.

**Personalized learning:** (multiple tenants only) For all overview metrics, the calculation for multiple tenants uses simple addition on each metric component.

---
language: "en"
---
# E-Learning registration metrics

## Registrations over time

![elearning-registrations-overtime.png](https://support.sosafe.de/__attachments/a_f47abcb4a795372243863e7f982934de439744d8f9ea5050bfa4ff3426529cd0/elearning-registrations-overtime.png?cb=6cb4d3e75de782179e38e2acb12168a3)

### **Definition**

Cumulative count of registrations over time. Users register only once, so campaigns created later will generally start with a non-zero registration count.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** All users included in either campaign or tenant are included, but each user is only counted one time, no matter how many campaigns that user is part of. Due to this behavior, the latest registration rate is likely not to match between the base registration rate and registrations over time metrics.

The bounds of the chart are expanded to include the time between the start of the earliest campaign and the current date.

**Personalized Learning:** (multiple tenants only) All users included in either tenant are included. Registrations are superimposed and the chart reflects the cumulative addition of total registrations from all tenants on each date.

The bounds of the chart are expanded to include the time between the start of the earliest tenant campaign and the current date.

## Registrations by user group

![elearning-registrations.png](https://support.sosafe.de/__attachments/a_afc25462e0cee6e417f05b5d03da7bbbb4432ca5e4ce69e551225f02380928cd/elearning-registrations.png?cb=e3dfe4f7f84237d8751e26b157aa8ea1)

### **Definition**

This shows the percent of invited users who have registered broken down by user group. The chart tooltip also gives the count of users in each user group who have registered and the total number of users in the user group.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** All user groups included in each campaign and tenant are included. If a user group is included in multiple campaigns, the components for that user group's bar are simply added together. This means, for example, if a user group has 15 members and is included in two selected campaigns, the bar will show starting rate out of 30. Due to this behavior, the latest registration rate is likely not to match between the registrations over time and registrations by user group metrics.

Values for individual bar counts and rates will not change for multiple tenants, since users are invited by user group.

**Personalized Learning:** (multiple tenants only) All user groups included in each tenant are included. Values for individual bar counts and rates will not change for multiple tenants, since users are invited by user group.

---
language: "en"
---
# E-Learning starting rate metrics

## Starting Rate by user group

![Elearning_started_user.png](https://support.sosafe.de/__attachments/a_ea98824d70c4512342893e60dfffc1a448f3aea0de43b1a20ddb66cf53afde04/Elearning_started_user.png?cb=41f977bcda8dea60dc04c04b28facf7d)

### **Definition**

This shows the percentage of invited users who have started at least one module, broken down by user group. The chart tooltip also gives the count of users in each user group who have started and the total number of users in the user group.

### Multiple campaigns / Multiple tenants behavior

**Classic Learning:** All user groups included in each campaign and tenant are included. If a user group is included in multiple campaigns, the components for that user group's bar are simply added together. This means, for example, if a user group has 15 members and is included in two selected campaigns, the bar will show starting rate out of 30.

Values for individual bar counts and rates will not change for multiple tenants, since users are invited by user group.

**Personalized Learning:** (multiple tenants only) All user groups included in each tenant are included. Values for individual bar counts and rates will not change for multiple tenants, since users are invited by user group.

---
language: "en"
---
# E-Learning user overview

The user overview table provides a set of user-specific metrics for each invited user in the campaign. The table is available if individual user tracking is enabled, and it can only be viewed for a single campaign.  

|     **Column**     |                                                                                              **Description**                                                                                              |
|--------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| First name         | User's first name (given name)                                                                                                                                                                            |
| Last name          | User's last name (family name)                                                                                                                                                                            |
| Email              | User's email                                                                                                                                                                                              |
| User group         | User's user group                                                                                                                                                                                         |
| Registered         | Registration date if the user has registered. Otherwise shows "Not registered".                                                                                                                           |
| Learning status    | The user's current learning progress. Possible values are **On track** , **Overdue** , or **Completed** . See [E-Learning on track metrics](https://support.sosafe.de/ProductDoc/e-learning-on-track-metrics.md) for more details. |
| Days overdue       | The number of days a user is past the deadline for their mandatory modules. Shows "0" if the user is not overdue.                                                                                         |
| Modules overdue    | The number of **incomplete** mandatory modules with a due date in the past. This column is automatically hidden if no users in the campaign are overdue.                                                  |
| Modules completed  | The number of completed modules out of the total assigned modules. Select the **Eye icon** to view the individual module breakdown.                                                                       |
| Completion results | Average score of all completed modules for the user.                                                                                                                                                      |
| Certificate        | Contains a button to download individual certificates in a ZIP file if the user has completed all mandatory modules. When incomplete, the button shows as disabled.                                       |

## Multiple campaigns / Multiple tenants behavior

Metric is not available.

### Module split filter behavior

For the **Modules completed** and **Modules overdue** columns, only modules that fit the filter are included in the counts.

Certificate availability is always determined by Mandatory modules, and is unaffected by the filter.

All other columns are unaffected.

## User-specific completed modules breakdown

Module breakdown for **completed** modules by a specific user. The table opens in a new dialog after clicking the **Eye icon** in the **Modules completed** column for the given user. When there are no completed modules for a user, the modal shows the text "This user hasn't passed any modules yet".  

|   **Column**    |                 **Description**                  |
|-----------------|--------------------------------------------------|
| Modules         | Name of the completed module.                    |
| Results (0-100) | Score achieved, or 100 if no score is available. |

### Multiple campaigns / Multiple tenants behavior

Metric is not available.

### Module split filter behavior

Only individual completion instances according to the filter setting are displayed.

---
language: "en"
---
# E-Learning user rating metrics

## User rating

**Definition**

This shows the mean of E-Learning user rating for all users in a tenant. Users can rate the E-Learning platform experience out of five stars. The five star display rounds to the nearest star. The metric also displays the total count of ratings received.  
**Impact**

This gives a good indication of how happy your employees are with the e-learning platform. If your rating is low, we suggest reaching out to find out whether there might be issues with deadlines being too tight, for instance.  
![elearning-userrating.png](https://support.sosafe.de/__attachments/a_998a73ea926992ed9e54dedbebbb72f95374e0ac3310f3879031ff99079c6cbe/elearning-userrating.png?cb=f2618419bc84d8fc271d83f5f3d741f4)

### Multiple campaigns / Multiple tenants behavior

Individual E-Learning user ratings from all included tenants are averaged. Since this metric always includes all campaigns for a given tenant, multiple campaigns in Classic Learning will have no effect on this metric.

---
language: "en"
---
# Follow-up campaigns

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/follow-up-campaigns)**,** [**German**](https://de.support.sosafe.de/pdok/folgekampagnen)

## Overview

As an administrator, you can now set up both Phishing Simulations and E-Learning courses on your own. The following article will guide you through setting up follow-up campaigns based on the results of previous campaigns.  
**Note** : Please log in to the Manager to check the duration of your current Phishing Simulation and E-Learning course. You can find campaign data in the upper right corner of the respective **Analytics** section.  
![Screenshot 2026-08-07 at 17.47.29.png](https://support.sosafe.de/__attachments/a_1ea81adc6dfda3402d6ef41368c6194fec1acfbe55fd769f72bc21f93a859ae1/Screenshot%202026-08-07%20at%2017.47.29.png?cb=4c09757121cb430a9d72f7773cce3af2)

## Phishing Simulations

### Key metrics

![Screenshot 2026-08-07 at 17.48.43.png](https://support.sosafe.de/__attachments/a_5b1d6414272640be445e319857d2adf0265d0ab96db4a7e46474d6447626851d/Screenshot%202026-08-07%20at%2017.48.43.png?cb=6dc881d53abb21e48b953c40a86d5ee0)

Here you can assess how resilient your organization is to phishing attacks.

* **Click rate**: The percentage of users who clicked on a link or element in a phishing email. The primary goal is to reduce this percentage over the long term.

* **Interaction rate**: The percentage of users who entered sensitive data on a fake landing page or enabled macros.

* **Reporting rate**: The percentage of users who actively reported the email using the phishing report button. A rising reporting rate is often more meaningful than a falling click rate, as it indicates an active "human firewall".

You can find a detailed breakdown of all Phishing analytics [here](https://support.sosafe.de/ProductDoc/simulation-base-metrics).

### Basic Phishing Simulations

Basic Simulations are designed to establish a stable baseline level of security awareness across your organization.  
**Note**: Basic simulations are available from the Essential package onwards.

* **Target audience:**All employees in the company (the full user list).

* **Focus:**Recognizing common phishing indicators (e.g., incorrect sender addresses, generic salutations and urgent calls to action).

* **Frequency:**Continuous, randomized distribution throughout the year to minimize habituation.

![Screenshot 2026-08-07 at 17.51.10.png](https://support.sosafe.de/__attachments/a_ef2173a18b99e519c19e62dfa7425e252939764e24c5d5606cd17ff6f0cb79b2/Screenshot%202026-08-07%20at%2017.51.10.png?cb=9ed669c05b4a20bd6a26f4a159917a04)  
**Our recommendation**:

* **Duration:** Approx. 1 year.

* **Number of templates:** 12 to a maximum of 24 for a 1-year campaign.

* **Difficulty:** Adjust difficultylevel and include templates with simulated login pages based on previous analytics.

* **Other**: If the click rate is very low (\< 5%), make templates more challenging.

### Targeted Phishing Simulations

**Note**: Targeted phishing simulations are available from the Premium package onwards. If the behavior-based simulation is currently enabled and you would prefer targeted simulations instead, please contact us to switch.

Unlike Basic Simulations, Targeted Simulations let you run separate campaigns for specific user groups.

* **Target audience:**High-risk departments such as Finance, HR, or IT Administration; also useful for addressing varying knowledge levels across groups.

* **Scenarios:** Templates that mimic real work situations (e.g., fake job applications for HR or spoofed invoices for accounting).

* **Goal:** Build awareness of sophisticated social engineering attacks.

![Screenshot 2026-08-07 at 17.51.48.png](https://support.sosafe.de/__attachments/a_ac98b2883def22a32b4e7f530aa8d84aabd6483b175dce1f839abeb1a4035810/Screenshot%202026-08-07%20at%2017.51.48.png?cb=f5dc62bb076b0139376ecfbf2f2a2d5c)  
**Our recommendation**:

* Run a basic simulation for all users with general templates.

* Additionally, run targeted simulations for high risk user groups.

* **Duration**: Approx. 1 year (align duration across all active campaigns).

* **Number of templates**: Users should receive 12--24 templates per year in total across all simulations.

* **Difficulty**: Adjust difficulty level and include templates with simulated login pages based on previous per-group analytics.

* **Other** : You can also create custom templates using our [++Template Studio++](https://support.sosafe.de/ProductDoc/simulation-studio-how-to-guide).

Detailed instructions for creating a targeted phishing simulation can be found [++here++](https://support.sosafe.de/ProductDoc/create-a-targeted-simulation).

### Behavior-based Simulation

**Note**: Behavior-based phishing simulations are available from the Premium package onwards. If you would prefer to use targeted simulations rather than behavior-based ones, please let us know, and we will disable this feature.

This simulation adapts dynamically to each user's behavior.

* **Target audience:**All employees in the company (the full user list).

* **Trigger logic:** Template difficulty adjusts based on each user's click behavior (users who identify easier templates will receive progressively harder ones).

* **Goal:**Keep users engaged by matching challenge level to their current knowledge.

![Screenshot 2026-08-07 at 17.52.11.png](https://support.sosafe.de/__attachments/a_666825a6eb456ea2bd3ab8b11ed75aef904576fc1d4f74dcba6e43341f15731a/Screenshot%202026-08-07%20at%2017.52.11.png?cb=691e9139c74c739a4eae1249af638732)  
**Our recommendation**:

* **Duration**: Approx. 1 year

* **Number of templates**: No fixed minimum --- the more templates available, the better the adaptation.

* You can also create custom templates using our [++Template Studio++](https://support.sosafe.de/ProductDoc/simulation-studio-how-to-guide).

You can find detailed instructions for creating a behavior-based phishing simulation [++here++](https://support.sosafe.de/ProductDoc/create-a-behavior-based-simulation).

## E-Learning

### Key metrics

![Screenshot 2026-08-07 at 17.49.10.png](https://support.sosafe.de/__attachments/a_3d8d2f6ec19d87bbaed494edf7bd0df341b714d0a56e21e83e7d36bed3a5f566/Screenshot%202026-08-07%20at%2017.49.10.png?cb=abd9ebf76f0a65d9f59a1b6bb44a0763)
Overview of the key metrics on **Analytics / E-Learning**

This is where progress through training modules is tracked --- particularly important for audits and certifications.

* **Learning Progress**: How many users are on track, and how many are falling behind? (Key metric: Useful for identifying early whether users are progressing at the right pace).

* **Completion Rate**: The percentage of users who have fully completed their assigned mandatory courses. (Most meaningful in the final weeks of the campaign).

You can find a detailed overview of all e-learning analytics [++here++](https://support.sosafe.de/ProductDoc/e-learning-overview-metrics).

### E-Learning courses for all users

**Note** : E-learning courses are available from the Essential package onwards. If a course in the course overview displays the message "*Older lesson format - cannot be edited*" please contact us to have it edited.

* **Target audience:** All employees (the full user list).

* **Focus:** Interactive knowledge transfer, understanding of security policies, identifying everyday risks, and completing competency assessments for audits.

* **Frequency:** Ongoing training throughout the year, with annual refresher sessions and pre-course assessments.

![Screenshot 2026-08-07 at 17.50.09.png](https://support.sosafe.de/__attachments/a_1b427e6e452686c91b6c4061c078bc0b7a57ff63a4f2e00b81a016b0630e8d1a/Screenshot%202026-08-07%20at%2017.50.09.png?cb=f0698640563b6b8ff29678bca103ee91)  
**Our recommendation**:

* **Duration**: Approx. 1 year.

* **Number of modules**: varies; typically at least 2--3 modules per month (120 learning minutes per year).

* Enable pre-course assessments for users who have previously completed cybersecurity training.

**Note**: Users added after the course starts will automatically receive an invitation. Learning paths (i.e., the modules) are dynamically distributed over the remaining course duration.

### E-Learning courses for specific user groups / Concurrent courses

**Note**: When a single course would not serve all employees equally well, this may lead to frustration, wasted time, and unnecessary module completion. While survey-based modules within a course already provide some personalization, running parallel courses may be the right choice in the following scenarios:

* Role-specific onboarding (Orientation)

* Different compliance requirements (Mandatory training)

* Targeted training for management or leadership

**Important**: Course assignment is based on user groups. Each user group can only be assigned to one course at a time. Avoid moving users or user groups between courses while they are running --- this can distort analytics and may cause users to repeat modules.

The more concurrent courses you run, the greater the administrative burden and the higher the risk of errors for the administrators.  
**Our recommendation**:

* **Duration**: Approx. 1 year (same duration for all courses)

* **Number of modules**: varies; typically at least 2--3 modules per month of course duration.

* Keep the number of parallel courses to a minimum to reduce administrative complexity.

* Enable pre-course assessments for users who have previously completed cybersecurity training.

### Migration to new SSO

If you haven't already done so, please switch to our new, improved single sign-on solution based on Auth0. It offers a much better user experience and is more secure as well. If you have admin rights, the migration only takes a few minutes. You can find more information [++here++](https://support.sosafe.de/ADOC/sso-migration-to-auth0).

### Custom modules

**Note**: Available from the Premium plan onwards.

You can also extend your e-learning course with your own modules. Two options are available:

* **Policy-to-Lesson:** Use the AI in [++Policy-to-Lesson++](https://support.sosafe.de/ProductDoc/policy-to-lesson) to convert company policies in PDF format into lessons, add a quiz, and activate them in a course just like any other module.

* **SCORM Upload** : Upload your own [++SCORM files++](https://support.sosafe.de/ADOC/custom-modules-lessons-general-information-faq) and activate them in the course.

---
language: "en"
---
# How are click rates evaluated while maintaining anonymization?

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/how-are-click-rates-evaluated-while-maintaining-an), [**Deutsch**](https://de.support.sosafe.de/pdok/wie-werden-klicks-ausgewertet-ohne-die-anonymisier)

Personal data are not obtained when carrying out and processing the phishing simulation.

Therefore, none of the behavioral data (e.g. clicks on links in the simulated phishing emails) are tied to personal data but instead assigned**randomly generated codes** and stored with these codes. The system conducts this anonymization process automatically (**privacy by design**).

---
language: "en"
---
# Human Risk Management

Preview the next iteration of cyber security risk awareness - the Human Risk OS™  
**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/human-risk-management), [**Deutsch**](https://de.support.sosafe.de/pdok/human-risk-management)  
🎉  
**Coming soon!**Reach out to your Customer Success Manager if you're interested in what you see here.

We're currently busy building out our Human Risk Management platform. We've prepared a short interactive demo to introduce some of the ideas and give you a preview of what will be available to you very soon. If you're curious about the concept of Human Risk Management overall, we've collected some info material further down in this article.

If you're more of a reader, check out this page from our glossary:

<https://sosafe-awareness.com/glossary/human-risk-management/>

If you'd rather hear from our Chief Security Officer Andrew Rose and CEO Niklas Hellemann, check out the following videos:  
<https://www.youtube.com/watch?v=09vLumL8QLg>

<https://www.youtube.com/watch?v=vGQdHgEXcRw>

<https://www.youtube.com/watch?v=tyF29JsQdMM>

<https://www.youtube.com/watch?v=TuCrCGnpKak>

[https://www.youtube.com/watch?v=-7rs86kHFD0\&t=1s](https://www.youtube.com/watch?v=-7rs86kHFD0&t=1s)

<https://www.youtube.com/watch?v=OcjSkS-hzK8>

---
language: "en"
---
# Instant Alerts

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/instant-alerts)

Sofie Instant Alerts help you to quickly inform the entire company about relevant attacks, vulnerabilities, or other urgent cyber security news. The Alerts are created in the SoSafe Manager and sent via the MS Teams bot Sofie, so that the employees will receive the alert as a direct message. Learn in this article how to create engaging alerts your employees. Find the feature in the [SoSafe Manager](https://manager.sosafe.de/) at **Sofie / Instant Alerts**.

## How to create Instant Alerts

You have the option to either create Alerts manually or use generative AI to create Alerts automatically.

### Creating Alerts manually

You can watch this short interactive presentation or check out the written guide below.  

1. **Choose an engaging headline**

2. **Add the message**

   1. Salutation

   2. Description: What has happened?

   3. Call-to-Action: Finish with a clear action - What does the employee need to do?

3. **Add an image to accompany your message (optional)**

4. Select **Send alert** to make sure it arrives immediately or unselect **Send immediately** to schedule it for a certain point in time. If you do not want to commit to it yet, you can also select **Save draft**.

![Screenshot 2025-07-31 at 18.08.17.png](https://support.sosafe.de/__attachments/a_0e09f675660f83cc27cc4e494da5fe0a52de126300aabf962db88769ec8da015/Screenshot%202025-07-31%20at%2018.08.17.png?cb=4c8f5d0952aa545dc8fdad3a3d104d0d)

![image-20240415-131700.png](https://support.sosafe.de/__attachments/a_4fc7ca4f26f2cba58e4dc454fec1dee44ad54e5e6813153eebeb747e5d3f01f0/image-20240415-131700.png?cb=236e83c164c1c7407220355e81d86cba)  

|                                            Use Case                                             |                                                                                          How Instant Alerts help                                                                                          |
|-------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Your company is targeted by a general or spear phishing campaign                                | Security leaders can instantly alert the whole company                                                                                                                                                    |
| If you are facing vulnerabilities or experiencing downtime, you need to inform others about it. | Instantly alert the whole company or specific user groups\* about dangerous vulnerabilities or expected downtime information. \*sending alerts to specific user groups will be available with full access |
| Your next audit is coming up                                                                    | Use Instant Alerts to easily remind your staff on important policies or processes before the next audit.                                                                                                  |

### Create Alerts with generative AI

You can watch this short interactive presentation or check out the written guide below.  

|                                                       Use case                                                       |                                             How Instant Alerts help                                             |
|----------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------|
| You want to inform the company about a new attack method that for example is targeting your industry or company size | **Keep awareness high** and quickly react to new attack scenarios using Instant Alerts for **micro-enablement** |

**Example:**

1. Select **Create new alert**

2. Select **Generate alert with AI**

3. Paste the link you want the AI to summarize

4. Select **Generate**

5. Optionally: Finetune and edit the auto-generated Alert to your needs. (Recommended)

6. Optionally: Upload an image to make the Alert more appealing for end-users. (Recommended)

![Screenshot 2025-07-31 at 18.10.20.png](https://support.sosafe.de/__attachments/a_0137d1997c30786c1be24c8d5b4681d66a53d7003487034e15bb726e7b5a3a2d/Screenshot%202025-07-31%20at%2018.10.20.png?cb=c34351b7c3b958030efc7f0016fd3732)  
![Screenshot 2025-07-31 at 18.11.29.png](https://support.sosafe.de/__attachments/a_de60534f38418fcadaabf265c7dfc5ebb92bc42185fa498d90bb38b2e672b679/Screenshot%202025-07-31%20at%2018.11.29.png?cb=17218b3e0757393c0d7f071e70d89ca9)

## How to send alerts in different languages

## Where to find Alerts: Drafts \& Scheduled and sent

Scroll down to find an overview of your **drafts** as well as all **Scheduled and sent alerts**.  
![Screenshot 2025-07-31 at 18.12.44.png](https://support.sosafe.de/__attachments/a_77864594f562b30005304129f8fe8d1069d5e6a49e94796b17ee4189a03367f0/Screenshot%202025-07-31%20at%2018.12.44.png?cb=c4785f24415c6fe2732da8dcc4a2ef01)

---
language: "en"
---
# ISO Analytics

You can find out more about our ISO analytics for Simulation and E-Learning on the pages below.

[ISO Simulation Analytics](https://support.sosafe.de/ProductDoc/iso-simulation-analytics.md)

[ISO E-Learning Analytics](https://support.sosafe.de/ProductDoc/iso-e-learning-analytics.md)

---
language: "en"
---
# ISO E-Learning Analytics

This article looks at ISO e-learning analytics for customers who use Personalized Learning. If you use classic e-learning, the calculations will be different.

## ISO Score

This represents the most recent month's ISO score. See [Proof of Implementation](https://sosafegmbh.atlassian.net/wiki/spaces/PDOC/pages/edit-v2/2093842630?draftShareId=eb76e042-7ea9-4ed6-9561-80b8346efc69#Proof-of-Implementation) down below for information about how it's calculcated.  
![elearning-isoscore.png](https://support.sosafe.de/__attachments/a_29da0c755eee72ab16e7613a7233276a24d8205f391610b9b29b0aa6d1d522d5/elearning-isoscore.png?cb=7aa37619b0cda6c7b014ba3b75acb448)

## Awareness Training Level

This chart shows past monthly ISO scores. Each month is cumulative and relies upon the number of completed mandatory modules from the start of the campaign till today AND the total number of assigned mandatory modules due by the last day of the past month.  
![elearning-isoawareness.png](https://support.sosafe.de/__attachments/a_72e4683b6d7b37f7b323a9ebe1e5874f9fd2ccef6f30b9601cae7936f0d198c1/elearning-isoawareness.png?cb=a935c92472b419c56a9dd5a5346929fd)

### Proof of Implementation

|         **Column**          |                                                                                                                                                                      **Description**                                                                                                                                                                      |
|-----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Month                       | Year and month for the calculation. All calculations are cumulative for the PL tenant. The date range runs from the start of the tenant's PL tenure until the end of the last day of the indicated month.                                                                                                                                                 |
| Total Employees             | Number of employees included in the campaign.                                                                                                                                                                                                                                                                                                             |
| Total Mandatory Modules Due | Total number of available mandatory modules due by the beginning of the current month.                                                                                                                                                                                                                                                                    |
| Total Completed Modules     | Total number of successfully completed mandatory modules by today.                                                                                                                                                                                                                                                                                        |
| Successfully Completed %    | Total number of successfully completed mandatory modules by today / total number of mandatory modules due by the beginning of the current month \* 100.                                                                                                                                                                                                   |
| Calculation                 | `Total number of completed mandatory modules by today / Total number of available mandatory modules due by the last day of the past month * 100` Unlike with classic e-learning, all modules in Personalized Learning are available to all users from the start of the campaign. Because of that, the ISO score is only concerned with mandatory modules. |

---
language: "en"
---
# ISO Simulation Analytics

ISO scoring gives a standard way for companies to show their progress for certification. Progress is tallied at the end of each month, and a progressing score is also shown for the current month.

## ISO Scoring

This represents the most recent month's ISO score. See [Proof of Implementation](https://sosafegmbh.atlassian.net/wiki/spaces/PDOC/pages/edit-v2/2094039301?draftShareId=db079659-8f56-4fe6-9524-4dcb701a17e2#Proof-of-Implementation) for information about how it's calculated.  
![simulation-isoscoring.png](https://support.sosafe.de/__attachments/a_bcd1afcf09bd9a001136166155d7cfbad6542c9b139f4767ad6688f1b4b2da32/simulation-isoscoring.png?cb=81f5a8f857b530ad87686ee329463ad7)

### Phishing training level

This chart shows past monthly ISO scores. The scores are cumulative and are based on the click rate, interaction rate and reply rate as of the end of the given month.  
![simulation-isotraining.png](https://support.sosafe.de/__attachments/a_1b0a39a419ecee953e0b63240f77aa43c7c72e91e431692ef107837bcb050e8a/simulation-isotraining.png?cb=ab3ef77f920f31f1e2934dab711f9cbe)

### Proof of Implementation

This chart provides all technical details for how the ISO scoring and phishing training level are calculated.  

|           **Column**            |                                                                                          **Description**                                                                                           |
|---------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Month                           | Year and month for the calculation. All calculations are cumulative. The date range runs from the start your product usage until the end of the last day of the indicated month.                   |
| Sent                            | Cumulative sent count as of the end of the month.                                                                                                                                                  |
| Clicks                          | Cumulative click count as of the end of the month.                                                                                                                                                 |
| Reports                         | Cumulative report count as of the end of the month.                                                                                                                                                |
| Interactions                    | Cumulative interaction count as of the end of the month.                                                                                                                                           |
| a                               | Clicks / Sent                                                                                                                                                                                      |
| b                               | 1 - (Reports / Sent)                                                                                                                                                                               |
| c                               | Interactions / Sent **Note that this is NOT the interaction rate.** The interaction rate denominator is the number of emails clicked where a click results in a user being sent to a landing page. |
| d **(Phishing Training Level)** | 1 - ( 0.4 \* a + 0.2 \* b + 0.4 \* c )                                                                                                                                                             |
| Scoring                         | A colored dot representing the health of the score for that month Red - (0 - 60) Poor Yellow - (60 - 80) Fair Green - (80 -100) Good                                                               |

---
language: "en"
---
# Level Zero Support

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/level-zero-support)

With Level Zero Support, Sofie becomes an advanced, AI-powered conversational support chatbot. It introduces interactive, two-way communication, enabling users to instantly receive personalized support about security questions. With its ability to automate routine inquiries and integrate with internal knowledge bases, Sofie streamlines operations and fosters a proactive security culture.

## What Level Zero Support can do

Users at your organization can easily and quickly send their inquiries to the Sofie bot via the usual messaging within Teams. Within seconds, Sofie will respond based on the combined knowledge from the company database and the core knowledge of the LLM (Large Language Model).

If Sofie cannot provide an answer or if the query requires human intervention, the bot can automatically generate an email with all pertinent conversation details. This email is then sent to a predefined email address for further action.  
![zero level example.png](https://support.sosafe.de/__attachments/a_425ceefab3106f8b8281d86a388a7fab66e4c0915d78eb8f55a1089c343ba5db/zero%20level%20example.png?cb=eb097c0b1ce5575ceef815564168d7a5)
An example of a user interaction with Sofie

## Setting up Level Zero Support

After installing the MS Teams app, you should set up Level Zero Support according to your needs.

![Zero Level Configuration.png](https://support.sosafe.de/__attachments/a_66b19b98b603cddfb948a3f7b2a90a7ff05d363b589aa61569f9ea2daa985736/Zero%20Level%20Configuration.png?cb=ccaad8c85e16338fdbcfeb2219b51225)

### Enable feature

Activate the toggle **Feature** to activate Level Zero Support. If the toggle is inactive, Sofie will not respond to any user requests.

### Annotations

Activating this toggle will enable Sofie to reference documents uploaded to the Knowledge management section (more details down below) in her responses.

### User onboarding

Activating this toggle means Sofie will initiate an onboarding program for each user, engaging them through weekly usage examples and tips. Interaction is monitored, and once a user reaches a predetermined number of messages, the program concludes for them, marking them as "onboarded users". Refer to the Analytics section down below for more details.  
![onboarding.png](https://support.sosafe.de/__attachments/a_b93471b6dea3bc075685a49ddff8997f3cf0138d6d400e188ec31fd6326b9146/onboarding.png?cb=cc00c500a26eb23d159bf07dd8c4fd8b)
User onboarding example

### IT Support handover

![handover.png](https://support.sosafe.de/__attachments/a_44e7eb8964b140d311f932175f9b1ed49b91cfa54ff0264b21006fd28480a82e/handover.png?cb=eaa03cf5a7e5703c69962548eca57e81)
Handover email example

Activating this toggle means Sofie can hand over requests that require human intervention to your support team or ticket system. When Sofie cannot resolve a query or identifies the need for direct human support, she prompts the creation of a support ticket. This ticket consists of an email containing all pertinent details from the prior conversation and is sent to the email addresses you specify.

### Simple email template

When activated, handover emails are formatted in plain text so they are easier to process for ticket systems.

### Collect user feedback

Activating this toggle means Sofie will follow up and ask for feedback after a user interaction. Feedback scores are shown in the analytics dashboard.

## Knowledge management

Here you can upload knowledge files that Sofie can use to make sure her replies follow your organization's guidelines.  
![knowledge management.png](https://support.sosafe.de/__attachments/a_6fcc041d740b0bafc18b8f2764da77912a253ffc120062f6ae9f23ac469b37f2/knowledge%20management.png?cb=91bee7e7383321165c8ea8358738b985)

You can upload a maximum of 200 files. Only PDF files are accepted and they must be smaller than 10 MB.

We recommend uploading files that are specific to your organization and include information relevant to questions your users might ask Sofie. These include:

* IT Security Best Practices

* IT Governance Policies

* CISO office documentation and procedures

* Internal support escalation procedures

* Company FAQ

You can upload files using the dropzone on the page or click on it to select files. After the upload, you will see the files in the table below. There you can also edit their metadata. See the following table for more information:  

|  **Field**  |                                                                                                              **Description**                                                                                                               |
|-------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Name        | The name of the file you uploaded. If the Annotations feature is turned on, Sofie will use this file name to let your users know where we took the answer from. You can edit it to make it more friendly or understandable for your users. |
| Type        | The type of knowledge file. Use this to organize and categorize the files you upload.                                                                                                                                                      |
| Public Link | This is a public link you can choose to provide for this file. This is useful for the Annotations feature as the link will be displayed to your users when Sofie answers using the knowledge from your files.                              |
| Enabled     | On: The file is available to use by Sofie Off: The file is stored in the Manager, but it will not be used by Sofie to answer questions.                                                                                                    |

To delete a file, select it in the table and then select the **Delete** button. You will be asked to confirm this action.

## Analytics

The Analytics provide a basic overview of how your users are interacting with Sofie.  
![sofie analytics.png](https://support.sosafe.de/__attachments/a_31843e69ae298c55e45fb3f0031da0ea1a8f018177034cb7157ba1273085ea53/sofie%20analytics.png?cb=68b5d50ba4b27d7cd7e5043c768d07c5)

---
language: "en"
---
# Level Zero Support FAQ

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/level-zero-support-faq)

**What powers Sofie, and how does it function?**

Sofie is powered by a sophisticated language learning model, which enables it to comprehend and interact with users on various cybersecurity topics. It functions by analyzing the text of queries it receives and using its advanced understanding of language and context to provide accurate, informative responses. The chatbot is designed to handle a broad spectrum of security-related questions, delivering not just information but also actionable advice and support. It's capable of continuous learning from interactions, which helps in refining its responses and improving its interaction quality over time. This technology integration ensures that Sofie is equipped with up-to-date knowledge and understanding, essential for effective cybersecurity awareness and support.

**How many languages can Sofie understand?**

Sofie supports multiple languages, making it accessible to a diverse user base.

**Can we customize Sofie's appearance and communication style?**

Yes, Sofie offers customization options for its appearance, name, and conversational tone to fit your organization's branding and preferences. See [Sofie customization](https://support.sosafe.de/ProductDoc/sofie-customization.md) for more details.

**What formats are accepted for training materials?**

Sofie can be trained with knowledge bases and documents in a .pdf format.

**How do I send my knowledge base .pdfs to SoSafe for training?**

You can upload your knowledge files via the the SoSafe Manager.

**What happens if Sofie doesn't know an answer?**

If Sofie encounters an unfamiliar question, it will seek assistance from IT personnel or direct the query to the appropriate channel for further support. You can define the support e-mail address to send these questions in the Manager.

**Can Sofie integrate with our security tools?**

Not at the moment. However, we are constantly improving Sofie, eventually Sofie will be able to integrate with other tooling.

**Will security responses come directly through Sofie**

No, security personnel will have to respond through another channel.

**Can Sofie's rollout be limited to specific Teams groups?**

Sofie can be strategically rolled out to certain groups within Teams, allowing for targeted implementation and feedback.

**How is data collected by the chatbot processed and stored?**

Data collected by Sofie 2.0, including Microsoft Teams chat messages, names, and email addresses, is processed under the guidelines set by the SoSafe Beta Program General Terms and Conditions and the Data Processing Agreement. The purpose of this data processing includes collection of feedback on the Beta Content and providing interactive cybersecurity awareness and support. Data is stored securely for the duration of the Beta Subscription Agreement and deleted subsequently to ensure user privacy.

**Are conversations stored in a way that could compromise sensitive information?**

Conversations and data collected by Sofie are stored with stringent security measures to prevent compromising sensitive information. These measures include encryption of data in transit and at rest, and adherence to the highest standards of data protection, ensuring compliance with GDPR, CCPA, and other relevant data protection laws.

**Does OpenAI use the information provided in chats to train their models?**

OpenAI does not utilize customer-submitted data through its API for the training of OpenAI models or the enhancement of its services.

**Who has access to the conversations within SoSafe, which employees or contractors?**

Access to conversations and data collected by Sofie is strictly controlled and limited to authorized SoSafe employees. These individuals are bound by confidentiality agreements and the company's data protection policies to ensure the security and privacy of user data.

**Does the chatbot comply with GDPR, CCPA, and other relevant data protection laws?**

Yes, Sofie is designed to comply with all relevant data protection laws, including GDPR and CCPA. The chatbot incorporates data privacy and compliance measures from the outset, ensuring that user data is processed and stored in accordance with these laws.

**How does the chatbot handle data subjects' rights, such as access, rectification, erasure, and data portability?**

Sofie and SoSafe have established procedures to address data subjects' rights, including access, rectification, erasure, and data portability. Users can request to exercise these rights through designated channels, and SoSafe is committed to responding to such requests in compliance with applicable data protection laws.

**Can users opt-out of data collection or delete their data from the chatbot's records?**

Yes, users have the option to opt-out of data collection or request the deletion of their data from the chatbot's records. SoSafe respects users' rights to privacy and provides mechanisms for users to withdraw consent and have their data erased in accordance with data protection laws.

**What security measures are in place to protect against data breaches or unauthorized access to the data collected by the chatbot?**

SoSafe employs robust security measures to protect against data breaches or unauthorized access, including encryption of data in transit and at rest, secure data storage solutions, and regular security assessments. Additionally, subprocessors such as Microsoft Azure, and OpenAI are selected based on their compliance with high security standards, including ISO 27001 and SOC certifications.

**Is data encrypted both in transit and at rest?**

Yes, all data collected by Sofie is encrypted both in transit and at rest. This ensures that personal and sensitive information is securely protected from unauthorized access or interception.

**Is any of the data collected by the chatbot shared with third parties? If so, for what purposes?**

Data collected by Sofie may be shared with subprocessors listed in the agreement, such as Microsoft Azure, and OpenAI, for the purposes of providing the service, including chat bot hosting, product analysis-focused data collection, and interactive awareness and support. These subprocessors are carefully chosen based on their data protection standards and security certifications.

**How do third-party integrations comply with data protection standards?**

Third-party integrations with Sofie such as those provided by Microsoft Azure, and OpenAI, comply with data protection standards by adhering to certifications like ISO 27001 and SOC 2/3. These standards ensure that data is processed and stored securely, maintaining user privacy and compliance with data protection laws.

---
language: "en"
---
# Classic Phishing Simulation

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/phishing-simulation), [**Deutsch**](https://de.support.sosafe.de/pdok/phishing-simulation)

If you want to learn more about our classic whiteglove Phishing Simulation service, check out these pages:

* [Phishing Template FAQ](https://support.sosafe.de/ProductDoc/phishing-template-faq.md)
* [Spear Phishing FAQ](https://support.sosafe.de/ProductDoc/spear-phishing-faq.md)
* [How are click rates evaluated while maintaining anonymization?](https://support.sosafe.de/ProductDoc/how-are-click-rates-evaluated-while-maintaining-an.md)

---
language: "en"
---
# Phishing Template FAQ

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/phishing-template-faq), [**Deutsch**](https://de.support.sosafe.de/pdok/phishing-template-faq)

## What adjustments can be made to the phishing templates?

Our SoSafe Select templates have proven effective over the years. They provide different levels of difficulty and work with various psychological factors. It is not recommended to adjust these templates outside of the specified placeholders.

There are various placeholders in the templates that we can tailor to your company. In the initial stage, these include the sender address and company domain, salutation, phishing link, and signature, for example. We can also adjust any logos.

The scope of (further) adjustments depends on the booked package.

### **Customized templates:**

Customized spear phishing templates (**Premium**) can be adjusted to suit your internal communications (manner of speech, signature), thereby increasing the difficulty.

Further information can be found in the [Spear Phishing FAQ](https://support.sosafe.de/ProductDoc/spear-phishing-faq.md).

### Can real names be used for the sender?

Real names are available in the **Premium Package** on request. This increases the difficulty of the template significantly and should be **discussed with the person whose name is being used**.

If an individual responds to a simulated email from someone they believe to be an actual coworker, this response is not sent to the respective employee, but rather to us. We are however unable to read it and only count the number of responses to an email (answer rate). The person who responded will receive an automated response in which they are notified that they responded to a simulated phishing email. It may also be possible for the users to personally contact the supposed sender to ask whether the e-mail is genuine. The person whose name we are using should be prepared for this and capable of identifying the email as a phishing simulation and directing the recipient to the learning page if they are asked about the email.

However, in our simulations we state that fake names also lead to high click rates, meaning that real names are not absolutely necessary.

### Can we also exclusively use external templates?

We do recommend using a **wide range** of different templates, including your own and those that we provide. However, if you want to use external emails only, please discuss this with your Implementation Manager.

### Are the simulated phishing emails actually sent from our domain?

No. The phishing emails are solely sent from **our servers with our domains**. The domains you see in the whitelisting list (in the SoSafe Manager under Settings / Whitelisting), and which a user could see if they try to respond to a simulated email.

The technology used for this ("domain spoofing") is very common. This way actual criminals can easily make an email look as it came from an internal address.

### Does it make sense to adjust the signature?

Please note that adjusting the signature makes the templates considerably **more difficult**.

We are happy to replicate your signature (**Premium Package**). This can be done for various language, too. Please send your Implementation Manager your internal signature and he/she will handle it from there.

### What are interactive templates?

Interactive templates are **landing pages** that users are directed to after clicking on a link in a phishing mail. On this page they are for example asked to log in, deceiving users to give up their login credentials. Of course, this is all part of a phishing simulation and the users will be forwarded to our landing page.

Currently, 20 different interactive templates are available, and there are still more to come.
Example of an interactive template  
![image-20240207-105759.png](https://support.sosafe.de/__attachments/a_19753d8462ff622e2d5ce88ad106f00269c075435d75b08a017666568eba9fb5/image-20240207-105759.png?cb=0864c25b41708779756ba6633d58d592)

### Our internal communication works / looks differently.

Not all templates are perfectly tailored to your manner of speech. This is intended and good for these reasons

* This way we can offer **different levels of difficulty**. Templates that are supposedly simple often achieve a high click rate.

* We also want to achieve a **learning effect**, as the templates should be puzzling for the users at first glance.

Of course, we can tailor the customized phishing templates (Premium Package) to your exact internal communication (manner of speech, signature), thereby increasing the difficulty.

---
language: "en"
---
# Policy-to-Lesson

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/policy-to-lesson)**,** [**German**](https://de.support.sosafe.de/pdok/policy-to-lesson)

Company policies are crucial documents for every organization. However, they are also typically long, complicated, and difficult for employees to engage with, even with traditional compliance training. Low engagement leads to low retention and thus compliance and security risks.

With *Policy-to-Lesson*, you can now turn multi-page PDFs into bite-sized, engaging e-learning lessons - with no manual effort. This is achieved by combining the power of AI with SoSafe's educational concept, lesson structure and curated asset library.

As of August 6, 2026, any progress you make on editing and reviewing lessons is automatically saved. This allows you to collaborate with other team members to improve your lessons and/or get aproval.

## Interactive demo

Feel free to try out this interactive demo or proceed directly to the step-by-step instructions.  

## Overview page

While working with Policy-to-Lesson, your work gets saved continually. If you return to the overview or close your browser window, any progress made will be saved. This also allows you to collaborate with other team members.

When navigating to **E-Learning / Policy-to-Lesson** , you will find an overview of all lessons created with this feature. You can edit all lessons that have not been published yet by clicking the **pen icon** in the corresponding row. Selecting the **eye icon** will take you to a preview of the lesson and selecting the **trash can icon** will delete the lesson. **Deleted lessons cannot be recovered. This action is permanent and cannot be undone.**You can of course upload your policy file again and create a new lesson.  
![Screenshot 2026-08-05 at 13.50.43.png](https://support.sosafe.de/__attachments/a_3d5b0a87a2d2c044f35b0b11a45a3330736c983cc8fecf86d7fb2a0549c43465/Screenshot%202026-08-05%20at%2013.50.43.png?cb=afcbac81a439811de8895e75c61bccaa)

## Step-by-step instructions

### 1. Uploading your policy

In the Manager, navigate to **E-Learning / Policy-to-Lesson** . On this page, select **Create new lesson**.  
![Screenshot 2026-05-07 at 14.54.51.png](https://support.sosafe.de/__attachments/a_6d18eb8fac5065cc9d850e17bb6d97f2fab53f1cf7ca29389e2ee903eae292e2/Screenshot%202026-05-07%20at%2014.54.51.png?cb=6e3cfcca3bbe84d86b6eb496b3b70200)

Simply drag and drop the policy PDF file you want to turn into a lesson onto the page or click to open the file picker.  
![Screenshot 2026-05-07 at 14.55.21.png](https://support.sosafe.de/__attachments/a_3817d7d2453c156d2ef07f8f000fc1dc50207ece5734e39964e1d57e349b6b03/Screenshot%202026-05-07%20at%2014.55.21.png?cb=3357664e54f52f5d41e477370f087188)

The file will now be processed. This will likely take a few minutes.  
![Screenshot 2026-05-07 at 14.55.37.png](https://support.sosafe.de/__attachments/a_272e55c08f4dc5df65a9e2b18a4a1747301dfda4407c5db681e8578f91f1fd5f/Screenshot%202026-05-07%20at%2014.55.37.png?cb=f6892f9a37b6930075adefd825defe33)

#### 2. Content review \& editing

Once the process is finished, you will be shown a preview of the generated lesson. You can use the arrows at the bottom to navigate between the pages or start reviewing and editing immediately by selecting **Start review**.  
![Screenshot 2026-05-07 at 15.27.45.png](https://support.sosafe.de/__attachments/a_f3571858ee8c015a87a543b3f3019738c5ec9b9cfdd0d9123624d583243a3543/Screenshot%202026-05-07%20at%2015.27.45.png?cb=1379d5eaf3c06d4d0167624a7f689aa3)

You can select the individual content boxes in the menu on the left to open the content editing text fields. In addition to changing text, you can format most fields by making text **bold** , *italic* , ++underlined++ or strikethrough using the corresponding buttons.

Move between the pages using the **Next page** and **Back** buttons. Once you're on the last page, you can select **Finish** to return to the process overview. There, select **Confirm** to proceed with the next step.  
![Screenshot 2026-05-07 at 15.28.08.png](https://support.sosafe.de/__attachments/a_4ed64de7a8a79e7d67789a84debc3b4a163f5bac967b0549782a4a39343d55dc/Screenshot%202026-05-07%20at%2015.28.08.png?cb=33bee9100974b2d67d6ef9853c02b74e)

#### 3. Quiz and acknowledgment

At the end of the generated lesson, your users will be asked to acknowledge that they have read and understood the policy. If you wish, you can add an automatically generated quiz before the acknowledgment. Toggle the corresponding switch and then select **Start review** to review and edit the quiz answers. This will work just like editing the content earlier. The correct answer to the quiz questions will be highlighted.

If you do not wish to add a quiz, simply select **Confirm** to proceed.  
![Screenshot 2026-05-07 at 15.29.01.png](https://support.sosafe.de/__attachments/a_e1a21fdf85704a382121809fc304c79f7a360aac5af208ec1eab1370009be6e0/Screenshot%202026-05-07%20at%2015.29.01.png?cb=de3fa40bf6e71ac671ff893d4ecc57e8)  
![Screenshot 2026-05-07 at 15.29.34.png](https://support.sosafe.de/__attachments/a_00e9d750e13bae07e1d83d4559ab55852d70063f7bdaafe98acdcc41b1d906d9/Screenshot%202026-05-07%20at%2015.29.34.png?cb=ad5cfc9218dabfbb350e1e61b787cccd)

#### 4. Lesson summary review

In this brief step, you can edit the lesson summary. Make any desired changes and select **Confirm** to proceed.  
![Screenshot 2026-05-07 at 15.30.10.png](https://support.sosafe.de/__attachments/a_45193e81e608c03b3f0a8acdd758d1f8ef069d9631550d61c013f16151cf371b/Screenshot%202026-05-07%20at%2015.30.10.png?cb=61e2407360106d5ba2c38b967c1733a8)

#### 5. Translations

If you do not wish to add any translations, simply select **Continue without translations** . If you do wish to add them, select **Add translations** . A new dialog window will open and show a list of languages. Make your selection and click **Apply** . The translation process will start. This can take a moment, depending on the amount of text and languages. Once the translations are ready, you can preview them by selecting the corresponding tab at the top of the lesson preview. If you're happy with your translations, select **Confirm** to proceed.  
![Screenshot 2026-05-07 at 15.30.44.png](https://support.sosafe.de/__attachments/a_06b1f15ce8d1c3ac5bc1d81d34c2bc2210b0d4f4e10848df78f44f6ed2fec862/Screenshot%202026-05-07%20at%2015.30.44.png?cb=38c990c279b5757ca0f4ff52ae88051e)  
![Screenshot 2026-05-07 at 15.31.06.png](https://support.sosafe.de/__attachments/a_de55e127c9862b163749afd4b5a2e303ca76c672c370003de1016e1e49991adc/Screenshot%202026-05-07%20at%2015.31.06.png?cb=df249cf5dc9d51072195b7045ff494cb)

#### 6. Adding lesson to campaigns

Here you can add your lesson to any existing campaigns. It will be added as an optional lesson for your learners to complete. Select **Add lesson to campaign** and a new dialog window will open. Make your selection and click **Save** , followed by **Confirm** . Alternatively, you can select **Skip for now** . This will not add it to any campaigns now. You can add it to a course at any time using the **E-Learning / Course Management** page. Learn more here: [E-Learning course management](https://support.sosafe.de/ProductDoc/e-learning-course-management.md).

![Screenshot 2026-05-07 at 15.41.52.png](https://support.sosafe.de/__attachments/a_a1e8f6d2e107145b83b46855c4ca1a0a1a1c26ade366e6eb44bffa46064ffc41/Screenshot%202026-05-07%20at%2015.41.52.png?cb=7ae7ee686918318b56014b6fe7f7de7c)  
![Screenshot 2026-05-07 at 15.42.36.png](https://support.sosafe.de/__attachments/a_2626569ee06cde1b3b84dcf9db7cf6b2ea9a290c04e7f79a674eee1c2cab4d4e/Screenshot%202026-05-07%20at%2015.42.36.png?cb=2e0ea5b3358f0dcdcc0ccd00fb638521)

#### 7. Publish

Once all steps are completed, select **Publish lesson**!  
**Caution:**Currently, published lessons cannot be edited or deleted.  
![Screenshot 2026-05-07 at 15.43.35.png](https://support.sosafe.de/__attachments/a_6b37be2b86bed175d61c9e00db868e5034ed961d7e2c213b8e9cc2976876d910/Screenshot%202026-05-07%20at%2015.43.35.png?cb=929f50f93e2e4a4152ff393328d50513)

---
language: "en"
---
# QuickEdit - Template customization

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/templates-mit-quickedit-anpassen)

## Introduction

QuickEdit allows you to **quickly** and **independently** duplicate and **customize any existing SoSafe phishing template**. This means you can custom-tailor any template to the specifics of your organization without needing to know HTML or having to rely on SoSafe support.

Specifically, you can:

* edit the subject, sender and email text elements

* edit the sender email address

* add/remove custom placeholders

* replace existing images

* add translations

## Limitations

Currently, you cannot:

* insert new layout elements

* add images where the original template didn't include them

* change formatting such as fonts

* add external links or QR codes

* add or customize learning hints

* re-use any edited templates in other simulations

## Prerequisites

You need to be on the **Professional** , **Premium** or **Ultimate** tier and have the **Simulation Studio**.

## Best practices

The best use for QuickEdit is to take existing SoSafe templates that are proven to work and improve them by **making them match your organization's specific context** even better. This allows **higher efficacy while minimizing your time spent** on awareness building measures or any dependencies on custom support.

## Demo walkthrough

## How to use QuickEdit

### Accessing QuickEdit

When creating any kind of simulation (basic, targeted or behavior-based), you can make changes to any template you've added from the library by selecting the **Edit** icon.  
![Screenshot 2025-07-30 at 14.53.01.png](https://support.sosafe.de/__attachments/a_df9e584711f6eac7e52d65e57023f5efcf6be5857742c1159b3228e6b9f367c5/Screenshot%202025-07-30%20at%2014.53.01.png?cb=e9d523264dee714a141cb5a78d35f133)

### Editing text \& adding placeholders

You will start with a view of the template. Pretty much all elements can be clicked and then edited.  
Note that no changes to the template will be permanently saved until you click **Save** on this level.

As an example, we can edit the **Subject** of the template by clicking the existing subject. A new dialog window will open (see below).  
![Screenshot 2025-07-30 at 14.53.19.png](https://support.sosafe.de/__attachments/a_2b6238ea5829128628cf242dda8c067f88190f75a39ae5e5741fbc51387170e9/Screenshot%202025-07-30%20at%2014.53.19.png?cb=5dcfefc2335dc4a6d90e355049ba27f0)  
The edit dialog window is a basic text editor. Note that linebreaks will not carry over into the template.

Text inside `{curly braces}` represents placeholders. In the final email sent to users, these will be filled out with actual content. `{recipient_first_name}`, for instance, would turn into the learner's actual first name (e.g. Jane).

Example: `{current_month}` would turn into the current month as of the date that the email is sent (e.g. August). In addition, you can add modifiers to both `{current_month}` and `{current_date}` to refer to dates in the past or future. That means that if `{current_month}` is "August", `{current_month_minus_1}` would be "July". Current placeholder options revolve around the recipient's info, your company info and the current date.

Select **Save** to apply your changes. Note that this does not save the entire template. After you've modified an element, it will be highlighted in orange so you can see it is no longer the default.  
![Screenshot 2025-07-30 at 14.53.41.png](https://support.sosafe.de/__attachments/a_c5b4c7aa9eccb7312710cb3f0a3b5c1257220cf693015d3b4d6befa8c7025067/Screenshot%202025-07-30%20at%2014.53.41.png?cb=1c9c8593097c1c17fe7aecc5be3fe261)
1. edit dialog  
![Screenshot 2025-07-30 at 14.54.17.png](https://support.sosafe.de/__attachments/a_8f7e7e6fa3f68befc2e81a4920d9bee7ee066920b5cefbe91097e8cae87ed335/Screenshot%202025-07-30%20at%2014.54.17.png?cb=edb31224f26833c8a7759a3386b8e368)
2. type "/" to open the placeholder selection  
![Screenshot 2025-07-30 at 14.54.30.png](https://support.sosafe.de/__attachments/a_8e6ad12ade8052d6538f47e54d83b37efe5986e35896f8fe7abfa33ce7a172d9/Screenshot%202025-07-30%20at%2014.54.30.png?cb=97733dc0aa9ff176764f8cceb478b229)
3. start typing to search within available placeholders

### Editing images

While it is currently not possible to add completely new images to templates, you can replace existing ones. In the example above, you can click on the spreadsheet logo and the following dialog window will open:  
![Screenshot 2025-07-30 at 14.55.50.png](https://support.sosafe.de/__attachments/a_e2b406854c8012e56c6bdff49ded90ab89d0e5230dd7514b459d08bf6ce02bc4/Screenshot%202025-07-30%20at%2014.55.50.png?cb=a70d7b1d77f53e926c0e4376e31a7574)

Simply add a custom image you would like to use and it will be displayed:  
![Screenshot 2025-07-30 at 14.56.05.png](https://support.sosafe.de/__attachments/a_f69665635e23e14cac8be8ec40668949937925707a014057f48b7be04b7325cd/Screenshot%202025-07-30%20at%2014.56.05.png?cb=955fe425e59c0f980e8df5f225194fbb)

### Learning hints

Some elements have a greenish-blue dot displayed at the top right. In our example, this applies to the sender name "Human Resources", for instance. These elements are connected to learning hints that are shown on the website your users will be sent to if they click an email (called the learning page). These hints are specific to the content of the original template and since they might no longer be correct if you change the content, any such learning hint will be disabled if you make changes here. This is highlighted if you click on a corresponding element. If you select **Discard**, no changes will be applied and the learning hint will still be shown. It is up to you to decide whether your customization of this element is more important than the learning hint or not. Nothing breaks if you do make changes, all that happens is that this specific learning hint is no longer displayed on the learning page.

### Previewing the actual email

After saving the template, it will show up in your selection and carry an **Edited** tag. Select the **Eye** icon to the right to get a preview of the email with all placeholders filled out based on your own information and the current date.  
![Screenshot 2025-07-30 at 16.11.17.png](https://support.sosafe.de/__attachments/a_6f1db92ac734bf2fd4a5bd085ec216aad63a7bc147945f2c4d9afbb85d235bb8/Screenshot%202025-07-30%20at%2016.11.17.png?cb=d4dfed23d01fcbb0eb93c85444f1ac8f)

### Restoring original templates

If you are not happy with your changes, you can either select the **Edit** icon again or **select** the template (1) and then **remove** it (2). Once you have done that, you can add it back from the library.  
Note that all changes you make only apply to the Simulation you are currently creating or editing. Edited templates are currently not available throughout your account.  
![Screenshot 2025-07-30 at 16.11.17 copy.png](https://support.sosafe.de/__attachments/a_a938becaaaf532b4ffd7416f778a96979d7e107d682cc9872151fc77d72ee9ce/Screenshot%202025-07-30%20at%2016.11.17%20copy.png?cb=9f34663ee85ce77bb3644e0ef4509f9b)

### Languages \& translations

We recommend implementing all changes you make across all language versions you are using to ensure the experience is consistent for all users.  
![Screenshot 2025-07-30 at 16.26.43.png](https://support.sosafe.de/__attachments/a_657010def9b2ceaee612e66b852cb8eb393abcf756bb344a96a533e054b58456/Screenshot%202025-07-30%20at%2016.26.43.png?cb=e5f6a1f5cf80e91fb7ff37064298e1a1)  
If you are interested in automated translation solutions, please reach out to your Customer Success Manager!

## FAQ

**Q: Can I create a new template from scratch?**

**A:** Yes, but not with QuickEdit. Use our fully-fledged Simulation Studio for this purpose. Find our guide here: [Template Studio](https://support.sosafe.de/ProductDoc/simulation-studio-how-to-guide.md)

**Q: Why can't I edit everything, including formatting?**

**A:** For full customization options, we already have the Simulation Studio option. In talking to customers, we found that most prefer being able to make small tweaks to existing templates on their own without having to know HTML or running the danger of breaking templates. That being said, **we plan to continue working on QuickEdit** and add further customization options without adding complexity.

---
language: "en"
---
# Report: Personalized Learning Data

Here you will find details about each column in the E-Learning report (Personalized Learning)

## Column: customerId

**Description:**

Internal SoSafe customer ID. It associates each user with the correct customer.

## Column: Mandant

**Description:**

Official name of the customer in the SoSafe Manager.

**Note:**

This field is especially useful in multi-tenant data exports.

## Column: Campaign

**Description:**

Specific learning campaign to which the user is assigned to.

**Note:**

This field is especially useful in multi-tenant data exports.

## Column: User ID

**Description:**

Internal SoSafe User ID. Used for internal tracking and analytics across learning modules.

## Column: Firstname

**Description:**

User's given name, pulled from the identity provider or user import file. Information pulled from User Management → Users.

## Column: Lastname

**Description:**

User's family name, pulled from the identity provider or user import file. Information pulled from User Management → Users.

## Column: Email

**Description:**

User's email address. This is their unique login credential and also the primary channel for email-based training delivery. Information pulled from User Management → Users.

## Column: Language

**Description:**

Language in which the user receives their training content.

## Column: Created

**Description:**

User SoSafe account creation date. This is when the user was first imported or synced, but not necessarily when training began. Information pulled from User Management → Users.

## Column: Registered

**Description:**

User training registration date. This is when the user registered and logged into the E-Learning Platform the first time.

## Column: Active

**Description:**

Indicates whether the user is currently considered an active learning account in the system. Users will be deactivated via identiy provider or manual via User Management → Users.

## Column: Progress \[Deprecated\]

**Description:**

Numerical value that reflects a user's progression through their assigned learning path. This column is a deprecated artifact and will be removed in a future update.

## Column: Level Achieved \[Deprecated\]

**Description:**

Deprecated artifact that will be removed or enhanced in a future update.

## Column: User Group

**Description:**

Organizational group or groups to which the user belongs. The content depends on the customer's feature configuration:

If Profile-Based Personalization is enabled:

* The column will display all user groups the individual user belongs to.

* Groups are shown in alphabetical order, separated by a delimiter.

* These groups are used to determine role-based content or risk-based personalization.

If Profile-Based Personalization is not enabled:

* The column will show the user's group, as imported from your connected identity provider (e.g. Microsoft Entra, Okta) or your manual user upload.

* Each user will belong to exactly one group.

## Column: Passed modules

**Description:**

Total number of completed training modules (mandatory + optional) out of the total number of modules assigned to the user based on the filter set in the Analytics dashboard at the time of download.

**Display format:**

X / Y

* X = Number of completed modules

* Y = Total number of assigned modules

This is an aggregated completion count that combines both required and optional modules.

**Example:**

1 / 63 → The user has completed 1 out of 63 total assigned modules.

## Column: All modules passed

**Description:**

Flag that indicats whether the user has completed all assigned modules. It includes both mandatory and optional ones based on the filter set in the Analytics dashboard at the time of download..

* Yes → The user has completed 100% of their assigned modules.

* No → At least one assigned module (mandatory or optional) is still incomplete.

**Note:**

This column is helpful for quickly filtering users who have fully completed their training.

## Column: Overdue mandatory modules

**Description:**

Total number of mandatory learning modules that are currently past their due date and still incomplete, relative to the total number of modules that are due.

**Display format:**

X / Y

* X = Number of due modules that the user has not completed (i.e., overdue)

* Y = Number of mandatory modules that are due

If a user has mandatory modules assigned but none of them have reached their due date yet, this column will show 0 / 0.

**Example:**

How "Overdue Mandatory Modules" is Calculated:

Let's walk through a sample scenario to illustrate how this column works.

**User:** ***Jordan M.***

* User account created: *March 11*

* User first logged in and completed the initial survey: *March 15*

* Learning path calculated: *March 15*

* Module due date: *April 12* *(28 days after learning path calculation)*

**Between March 15 and April 11**

* Jordan has mandatory modules assigned.

* But none are past their due date yet.

* Overdue Mandatory Modules will display:

  0 / 0 *(Modules are not yet due, so none can be overdue)*

**On or after April 12**

The first set of mandatory modules becomes due. At this point:

* If Jordan has completed 3 out of 4 due modules:

  → 1 / 4 will display (1 module is overdue)

* If Jordan has completed all due modules:

  → 0 / 4 will display (0 overdue modules)

* If Jordan has completed none:

  → 4 / 4 will display (all are overdue)

**Important Notes:**

* Due dates are dynamic and always calculated as 28 days after a learning path is created or recalculated.

* Learning paths are recalculated when:

  * The user completes the initial survey

  * There is no initial survey and the user logs in for the first time

  * A manager updates the Personalized Learning setup (e.g., assigned additional modules), and the user logs in again

  * The system assigns a default path overnight if the user never logs in (to avoid a permanent 0 / 0)

**Note:**

The numbers in this column may fluctuate over time based on when the learning path was calculated, user activity, and any changes made to the training configuration. This means a user who shows 0 / 0 today could show 2 / 4 tomorrow as due dates pass or their assigned modules change.

## Column: Passed mandatory modules

**Description:**

Total number of mandatory modules the user has completed out of the total number of mandatory modules that have been assigned to them.

**Display format:**

X / Y

* X = Number of completed mandatory modules

* Y = Total number of mandatory modules assigned

This count accumulates over time as users complete more training. It includes both on-time and overdue completions.

**Example:**

4 / 6 → The user has completed 4 out of 6 mandatory modules assigned to them.

## Column: Passed optional modules

**Description:**

Total number of optional modules the user has completed out of the total number of optional modules they were offered.

Display format:

X / Y

* X = Number of completed optional modules

* Y = Total number of optional modules assigned

Optional modules are not required to be completed but may be offered to deepen learning or cover additional topics.

**Example:**

2 / 5 → The user has completed 2 out of 5 optional modules that were available to them.

## Column: Recently finished module

**Description:**

Completion date of the most recently finished training module (mandatory or optional) for each user.

## Column: \[Learning Module Name\]

**Description:**

Each column in this section represents the title of a specific training module available on the SoSafe platform (e.g., *"Importance of Cyber Security"* , *"Device Theft"* , *"Detecting Phishing Mails"*). These modules cover key cybersecurity and compliance topics.

* A date in a cell indicates that the user completed that module on that specific date.

* A blank cell means the user has not completed that module.

**Important** : A blank cell does not necessarily mean the module is part of that user's learning path.

Learning paths in Personalized Learning are individually generated, so not every module applies to every user.

**Example:**  

| Importance of Cyber Security | Device Theft |
|------------------------------|--------------|
| 10.04                        | *(blank)*    |
| *(blank)*                    | 31.03        |

* User 1 completed *"Importance of Cyber Security"* on April 10.

* User 2 completed *"Device Theft"* on March 31.

* The blank cells do not confirm whether the modules were skipped, incomplete, or simply not assigned in their personalized path.

## Column: Division

**Description:**

User's organizational division, department, or business unit. The value is typically pulled from your identity provider.

## Column: Login_identifier

**Description:**

Login handle or system-level credential used to uniquely authenticate the user.

It may differ from the user's email address if configured (e.g., in SSO environments where user principle names or employee IDs are used instead).

---
language: "en"
---
# Reporting & data exports

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/reporting)**,** [**German**](https://de.support.sosafe.de/pdok/reporting-daten-export)

Here you will find further details about the different Reports which can be downloaded from the Analytics dashboards.

For E-Learning and Phishing Simulation we provide a general PDF report that includes the charts shown on the respective Analytics page as well as data reports in the form of Excel sheets or comma separated text files.

## Report types

### PDF

The PDF export is essentially your Analytics page as a single PDF document. It also features a legend at the bottom that explains the individual metrics briefly.  
![Screenshot 2026-05-19 at 15.51.51.png](https://support.sosafe.de/__attachments/a_8179c44610692bd0cf6276dc9c3b37ff9ff7227bfe0d54cb1bc50e7ca81d7468/Screenshot%202026-05-19%20at%2015.51.51.png?cb=d3cf26c174cadd0ff5cb1d62f7719e4c)
PDF report preview

### KPI data

The KPI data export includes all important KPI data in a machine-readable file.

For Phishing Simulations, this includes the click rate, interaction rate, reporting rate, and many more. The file also contains template-specific data.  
![Screenshot 2026-05-19 at 15.51.07.png](https://support.sosafe.de/__attachments/a_97e31cc4348d20bc05b4d9eb55340c34f4a021d8441421f6b316734a70daf539/Screenshot%202026-05-19%20at%2015.51.07.png?cb=220dd1a0ebc47f55b9db5c902ba45a70)
KPI data report preview

For E-Learning, this includes an overview of the campaigns you selected.  
![Screenshot 2026-05-19 at 15.59.14.png](https://support.sosafe.de/__attachments/a_3203d579641a0a98dabfaaacfdf7f2aab42151b8a1cf9d56fc33454a12c12f7d/Screenshot%202026-05-19%20at%2015.59.14.png?cb=0c84e07380bdb063dcadb14cc23cc9fc)

### Data

**Note:** Depending on your data privacy settings, some data may not be available.

For **Phishing Simulations**, the raw data export includes all emails sent with full records of which template was used, which user group the recipient was in, when it was sent, how it was interacted with etc. See the screenshot below for an example.  
![Screenshot 2026-05-19 at 15.49.52.png](https://support.sosafe.de/__attachments/a_92d03a96de54f267593c0b23cc76e3abac050c96058fb5fd3d1dd88df39365fe/Screenshot%202026-05-19%20at%2015.49.52.png?cb=74a1b6586ed532f83673eda902f95c47)
Simulation data report preview

For **E-Learning**, the raw data export includes all users from the selected campaigns alongside their learning progress.  
![Screenshot 2026-05-19 at 15.58.04.png](https://support.sosafe.de/__attachments/a_4bd911eacb6dfe5f81860eb1236a5fe1746f764005b1f7bfce7dca25d7a9875a/Screenshot%202026-05-19%20at%2015.58.04.png?cb=8c2cc5e71e91c532565f77c6cad495ac)
E-Learning data report preview

## How to download reports

The procedure for downloading reports is the same for E-Learning and Phishing Simulation Analytics and pretty simple.

1. **Filter data by campaign and date range**

   By default, the Analytics will show your currently active campaign. This is shown below **Phase** . Select that box to select any campaigns you're interested in or choose **Cumulative** to get all data.

   In addition, you can apply a date filter. To do so, select the date picker below **Date range**.

For technical reasons, the date filter cannot be applied to E-Learning raw data exports. It works in all other scenarios.

2. **Choose which type of report to download**

   Select the **Downloads** button at the top right and a list of options will be shown. See the section above for more information about which information which type of report contains.

![Screenshot 2026-05-19 at 15.19.57.png](https://support.sosafe.de/__attachments/a_0eab81928c0d96c1acb02ddbdd40fad9cee261b3f6279cb165177e180dba37a9/Screenshot%202026-05-19%20at%2015.19.57.png?cb=5674a6b92ef67afe08666e41929c2006)

3. For **Download data** only:

   After you select **Download data** , you will be shown a preview of the data export. You can customize the columns that will be included in the export by selecting **Edit Columns** . Select **Save** once you're happy with your selection and then **Download CSV** or **Download XLSX** . You will see a notification stating that your export is being prepared, which can take a few minutes. You will receive an email with a download link once it's ready. In addition, all exports from your last 7 days are available to download by navigating to **Analytics / Exports**.

![Screenshot 2026-05-19 at 15.54.06.png](https://support.sosafe.de/__attachments/a_04861b79c2bf1c74da171ac8fd85d029750b83c34509783cd1e9cc47c75bf358/Screenshot%202026-05-19%20at%2015.54.06.png?cb=a80e081be76a33f7ea40614da7e9250c)  
![Screenshot 2026-07-14 at 15.41.18.png](https://support.sosafe.de/__attachments/a_38143db198c35186a0abaec51abb6ae0dafe8713b6f94115e6c985d6dc9b7c0f/Screenshot%202026-07-14%20at%2015.41.18.png?cb=9c63ff7f88e2b7770524902908042dfe)

## Archived campaigns

After the end of a campaign, its data gets archived. If you select such a campaign, the following banner will be shown.  
![Screenshot 2026-05-19 at 11.51.00.png](https://support.sosafe.de/__attachments/a_fc3fa6c91ebba60f8f6caf78521f16b59926400253910142288cb6d6098dd723/Screenshot%202026-05-19%20at%2011.51.00.png?cb=2557696fbf3ee03703f83668f9849c89)

Most data will continue to be available, both in the regular Analytics and in any exports. One thing to note is that the raw data export is based on live data, so information such as user groups might not reflect the state at the time of the campaign but rather the current state.

For instance, if a user was part of group A during a campaign but has since moved to group B, exports for the archived campaign will show them as a member of group B.

---
language: "en"
---
# Simulation base definitions

This page provides a business-level overview of each individual metric for Simulation Analytics. Each definition includes calculations and conditions for each metric component and the principal metric. To learn about the actual KPIs, select the section you're interested from this list:

[Simulation overview metrics](https://support.sosafe.de/ProductDoc/simulation-overview-metrics.md)

[Simulation overview over time metrics](https://support.sosafe.de/ProductDoc/simulation-overview-over-time-metrics.md)

[Simulation click rate metrics](https://support.sosafe.de/ProductDoc/simulation-click-rate-metrics.md)

[Simulation user metrics](https://support.sosafe.de/ProductDoc/simulation-user-metrics.md)

## Base number definitions

### Click count

Count of clicks on a phishing element (e.g., image, link, simulated attachments).

### Interaction count

Count of interactions on our simulated landing pages. They are recorded when the user tries to add their password in the password field on the page. There is never any danger. No contents are loaded or executed and no passwords can be logged: Users cannot enter passwords into our simulated login masks. Instead, they are immediately taken to the learning page when they click on the password field.

### Landing page visit count

Count of visits to our simulated landing pages. Certain simulation phishing emails take the user to a landing page where they are invited to enter their personal credentials.

This count forms the denominator for the Interaction Rate. Clicks that result in the user being sent to a learning page are not reflected in the Interaction Rate, but in the Learning Rate.

### Reply count

Percentage of emails sent, to which users sent a reply mail. This does not count automatic replies such as out of office replies. In a real phishing attempt, this is often the starting point for cyber criminals to launch complex social engineering attacks on users.

### Reported count

Count of simulated phishing emails that were reported with the Phishing Report Button. This is a premium feature, and the metric will be 0 if unavailable.

### Open count

Count of successfully sent emails that were opened in a mail program where the subsequent downloading of external images was also permitted (automatically or through user interaction). Since downloading external images is often disabled, this does not correspond to the number of actually read phishing emails. The latter figure cannot be determined.

### Mobile count

Count of visits to our learning pages or simulated phishing websites (after a click on a phishing element) viewed on a mobile device (smartphone or tablet).

### Learning count

Count of learning page visits after an element in a phishing email has been clicked. Reading at least two explanatory texts is considered to be a learning page visit. Visits via the phishing report button are not included.

### Learning page mail click count

Count of simulated phishing emails where a click resulted in the user being prompted to learn more about real phishing emails.

This count forms the denominator for the Learning Rate. Clicks that result in the user being sent to a landing page are not reflected in the Learning Rate, but in the Interaction Rate.

`click count + interaction count - landing page visit count`

### Sent mails count

Emails that were successfully delivered to the recipient without any errors.

### Count of users in user groups

Count of the number of users by each user group in a campaign. Many customers require a minimum number of users in a group before viewing aggregated data for that group is allowed. This is to maintain privacy where individual results could be directly attributed in a group with too few users.

### Org baseline

In the Simulation Analytics, Org baseline refers to the average value of a given KPI across your entire organization.

---
language: "en"
---
# Simulation metrics

Our Phishing Simulation Analytics aim to provide you with insights into your users' behavior so that you can track improvements over time and identify possible weak spots. Recently we've reworked the Analytics page to make this easier.

## Campaign selection \& date filter

You can view your Analytics both for specific campaigns and specific timeframes. By default, the Simulation Analytics will show your **current campaign** with no date filter applied. To change which campaigns to show, select the box below **Phase** and make your selection. If you choose **Cumulative** , data from all available campaigns will be shown. To apply a date filter, select the box below **Date range** and choose from the **Last 30 days** and **Last 90 days** filters or specify a custom range.  
![Screenshot 2026-05-19 at 14.35.57.png](https://support.sosafe.de/__attachments/a_d70abdf9800f3fdcbc25b1e0620873f1e6f7f89f78c95f14d2765497c15bae5c/Screenshot%202026-05-19%20at%2014.35.57.png?cb=b945ac310043ab7b5f93c21f2d16aa5b)

## Core metrics

![simulation_analytics.png](https://support.sosafe.de/__attachments/a_ae5ad0f90f9b76dfca5cb2909ab0e110c415f57405291483c61b0a13b0619a25/simulation_analytics.png?cb=208c4c2b7e2bfbc23e06093c1797b1b7)

Our core metrics for your security culture are the **Click rate,** the **Interaction rate** and the **Reporting rate**.

**Click rate:**Percentage of simulation emails where the user clicked on an element in the email.

**Interaction rate:**Certain simulated phishing emails direct the user to a landing page (such as a fake login page) when the user clicks on a link. The interaction rate takes the number of visits to these landing pages as a baseline and shows the percentage of users who tried to interact with it (for instance by trying to enter account data).

**Reporting rate:**Percentage of simulation emails where the user reported it using the Phishing Report Button.

In addition, we provide over time charts that allow you to see how these metrics develop over time and how they compare to your industry benchmark. Note that you can select the industry to benchmark against at the top right.

Furthermore, to the right of the over time chart, you can dig deeper into how individual user groups performed, which psychological tactics were particularly effective as well as which templates stood out.  
![Screenshot 2026-03-25 at 16.52.55.png](https://support.sosafe.de/__attachments/a_c34a5f484030826259e1cb53b5f93d6ab5ea40f3886d699535cefbe040554a49/Screenshot%202026-03-25%20at%2016.52.55.png?cb=a77c80b09a1663a9d86e5151023588e1)  
![Screenshot 2026-03-25 at 16.52.59.png](https://support.sosafe.de/__attachments/a_55835037666649d04036341953bc4dad2663ac48f3a4e96718cf5adf03e07d5c/Screenshot%202026-03-25%20at%2016.52.59.png?cb=390c14e4a15affd912eb0d68a930b29c)

The Phishing Simulation Analytics also contain more detailed charts that allow you to look into these metrics for any user group, difficulty level, psychological tactic etc. You can find out more about these in the other Phishing Simulation Analytics pages:  
* [Simulation base definitions](https://support.sosafe.de/ProductDoc/simulation-base-definitions.md)
* [Simulation overview metrics](https://support.sosafe.de/ProductDoc/simulation-overview-metrics.md)
* [Simulation overview over time metrics](https://support.sosafe.de/ProductDoc/simulation-overview-over-time-metrics.md)
* [Simulation click rate metrics](https://support.sosafe.de/ProductDoc/simulation-click-rate-metrics.md)
* [Simulation user metrics](https://support.sosafe.de/ProductDoc/simulation-user-metrics.md)
* [Simulation dispatch rate metrics](https://support.sosafe.de/ProductDoc/simulation-dispatch-rate-metrics.md)
* [Trusted Clicks - Removing bot clicks from Analytics](https://support.sosafe.de/ProductDoc/trusted-clicks.md)

---
language: "en"
---
# Simulation click rate metrics

The following metrics allow you to dive deeper into your users' click behavior. Unless otherwise specified, all click rates and values are based on the number of emails **successfully** sent.

## Click rate by difficulty

Simulation emails are rated by the difficulty to determine whether or not they are from a legitimate sender. This chart breaks down the click rate into each difficulty category: "Easy", "Medium", and "Hard"  
![Bildschirmfoto 2024-07-17 um 10.19.35.png](https://support.sosafe.de/__attachments/a_46c2902f64d5e4fe86bddcaafb54943c4c87aeadac52dc6a619cdcc6d8e36f79/Bildschirmfoto%202024-07-17%20um%2010.19.35.png?cb=dba9ed5081013818788bf8d9e2f226b9)

## Click rate by context

Some simulation emails appear to come from a business, while others appear to come from a private individual sender. This chart breaks down the click rate into the two categories.  
![Bildschirmfoto 2024-07-17 um 10.19.51.png](https://support.sosafe.de/__attachments/a_8663a11bb7df496fc22d8822f094a708dbe060dceaea15ffd6835e0e576cec32/Bildschirmfoto%202024-07-17%20um%2010.19.51.png?cb=ee13e829a607d586f14196eacfdd4869)

## Click rate by psychological tactic

Each simulation email appeals primarily to one of several emotional manipulation categories. This chart breaks down the click rate by category. The rate values can be viewed by hovering on the chart.

**Impact:** This information can be used in your internal communications. Highlight tactics your users are particularly susceptible to.  
![clickrate-tactic.png](https://support.sosafe.de/__attachments/a_39e611ef9c58714bcec29ea2113c70236965b9cbe59c21134d336c7a4a48a2a3/clickrate-tactic.png?cb=999bb5ced5b1d980009ae7ba988db37c)

## Click rate by technological method

Each simulation email tricks users through one of several technological tactics. This chart breaks down the click rate by tactic. The rate values can be viewed by hovering on the chart.

**Impact:** This information can be used in your internal communications. Highlight methods your users are particularly susceptible to.  
![clickrate-method.png](https://support.sosafe.de/__attachments/a_11ac0e309a2fcf5e011939e696049b97168bbfed10c486f15c94f64f922a3802/clickrate-method.png?cb=cb92672017426b09eae8f4d5c0b0157b)

## Click rate by template

This chart shows the Click rate broken down by template. Template click and send counts can be viewed via the tooltip.

**Impact:**You can use this information to adapt your internal communication but also to gather insights for future campaigns.  
![clickrate-template.png](https://support.sosafe.de/__attachments/a_58e7a6b12658183d21759e202958761e51336d971b683c8232375d6579fa10f9/clickrate-template.png?cb=867f82930cac837c724aed7526587a17)

## Click rate by template expanded

Each template has an individual card showing the template name, click rate, and click ratio. There is a "More details" link at the bottom of each card that allows viewing the Subject, Sender, Context, Difficulty, and total number of emails sent (including failed emails), and a link to the learning page or landing page where the user is directed when clicking on a link in the email.  
![Bildschirmfoto 2024-07-17 um 10.21.22.png](https://support.sosafe.de/__attachments/a_4bfd0710edac5189ba25703ab4cab3e9bb2eb534981931016769e4d8c68797d5/Bildschirmfoto%202024-07-17%20um%2010.21.22.png?cb=6bf314b7e85b2491de2799a6756fb0ba)

## Multiple clients / Multiple tenants behavior

For all click rate metrics, the calculation for multiple clients and tenants combines events from all included campaigns. Total counts will therefore be the sum of all individual campaign accounts, and the rates will be the division of the combined sums.

Since user groups exist within a single tenant, multiple tenants will simply show the union of all user group scores in each tenant.

---
language: "en"
---
# Simulation dispatch rate metrics

The **Dispatch rate** (Share of emails sent) shows the percent and count of emails in the current campaign that have been sent compared to the total number of emails expected to be sent for the campaign

The **Error rate** shows the percent and count of emails that were unsuccessful in being sent in comparison to the overall number attempted sent emails. When the error count is greater than 0, this number will show in red. Otherwise it will show in green.  
![Bildschirmfoto 2024-07-17 um 10.25.11.png](https://support.sosafe.de/__attachments/a_00c2c86c2ce45e6ae335d9d5cf95ea23697fa6302e705b8d3a525d50e322cf36/Bildschirmfoto%202024-07-17%20um%2010.25.11.png?cb=9c1d8507f85ddc4b658f4752c7810d20)

## Calculations and Definitions

**Sent mail count:** The actual number of mails already sent in the campaign. All dispatched mails are considered 'sent' regardless of whether or not they were received by the recipient.

**Expected remaining mails:** The number of mails still expected to be sent to all ACTIVE users in the campaign. If additional users are added into a campaign later, their expected mails are also considered in this count.

**Planned total mails:** Number of sent mails + Expected remaining mails. At the end of a campaign, the number of remaining mails to be sent should be 0, so the Planned total mails is equal to the number of mails that has been sent.

**Error count:** The number of mails that were sent, but not received by the recipient.

**Dispatch Rate:** Sent email count / Planned total mails.

**Error rate:** Error count / Sent mail count.

## Dispatch Rate -- Multiple clients / Multiple tenants behavior

Each count value is calculated as the sum of the respective values from all individual campaigns. Rates are calculated based on the combined counts.

---
language: "en"
---
# Simulation overview metrics

## Click rate

**Definition**

Percentage of successfully sent emails where the user clicked on an element in the email.

**Calculation**

`Click count / Sent mails count`

**Impact**

A high Base Click Rate suggests that employees are still prone to phishing attempts, indicating a need for further training. A decreasing trend in this metric demonstrates improved awareness and reduced risk exposure.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (4).png](https://support.sosafe.de/__attachments/a_ca26bef0012193418302811ee808046eb562af2ec7ba1975573847bed5850940/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(4).png?cb=509fb6ca764eaa35e2950b4309241763)

## Interaction rate

**Definition**

Certain simulated phishing emails direct the user to a landing page (such as a fake login page) when the user clicks on a link. The interaction rate takes the number of visits to these landing pages as a baseline and shows the percentage of users who tried to interact with it (for instance by trying to enter account data).

**Calculation**

`Interaction count / Landing page visit count`

**Impact**

This metric measures how often users engage with phishing landing pages after clicking a simulated phishing email. A high rate may indicate curiosity or a lack of awareness. A declining rate suggests increasing skepticism and awareness.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (10).png](https://support.sosafe.de/__attachments/a_d8323afdf9a2c40c5d16daa2cc23325d8d600f8c7a7af8dea1f557d269960c34/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(10).png?cb=521ca7e630f322a481f6f2f482079014)

## Reply rate

**Definition**

Percentage of emails successfully sent where the user replied to the email. Automated replies are not counted.

**Calculation**

`Reply count / Sent mails count`

**Impact**

Replying to phishing emails is a significant risk factor, as it indicates susceptibility to social engineering attacks. A high Base Reply Rate highlights potential vulnerabilities and the need for targeted security awareness training on phishing mail threats.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (3).png](https://support.sosafe.de/__attachments/a_c662ca3461ddd50f66028520b570f38faee6433ffbe153c450383cc9f1250a3c/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(3).png?cb=a603d3c43e4cfaefd8dcc42fee92d4b7)

## Reporting rate

**Definition**

Percentage of emails successfully sent where the user reported the email using the Phishing Report Button.

**Reported external emails**

The number of emails reported via the Phishing Report Button that were not part of a SoSafe simulation campaign.

**Calculation**

`Reported count / Sent mails count`

**Impact**

A higher Base Reporting Rate indicates strong employee awareness and proactive threat identification. An increase in this metric suggests that users are effectively recognizing and reporting phishing attempts, contributing to overall organizational security.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (8).png](https://support.sosafe.de/__attachments/a_481967d9fdaad499d5e1967436bfef3c0a4c30475019e4f719e9cf6e6fdfeae9/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(8).png?cb=67b5c846e61752d1872f6b212b05ec21)

## Open rate

**Definition**

Percentage successfully sent emails where the user downloaded the tracking pixel in the email.

**Calculation**

`Open count / Sent mails count`

**Impact**

A high Base Open Rate suggests that employees are opening phishing emails, potentially increasing the risk of compromise. Monitoring this metric helps determine if users are becoming more cautious about unsolicited emails over time.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (2).png](https://support.sosafe.de/__attachments/a_ae0e0783b1bb00bc3181417b24e1b76dc2e25af960be9b43c2d7e8b5f4d99005/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(2).png?cb=9a22ffee2aa1c3d4bc5d832fb151d37f)

## Share of emails sent

**Definition**

The percentage of all emails planned in the campaign that have actually been sent.

**Error rate**

The percentage and number of sent emails that were rejected by the mail server.

**Calculation**

`Emails sent / Emails planned in campaign`

**Impact**

Think of this as your campaign progress. If this value is at 0%, no simulated phishing mails have been sent as part of your selected campaign. The error rate is helpful to determine if there might be an issue with your Whitelisting settings or other technical issues.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (1).png](https://support.sosafe.de/__attachments/a_da3470b659b5e218686bff975c34114b106b176d77e0d0b8bc37e2a927615b61/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(1).png?cb=55d4cb646650f5fbaf968dff7885d253)

## Mobile click rate

**Definition**

Percentage of emails clicked where the user was on a mobile device.

**Calculation**

`Mobile count / Click count`

**Impact**

This metric helps assess how often users interact with phishing emails on mobile devices, which may pose additional risks due to limited security controls (e.g., lack of email previews or URL visibility). A high rate suggests that security training should emphasize mobile-based phishing risks.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (5).png](https://support.sosafe.de/__attachments/a_3df7f7e5e42224c2b771ea6f2aa9498f6b8fe5e0d2d20fdbbaaa106a577ef2fb/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(5).png?cb=0cd60068684e0131c02638cc6d64f426)

## Learning rate

**Definition**

Certain simulated phishing emails direct the user to learn more about phishing when the user clicks on a link. This metric marks the percent of these emails where a user visited the learning page and clicked at least two explanatory texts, compared to the overall number of this type of email that was sent and clicked.

**Calculation**

`Learning count / Learning page visit count`

**Impact**

A higher Base Learning Rate indicates that users who engage with phishing emails are taking the opportunity to educate themselves and engaging with the learning content, leading to improved long-term awareness. A low rate suggests a need to optimize training visibility and engagement strategies.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (7).png](https://support.sosafe.de/__attachments/a_08dfda37fe08bcbe3c83f9cdbe60ee3ff4b715695c84cf50114d3b0fbfc36fff/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(7).png?cb=a24ab18b3f2234de6bb6f7712cbeb659)

## User group comparison

This chart provides an overview of the metrics above broken down by your user groups. You can use the filter at the top to only look at specific user groups and also change the sorting by selecting a column.

### **Impact**

This chart helps you figure out which departments need to improve in which area. Use this information to address specific weaknesses in your security culture.  
![manager.sosafe.de_35ca99ed62dc3544_analytics_simulation (9).png](https://support.sosafe.de/__attachments/a_c15768b5e3390ea73220f7d9f17c502dfe66ce0fe9c5491df33863b2caaecee4/manager.sosafe.de_35ca99ed62dc3544_analytics_simulation%20(9).png?cb=f25a13f74b5c0ab85e910c76861806c3)

### Multi-column sorting

In both the user group comparison and the template performance table, you can use multiple columns to achieve complex sorting. As an example, if you first select **Open rate** and then **Click rate**, you will get a table orders groups by their open rate first and if the open rate is the same for several groups, it will then sort these groups by their click rate. The order is indicated by a small number in the header row for that column.

If you click on a column a second time, it will change sorting from descending to ascending. Clicking it a third time removes the column from the current sorting. If all columns are deactivated, the table will default back to alphabetical sorting based on the user group name.  
![Screenshot 2026-05-19 at 11.18.49.png](https://support.sosafe.de/__attachments/a_c34db7de9cab1d22f0e3f135c5a1ee2ac671f4fde10a91c0a5644c39ae82953a/Screenshot%202026-05-19%20at%2011.18.49.png?cb=81eacdf6cf2960f0d894fc1515cf5710)
Note that the bold row at the top is the **Org baseline** row, which is always shown at the top.

Multiple clients / Multiple tenants behavior  
For all Overview metrics, the calculation for multiple clients and tenants combines events from all included campaigns. Total counts will therefore be the sum of all individual campaign accounts, and the rates will be the division of the combined sums.

---
language: "en"
---
# Simulation overview over time metrics

The metrics explained in [Simulation overview metrics](https://support.sosafe.de/ProductDoc/simulation-overview-metrics.md) also feature in charts showing their development over time. Data is shown for the time between the campaign start date and their current date. Hovering over the chart line allows you to view the exact data for a given date. Note that all charts with the exception of the Emails sent over time chart are cumulative.

**Industry benchmark**

Benchmarks are provided as a way for users to get an understanding of their performance related to the average performance in their industry. Values are industry-specific, and users with no industry will see a benchmark value that is the average across all industries. When activated, the graphs will show an additional horizontal line representing the results of the top 20% performers in your industry. If no industry information is set up for your account, you will see a benchmark value averaged based on the top 20% performers across all industries. These values are based on our internal data.  
![simulation-overtimewide.png](https://support.sosafe.de/__attachments/a_659ac7d55f4bdee278aeae07a61ca082f8d618a63a13478c562e3f38497cc885/simulation-overtimewide.png?cb=4b5415b535447369424b7c74e11f10c7)
Examples of over time charts

## Emails sent over time

This chart is an exception since it does not show cumulative data. Instead, it shows how many simulated emails were sent on a given day throughout the campaign.  
![simulation-emailovertime.png](https://support.sosafe.de/__attachments/a_4790a88929e645ff005efc420cbe0f973ca981f94730bfabb774d2d7ec173bf0/simulation-emailovertime.png?cb=72c8f683aaa6864c1a4f80db1d82a1dd)

## Click rate over time

Cumulative click rate over the length of the campaign. Cumulative values are based on all data points between the start of the campaign and the current date.  
![simulation_clickrate2.png](https://support.sosafe.de/__attachments/a_5b3d19126535e3d8ab955a78627015669c70edc990c5b0cd76566c946e419ba1/simulation_clickrate2.png?cb=3b2f7e41cf139b38804729bd7f5dfb1a)

## Learning rate over time

Cumulative learning rate over the length of the campaign.  
![simulation_learningrate2.png](https://support.sosafe.de/__attachments/a_932c8db55e34c2788f1aad9ff023b6b24a21fd3c1e66029f0ba50b9d6e437c35/simulation_learningrate2.png?cb=458e22e71be9cb33b6d9179a204b7c66)

## Interaction rate over time

Cumulative interaction rate over the length of the campaign.  
![simulation_interactionrate2.png](https://support.sosafe.de/__attachments/a_283c4c6ad2140237a51c7d35ed43169ead3c52a7f84e0f266ec17e740ac0e7de/simulation_interactionrate2.png?cb=827dbf7983fc5e625b1260823ac44fce)

## Reporting rate over time

Cumulative reporting rate over the length of the campaign.  
![simulation_reportingrate2.png](https://support.sosafe.de/__attachments/a_bc928f8414e9873cd68df76a728535a6fe0acfd4219f77e7acd7afbe6094ee74/simulation_reportingrate2.png?cb=fc3eb18b66bbaa7af4e0fc2d018faf42)

## Reply rate over time

Cumulative reply rate over the length of the campaign.  
![simulation_replyrate2.png](https://support.sosafe.de/__attachments/a_537d89024babb1e8d47e9db68ccec9c2a4c76548f9d5b08c1d67c6d450797691/simulation_replyrate2.png?cb=90dc479dd4220d653c6a840209db369b)

## Multiple clients / Multiple tenants behavior

For all over time metrics, the calculation for Multiple Clients and Tenants combines events from all included campaigns. Total counts will therefore be the sum of all individual campaign accounts, and the rates will be the division of the combined sums.

---
language: "en"
---
# Recreate Attack (Beta)

**Read this article in:** [**German**](https://de.support.sosafe.de/pdok/simulation-recreate-attack)  
Recreate Attack is a brand new feature currently in Open Beta. It is available to all customers on the **Premium** or **Ultimate** package. We welcome you to try it out and provide feedback!

With Recreate Attack, you can turn **real phishing emails** into **safe, realistic simulations** in minutes - helping your employees learn from the threats that matter most, while keeping your organization secure. This allows you to quickly adapt to emerging real threats your organization is facing and train your employees accordingly.

## How it works

Recreate Attack is a new capability in Template Studio. Instead of starting from a blank template or a generic library item, you can:

1. Upload a screenshot of a real phishing email

2. Let AI recreate the email structure and content

3. Review and fine-tune the result

4. Use it in a phishing simulation

All in a matter of minutes.

## Demo walkthrough

## Instructions

1. Go to **Phishing Simulation / Template Studio** and select **+ Create custom template**.

   ![Screenshot 2026-01-28 at 13.43.37.png](https://support.sosafe.de/__attachments/a_437f41f5a703cc37b44772a247b7d9d9dc335f6aab7decd13753370d33dce85b/Screenshot%202026-01-28%20at%2013.43.37.png?cb=29b2cc972b565489a8480733fd6a4a57)
2. Select **Recreate from a real phishing mail**. A new dialog window will open.

   ![Screenshot 2026-01-28 at 13.44.18.png](https://support.sosafe.de/__attachments/a_dc51620e420d7d30f8f12f7295aec80e478c3d4fd36b2bb4d1bfed727e739b61/Screenshot%202026-01-28%20at%2013.44.18.png?cb=6183a9f56019995088b4ad6cc9f0a5c2)
3. By default, the template will be created in your organization's standard language. You can add additional languages from the dropdown menu. The AI will create automated translated versions of this template for you.

4. Upload a screenshot of a phishing email you want to recreate. This could be an impersonation attempt, a credential-harvesting email, or any other type of phishing message you want employees to learn from. After selecting your image, Recreate Attack will begin analyzing the contents, remove or neutralize all malicious elements and recreate the email as a safe draft that you can then refine. A notification at the bottom right will keep you informed of the progress, which can take a few minutes. Note that the template will be given a name based on the content of the screenshot as well.

![Screenshot 2026-01-28 at 13.44.49.png](https://support.sosafe.de/__attachments/a_641376d6b9b58b0408b4a0e45ba6ff8f43107ab3115485eb1873feed627ea205/Screenshot%202026-01-28%20at%2013.44.49.png?cb=3a764e136a4a0a739889019f6bdbfed3)  
![Screenshot 2026-01-28 at 13.48.57.png](https://support.sosafe.de/__attachments/a_ad6ca8036ff447aa7d8d7d50edd1dc5773713fd49fb73dad4b356b546c7d1e52/Screenshot%202026-01-28%20at%2013.48.57.png?cb=7daa802232a685166bbe58ba79029601)

You can safely navigate elsewhere in the manager and return to **Phishing Simulation / Template Studio** later.

## Review and customization

Once the process has finished, you can review and customize the template that has been created. To preview the template, simply select the **eye icon** in its row. Furthermore, you can select the pen icon to customize your template by:

* editing text

* replacing placeholders or images

* improving realism by fine-tuning sender names, addresses and other elements

For more details on editing templates, check out our [QuickEdit documentation](https://support.sosafe.de/ProductDoc/quickedit-template-customization.md).

Once you're happy with your template, you can save it and use it when setting up a phishing simulation!

## Limitations

The same limitations from QuickEdit apply. This means specifically:

* insert new layout elements

* add images where the original template didn't include them

* change formatting such as fonts

* add external links or QR codes

* add or customize learning hints

## Additional information

### Why this matters

#### Train on real threats

Employees learn best from examples that feel familiar. Recreate Attack lets you train on the **exact types of phishing emails** your organization is seeing today - not last year.

#### Respond faster

What used to take hours or days can now be done in minutes. That means faster reaction to emerging threats and quicker reinforcement for employees.

#### Keep simulations safe

All recreated emails are fully sanitized. No real malicious links or payloads are ever included. Simulations remain safe at all times. And while you can customize the sender domain, all domains are fully controlled by SoSafe.

### What Recreate Attack is - and isn't

#### Recreate Attack is:

* A fast way to turn real phishing emails into simulations

* A self‑service workflow inside Template Studio

* Designed for realism, speed, and control

#### Recreate Attack is not:

* A live threat detection or monitoring tool

* An automatic campaign launcher

* A way to send real malicious content

## Open Beta: What to expect

Recreate Attack is currently available as an **Open Beta**.

The following features are available:

* Screenshot-based phishing email recreation

* Automated translations

* Template customization

Some advanced automation - such as automated learning hint generation, and more advanced sender modeling - is planned for later.  
**Your feedback during the beta will help shape the next iteration.**

If you'd like to see Recreate Attack in action or share feedback during the Open Beta, **reach out to your SoSafe Customer Success point of contact or explore it directly in Template Studio**.

---
language: "en"
---
# Template Studio

**Read this article in:** [**German**](https://de.support.sosafe.de/pdok/simulation-studio-how-to-guide)

Template Studio helps you create, customize, and manage phishing email templates with ease.

You can access Template Studio by logging in to the [SoSafe Manager](https://manager.sosafe.de/) and navigating to **Phishing Simulation / Template Studio**. You will be shown an overview of your templates along with their details.

## Overview

![Screenshot 2026-03-11 at 10.29.05.png](https://support.sosafe.de/__attachments/a_32fe6b02cb1c41429a0743ade0ab9263ea4743f9afddc95590fed8654cf366cf/Screenshot%202026-03-11%20at%2010.29.05.png?cb=5a936e351babc9420d7593e852b0a904)

Starting here, you have a few options. Using the template list, you can preview, remove and edit existing templates. You can also use the search box to find a specific template based on the subject. If you want to edit an existing template, you can find detailed instructions here: [QuickEdit - Template customization](https://support.sosafe.de/ProductDoc/quickedit-template-customization.md)

## Creating custom templates

Select **+ Create custom template** to get started. You will now be presented with 2 options:

* **Start from scratch:**Start with a blank template, either all on your own or with the help of AI. This is the process that will be explained below.

* **Recreate from a real phishing mail:** Simply upload a screenshot of an email and our AI will turn it into a customizeable phishing template! You can find a full guide here: [Recreate Attack (Beta)](https://support.sosafe.de/ProductDoc/simulation-recreate-attack.md)

In the **Template Creator**, you can start from a blank canvas or opt to use Sofie AI for an automated start. Note that Sofie AI requires you to be on the Premium or Ultimate package.

* Enter a subject line and select the desired language for your phishing template

  ![Screenshot 2024-10-31 at 14.39.09.png](https://support.sosafe.de/__attachments/a_c287adb97cc8593d91d9eceb03da92ee8d4773f93615fb3a3435ce07ff7c106e/Screenshot%202024-10-31%20at%2014.39.09.png?cb=3a8051832a487212389514f4ccfce981)

### **Using Sofie AI for template creation**

1. **Insert a prompt** describing the type of phishing template you need into Sofie AI's text box.

2. Select from three difficulty levels: **Easy, Medium, or Hard** , for varying sophistication in the template and click **Generate**.

   ![Screenshot 2024-10-31 at 14.39.51.png](https://support.sosafe.de/__attachments/a_29cf774fc1cea20ab5c8e1782b2b8a124588ab1b3c97b49b47fecd3e873de87e/Screenshot%202024-10-31%20at%2014.39.51.png?cb=54526f560ae051965e4ec32105b03a03)

### **Customizing Template details**

1. Setting up sender information

2. Enter the **Email prefix** and **Domain** (required fields) to define the sender details. Optionally, you can also specify a **custom sender name.**

   ![Screenshot 2024-10-31 at 14.43.01.png](https://support.sosafe.de/__attachments/a_b59e7bce9c6541c14105d7821cb1a9a69c2fcbae55702f1a114092fc576459dc/Screenshot%202024-10-31%20at%2014.43.01.png?cb=13a0ade249003aea9b15d2aa64dd0a4a)

### **Adding content elements**

1. Customize your template further by dragging and dropping the following elements:

   * Date

   * Fake attachment (type, size, and name, displayed as an image)

   * Salutation and Name (to personalize each email)

   * Link (mandatory field) - This link directs users to a learning page if they click within the phishing email.

     ![Screenshot 2024-10-31 at 14.45.33.png](/__attachments/a_a3477613449a435a795fc7f825066b355e5e385e10bf205648ebf656516398d7/Screenshot%202024-10-31%20at%2014.45.33.png?cb=4a90cd5236e824fd738a11ca4d81b6ec)

2. Choose between fake attachment types, size and name in the form of an image to insert into the email.

   ![Screenshot 2024-10-31 at 14.47.13.png](https://support.sosafe.de/__attachments/a_63a8077366075431807b39d980e9315a1fef3fa2ef479f66143c130e00e73422/Screenshot%202024-10-31%20at%2014.47.13.png?cb=f299f058114f1807047292b04f4a07b5)

### **Translating your template**

1. Using AI translation for multilingual templates

2. Once your template is complete, choose Translations to convert it into multiple languages with the help of AI.

3. Done with your creation? Now choose to translate you r phishing template into multiple different languages of your choice with the help of AI.

   ![Screenshot 2024-10-31 at 14.50.06.png](https://support.sosafe.de/__attachments/a_7e6d263166932adc00aa7c78319c54ef5c23d8338fcb5adf94d9c7101149b878/Screenshot%202024-10-31%20at%2014.50.06.png?cb=459d64d2f8788c64743c1da0a98fae9c)
4. Choose to preview and edit your freshly translated phishing templates as needed next to the subject line.

   ![Screenshot 2024-10-31 at 14.50.30.png](https://support.sosafe.de/__attachments/a_291c4075b6a0b766c081c4b60281b41240e5c27740fff8efae0ab4804055fee5/Screenshot%202024-10-31%20at%2014.50.30.png?cb=ee0161bb91d79736042955d2f99891d8)

---
language: "en"
---
# Simulation user metrics

## User rating

**Definition**

This shows the mean simulation user rating for all users in a tenant. Users can rate the Simulation platform experience out of five stars. The five star display rounds to the nearest star. The metric also displays the total count of ratings received.

Regardless of which campaigns are selected, this metric always shows all user ratings for the current tenant.  
**Impact**

This gives a good indication of how happy your employees are with your simulation. Users sometimes react negatively to getting "caught" or if they feel like they are getting tested and evaluated. We recommend positive communication alongside a zero-blame culture.

### Multiple tenants behavior

Individual Simulation user ratings from all included tenants are averaged.  

![simulation-userrating.png](https://support.sosafe.de/__attachments/a_4722e7ee4a39b0c89fdf21a94d688c0b48a60fafb539eb110506cd7db916d94e/simulation-userrating.png?cb=09723041520cd8f22f1e43a9e1ce56fd)

## User agent metrics

**Definition**

User agent metrics break down click counts in a campaign by data provided by the user's browser. The pie charts show the overall percentage of the whole, but counts and specific percentages can be viewed via the tooltip by hovering on a pie chart category.

When six or fewer categories are present, all are shown. When more than six categories are present, only the five highest count categories are shown. Others are grouped as "Other" but the overall count is shown in the middle of the chart.

* Click count broken down by browser

* Click count broken down by operating system

* Click count broken down by browser version within each browser. One card is shown for each browser, with up to three cards on each row

**Impact**

This information can be useful to find out whether outdated browser versions are still in use across your organization.

**Multiple clients / Multiple tenants behavior**

For all user agent metrics, the calculation for multiple clients and tenants combines events from all included campaigns. Total counts will therefore be the sum of all individual campaign accounts, and percentages will be calculated accordingly.  
![simulation-agent.png](https://support.sosafe.de/__attachments/a_3a9a0b67ba63daa5615bc37d241b3d8dc2c23b5af62a18ff820b1f3a19a0e05a/simulation-agent.png?cb=999d2aaecb9ef55fd8b2a89611bce05b)  
![simulation-browserversions.png](https://support.sosafe.de/__attachments/a_fafb2ccaf8cdb405194150e423572a2529691f43357abf520fa797eba3a84dff/simulation-browserversions.png?cb=65a0ffd05275b718ca454d6c8e031bf6)

## User overview table

The user overview table provides a set of user-specific metrics for each invited user in the campaign. The table is available if "Individual User Tracking" and "Individual User Data in Customer Report" are enabled, and it can only be viewed for a single campaign.  

|    **Column**    |                            **Description**                            |
|------------------|-----------------------------------------------------------------------|
| Name             | User's first and last name                                            |
| Email            | User's email                                                          |
| User group       | User's user group                                                     |
| Emails sent      | Count of emails sent to the user                                      |
| Click rate       | User's individual click count. Not rate as stated in the title.       |
| Open rate        | User's individual open count. Not rate as stated in the title.        |
| Interaction rate | User's individual interaction count. Not rate as stated in the title. |
| Learning rate    | User's individual learning count. Not rate as stated in the title.    |
| Reply rate       | User's individual reply count. Not rate as stated in the title.       |
| Reporting rate   | User's individual reporting count. Not rate as stated in the title.   |

---
language: "en"
---
# Sofie customization

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/sofie-customization), [**Deutsch**](https://de.support.sosafe.de/pdok/sofie-anpassen)

To make sure Sofie works well for your organization, you can also customize Sofie's name and look.  
Whenever you customize Sofie, you will have to download the new manifest file in the SoSafe Manager and upload it in the [MS Teams Admin Center](https://admin.teams.microsoft.com/). Before you do this, the changes cannot be applied.  
![cyberrcharlie.png](https://support.sosafe.de/__attachments/a_c3a4ea7f0a5e1ca303674d6b167e736271b5559a3a691a06509d3ada264520ff/cyberrcharlie.png?cb=7629f278f724c271b39d7dd7a0fa8cbf)
An example of a highly customized Sofie

## Customization options

### Avatar

This is what your bot will look like! Upload a PNG file (192 x 192 px) to represent your bot. For more technical details, refer to the official [Teams documentation](https://learn.microsoft.com/en-us/microsoftteams/platform/concepts/design/design-teams-app-icon-store-appbar).

### Icon

The icon will be shown in the apps bar on the left of your users' Teams window. The PNG file must be 32 x 32 px and use white on a transparent background. For more technical details, refer to the official [Teams documentation](https://learn.microsoft.com/en-us/microsoftteams/platform/concepts/design/design-teams-app-icon-store-appbar).

### Name

Sofie can be anyone you like! We like her the way she is, but pick whatever works best for your organization.

### Full name

If the intended full name for your bot is longer than 30 characters, you can use this field. To keep things simple, you can use the same name in both fields.

### Description

Here you can provide a short description of your bot that is shown when space is limited. It is also the headline for the full description on the app's details page.

### Full description

This is a longer description of your bot and will be shown in the app details and when hovering over your bot's avatar in Teams, for instance.

### Welcome message

Make sure Sofie introduces herself in style. Make sure it fits your bot's character!

---
language: "en"
---
# How to communicate Sofie Instant Alerts to your staff

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/sofie-instant-alerts-mitarbeitende-informieren)

Here's an email template you can use to share with your staff that you'll extend your current awareness program:

**Subject:**Awareness Training: New MS Teams app Sofie Instant Alerts

Dear colleagues,  
![image-20240206-140829.png](https://support.sosafe.de/__attachments/a_1084b38ad3967771a99013c2ae98a2c03c62cf3300a26da8274786e9b06cc2a9/image-20240206-140829.png?cb=b39674266586fe856c513236b5b76817)

As part of our security awareness training at `[COMPANY NAME]`, we will install Sofie Instant Alerts to MS Teams. This is an additional feature we implement with our security awareness provider SoSafe to further strengthen our cyber defense.

**What are Instant Alerts?**

Cybercrime is developing at a rapid pace, so everyone needs to put awareness at the top of their minds to stay safe from upcoming threats. We at `[COMPANY NAME]` want to empower you to continuously react safely to new attack techniques. The MS Teams bot Sofie Instant Alerts will alert you whenever urgent security news comes in -- so you can help us stay safe together.

**Where can you find it?**

Sofie Instant Alerts will alert you whenever an urgent topic comes up and guide you what to do. The MS Teams bot will automatically appear on the left side menu in MS Teams and you will receive the alert as a direct message.

**What do you need to do when an Alert comes in?**

1. Stay calm and rest knowing: if there is anything you need to do, Sofie will guide you

2. React to the Alert with an emoji to confirm that you have seen it.

**When will** `[COMPANY NAME]`**start using Sofie Instant Alerts?**

The installation will take place `[ENTER DATE/PERIOD]`.

---
language: "en"
---
# Sofie - Instant Alerts & Level Zero Support

**Read this article in:** [**Deutsch**](https://de.support.sosafe.de/pdok/sofie-instant-alerts-level-zero-support)

Sofie has gotten lots of improvement and new capabilities recently.

Check out [Instant Alerts](https://support.sosafe.de/ProductDoc/instant-alerts.md) to find out how she can help you keep your team up to date on security-related topics.

Meanwhile, the new [Level Zero Support](https://support.sosafe.de/ProductDoc/level-zero-support.md) feature enables her to act as a chatbot able to handle all kinds of requests related to security at your organization.

In addition, you can now customize Sofie to suit your organization's look and needs: [Sofie customization](https://support.sosafe.de/ProductDoc/sofie-customization.md)

---
language: "en"
---
# Sofie Policy Management

Sofie's **Policy Management** helps you roll out policies, prompt employees to read \& acknowledge them, and to track the corresponding acknowledgements.

## What Policy Management can do

Sofie can send policies directly to your users through Microsoft Teams or Slack. Users can read the policy and then acknowledge it directly with a quick interaction with Sofie. Once users have acknowledged a policy, you can download a complete report from the SoSafe Manager, which is critical for compliance audits.

### Prerequisites

You must have the Sofie app connected to your MS Teams or Slack workspace. If you have not connected it yet, please follow the instructions in this article first: [Sofie installation and customization](https://support.sosafe.de/ADOC/sofie-installation)

## **How to manage your policies**

The main dashboard is organized into three tabs to help you manage your policies.  
![image-20251030-134913.png](https://support.sosafe.de/__attachments/a_f7342c79841bfda0ec039261907a1913cac2a7de3130fabae22ee1b6116b3507/image-20251030-134913.png?cb=ed80773653247bda7baaf402e2892410)

* **Sent tab:** Here you can see all policies that have already been sent. You can view the acknowledgement rate, preview the message, or resend the message to users who may not have received it. You can also download an audit report of the acknowledgements:

  1. Select the checkbox next to one or more policies in the list.

  2. In the upper right of the table, select the **Download audit** button.

  3. A separate CSV file containing the acknowledgement details will be downloaded for each policy you selected.

* **Scheduled tab:** This tab shows all policies that are scheduled to be sent in the future. You can choose to edit, preview, or delete any scheduled policy.

* **Draft tab:** This tab contains all policies that you have saved as a draft. You can choose to edit, preview, or delete any draft.

## **How to create and send a new policy**

This section will guide you through creating, configuring, and sending a new policy to your users.

### **Step 1: Navigate to Policy Management**

1. In the main navigation menu, select **Sofie**.

2. Select **Policy Management** from the sub-menu. This will open your main dashboard, showing all previously sent policies.

#### **Step 2: Create your policy message**

1. In the top right corner, select **New policy**. This opens the policy editor.

2. Fill in the required fields to create your message for the users:

   * **Headline:** Write a clear and concise headline to get your users' attention.

   * **Link:** Insert the link to the policy document. Ensure that all targeted users have permission to access this link.

   * **Message:** Write a short message to explain what the policy is about and what you need users to do. You can use the placeholder text as a starting point.

![image-20251030-125836.png](https://support.sosafe.de/__attachments/a_8cd8fdea0a8540682f499f7b92e8686397f0bb1e04dba9baf4bdfdeb2a0bbd7a/image-20251030-125836.png?cb=7d10dda619b0e6a8057aa27dd86ae7c2)
The policy editor interface

#### **Step 3: Add translations (optional)**

If your organization operates in multiple languages, you can provide translations for your policy message.

1. Next to the default language, select the **+ icon** to add a new language.

2. Choose the language you want to add from the list.

3. Use the **Languages** dropdown menu to switch between translations and edit the text for each language.

#### **Step 4: Define the target audience**

By default, a new policy is sent to all users. You can target it to specific groups.

1. On the right, select the **Target audience** tab.

2. Select one or more user groups you want to send the policy to.

![image-20251030-130100.png](https://support.sosafe.de/__attachments/a_119753ab1e1fdf9457cd6b38efa672ded202b487258e54726804551f88863ce6/image-20251030-130100.png?cb=ba30621d5ec1d690a7bf362fb44f1ffb)
Target audience interface

#### **Step 5: Send or schedule your policy**

Once you have configured your message and audience, you have three options at the bottom of the screen:

* **Save as draft:** Select this to save your work and return to the dashboard. Your policy will be saved under the **Drafts** tab for later editing.

* **Schedule:** Select this to send the policy at a future date and time. A dialog window will appear where you can set the delivery time and confirm your settings.

* **Send now:** Select this to send the policy immediately. A confirmation window will appear where you can review your settings before sending.

After sending or scheduling, you will be taken back to the main dashboard.  
![image-20251030-130402.png](https://support.sosafe.de/__attachments/a_0cc873395bcf99afa25bef97d1140ff5303ecb42a81bc6f2f2562c1c3597cab4/image-20251030-130402.png?cb=0d1df8c77fc4d1408f434884b7763c5c)
The scheduling interface

## **What your users will see**

It is helpful to know what your users will experience when they receive a policy.

Users will receive a direct message from Sofie within Microsoft Teams or Slack. This message will display the **Headline** and **Message** that you configured earlier. Below the message, they will see two buttons:

* **Read Policy:** Selecting this button opens the link to the policy document you provided.

* **Acknowledge Policy:** After reading the document, the user can select this button to confirm their acknowledgement. This action is automatically recorded in the SoSafe platform, along with the user's details and a timestamp.

![image-20251030-130534.png](https://support.sosafe.de/__attachments/a_bb394b60fcb73753ec34a07a7b142f2a6b775f97626b33c2fc45d1eaa93184b6/image-20251030-130534.png?cb=5bc1119ecbeadfb2b138cc8fa925b5fd)
Sofie Policy message in MS Teams

---
language: "en"
---
# Spear Phishing FAQ

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/spear-phishing-faq), [**Deutsch**](https://de.support.sosafe.de/pdok/spear-phishing-faq)

## What are customized phishing templates?

Together with you, our Social Engineering Team can build completely new and customized phishing templates specifically for your organization's needs to create even more realistic looking attacks.

### What are spear phishing templates?

Compared to general phishing templates that cannot be adjusted at all, spear phishing templates have various placeholders. These can be adjusted and adapted specifically to the organization and its recipients, such as salutations, banner, and content.
Example of a spear phishing template  
![image-20240207-110354.png](https://support.sosafe.de/__attachments/a_6663f7da55797b6a1858fdf5a42059d80ee138bd40c3ee68f845b476ec73e716/image-20240207-110354.png?cb=afb08006a4f0619b550b11f9bbcf8219)

### What is the difference between spear phishing templates and customized phishing emails?

**Spear phishing templates** are limited to its customization and have specified, **customizable placeholders**.

**Customized phishing emails** are built completely **from scratch** to fit your organization's needs which also increases the difficulty level.

### Do you have suggestions for individual templates?

There are several options for the creation of individual templates:

* We are happy to replicate templates that are based on a **real attack** that you have experienced in the past.

* Also, we recommend using**typical internal emails** as example.

* Another option is customizing a **template from our database to your specific needs**, such as CEO fraud or other industry-specific attacks.

Please contact your Implementation Manager for further information.

## Why is it that my phishing template idea was not implemented as expected?

Our team of phishing experts is familiar with a range of tactics that get recipients to click on the fake links. However, our top priority is not to trick the users, but to achieve a learning effect. This is why there should always be some clues with which users can identify the message as a phishing email.

Our experts closely examine each individual template and determine whether they can improve certain psychological vectors or enhance the learning effect. Of course, we are always open to feedback. Please simply approach your Implementation Manager.

---
language: "en"
---
# Trusted Clicks - Removing bot clicks from Analytics

**Read this article in:** [**English**](https://support.sosafe.de/ProductDoc/trusted-clicks)**,** [**German**](https://de.support.sosafe.de/pdok/trusted-clicks)**,** [**Dutch**](https://nl.support.sosafe.de/UDOCNL/trusted-clicks)**,** [**French**](https://fr.support.sosafe.de/ADOCFR/trusted-clicks)

Starting March 4, 2026, SoSafe will automatically filter out automated bot clicks from Phishing Simulation Analytics. If you notice that click rates on new campaigns appear lower than before, this article explains why and what it means for your data.

## What are bot clicks?

Many organizations use email security tools - such as Microsoft Defender, Proofpoint, Barracuda, Mimecast, and others - that automatically scan links in incoming emails. When SoSafe sends a simulated phishing email, these tools may automatically "click" the links in the email as part of their security scanning process.

These automated clicks (sometimes called "ghost clicks" or "bot clicks") are not performed by real employees. They happen before anyone reads the email and can significantly inflate click rate metrics in your Analytics dashboards.

## What is Trusted Clicks?

Trusted Clicks is SoSafe's detection system that identifies and filters out automated bot clicks from your Phishing Simulation Analytics. It works by analyzing click behavior patterns to distinguish between human interactions and automated security tool scans.

When Trusted Clicks identifies a bot click, that click is **still recorded but filtered out of your reports**. No data is lost -- bot clicks are kept in the background so they can be referenced if needed. They simply won't appear in:

* Analytics dashboards (click rate charts, KPIs)

* Exported reports

* Campaign performance summaries

All click metrics you see reflect **genuine employee interactions only**.

## How does bot detection work?

SoSafe's bot detection system uses a honeypot-based approach combined with multiple behavioral signals to determine whether a click is automated or human.

**Honeypot detection:** Each phishing simulation email includes a hidden link that is invisible to human recipients but detectable by automated security scanners. When a scanner "clicks" this hidden link, the system identifies the source IP and flags all associated click events from that IP for the same email as bot-triggered.

**Additional detection signals include:**

* **Click timing patterns** -- Bot clicks typically occur within milliseconds of email delivery, far faster than a human could read and click.

* **Same-actor correlation** -- When a honeypot click is detected, all clicks from the same IP address for the same email within a short time window are flagged as bot activity.

* **Known bot signatures** -- SoSafe maintains a database of known email security tool behaviors and user-agent signatures (e.g., Microsoft Defender, GoogleImageProxy, HeadlessChrome).

* **Click source analysis** -- The system evaluates the origin of the click to identify automated security infrastructure vs. end-user devices.

The detection system uses a weighted scoring model. When combined signals exceed a confidence threshold, the click is classified as a bot click and filtered from analytics.

## What changed and when?

Trusted Clicks filtering applies to phishing simulation data from March 4**onward**.

* **Data from March 4 onward** -- Bot clicks are automatically filtered out. Click rates reflect human interactions only.

* **Historical data (before March 4)** -- Not affected. All historical reports, dashboards, and exports remain exactly as they were.

## How does this affect my data?

After March 4, you may notice that click rates on new phishing simulation campaigns appear lower compared to historical campaigns. This is expected and is a sign that the data is now more accurate -- it does not mean employee behavior has changed.

The magnitude of the change depends on your organization's email security setup. Platform-wide analysis shows that approximately 8% of all clicks are bot-generated on average, but this varies significantly:

* **Organizations with aggressive link-scanning tools** (e.g., Microsoft Defender Safe Links, Proofpoint sandboxing) may see a larger decrease -- in some cases well above 15%.

* **Organizations with lighter email security** may see little to no change.

**Example:** If a campaign previously showed a 15% click rate and a portion of those clicks were from bots, the same campaign type would now show a lower click rate -- reflecting only the clicks from real employees.

## Frequently asked questions

**Do I need to do anything to enable Trusted Clicks?**

No. Trusted Clicks is enabled automatically for all customers. No configuration or action is required on your end.

**Will my historical reports change?**

No. Historical data, reports, and exports are not affected. The filtering applies only to data collected from March 4 onward.

**Does this affect email open rates or other metrics?**

Trusted Clicks specifically filters bot clicks on phishing simulation links. Open rate tracking and other engagement metrics are handled separately and are not changed by this update.

**Can I disable Trusted Clicks?**

Trusted Clicks is enabled by default for all customers and cannot be disabled. The filtering ensures data accuracy and is considered a core part of the analytics experience.

**Does this affect compliance reporting?**

Yes, positively. Compliance reports are now more accurate because they exclude inflated click data from automated tools. This gives you a clearer, more defensible picture of actual employee risk.

**My email security tool is not listed above. Will it still be detected?**

SoSafe's bot detection is not limited to specific security tools. The honeypot-based approach detects automated clicks regardless of the specific tool, so coverage extends to most common email security solutions.

**I see a sudden drop in click rates starting March 4. Is this a bug?**

No. A drop in click rates starting March 4 is expected and means the filtering is working correctly. The lower rate reflects genuine employee clicks with bot activity removed.

---
language: "en"
---
# For Partners

## For Partners

Welcome to SoSafe! If you need help with our Cyber Security Platform from one of our partners, you've come to the right place.

[Summer Release (August 2025) -- SoSafe Partner Platform](https://support.sosafe.de/PDOC/summer-release-august-2025-sosafe-partner-platform.md)

### Recommended articles

*

  #### [SoSafe Partner Platform](https://support.sosafe.de/PDOC/sosafe-partner-platform.md)

  The SoSafe Partner Platform is designed for our Managed Service Provider (MSP) partners to seamlessly onboard and manage cybersecurity awareness training for clients with up to 250 employees.
*

  #### [Summer Release (August 2025) -- SoSafe Partner Platform](https://support.sosafe.de/PDOC/summer-release-august-2025-sosafe-partner-platform.md)

  Read this article in: German Welcome to the Summer Release of the SoSafe Partner Platform! This page highlights the most recent improvements released in August...
*

  #### [Welcome to the Zurich Cyber Security Awareness Platform](https://support.sosafe.de/PDOC/welcome-to-zurich.md)

  The Zurich Cyber Security Awareness Platform is designed for organizations invited by Zurich Insurance Group to seamlessly onboard and manage cybersecurity awareness training for organizations with up to 100 employees.

### Documentation

*

  #### [SoSafe Partner Platform](https://support.sosafe.de/PDOC/sosafe-partner-platform.md)

  * [Getting started: activate your SoSafe Partner Platform access](https://support.sosafe.de/PDOC/getting-started-activate-your-sosafe-partner-platf.md)
  * [Managing partner admin accounts](https://support.sosafe.de/PDOC/managing-partner-admin-accounts.md)
  * [How to create a new client](https://support.sosafe.de/PDOC/how-to-create-a-new-client.md)
  * [How to set up a new client](https://support.sosafe.de/PDOC/how-to-set-up-a-new-client.md)
  * [How to manage an NFR client](https://support.sosafe.de/PDOC/how-to-manage-an-nfr-client.md)
  * [13 more pages](https://support.sosafe.de/PDOC/sosafe-partner-platform.md)
*

  #### [Welcome to the Magenta Security Awareness Basic Support Hub, powered by SoSafe](https://support.sosafe.de/PDOC/welcome-to-the-magenta-security-awareness-basic-su.md)

  * [Magenta Security Awareness: Getting started - activate your SoSafe Platform access](https://support.sosafe.de/PDOC/magenta-security-awareness-getting-started-activat.md)
  * [Magenta Security Awareness: How to manage users](https://support.sosafe.de/PDOC/magenta-security-awareness-how-to-manage-users.md)
  * [Magenta Security Awareness: How to set up the awareness training](https://support.sosafe.de/PDOC/magenta-security-awareness-how-to-set-up-the-aware.md)
  * [Magenta Security Awareness: How to set up E-Learning](https://support.sosafe.de/PDOC/magenta-security-awareness-how-to-set-up-e-learnin.md)
  * [Magenta Security Awareness: How to manage E-Learning](https://support.sosafe.de/PDOC/magenta-security-awareness-how-to-manage-e-learnin.md)
  * [7 more pages](https://support.sosafe.de/PDOC/welcome-to-the-magenta-security-awareness-basic-su.md)
*

  #### [Welcome to the Zurich Cyber Security Awareness Platform](https://support.sosafe.de/PDOC/welcome-to-zurich.md)

  * [Zurich Cyber Security Awareness: First steps after migration](https://support.sosafe.de/PDOC/zurich-migration.md)
  * [Zurich Cyber Security Awareness: How to manage company info](https://support.sosafe.de/PDOC/zurich-how-to-manage-company-info.md)
  * [Zurich Cyber Security Awareness: How to manage users](https://support.sosafe.de/PDOC/zurich-how-to-manage-users.md)
  * [Zurich Cyber Security Awareness: How to set up E-Learning trainings](https://support.sosafe.de/PDOC/zurich-how-to-set-up-e-learning-trainings.md)
  * [Zurich Cyber Security Awareness: How to manage E-Learning trainings](https://support.sosafe.de/PDOC/zurich-how-to-manage-e-learning.md)
  * [6 more pages](https://support.sosafe.de/PDOC/welcome-to-zurich.md)

[Next Page](https://support.sosafe.de/llms-full.txt/1)
