Test employee phishing awareness with a safe simulated login page

Sends a harmless fake login link to your team and logs who clicked it, without collecting real passwords.

How the work actually flows

A straight line. Runs once per each employee tested.

Pattern: Sequence (1) ยท Multiple Instances with a priori Run-Time Knowledge (14)

flowchart TD trig(("you load list of employees")):::human s0[["generate trap link"]]:::mi s1["record link clicks"]:::task s2[("log result to spreadsheet")]:::store trig --> s0 s0 --> s1 s1 --> s2 out[/"log of who clicked test link"/]:::out pay{{"awareness data without manual tracking"}}:::pay s2 --> out out --> pay classDef task fill:#e7f6fe,stroke:#34b8f0,color:#2c2a29 classDef svc fill:#f6f8fa,stroke:#7c8795,color:#2c2a29 classDef mi fill:#e7f6fe,stroke:#0079a8,color:#2c2a29,stroke-width:2px classDef human fill:#fff,stroke:#0079a8,color:#0079a8 classDef store fill:#f6f8fa,stroke:#0079a8,color:#2c2a29 classDef trig fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigtime fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigdata fill:#8ad4f5,stroke:#0079a8,color:#06314c,font-weight:bold classDef gate fill:#fff,stroke:#e8a23d,color:#6b4708,font-weight:bold classDef out fill:#1f9d6b,stroke:#167a53,color:#fff,font-weight:bold classDef pay fill:#06314c,stroke:#021f33,color:#fff
A stepRuns once per itemA personA record or sheetResultPayoff
Build size
Standard

A mid-size build with several tools working together.

Business functions
Spreadsheet & Database OpsSecurity & Compliance
Connects
Google Sheets

The problem it solves

You want to know how your team would react to a phishing email before a real attacker tests them for you. Running that test by hand means building a fake page, tracking who clicks, and writing up the results yourself, which takes time you don't have.

Who it fits

Security and compliance teams running authorized phishing-awareness training for their own organization.

How it works

  1. You load the list of employees you're testing
  2. It generates a safe, non-malicious trap link for each person
  3. It records when someone clicks the link
  4. It logs the result and timestamp to a spreadsheet, with no real credentials ever collected
What you get

Employees who click the test link

You get a safe simulated phishing link sent to your team with every click logged, so you see who needs more security training.

What you get

A spreadsheet showing who clicked the test link and when, for use in awareness training reports.

What you need

A Google Workspace account for Google Sheets, and optionally a hosting service for a realistic trap page.

We can build this. But should you?

The hard question is not how to build it. It is whether this is the right thing to build first.

That is what a Fractional Chief AI Officer figures out with you, before anyone writes a line of code.

Let's Talk Strategy

Related automations

Back to the AI Playbook