Run phishing simulations and track employee click-through

Sends simulated phishing links to your team and logs who clicks, so you know where security training is needed.

How the work actually flows

A straight line. Runs once per each employee.

Pattern: Multiple Instances with a priori Design-Time Knowledge (13)

flowchart TD trig(("security team starts simulation")):::human s0[("load employee list")]:::store s1[["send tracked link to employee"]]:::mi s2["log link clicks"]:::task s3[("record results in spreadsheet")]:::store trig --> s0 s0 -->|"one per each employee"| s1 s1 --> s2 s2 --> s3 out[/"spreadsheet of who clicked"/]:::out pay{{"know where training is needed"}}:::pay s3 --> out out --> pay classDef task fill:#e7f6fe,stroke:#34b8f0,color:#2c2a29 classDef svc fill:#f6f8fa,stroke:#7c8795,color:#2c2a29 classDef mi fill:#e7f6fe,stroke:#0079a8,color:#2c2a29,stroke-width:2px classDef human fill:#fff,stroke:#0079a8,color:#0079a8 classDef store fill:#f6f8fa,stroke:#0079a8,color:#2c2a29 classDef trig fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigtime fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigdata fill:#8ad4f5,stroke:#0079a8,color:#06314c,font-weight:bold classDef gate fill:#fff,stroke:#e8a23d,color:#6b4708,font-weight:bold classDef out fill:#1f9d6b,stroke:#167a53,color:#fff,font-weight:bold classDef pay fill:#06314c,stroke:#021f33,color:#fff
A stepRuns once per itemA personA record or sheetResultPayoff
Build size
Standard

A mid-size build with several tools working together.

Business functions
Spreadsheet & Database Ops
Connects
Google SheetsEmail

The problem it solves

You know your team is a target for phishing, but you don't actually know how they'd react to a real attempt until it happens for real. Running a fair internal test and tracking the results by hand is hard to do consistently.

Who it fits

Security and IT teams running internal phishing awareness testing.

How it works

  1. The system loads a list of employees from a spreadsheet
  2. It generates a unique tracked link for each person and emails it to them
  3. When a link is opened, the system logs who clicked and when
  4. Results are recorded in a spreadsheet for your security team to review
What you get

Employees who need more security training identified

Simulated phishing links go out to your team and every click gets logged so you know where training is needed.

What you get

A spreadsheet showing which employees clicked the simulated link, so you know where to focus training.

What you need

A Google account for the spreadsheet and an email service to send the test links.

We can build this. But should you?

The hard question is not how to build it. It is whether this is the right thing to build first.

That is what a Fractional Chief AI Officer figures out with you, before anyone writes a line of code.

Let's Talk Strategy

Related automations

Back to the AI Playbook