People and vendors

Training and acknowledgement

Run security awareness and policy attestations with minimal friction.

Training and acknowledgement

Training and policy acknowledgement are high-signal controls because they connect written intent (policies) to real people behavior.

The Awareness page is /personnel/awareness. The public assignment page at /training/attest/[assignmentId] is where a recipient completes the assigned material and attestations.

Use this when…

  • you need baseline training + acknowledgement readiness for audits/certifications (SOC 2 / ISO are common examples)
  • you want consistent policy attestation records
  • you want to reduce “we never told employees that” risk
  1. Make sure your core policies are current.
  2. Launch acknowledgements for the policies that matter.
  3. Track completion and follow up via tasks.
  4. Repeat on a simple cadence (e.g. annually, plus on major policy changes).

Training plans, campaigns, and assignments

  • A training plan is the reusable definition: content/policies, audience rules, schedule, and reminders.
  • A campaign is a launched run of that plan.
  • An assignment is one recipient's work and completion state.

Audiences can target all personnel, organization users, canonical personnel, identity-provider groups, email domains, selected people, or rule-based populations. Preview the audience before launch, especially when source groups or employment status have recently changed.

The Awareness directory shows campaign state and summary cards; filters help separate pending, in-progress, completed, overdue, or cancelled work. Open a campaign to inspect participants, deadlines, completions, and the associated plan. Personnel detail also shows the campaigns and manual completions belonging to that canonical person.

  1. Keep the personnel population and identity groups current.
  2. Define a stable baseline plan, then add role-specific training only where risk warrants it.
  3. Attach the exact approved policy versions recipients should acknowledge.
  4. Choose a realistic due date and reminder schedule.
  5. Review the audience before launching; do not rely on a stale exported list.
  6. Follow up on overdue assignments and document justified exclusions.
  7. Preserve manual completion evidence only when an external or offline course is genuinely equivalent.

Completion records prove that the workflow was completed. They do not prove understanding, behavioral change, or course quality. Use incident trends, exercises, role-specific checks, and management review where your risk assessment requires stronger assurance.

Compliance angle

  • SOC 2 / ISO 27001: awareness and policy acknowledgement is widely expected.
  • GDPR: training is part of accountability; it also reduces likelihood of privacy incidents.