Run security awareness training for a client
Generate a client's annual Security Awareness Training, edit it down before publishing, publish and assign it with a due date, then see the assignment on that training's own Training Records, in Micro-Trainings, and in the fleet-wide Training Records list.
What you will have
- Generate a new annual training for a client already in the awareness program.
- Watch it write, then use Edit to retitle it and trim its lessons and knowledge check.
- Find Regenerate lessons, Archive, and Delete training in the same menu, and know when each applies.
- Publish the training and Assign it with a due date.
- See the assignment reflected in that training's own Training Records.
- Find the separate Micro-Trainings pillar and the fleet-wide Training Records page.
Why it works this way
Editing the Jurisdiction, Province, Industry, or Compliance Frameworks fields changes only what is stored on the training, not the lesson text already written. Regenerate lessons from current frameworks is the separate, deliberate step that re-authors the lessons and knowledge check to match, and it discards any hand-edited lesson text, so it asks first.
Publishing a training is enough on its own: the daily sweep re-assigns every published, client-scoped training each morning to anyone at that client who does not already hold it. Running Assign by hand is only needed to set a due date, or to enroll everyone immediately instead of waiting for the next morning's sweep.
There is no per-employee opt-out of the annual training. Delete training only works before anyone has completed it; once even one person has, delete is refused and Archive is the way to retire the training instead, keeping every completion record on file.
Steps
Open CyberSentry > Awareness > Security Awareness Training.
This trial tenant's list read "No trainings yet. Generate the first annual training to get started," with columns for Title, Client, Year, Frameworks, Status, Completions, and Updated waiting to be filled in. New Training sits above the table, next to a small chevron for its own options.
Open CyberSentry > Awareness > Security Awareness Training. Press New Training and pick a client.
The picker offers only the clients whose service plan includes Security awareness training. Choosing Bluebird Dental pre-filled Year (2026) and Industry (Healthcare) from the client's own record, and left Jurisdiction (country) and Province / state blank, because no billing country is recorded on that client. The form says so in its own words rather than quietly falling back: an amber line above Compliance Frameworks reads that no country is recorded for this client, that the training will cite vendor-neutral standards (ISO 27001, SOC 2, NIST CSF) instead of the law that actually applies, and names the two fields that fix it - Jurisdiction here, or the client's billing Country on their record. The same line appears when the province or the industry is missing or is not one the mapping knows.
Press New Training and pick a client. Fill in Jurisdiction and Province / state, then press Generate Training.
Typing CA and ON re-derived Compliance Frameworks on the spot, from ISO 27001, SOC 2, NIST CSF to PHIPA (Ontario), PIPEDA, and the amber line disappeared because all three facts were now known. Country comes first, then the industry, then the province or state where the governing statute is a provincial one. Everything on this form is editable before you generate, and correctable afterwards on the training itself, and whatever is left in Compliance Frameworks is exactly what gets stored, so a framework the mapping does not know can be added by hand and one that does not apply can be removed. Setting each client's billing country on their record, and a Default Client Country under Settings > Company > Company Profile for the ones you have not filled in individually, is what keeps this form from needing the correction at all.
Fill in Jurisdiction and Province / state, then press Generate Training. Wait for the AI to finish writing the training.
The status pill read Writing… with a banner underneath explaining the training usually takes one to three minutes and that the page can be left and revisited. The Lessons card below showed the same message in place of any lesson text until the job finished. Regenerate lessons from current frameworks sits in the actions menu the whole time too, but it stays greyed out for as long as the status pill reads Writing…. Clicking it anyway, or opening New Training in another tab and generating the same client and year again, does not start a second AI run: the door refuses it, in this exact sentence, "This training is being written by AI right now. Wait for it to finish - it usually takes a minute or two - then try again." That refusal is what keeps a training from ever being written, or paid for, twice.
Note: The status pill shows one of five states: Draft, Writing… (pictured here), Published, Archived, or Generation failed. Generation failed means the AI never produced lessons for the training, so it is an empty shell that does not count as covering the client for the year; open a failed training to see why it failed and to Regenerate or Delete it. This trial tenant has never had a generation fail, so that state is named here from the product's own label rather than pictured.Wait for the AI to finish writing the training. See the finished draft, with its jurisdiction and industry shown beside the status.
The AI landed on a title of its own choosing, eight lessons, and a five-question knowledge check, with the Draft status, Bluebird Dental, 2026, and Healthcare shown together on one line. That same line is where a later correction to Jurisdiction, Province, or Industry would also show, via Edit.
Note: This training already showed Assigned 1 / Pending 1, with a Training Records row for the client's billing contact, at this Draft stage, before this walkthrough published or assigned anything. That looked like a pre-existing data quirk on this trial tenant rather than something to repeat.See the finished draft, with its jurisdiction and industry shown beside the status. Press Edit and retitle the training.
Edit turns the whole page into a form: the title, the jurisdiction fields, every lesson (title, body, reorder, remove), and every knowledge-check question and its options all become editable in place. This walkthrough retyped the title to Northwind Phishing Basics, then removed lessons and knowledge-check questions down to three short lessons and two questions, for a small synthetic example. Jurisdiction, Province / state, and Industry can be corrected here at any time; changing them re-derives Compliance Frameworks immediately, but the already-written lesson text is untouched until Regenerate lessons from current frameworks is run afterward.
Press Edit and retitle the training. Save, and see the trimmed training back on the detail page.
One Save committed the new title, the three remaining lessons, and the two remaining knowledge-check questions together. The training stayed in Draft, unpublished, exactly as it was before editing.
Save, and see the trimmed training back on the detail page. Open the actions menu next to Edit to find Regenerate lessons from current frameworks.
The menu held Publish at the top, then Regenerate lessons from current frameworks, then Archive, then Delete training. Regenerate re-authors every lesson and the knowledge check from whatever jurisdiction and frameworks the training currently carries, discarding any hand-edited lesson text, so it is the fix after changing those fields, not before.
Open the actions menu next to Edit to find Regenerate lessons from current frameworks. The same menu holds Archive and Delete training.
Delete training only works while nobody has completed the training yet. Once even one person has, delete is refused and Archive takes its place: archiving retires the training, stops its assignments and reminders, keeps every completion record, and frees the client and year for a fresh training.
The same menu holds Archive and Delete training. Click Publish and see the status flip to Published.
Only a Published training can be assigned to anyone. The Assigned, Completed, Pending, and Completion Rate tiles carried over unchanged from Draft.
Click Publish and see the status flip to Published. Choose Assign… from the same menu and set a due date.
The dialog explained that the training is assigned to everyone at the client, that assigned users are notified and reminded until they complete it, and that anyone who already holds an assignment is skipped. The only field is an optional due date; this walkthrough set one about a month out. There is no per-employee list here to exclude anyone from: the training is assigned to everyone at the client, with no opt-out on this dialog or anywhere else. Someone who should no longer owe it needs to be deactivated instead, which drops their pending row out of the compliance pool while any training they already completed stays on the record.
Choose Assign… from the same menu and set a due date. See the assignment in this training's own Training Records.
The Training Records table lists NAME, EMAIL, DUE, STATUS, and COMPLETED ON. This table now carries three rows: one Completed, with the date it was finished, and two Pending, each carrying the same Oct 15, 2026 due date this walkthrough's Assign step set. Before any assignment, this same table instead reads Will Be Assigned To and lists only who an assign would enroll, because nobody owes the training yet; assigning switches it over to the real tracked pool. Each newly-assigned person also gets an in-app notification right away, and that always works whether or not email is set up. The emailed copy of the same notice only goes out once a Training mailbox is connected under Settings > Email; this trial tenant has none connected (no EmailLog row for this assignment exists at all), so the email side of the notice stayed held while the in-app one still ran. From assignment, a daily reminder sweep nudges anyone still pending: every 7 days by default, speeding up to every 2 days once the due date is within a week or has already gone by, and every 14 days when there is no due date at all. Reminders do not stop once the due date passes; they keep coming, faster, and only stop when the person finishes the training or the assignment hits its 10-reminder cap.
Warning: Both pending rows here are Bluebird Dental Contacts-tab entries, not Portal Access users; this client has zero Portal Access users, so there was no client-side sign-in to confirm the in-app notification from this pass. Confirm a client actually has Portal Access users under Clients > the client > Users > Portal Access before expecting an assignment to reach someone who can sign in and see it.See the assignment in this training's own Training Records. Open Micro-Trainings, the separate weekly pillar.
Micro-Trainings generates one short lesson plus a one-question quiz per client industry every Monday. It is an internal surface for staff to read today, not a client-facing page. Generate This Week re-runs the job on demand and is idempotent, so it never regenerates a week and industry pair that already exists.
Open Micro-Trainings, the separate weekly pillar. Open Training Records, the fleet-wide compliance list.
This page rolls up every completed annual training across every client, in the program or not; Total Completions and Users Trained both read 0 here because nobody had finished Northwind Phishing Basics yet. The download icon exports the full list as CSV for an audit or a cyber-insurance renewal.
Open Training Records, the fleet-wide compliance list.
If it did not work
- If the Client picker on New Training is empty, no service plan includes Security awareness training yet; add it under Billing > Service Plans > the plan > Included functions.
- If Regenerate lessons from current frameworks seems like the fix for a training that reads oddly, use it only after changing the Jurisdiction, Province, Industry, or Compliance Frameworks fields; it discards any lesson text edited by hand, so it asks first.
- If Delete training is missing or refused, someone has already completed the training; use Archive instead.
- If an assignment does not seem to reach anyone, confirm the client actually has Portal Access users (Clients > the client > Users > Portal Access), not just manual Contacts.
Questions this page answers
I changed the frameworks. Why do the lessons still say the same thing?
Editing the frameworks changes the list stored on the training, not the words that were already written. The lessons were authored once, from whatever the frameworks were at that moment. To make the lessons match the new list, open the actions menu and choose Regenerate lessons from current frameworks: it re-authors every lesson and the knowledge check from the jurisdiction and frameworks the training now carries. It takes one to three minutes and it discards any lesson text you edited by hand, so it asks you to confirm first. The same applies after correcting the Jurisdiction or Industry: those change what SHOULD be cited, and Regenerate is what makes the lessons say it.
Can I edit the lesson text or the knowledge check?
Yes. Press Edit and the page becomes an editor: retitle the training, correct the jurisdiction (country, province or state, industry), change the framework list, rewrite any lesson's title or body, add, remove and reorder lessons, and edit the knowledge check (question text, the answer options, which option is correct, and adding or removing questions). One Save commits all of it. Every lesson needs a title and body and every question needs at least two options with one marked correct, so a half-finished edit is refused rather than shown to an employee as a blank lesson. You can edit at any status. If people have already confirmed their training record, the save tells you how many did: their records are kept and never rewritten, and nobody is asked to take it again.
How do I delete a training, and when should I archive instead?
Delete is in the actions menu and it removes the training outright, along with any assignments still pending on it. It only works while nobody has completed the training. Once even one person has confirmed their training record, delete is refused and you are told how many: those records are the compliance evidence you hand an auditor, so they are never destroyed. Archive is what you want in that case. Archiving retires the training, stops assignments and reminders, keeps every completion record, and frees the year up so you can author a fresh training for the same client. That is also the fix if you are told a training already exists for this client and year.
How do I assign this training to a client's employees?
Publish the training first - only a published training can be assigned (the assignment notice links to the employee's Security Training page, which lists published trainings). Then open the actions menu (next to Edit) and choose Assign. The training goes to everyone at the client who can SIGN IN to the portal: every active, non-internal person there who holds a portal role or is the client owner (the primary contact is one, so they are always included). Someone who is only a contact on file is NOT assigned, because they have no way to open a training and would sit as Pending forever - give them access on the client's Portal Access tab first, and the next assign picks them up. Beyond that there is no way to pick a subset, because annual awareness training is a requirement for the whole company; the only option in the dialog is a due date, and that date is the Due column in Training Records. Assigning is idempotent, so users who already hold an assignment are skipped and you can re-run it safely.
Do I have to assign every training manually?
No. The daily sweep tops up every PUBLISHED, client-scoped training of the current year: it re-assigns it to everyone at the client who can sign in to the portal, which creates rows only for people who do not already have one. So publishing is enough to get everyone with portal access enrolled, and anyone hired later is enrolled automatically on the next morning's sweep, with their own notification and reminders. The sweep never enrolls a contact-only person either - grant them portal access and the next morning picks them up. Assign by hand only when you want to set a due date or start immediately.
What are Micro-Trainings and who sees them?
Every Monday the weekly job generates one short lesson plus a 1-2 question quiz per distinct client industry (and one generic set). Right now they are an internal surface - your team can read them and take the quiz here; a client-facing door is a planned follow-on. Generate This Week re-runs the job on demand; it is idempotent, so an existing week/industry is never regenerated.
What is this page, and how do I export it?
Every annual-training completion across all clients, newest first - the compliance artifact. The tiles count the whole table; the list shows the most recent 500. Use Export on the list to download the full set as CSV for an audit or insurance renewal. Records are kept even after a client is offboarded or deactivated - they are historical evidence.
My clients are not in the United States. Will the training cite the right laws?
Yes, as long as the client record says where they are. Jurisdiction is the first thing the content engine looks at: Canada gets PIPEDA plus the provincial statutes that apply (Quebec Law 25, BC and Alberta PIPA, and the provincial health privacy acts such as Ontario PHIPA or Alberta HIA for clinics); the United Kingdom gets UK GDPR and the Data Protection Act; EU countries get GDPR, with NIS2 and DORA where they apply. An Ontario clinic with Jurisdiction Canada, Province Ontario and Industry Healthcare gets PHIPA and PIPEDA, and the lessons name and explain both. Set each client's billing country on their record, and set your Default Client Country under Settings > Company > Company Profile for everyone you have not filled in individually; when neither says anything, the country your billing Currency implies is used as a last hint. If nothing answers, the training falls back to vendor-neutral standards (ISO 27001, SOC 2, NIST CSF) rather than American law, and the New Training form SAYS SO in a warning line above the framework list, naming the field that fixes it. The same line appears when a province or an industry is missing or is not one the mapping knows. The jurisdiction and the framework list are both editable before you generate and correctable afterwards on the training itself, and what you leave in the framework field is exactly what gets stored, so you can add a framework the mapping does not know about or remove one that does not apply to this client.
Why does this training cite these particular laws?
Because of the Jurisdiction, Province / state and Industry recorded on it, shown beside the status at the top. The compliance frameworks come from the country first, then the industry, then the province or state where the governing statute is a provincial one. A Canadian law firm in Ontario gets PIPEDA and the Law Society Rules of Professional Conduct; an Ontario clinic gets PHIPA and PIPEDA; a US insurer gets GLBA, the NAIC Model Law and HIPAA. The lessons name each of those by name and explain what it actually requires, because a lesson that describes a duty without naming the law that imposes it is rejected and rewritten. If any of the three facts is missing, or is not one the mapping knows, the list widens to whatever is still certain: that country's general baseline, or vendor-neutral standards (ISO 27001, SOC 2, NIST CSF) when no country is recorded. Press Edit and a warning line above the framework list says WHICH fact is missing and which field fills it, so you are never left guessing why a training cites no statute. The jurisdiction is copied onto the training when you create it, taken from the client's billing country (or, if that is blank, your Default Client Country under Settings > Company > Company Profile), so the artifact keeps citing the law that applied for that year even if the client later moves. You can CORRECT it here at any time: press Edit and change Jurisdiction, Province / state or Industry, and the framework list re-derives as you do. Changing it does not rewrite the lessons on its own, so follow it with Regenerate lessons from current frameworks.
Can I excuse one employee from the annual training?
No, and that is deliberate: annual awareness training covers everyone at the client, so there is no per-person opt-out to get wrong or forget. If someone should no longer owe it, they should no longer be an active portal user at that client. Deactivating them (offboarding) drops their pending row out of the compliance pool automatically, and any training they already completed stays on the record as evidence.
What do the "Writing…" and "Generation failed" statuses mean?
Writing… means the AI is composing that training right now - it takes one to three minutes, the row updates itself when it lands, and the training cannot be published, assigned or edited until it does. Generation failed means the AI never produced lessons for it: the training is an empty shell, and it does not count as covering that client for the year, so you can start a fresh one for the same client without deleting it first. Open a failed training to see why it failed and to either regenerate or delete it.
What happens after I assign a training?
Assigning always works, and each newly-assigned user always gets an in-app notification - the program runs in-portal whether or not you use email. The EMAIL copy of that notice goes out once a Training mailbox is connected under Settings → Email; until one is, the email is held and nothing else changes. From then on the daily reminder sweep nudges anyone who has not completed it, starting one interval after assignment - every 7 days normally, every 2 days once the due date is within a week or overdue, every 14 days if there is no due date, with a hard cap of 10 reminders per assignment. Training Records on this page says which of the two things it is holding: BEFORE the first assign it reads Will Be Assigned To, the people an assign would enroll, because nobody owes the training yet; AFTER it tracks the real assigned pool (assigned / completed / pending / completion rate), with a Due column showing the deadline each person is working to and marking it once that day has passed. Someone who is offboarded before completing simply drops out of the pending pool, while completed records are kept.
I clicked Generate and nothing happened - is it working?
Yes. Writing a full annual training - six to eight lessons plus a knowledge check, tuned to that client’s jurisdiction and industry - takes the AI one to three minutes, so the training is created straight away and marked as being written while the work continues in the background. The page refreshes itself when the lessons land. You do not need to wait on it, and you should not click Generate again: a second click is refused precisely so you are never charged twice for the same training.
Was this helpful?