> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/glossary-terms.md).

# Glossary/Terms

#### **Administrators**

Users with elevated permissions who can configure simulations, assign trainings, and manage reports. Administrators have full access and bypass all permission checks. *Administrators oversee compliance activities and ensure security awareness programs run effectively.* Herd uses a three-role model: **Administrator**, **Operator**, and **Member**.

#### **AI Coach**

Herd's AI governance and enablement area that scores how effectively your team prompts AI tools like Claude, ChatGPT, and Microsoft Copilot, then turns the results into coaching. *AI Coach is a coaching signal, not a performance evaluation — it describes prompting habits, not the person. Access is gated by the `ai_governance.*` permissions and is currently in beta.*

#### **AI-Generated Training**

Trainings automatically created using AI for faster deployment. *AI trainings provide a quick way to generate content at scale.*

#### **AI-Generation**

The process of automatically creating phishing templates or trainings using artificial intelligence. *AI-Generation enables admins to produce content quickly without starting from scratch.*\
\\

#### **App Destination**

The application or endpoint where a training or notification is delivered. *App Destinations ensure users receive their assigned trainings and reminders in the right platform, such as email, Slack, or other integrations.*

#### **Archive**

Retiring a training, track, or policy without deleting it. Archived items are hidden from active lists, blocked from new assignments, and excluded from reports — but keep all historical data and can be unarchived at any time. *Archiving is blocked while in-flight assignments exist, so records are never orphaned.*

#### **Assigned Training**

A training course that has been allocated to a user or group. *Assignments ensure employees receive the correct learning modules for compliance.*

#### **Audit Evidence**

Documentation (e.g., exported reports) used to prove compliance during an audit.\
\&#xNAN;*Audit evidence demonstrates that required security training has been delivered and tracked.*

#### **Branched Training**

A training whose quiz steps route learners down different paths based on their answers, via per-step branching rules. *A wrong answer can detour through remedial content while confident learners skip ahead — reporting stays comparable because the authored steps are shared.*

#### **Campaign**

A collection of phishing simulations sent to specific users, teams, or groups. *Campaigns deliver templates to targeted audiences for awareness testing.*

#### **Click Rate**

The percentage of recipients who clicked a phishing link. *Click rates reveal how many users fell for the simulated attack.*

#### **Close Training**

Retiring a *sent* training so members no longer see it — pending assignments disappear from their chat surfaces and reminders stop — while the library entry and all reporting stay intact. *Closing is softer than archiving and fully reversible: reopening resumes reminders and re-delivers each member's current step.*

#### **Compliance Campaign**

A trackable program that bundles a compliance framework, required trainings, policies, and assigned users into a single due-date window. *Compliance campaigns give teams an audit-ready view of progress toward frameworks like SOC 2, ISO 27001, or HIPAA.*

#### **Compliance Tracking**

Monitoring user participation and results to ensure regulatory or policy requirements are met. *Compliance tracking ensures the organization stays audit-ready.*

#### **Conversational Training**

An interactive, chat-based training built around learning objectives instead of fixed steps, delivered as a real-time dialogue with HerdAI. *Conversational trainings adapt to the learner, confirming understanding before moving on.*

#### **CSV Export**

A downloadable file containing detailed results from the Reports Page. *CSV exports are commonly used as audit evidence.*

#### **Custom Training**

Tailored security awareness training created specifically for your organization. *Custom trainings address company-specific risks and policies.*

#### **Deepfake**

A simulated attack that uses AI-generated audio or video to impersonate a trusted person. *Deepfake simulations test whether employees can spot synthetic media used in social engineering.*

#### **Delivery Mode**

How a training presents its content: **Step-by-step** (fixed content cards delivered in sequence) or **Conversational** (HerdAI teaches the material one-on-one in chat). *Delivery mode is chosen per training and can be changed later; it's independent of the delivery channel (Slack, Teams, browser, or email).*

#### **Delivery Status**

The result of an email being sent (e.g., Delivered, Bounced, Failed). *Delivery status helps troubleshoot issues with email campaigns.*

#### **Email Template**

A customizable phishing email design used to build simulations. *Templates allow admins to replicate realistic phishing attempts for training purposes.*

#### **Gamification / Points**

The points and leaderboard system that rewards users for completing trainings and engaging with phishing simulations. *Gamification adds friendly competition to drive engagement; managing leaderboards and points requires the `gamification.manage` permission.*

#### **Group**

A collection of Operators that share a set of permissions. *Operators inherit the combined permissions of every group they belong to, and groups can sync members from Okta, Azure AD, Google Workspace, or Slack to mirror your org structure.*

#### **HerdAI**

Herd's built-in AI assistant for creating trainings, drafting phishing simulations, and surfacing risk insights. *HerdAI can generate a complete training from a topic or reference document in seconds.*

#### **HRIS**

Human Resource Information System — your HR system of record, such as Workday or BambooHR. *Herd's read-only HRIS integrations pause outreach for employees on leave and keep hire dates and employment status current.*

#### **Human Risk Score**

An organization, team, and per-user risk score out of 100 — **lower is better** — computed nightly from phishing results, mandatory-training completion, security alerts, access & identity events, and AI usage, and bucketed into Low, Medium, High, or Critical bands. *The numeric score, drivers, and trends are part of the Enterprise plan; the qualitative band is available to everyone.*

#### **Landing Page**

The web page a recipient sees after clicking a phishing link or scanning a QR code in a simulation. *Landing pages can include a credential-capture form to measure who would have submitted their password.*

#### **Leaderboard**

A ranking of users or teams by the points they earn from trainings and phishing simulations, viewable in Slack or on a public web page. *Leaderboards add friendly competition to drive engagement and reporting.*

#### **Mandatory Training**

A per-assignment flag marking a training as required for the selected users, optionally with a passing score that overrides the training's quiz threshold. *Overdue or late mandatory training raises a user's human risk score; on-time completion reduces it.*

#### **Member**

A role for everyone else in your organization who interacts with Herd only through Slack or Teams — completing trainings, responding to simulations, and acknowledging policies. *Members have no web app access.*

#### **Notification**

A message sent to a user to inform them about a training assignment, reminder, or update.\
\&#xNAN;*Notifications keep users aware of upcoming or pending trainings and can be delivered through Slack or Teams.*

#### **Nudge**

A reminder that prompts a user to continue or complete their assigned training. Nudges appear by tagging the user in the thread of the training, ensuring visibility and timely follow-up. *Users can nudge themselves directly from the Slack Canvas, while administrators can issue nudges from the Trainings Page — either to individuals or to all recipients of a training. Admins can also send nudges for all unfinished trainings at once using the Health Page.*

#### **Open Rate**

The percentage of recipients who opened a phishing simulation email. *Open rates indicate how often phishing emails are being viewed.*

#### **Operator**

A role for team leads, department heads, and training coordinators who have web app access with permissions controlled by group membership. *Operators can only do what their group permissions allow, and an Operator can belong to multiple groups.*

#### **Policy**

A document — such as an Acceptable Use Policy or NDA — that users review and acknowledge in Slack or Teams. *Herd tracks who has and hasn't acknowledged each policy for audit-ready records.*

#### **Queue Training**

The option to schedule a training for release at a later time to stagger multiple trainings that are being assigned to users. *Queueing a training helps administrators plan ahead and stagger multiple trainings.*

#### **Quishing (QR Code Phishing)**

A phishing technique that hides the malicious link inside a scannable QR code, often moving the attack onto a personal mobile device. *In Herd, a `{{QR_CODE}}` placeholder turns any email template into a quishing simulation.*

#### **Quiz Progress**

Tracks the number of quiz questions answered correctly. *Quiz progress helps measure knowledge retention during training.*

#### **Recipients**

Users included in a simulation campaign. *Recipients define who receives the phishing simulation emails.*

#### **Report Rate**

The percentage of recipients who reported a phishing simulation as suspicious. *A rising report rate is one of the strongest signals of a healthy security culture.*

#### **Reports Page**

A high-level dashboard summarizing training and simulation outcomes. *The Reports Page gives admins an overview of organization-wide progress.*

#### **Runtime Trainings**

Trainings that are generated or delivered dynamically during a simulation or user workflow. *Runtime Trainings provide just-in-time learning based on how users interact with simulations.*

#### **SCORM**

Sharable Content Object Reference Model — a packaging standard for exporting a Herd training into other learning management systems. *Export a training as a SCORM package to use it in an LMS like Cornerstone, Docebo, or Moodle.*

#### **Security Awareness Score**

A summary measure of how well users identified and reported phishing attempts. *This score provides a quick snapshot of overall resilience.*

#### **Simulation**

A test scenario designed to mimic real-world phishing or social engineering attacks. *Simulations help measure how employees respond to threats in a safe environment.*

#### **Smishing**

Phishing delivered by SMS text message rather than email. *Smishing simulations test how employees respond to social engineering on their phones, where links can't be hovered over to preview them.*

#### **Status**

The current state of a training (e.g., Not Started, In Progress, Completed). *Statuses make it easy to track user progress and completion.*

#### **Steps**

The number of modules or lessons within a training. *Steps show how far a user has progressed through the material.*

#### **Story-Based Training**

A training written as a first-person account of a real-shaped attack, taken apart lever by lever, with an organization-wide tone dial (Reserved, Balanced, or Bold). *Story-based trainings teach the psychology of an attack from the target's point of view — and never use those tactics against the learner.*

#### **Threat Feed**

The page where industry threat events and phishing reported by your own team appear together, AI-ranked for your organization by relevance, severity, and recency. *Any feed event can be turned into a training draft or a phishing simulation with one click.*

#### **Threat Intel Feeds**

Curated security advisory and news feeds — such as CISA Alerts, NIST Cybersecurity Insights, and security-tagged Hacker News — that Herd ingests and can summarize for your team, with support for admin-supplied custom RSS feeds. *Ingested entries surface on the Threat Feed and can be delivered as a Slack or Teams digest.*

#### **Track**

An ordered sequence of trainings delivered to users on a cadence you choose. *Tracks let you define a learning path once and have Herd schedule each training automatically.*

#### **Trust Badge**

An embeddable "Trained by Herd" badge for your public compliance or trust page, linking to a live verification page that re-checks your status on every load. *The badge shows customers and prospects that your team runs its security awareness training through Herd.*

#### **Users**

Members of your organization who receive assigned trainings or participate in phishing simulations. *User activity and progress are tracked to demonstrate compliance and measure awareness.*

#### **Vishing**

Voice phishing — phone-based social engineering where an attacker poses as IT, an executive, or a vendor to extract information or access. *The safest response is to hang up and verify through a trusted channel.*

#### **WhatsApp Phishing**

Phishing delivered over WhatsApp rather than email or SMS — a message from an unfamiliar business number carrying a lure and a link. *Herd's WhatsApp simulations accept any international number and include real read receipts, unlike SMS.*
