Glossary/Terms
Terms that are used within Herd documentation.
Administrators
Users with elevated permissions who can configure simulations, assign trainings, and manage reports. Administrators have full access and bypass all permission checks. Administrators oversee compliance activities and ensure security awareness programs run effectively. Herd uses a three-role model: Administrator, Operator, and Member.
AI Coach
Herd's AI governance and enablement area that scores how effectively your team prompts AI tools like Claude, ChatGPT, and Microsoft Copilot, then turns the results into coaching. AI Coach is a coaching signal, not a performance evaluation — it describes prompting habits, not the person. Access is gated by the ai_governance.* permissions and is currently in beta.
Activity (Reports)
The tab of the Reports hub that holds your organization's activity log (the audit trail) together with the platform-health views that used to live under Settings → Monitoring: training, email, Slack, and Teams delivery, scheduled jobs, and queues. When something isn't arriving where it should, Activity is where you find out why and retry it.
AI-Generated Training
Trainings automatically created using AI for faster deployment. AI trainings provide a quick way to generate content at scale.
AI-Generation
The process of automatically creating phishing templates or trainings using artificial intelligence. AI-Generation enables admins to produce content quickly without starting from scratch. \
App Destination
The application or endpoint where a training or notification is delivered. App Destinations ensure users receive their assigned trainings and reminders in the right platform, such as email, Slack, or other integrations.
Archive
Retiring a training, track, or policy without deleting it. Archived items are hidden from active lists, blocked from new assignments, and excluded from reports — but keep all historical data and can be unarchived at any time. Archiving is blocked while in-flight assignments exist, so records are never orphaned.
Assigned Training
A training course that has been allocated to a user or group. Assignments ensure employees receive the correct learning modules for compliance.
Audit Evidence
Documentation (e.g., exported reports) used to prove compliance during an audit. &#xNAN;Audit evidence demonstrates that required security training has been delivered and tracked.
Branched Training
A training whose quiz steps route learners down different paths based on their answers, via per-step branching rules. A wrong answer can detour through remedial content while confident learners skip ahead — reporting stays comparable because the authored steps are shared.
Campaign
A collection of phishing simulations sent to specific users, teams, or groups. Campaigns deliver templates to targeted audiences for awareness testing.
Click Rate
The percentage of recipients who clicked a phishing link. Click rates reveal how many users fell for the simulated attack.
Close Training
Retiring a sent training so members no longer see it — pending assignments disappear from their chat surfaces and reminders stop — while the library entry and all reporting stay intact. Closing is softer than archiving and fully reversible: reopening resumes reminders and re-delivers each member's current step.
Compliance Campaign
A trackable program that bundles a compliance framework, required trainings, policies, and assigned users into a single due-date window. Compliance campaigns give teams an audit-ready view of progress toward frameworks like SOC 2, ISO 27001, or HIPAA.
Compliance Tracking
Monitoring user participation and results to ensure regulatory or policy requirements are met. Compliance tracking ensures the organization stays audit-ready.
Conversational Training
An interactive, chat-based training built around learning objectives instead of fixed steps, delivered as a real-time dialogue with HerdAI. Conversational trainings adapt to the learner, confirming understanding before moving on.
CSV Export
A downloadable file containing detailed results from the Reports Page. CSV exports are commonly used as audit evidence.
Custom Training
Tailored security awareness training created specifically for your organization. Custom trainings address company-specific risks and policies.
Deepfake
A simulated attack that uses AI-generated audio or video to impersonate a trusted person. Deepfake simulations test whether employees can spot synthetic media used in social engineering.
Delivery Mode
How a training presents its content: Step-by-step (fixed content cards delivered in sequence) or Conversational (HerdAI teaches the material one-on-one in chat). Delivery mode is chosen per training and can be changed later; it's independent of the delivery channel (Slack, Teams, browser, or email).
Delivery Status
The result of an email being sent (e.g., Delivered, Bounced, Failed). Delivery status helps troubleshoot issues with email campaigns.
Email Template
A customizable phishing email design used to build simulations. Templates allow admins to replicate realistic phishing attempts for training purposes.
Gamification / Points
The points and leaderboard system that rewards users for completing trainings and engaging with phishing simulations. Gamification adds friendly competition to drive engagement; managing leaderboards and points requires the gamification.manage permission.
Group
A collection of Operators that share a set of permissions. Operators inherit the combined permissions of every group they belong to, and groups can sync members from Okta, Azure AD, Google Workspace, or Slack to mirror your org structure.
HerdAI
Herd's built-in AI assistant for creating trainings, drafting phishing simulations, and surfacing risk insights. HerdAI can generate a complete training from a topic or reference document in seconds.
HRIS
Human Resource Information System — your HR system of record, such as Workday or BambooHR. Herd's read-only HRIS integrations pause outreach for employees on leave and keep hire dates and employment status current.
Human Risk Score
An organization, team, and per-user risk score out of 100 — lower is better — computed nightly from phishing results, mandatory-training completion, security alerts, access & identity events, and AI usage, and bucketed into Low, Medium, High, or Critical bands. The numeric score, drivers, and trends are part of the Enterprise plan; the qualitative band is available to everyone.
Landing Page
The web page a recipient sees after clicking a phishing link or scanning a QR code in a simulation. Landing pages can include a credential-capture form to measure who would have submitted their password.
Leaderboard
A ranking of users or teams by the points they earn from trainings and phishing simulations, viewable in Slack or on a public web page. Leaderboards add friendly competition to drive engagement and reporting.
Mandatory Training
A per-assignment flag marking a training as required for the selected users, optionally with a passing score that overrides the training's quiz threshold. Overdue or late mandatory training raises a user's human risk score; on-time completion reduces it.
MCP (Model Context Protocol)
An open standard that lets AI assistants such as Claude, Cursor, and Claude Code call tools on other systems. Herd runs an MCP server that those assistants connect to with your normal Herd sign-in, giving them read access to your reporting and the ability to create draft trainings, never to publish, assign, or message a learner. See the MCP Server page under API Documentation.
Member
A role for everyone else in your organization who interacts with Herd only through Slack or Teams — completing trainings, responding to simulations, and acknowledging policies. Members have no web app access.
Notification
A message sent to a user to inform them about a training assignment, reminder, or update. &#xNAN;Notifications keep users aware of upcoming or pending trainings and can be delivered through Slack or Teams.
Nudge
A reminder that prompts a user to continue or complete their assigned training. Nudges appear by tagging the user in the thread of the training, ensuring visibility and timely follow-up. Users can nudge themselves directly from the Slack Canvas, while administrators can issue nudges from the Trainings Page — either to individuals or to all recipients of a training. Admins can also send nudges for all unfinished trainings at once from Reports → Activity → Training.
Open Rate
The percentage of recipients who opened a phishing simulation email. Open rates indicate how often phishing emails are being viewed.
Operator
A role for team leads, department heads, and training coordinators who have web app access with permissions controlled by group membership. Operators can only do what their group permissions allow, and an Operator can belong to multiple groups.
Policy
A document — such as an Acceptable Use Policy or NDA — that users review and acknowledge in Slack or Teams. Herd tracks who has and hasn't acknowledged each policy for audit-ready records.
Queue Training
The option to schedule a training for release at a later time to stagger multiple trainings that are being assigned to users. Queueing a training helps administrators plan ahead and stagger multiple trainings.
Quishing (QR Code Phishing)
A phishing technique that hides the malicious link inside a scannable QR code, often moving the attack onto a personal mobile device. In Herd, a {{QR_CODE}} placeholder turns any email template into a quishing simulation.
Quiz Progress
Tracks the number of quiz questions answered correctly. Quiz progress helps measure knowledge retention during training.
Recipients
Users included in a simulation campaign. Recipients define who receives the phishing simulation emails.
Report Rate
The percentage of recipients who reported a phishing simulation as suspicious. A rising report rate is one of the strongest signals of a healthy security culture.
Reports Hub
The single Reports page that gathers every report your organization produces into six tabs: Completion, Simulations, Risk, Engagement, Policies, and Activity. The hub gives admins an overview of organization-wide progress and, under Activity, the platform's delivery health.
Runtime Trainings
Trainings that are generated or delivered dynamically during a simulation or user workflow. Runtime Trainings provide just-in-time learning based on how users interact with simulations.
SCORM
Sharable Content Object Reference Model — a packaging standard for exporting a Herd training into other learning management systems. Export a training as a SCORM package to use it in an LMS like Cornerstone, Docebo, or Moodle.
Security Awareness Score
A summary measure of how well users identified and reported phishing attempts. This score provides a quick snapshot of overall resilience.
Simulation
A test scenario designed to mimic real-world phishing or social engineering attacks. Simulations help measure how employees respond to threats in a safe environment.
Smishing
Phishing delivered by SMS text message rather than email. Smishing simulations test how employees respond to social engineering on their phones, where links can't be hovered over to preview them.
Status
The current state of a training (e.g., Not Started, In Progress, Completed). Statuses make it easy to track user progress and completion.
Steps
The number of modules or lessons within a training. Steps show how far a user has progressed through the material.
Story-Based Training
A training written as a first-person account of a real-shaped attack, taken apart lever by lever, with an organization-wide tone dial (Reserved, Balanced, or Bold). Story-based trainings teach the psychology of an attack from the target's point of view — and never use those tactics against the learner.
Threat Feed
The page where industry threat events and phishing reported by your own team appear together, AI-ranked for your organization by relevance, severity, and recency. Any feed event can be turned into a training draft or a phishing simulation with one click.
Threat Intel Feeds
Curated security advisory and news feeds — CISA Alerts, NIST Cybersecurity Insights, security-tagged Hacker News, and others such as KrebsOnSecurity, BleepingComputer, and Dark Reading — that Herd ingests and can summarize for your team, with support for admin-supplied custom RSS feeds. A new organization's starting set of enabled feeds is inferred from its Organizational Context; ingested entries surface on the Threat Feed and can be delivered as a Slack or Teams digest.
Track
An ordered sequence of trainings delivered to users on a cadence you choose. Tracks let you define a learning path once and have Herd schedule each training automatically.
Trust Badge
An embeddable "Trained by Herd" badge for your public compliance or trust page, linking to a live verification page that re-checks your status on every load. The badge shows customers and prospects that your team runs its security awareness training through Herd.
Users
Members of your organization who receive assigned trainings or participate in phishing simulations. User activity and progress are tracked to demonstrate compliance and measure awareness.
Vishing
Voice phishing — phone-based social engineering where an attacker poses as IT, an executive, or a vendor to extract information or access. The safest response is to hang up and verify through a trusted channel.
WhatsApp Phishing
Phishing delivered over WhatsApp rather than email or SMS — a message from an unfamiliar business number carrying a lure and a link. Herd's WhatsApp simulations accept any international number and include real read receipts, unlike SMS.
Last updated