> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/phishing-simulations/auto-generated-simulations.md).

# Auto-generated Simulations

## Overview of Auto-generated Simulations

Auto-generated simulations let Herd build realistic phishing and smishing templates for you automatically, so you always have fresh, relevant lures on hand without writing every template by hand. Each night, Herd produces new templates seeded from the apps your organization actually uses and from recent real-world threats—then keeps an audit trail of everything it created.

Auto-generated simulations are ideal when you want to:

* Keep a steady supply of **fresh, realistic templates** without authoring each one manually.
* Mirror the **apps your team relies on** so simulations feel believable to your users.
* Respond quickly to **threats your employees are actually reporting** with targeted follow-up simulations.

{% hint style="info" %}
Auto-generated templates are a **Beta** feature. The audit view is read-only—there's no approve or reject workflow on this page. Review and approval still happen on the individual template, and per-org auto-approval is configured in the [Simulation settings drawer](/herd-security-docs/simulations/phishing-simulations/navigating-phishing-simulations-page.md#simulation-settings).
{% endhint %}

***

## How Auto-generation Works

Herd runs a nightly job that generates a shared pool of phishing and smishing templates:

* **Seeded from your app stack** — The generator draws on the apps detected across your organization's environment, so the templates it creates impersonate the tools your team uses every day. Every active organization is guaranteed at least one fresh template matching its app stack.
* **Seeded from recent threats** — New templates are also modeled on recent real-world threat events, keeping your simulations current with the lures attackers are using now.
* **Pending review by default** — Newly generated templates land with an **auto-generated** status and stay pending review until they're approved—unless you've enabled auto-approval (see below).

***

## Follow-up Simulations from Reported Phishing

When an employee reports a real-world phishing email that Herd did **not** send, Herd can turn that report into a follow-up simulation:

* The reported email is surfaced to IT, and Herd models a new phishing template on the same attack pattern so your team can be trained against the specific lure they're being targeted with.
* A wave of reports describing the **same campaign** is clustered together, so duplicate reports collapse into a single follow-up simulation rather than flooding you with copies.
* If the reported email turns out to match a simulation Herd already sent, it's recorded as a report on that campaign instead—no new template is generated.

Follow-up templates created this way land pending review, just like the nightly pool.

***

## Reviewing the Auto-generation Audit

The auto-generated audit view gives you a read-only window into the nightly pipeline. Open it from **Simulations** to see what Herd has been generating and attaching.

At the top of the page you can switch between **Auto-generated Phishing** and **Auto-generated Smishing**, and the view is organized into three tabs:

* **Templates** — Every template the generator has produced. For each one you'll see the template name (which links to its detail page), the **Source** it was seeded from, its **Review** status, how many campaigns it's **Attached** to, and when it was **Generated**.
* **Generation runs** — A record of each nightly generation run, including its status (**Success**, **Empty**, **Partial**, or **Failed**), how many templates were **Generated**, how many were **Dup-skipped** as duplicates, how many were **Brand-skipped** (skipped due to a brand mismatch), how many **Failed**, the run's **Duration**, and any error message.
* **Attach runs** — A record of each run that attached generated templates onto your ongoing campaigns, showing when it **Ran**, the **Campaign** involved, its status (**Attached**, **Skipped**, or **Failed**), and the number of templates **Attached**.

***

## Auto-attaching Generated Templates to Campaigns

On an ongoing campaign you can enable **Auto-add new generated templates**. When it's on, the nightly attach job appends newly generated templates whose tags overlap your organization's tags onto that campaign—so your ongoing simulations keep refreshing on their own.

A few things to keep in mind:

* If your organization has **no tags configured**, the job skips the campaign until you add them.
* If your organization **requires template review** and you haven't turned on auto-approval for generated templates, newly generated templates won't auto-attach until they're approved.

To let generated templates flow in automatically, open the **Simulation settings** drawer (the gear on the Campaigns tab) and turn on **Auto-add generated templates without review** — phishing and smishing each have their own toggle in their respective panels. The toggle only takes effect while template approval is required for that channel; leave it off to review each generated template yourself before it goes live. See [Simulation settings](/herd-security-docs/simulations/phishing-simulations/navigating-phishing-simulations-page.md#simulation-settings).

You're all set—Herd keeps your simulation library fresh in the background while you stay in control of what goes out.
