For the complete documentation index, see llms.txt. This page is also available as Markdown.

Campaign Results

View detailed results from phishing campaigns to measure user responses, identify risks, and guide training efforts.

Campaign Results Overview

Campaign Results allow you to analyze how your users interacted with phishing simulations, giving you valuable insights into awareness and response. By reviewing open rates, click rates, and user actions, you can quickly identify strengths, gaps, and areas where additional training is needed.

Campaign Results are ideal when you need to:

  • Analyze open and click rates to measure how users respond to phishing attempts.

  • Track user responses (reporting, ignoring, or failing a simulation) for deeper insights.

  • Compare results across campaigns to measure improvements over time.

  • Identify at-risk groups or individuals and assign follow-up training to strengthen awareness.

  • Share insights with leadership to demonstrate progress in phishing resilience.

Prerequisites for Viewing Results

  • A started campaign: a campaign's Results tab unlocks once it has started sending. Until then the tab is disabled with the reason shown on hover.

  • User participation: target users need to have received and interacted with the phishing simulations.

Program-wide Reports

Click Reports in the Simulations section header to roll all your campaigns into one analytics view. A Reporting timeline control at the top scopes everything to a date range: pick a preset (Last 30 days, Last 60 days, Last 90 days, This quarter, Last quarter, or Last 12 months, the default) or a Custom range of up to 24 months. An Export Report button produces a shareable copy. Below the controls:

  • Key stats: four headline numbers across every campaign: Total Campaigns, Total Recipients, Avg Click Rate, and Avg Report Rate.

  • Last 30 days: a rolling strip with Sent, Click rate, and Report rate for the last 30 days, each compared with the 30 days before ("+2 pts vs prior 30 d").

  • Engagement funnel: organization-wide drop-off from delivered through opened, clicked, and credentials.

  • Trend chart: click rate and report rate over time, so you can see whether behavior is improving as your program runs.

  • Department leaderboard: which departments click least (and most), so you know where to focus.

  • Repeat offenders: the users who have clicked across multiple campaigns and are the best candidates for follow-up training.

  • Never engaged: people with no opens on any simulation, a sign simulations may not be reaching them.

  • Campaign table: every campaign with its date, recipients, click, report, credential, and reply rates, plus status. Click any column header to sort.

  • Monthly reports: a month-by-month summary you can export for stakeholders.

Small campaigns don't skew your averages. Campaigns with fewer than 3 recipients stay visible in the campaign list, but they're excluded from averaged rates and best/worst-performer comparisons (and annotated as low-sample), so a one-person test send can't distort your program metrics.

View by manager

At the bottom of the Reports view, View by manager shows phishing performance rolled up per team: pick a manager and a month to see their summary, a table of their direct reports, monthly reports, and NIST CSF category badges (PR.AT, DE.CM, RS.CO) tying results back to framework language, useful for audits and exec reporting.


Reviewing an Individual Campaign

Open a campaign from the Campaigns tab and switch to its Results tab (started campaigns open on it by default). The tab is organized top to bottom:

  • Five stat tiles: Delivered, Opened, Clicked, Submitted credentials, and Reported, each with its count and rate. Hover the info icon on a tile to see exactly how the rate is calculated.

  • Activity timeline and engagement funnel: a cumulative timeline of opened, clicked, credentials, and reported events since the campaign was sent, next to the recipient drop-off across delivered, opened, clicked, and credentials with tiles for Reported, Median time to click, Median time to report, Reply rate, and (for attachment lures) Attachment opens.

  • The people table: one row per recipient with Person, Delivered status, the time it was delivered (At), Outcome, Time from delivery to the outcome, Training (whether remedial training was assigned or completed), and Follow-up (the status of a follow-up phish, when the campaign sends them).

Above the table, outcome chips count and filter the people by their worst outcome: All, Submitted credentials, Opened attachment, Scanned QR, Clicked, Opened, Reported, Bounced, and No action. A Search people box finds someone by name or email (the search runs across the whole campaign, not just the rows loaded so far), and a sort selector orders the table by Worst outcome, Time to outcome, or Name. Large campaigns load in pages; click Load more to fetch the next batch.

Click anywhere on a row to open the person's drawer. It shows their channel and status and a Phishing history timeline for this campaign: Delivered, Opened, Clicked the link, Scanned the QR code, Opened the attachment, Submitted credentials, Replied, Reported, follow-up events (Follow-up scheduled, Follow-up sent, Follow-up passed, Follow-up clicked, Follow-up cancelled), and Training assigned / Training completed, each with the template involved and a timestamp. Use the arrows in the drawer to step to the previous or next person.

Use Export CSV on the campaign's breadcrumb row for audit evidence.


How Herd Tracks Engagement

  • Opened: when your organization has connected a mailbox (Microsoft 365 or Google Workspace), Herd omits the open-tracking pixel and instead reads the real read flag from the recipient's mailbox. This avoids false-positive opens from security gateways, image proxies, and preview-pane prefetch. The Results tab notes when opens come from the connected mailbox; because the mailbox is checked every 5 minutes, opens can take up to 5 minutes to appear. Organizations without a connected mailbox use a tracking pixel.

  • Clicked and Scanned QR: a link click or QR scan that reaches Herd's tracking URL.

  • Submitted credentials: the person submitted the form on a credential-capture landing page. Herd records that a submission happened, never what was typed. The rate is calculated against the recipients whose template's landing page supports credential capture.

  • Opened attachment: the person opened a tracked attachment link.

  • Reported: the person reported the simulation as phishing, counted toward the campaign's report rate.

How Herd tells people from scanners

Email security gateways (Mimecast, Proofpoint, Microsoft Defender Safe Links, and others) routinely open links and images in incoming mail, on delivery and again when someone clicks. Left uncorrected, those fetches would score people as opening or clicking simulations they never touched, corrupt their risk data, and could wrongly enrol them in remedial training. Herd classifies every hit on a tracking link before it counts:

  • Known scanner traffic is recognized by address range, browser signature, and behavior, and is never counted. Herd also plants an invisible link in every simulation email that only an automated scanner would follow; anything that fetches it (and any click, scan, open, or credential hit from the same source shortly after) is treated as scanner traffic. If a scanner reveals itself after a click was already counted, the click is retracted and any remedial training or follow-up it triggered is withdrawn if nothing has happened on it yet.

  • Opens that arrive within a few minutes of delivery are attributed to the gateway's delivery-time scan and are not counted (mailbox-connected organizations are unaffected, since their opens come from the mailbox itself).

  • Clicks and QR scans that arrive very soon after delivery are held rather than dropped, because a genuinely fast click exists. Herd confirms a held click as soon as the person's browser actually renders the landing page, or when the mail provider reports the message was read in their own mailbox; a click that nothing corroborates is written off after a grace period. While a click is held, the person's row shows Click pending confirmation (or QR scan pending confirmation) under the outcome pill, and the drawer explains that the click is being checked. That usually takes seconds, and 45 minutes at most.

  • Gmail's click-time link check is recognized and used as evidence for the person's own click rather than counted as a separate click, so the recorded click keeps the person's real device and browser.

The person's Phishing history shows what happened transparently: a held click reads pending confirmation, and a scanner's fetch reads security scanner, not counted. Neither is included in the counts, the outcome pill, or the rates.


Follow-Ups

When Send a follow-up phish is on in a campaign's delivery settings, Herd re-phishes users who fail with a different template after the delay you chose, reinforcing training where it's needed most. The Results tab shows a note that follow-up sends are on, each person's Follow-up column carries the status of their follow-up, and the drawer's history lists when it was scheduled, sent, passed, clicked, or cancelled.

Herd can also generate follow-up simulations from real-world phishing that your users report. When a recipient reports an actual phishing email that Herd did not send, that reported attack pattern is fed into Herd's simulation-generation pipeline to create a realistic follow-up simulation modeled on the live threat, so employees are trained against the specific lures they're actually being targeted with. A wave of reports for the same campaign produces a single follow-up simulation rather than duplicates.


Ongoing Campaign Schedule

For ongoing campaigns, the Audience tab's Members view tracks the rolling cadence and upcoming sends with four tiles: Members (the current enrolment), Sent this period, Expected this period, and Next send. The campaign list's When column shows the same next-send date at a glance.

Last updated