> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/phishing-simulations/navigating-phishing-simulations-page.md).

# Navigating Phishing Simulations Page

The Phishing Simulation page lets you create, manage, and track phishing templates and campaigns all in one place

## Overview of Phishing Simulations

The **Simulations** section is your central hub for building and managing phishing awareness campaigns in Herd. Here you can create and customize phishing templates, organize them into campaigns, and monitor their performance. You'll also be able to open existing campaigns and review detailed results, helping you measure effectiveness, track progress, and strengthen your team's readiness against real-world phishing threats.

### Accessing the Simulations Section

**Step 1:** On the left-hand sidebar, click **Simulations**.

**Step 2:** This opens the email channel on the **Campaigns** tab, the default landing view. The section is laid out in two parts:

* **The section header** stays in place on every page in the section. The channel you're in is selected under **Simulations** in the sidebar (**Email**, **SMS**, **WhatsApp**, and **Voice**, where they are enabled for your organization). On the right of the header are the **Reviews** button (shown to people who can approve for that channel, when approval is turned on or whenever there are items waiting for a reviewer; it carries a pending count), the **Reports** button, the section's **New** action (**New campaign**, **New template**, or **New landing page**, depending on the tab you are on), and the settings gear.
* **The content card** holds three tabs, **Campaigns**, **Templates**, and **Landing pages**, plus the filters, search, and table for whichever tab is open.

When you open a campaign, template, or landing page, the header condenses to a breadcrumb row (**Simulations › Email › Campaigns**, for example) with the page's own actions on the same line.

## Simulation settings

Click the **gear icon** in the section header (it is available on every tab) to open the **Simulation settings** drawer. You can also deep-link it with `/simulations/email/campaigns?settings`. It is organized into panels:

* **Phishing**
  * **Template Rotation Window** stops users from receiving the same phishing template twice within the configured window. In a multi-template campaign, once every template has been sent to a user recently, Herd falls back to the least-recently-used one. Allowed range **0–730 days**, default **90**; set **0** to disable the no-repeat guarantee.
  * **Phishing Approval** (Beta): when enabled, new phishing templates must be approved before they can be used in campaigns. Turn on **Require approval for new templates**. There is no approver picker here — who may approve is set by the **Phishing > Template > Approve** permission (see [Who can approve](#who-can-approve)).
  * **Auto-add generated templates without review** (Beta): when template review is required, lets nightly **auto-generated** phishing templates skip review and flow straight into your ongoing campaigns. Hand-authored templates still require approval. Only takes effect while Phishing Approval is on.
  * **Monthly manager phishing report**: in the first week of each month, during your business hours, each manager whose direct reports clicked a phishing simulation the month before gets a Slack message (or Teams, if they aren't on Slack) listing who clicked. The tile has two switches:

    * **Compile the monthly phishing report** (on by default): on the 1st of each month, summarizes last month's phishing simulations. Turning it off also stops the manager messages.
    * **Message managers about direct reports who clicked**: sends the manager messages. While the report is off, this switch reads as paused.

    Changing either switch needs permission to manage phishing campaigns. You can deep-link straight to this tile with `/simulations?settings=managerReport`, and turn the messages on or off from [Settings → Admin notifications](/herd-security-docs/settings/settings/admin-notifications.md), which also shows when they were last sent.
* **Smishing** (shown when you have access to SMS simulations)
  * **Smishing Approval** (Beta): the same review control for smishing (SMS) templates.
  * **Auto-add generated templates without review** (Beta): the smishing counterpart of the phishing bypass; only takes effect while Smishing Approval is on.
* **WhatsApp** (shown when the WhatsApp channel is enabled for your organization)
  * The same review control for WhatsApp templates, plus the **Bypass review for auto-generated WhatsApp templates** toggle. See [WhatsApp Phishing Simulations](/herd-security-docs/simulations/whatsapp-phishing-simulations.md).
* **Voice** (shown when the Voice channel is enabled for your organization)
  * **Consent attestation**: an admin has to complete this before any voice campaign can launch. Withdrawing it moves every scheduled voice campaign back to **Draft**. See [Before You Start with Voice Simulations](/herd-security-docs/simulations/voice-simulations/before-you-start.md).
  * **Require approval for new attack types**: when enabled, a new voice attack type waits in the **Reviews** tab under **Voice** until a reviewer clicks **Approve**, and shows as locked in the **New campaign** dialog until then. See [Voice Attack Types](/herd-security-docs/simulations/voice-simulations/attack-types.md#approving-new-attack-types).

A **View auto-generation audit & history** link at the bottom of the drawer opens the [auto-generated simulations](/herd-security-docs/simulations/phishing-simulations/auto-generated-simulations.md) audit view.

{% hint style="info" %}
Changing these settings requires the **Org Settings** permission; viewing follows the same permissions as the simulations pages themselves.
{% endhint %}

### Who can approve

Every simulation channel uses the same rule: **who can review and approve is set by that channel's approve permission** — **Phishing > Template > Approve**, **Smishing > Template > Approve**, **Whatsapp > Template > Approve**, and **Vishing > Template > Approve**.

* **Admins** always hold all four.
* **Operators** hold them only through a group that has been granted the permission, in **People › Groups**.
* **Members** can't approve.

The **Reviews** tab (and the **Reviews** button in the section header) only appears for people who can approve on that channel. See [Managing Roles, Groups, and Permissions](/herd-security-docs/how-to-documentation/managing-roles-groups-and-permissions.md#who-can-approve-simulation-templates).

## Exploring the Email Template Library

Open the **Templates** tab to see every phishing email template available to you. The library is a table with one row per template:

* **Template**: a thumbnail, the template name, its subject line, and its first few tags. A star at the front of the row marks the template as one of your **favorites** (favorites are personal to you, not shared with other admins).
* **Source**: **Herd** for prebuilt templates from Herd's catalog, **Custom** for templates your organization authored, or **Generated** for templates Herd produced automatically.
* **Difficulty**: **Foundational**, **Moderate**, or **Advanced**.
* **Review**: **Approved**, **Pending review**, or **Rejected**. Hover a **Rejected** pill to see the reviewer's reason.
* **Used**: how many campaigns have used the template and when it was last used, or **Never used**.
* **Updated**: when it was last changed.

Click **Template** or **Updated** in the header row to sort. Click anywhere on a row to open a **preview drawer** showing the email as recipients will see it, its landing page, link text, tags, and the campaigns it is used in. Use the arrows in the drawer to step through the list, or click **Open template** to go to the full template page. Reviewers also get **Approve** and **Reject** (with a required reason) in the drawer.

Above the table you'll find:

* A **Table** / **Tiles** toggle. The tile view shows larger previews and offers its own sort (**Newest first**, **Oldest first**, **Name A–Z**, **Recently updated**).
* **Export CSV**, which exports the list exactly as it is currently filtered.

#### Creating New Email Templates

While you are on the **Templates** tab, click [**New template**](/herd-security-docs/simulations/phishing-simulations/creating-email-templates.md) in the section header to build a new email template.

#### Searching and Filtering Templates

Use the **Search** box to find a template by name or subject. Click **Filters** to expand the filter panel (the badge on the button counts how many filters are active):

* **Collection**: **All collections**, or one of your organization's collections. While a collection is selected, pencil and trash icons beside the selector let you **Rename** or **Delete** it (deleting a collection never deletes the templates in it).
* **Source**: **Any source**, **Herd**, **Custom**, or **Generated**. Templates Herd generated for your organization specifically (for example from a threat-feed entry) appear under **Generated** as well as **Custom**.
* **Difficulty**: **Any difficulty**, **Foundational**, **Moderate**, or **Advanced**.
* **Usage**: **Any usage**, **Used**, or **Unused**.
* **Archive state**: **Active** (the default), **Archived**, or **All**.
* **Starred**: narrow the list to your favorites.
* **Selected**: show only the templates you currently have checked.
* **Tags**: click tag chips to narrow the list to templates carrying any of the selected tags.

Every filter is applied across your whole library, not just the rows on screen, and your choices are remembered per organization. **Clear filters** resets everything.

#### Working with several templates at once

Tick the checkbox on one or more rows (or **Select all shown** in the header) and a toolbar appears above the table with the count of selected templates and these actions:

* **Archive** (or **Unarchive** when you are viewing archived templates). Only templates your organization owns can be archived; Herd's catalog templates are skipped.
* **Tag**: add tags to every selected template.
* **Add to collection**: put the selected templates into an existing collection, or type a **New collection** name to create one on the spot. Collections can hold your own templates and Herd's catalog templates.
* **Share for whitelisting**: generate the details your mail administrator needs to allowlist the selected templates.
* **Approve** (reviewers only): approve every selected template that is awaiting review.

Your selection survives opening a template and coming back, so you can check a few rows, inspect one, and return without starting over.

Now that you're familiar with the Email Template Library, the next step is to create a new template.
