Add several people to the platform administration, instead of sharing a single account.
Limit the scope of each one: someone who only manages training doesn't need to see or touch the phishing simulations.
Remove access from someone who changed positions or left the company, without losing the record of what they did.
Know at any time who has access, at what level, and whether they're active.
Navigation: Configuración → Usuarios
Click on New user.
Fill in the fields:
Email — the address the person will use to log in.
Full name.
Role — the person's position in your organization, for example "Security Analyst." It's free text and only serves as a reference so you can recognize each person on the list.
Access type — this is where you define the actual permissions.
Save. The person receives an email to set their password, and with that they can already log in.
Role and Access type are two different things and it's easy to confuse them. Role is the position and doesn't change anything about what the person can do; Access type is the permission.
Administrator — full access to your company's panel: simulations, Academy, collaborators and groups, Insights, incident inbox, and all settings, including this very users screen.
Academy Administrator — access only to training. Can create and edit courses and custom courses, build and edit learning paths, enroll collaborators and extend their deadlines, manage quizzes and their questions, and view Academy's analytics and audit log. They can view collaborators, departments, and groups, but cannot modify them.
An Academy Administrator does not see phishing simulations, nor the incident inbox, nor the company settings, and cannot create or edit users.
The table lists one row per user, with Email, Role, Access, and Status (Active or Inactive). You can filter by any of these columns and download the list.
From the menu in the last column:
Edit — change the name, position, or access type.
Deactivate / Activate — asks for confirmation before applying. An inactive user cannot log in, but remains on the list and keeps their history.
There's no delete option on this screen: the way to remove someone's access is to deactivate them. Changes to access type and activations or deactivations are recorded in the Audit Log, along with who made them.
There's an additional level, Support, designed so that an external person can manage only the reinforcement templates —the recommendation pages a collaborator sees after falling for a simulation— without seeing any other section of the panel.
It doesn't appear in the Access type selector: it's set up by the Whalemate team upon request. If you need to grant this access to a vendor or someone from another area, write to us and we'll enable it.
What's the difference between "Role" and "Access type"?
Role is the person's position and is purely informational: you write it freely and it doesn't enable or block anything. Access type is the actual permission, and it's what determines which screens they see.
I need someone to manage only training, without touching simulations. How do I do that?
Give them Academy Administrator. With that access they go straight into Academy and don't see simulations, the incident inbox, or settings.
I created the user and the person says they didn't receive anything.
The email to set the password is sent at the moment of saving. Ask them to check their spam folder, and confirm that the address you entered is spelled correctly: if there's a typo, the email was sent to that wrong address. You can fix it with Edit.
Someone left the company. Should I delete them?
Deactivate them. There's no delete option, and that's intentional: deactivating removes their access immediately while their prior activity stays in the Audit Log, which is what you need if something needs to be audited later on.
Can there be more than one Administrator?
Yes. You can have several users with Administrator access and several with Academy Administrator access, in whatever combination suits you.
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap