See a collaborator's risk score and which factors are driving it.
Review a person's complete history: which simulations they received, which they opened, which they clicked on, what they reported.
Detect who fell for more than one campaign in the last six months, with details on which ones.
Download a person's events to CSV or Excel to attach them to a case.
Decide who to assign training to with concrete evidence in hand.
This screen doesn't have its own item in the menu. There are two doors:
The full listing: Insights → Analítica de simulaciones and, in the quick access card, Análisis de empleados.
A person's profile, directly: Colaboradores → row's three-dot menu → Estadísticas.
The "Employee Analysis" listing
The table has one row per collaborator with the columns Nombre, Apellido, Correo electrónico, Departamento, Grupos, Reincidencias, Estado and an Estadísticas button.
In Grupos you see the number of groups the person belongs to; clicking on it expands the list with the names.
In Reincidencias you see a number. If it's 1 or more, clicking on it opens a detail with the name of each campaign, the date and the type of event. When the number is 2 or more, it's colored red and adds a warning icon.
What that column counts: campaigns from the last six months in which the person had at least one compromising event —a click, a credential submission, a download, opening a file—. It's counted only once per campaign, and sends, email opens, reports and failed sends don't count. So 1 doesn't mean repeat offender: it means they fell for one campaign. The six-month window is fixed and can't be changed from this screen.
Estado distinguishes Activo from Eliminado: the listing also includes collaborators who have been removed, and active ones appear first.
The filters icon, at the top right of the table, opens the search by Nombre and by Correo electrónico.
Both filters search from the beginning of the text. Typing
Pérezin Nombre won't find Juan Pérez, and typingperez@in Correo electrónico won't find[email protected].
Click on a column header to sort. Avoid sorting by "Grupos": right now the screen crashes and an error page appears (it recovers by re-entering). The rest of the headers sort correctly.
The table shows 20 rows per page and is paginated with the controls below.
The row's Estadísticas button opens that person's profile.
A person's profile
The header shows the person's name and, at the top right, the period selector.
The default period is the previous three calendar months, and the current month is left out. If you launched a campaign this week, the profile will appear empty until you manually extend the range. The options are Últimos 30 días, Mes anterior, Últimos 3 meses, Últimos 6 meses, or a custom range with From and To dates (the range can't exceed one year). Whatever you choose is saved in your browser for the next time you log in.
Risk score — the large gauge, from 0 to 100 with two decimal places. The color changes by range: green up to 20, yellow from 20 to 40, amber from 40 to 60, red from 60 to 80 and dark red above 80. The information icon opens How does it work?, with an explanation of the metric.
This number doesn't depend on the selected period: it always shows the person's current score. Changing the date range moves the activity charts and the events table, not the gauge.
Risk analysis — the radar chart with the four factors that make up the score: Probabilidad de clic, Riesgo de robo de credenciales, Falta de capacitación and Potenciador. It also doesn't depend on the period.
Latest events — the five most recent events, written in natural language ("So-and-so clicked on a phishing email"), with the campaign name and how long ago it happened. The See all button scrolls down to the events table.
Phishing activity summary — four series over the selected period: Enviado, Abierto, Clicado and Comprometido, in quantity and percentage.
Monthly activity — the same four series grouped by month, with a selector for Cantidad or Porcentaje.
Events — the complete table for the period, with the download icon that offers CSV, Print and XLSX.
The exported file comes down without the Date and Time columns you see on screen, and with three header columns in English. It exports what's loaded in the table.
Reincidencias shows 1. Is the person a repeat offender?
No. That 1 means they fell for one campaign in the last six months. Repeat offender is from 2 onward, which is when the number turns red with the warning icon.
The Reincidencias number doesn't match Campaign Impact nor a campaign's detail.
That's correct, and it's on purpose: the three screens answer different questions. Here, campaigns with at least one compromising event in the last six months are counted. In Campaign Impact it's people who fell for two different campaigns in the period you filtered. In a campaign's detail it's those who fell for it there and had already fallen before for another campaign, looking at the entire history with no date limit.
The person just fell for a simulation and their profile appears empty.
It's the default period: it's the previous three calendar months and the current month is left out. Change the range to Últimos 30 días and you'll see the recent activity.
If I change the period, does the risk score change?
No. The gauge and the radar always show the current status. The period affects the events and the activity charts.
Can I see the history of someone I removed?
Yes. The listing includes removed collaborators, with Estado: Eliminado, and their profile remains accessible.
How is the risk score calculated?
With the same engine that feeds all the risk views on the platform. On the screen it appears as "Employee Risk Score (ERS)" and it's the same metric as the Human Risk Score: the details on what raises it and what lowers it are in that article.
Can I export a person's history?
Yes, from the download icon on the Events table, in CSV or XLSX. Keep in mind the clarification above about the file's columns.
I can't find "Employee Analysis" in the menu.
It's not in the side menu. You access it from Insights → Analítica de simulaciones, in the quick access card, or directly to a person's profile from Colaboradores → three dots → Estadísticas.
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap