This is the first version of the feature. We will soon be adding improvements such as more granular permissions for managing these pages.
Lets you customize the educational content an employee sees right after falling for a simulation.
Removes the dependency on the Whalemate team to update messages, logo, or recommendations.
Lets you have a different page for each attack type (Phishing, Smishing, QRishing), independently.
If you do not configure your own page, your employees keep seeing Whalemate's default page, with no interruptions.
Navigation: Settings → Reinforcement templates
Go to Settings → the reinforcement templates section. You will see three independent blocks: Phishing, Smishing, and QRishing.
Choose the attack type you want to configure in the selector (Phishing / Smishing / QRishing). One block is shown at a time, not all three together.
Write or paste your template's HTML directly into the editor.
As you edit, you can see the preview below, in an isolated environment.
Click Save to create or replace the template for that attack type. The button is only enabled if there is content and you made some change.
If you already have an active template configured, the Restore default option appears.
The HTML must be valid and weigh at most 2 MB. If it does not meet these requirements, Save rejects it with an error message.
For security reasons, scripts, forms, and other interactive elements (iframes, embedded objects, etc.) are automatically removed from your HTML before it is saved. Styles (CSS) are preserved.
Who can manage these templates. Besides an administrator, you can grant access with the Support role, designed so that someone external can manage the reinforcement templates without seeing the rest of the panel. A user with that role goes straight into this screen, can create, edit, restore, and delete templates, and cannot access any other section. This access is configured by the Whalemate team on request: it does not appear in the access type selector on the Users tab.
Can I use the same template for all three attack types?
No. Each type (Phishing, Smishing, QRishing) has its own independent template. If you want the same content in all three, you have to write it separately in each one.
What happens if my HTML is not valid or weighs more than 2 MB?
When you click Save, the system rejects it and shows an error message. The previous template (if there was one) is not modified.
Can I include forms or scripts in my template?
No. For security reasons, any script, form, or other interactive element is automatically removed on save. You can use styles (CSS) to customize the appearance.
How do I replace a template that is already configured?
Edit the content in the same editor and click Save; the previous template is replaced directly, with no additional confirmation step.
Do you have feedback or want to request improvements? Tell us at roadmap.whalemate.com/roadmap