Feature - Awareness portal

What’s New

  • New portal UI
  • Policy Attestation - acknowledge selected Eramba policies inside the training
  • Questionnaire pool - random questions, configurable per attempt
  • Direct video link - embed via iframe, not just upload
  • New schedule - Once or Recurring (recurring spawns Cycles)
  • Advanced reminders - repeating After Start, Before End, Non-Completion

User accounts:

  • the main fix here is that we will stop listing users in user lists when they do not have Main portal assigned - after we fix this it should resolve the performance of the system as well
    should be considered here: Feature - Access Management Updates

Final Field Names

Tab Section Field
General Title
Description
Audience
Content Policy Attestation Associated Policies
Button Text
Questionnaire Questionnaire (upload)
Question Pool (toggle) → Questions Per Attempt
Show Correct Answers (toggle)
Set Passing Score (toggle) → Passing Threshold, Max Attempts
Button Text
Video Video (upload)
Direct Link (iframe)
Button Text
Disclaimer Disclaimer Text (upload)
Button Text
Portal Settings Welcome Message (toggle + rich text)
Thank You Message (toggle + rich text)
Content Order (drag & drop)
Schedule Type (Once | Recurring)
Repeat every
Period
Start Date
End Date
Notifications Invitation Email subject
Email body
After Start Reminder (toggle) First reminder after (days)
Repeat every (days)
Maximum reminders
Subject
Body
Before End Reminder (toggle) Days before end date
Subject
Body
Non-Completion Notification (toggle) Subject
Body

Views:
Awareness Programs
Purpose
what awareness programs exist and what state are they in?
One row = one Awareness Program.

Awareness Cycles
One row = one Awareness Cycle

User Cycle Assignments
Purpose
who did what, when, and with what result?
One row = one User Cycle assignment.

Notifications
One row = one reminder/notification
who was notified and when?

views prototype:
awareness_program_prototype.html (8.3 KB)

Are we able to answer these questions?

  • % of people compliance (this gives overal compiliance) - cycles view
  • who (is|is not) compliant and to what “cycle” - User Cycle
  • what notifications where sent to a user - Notification
  • when a user completed a training - User Cycle

UI: https://www.figma.com/design/NptSbK23ZHLEE0b55WJksv/Eramba-portals?node-id=3933-135511&p=f&t=hBgiqmmNdOm9IPwG-0

Pause functionality:

Awareness program - start/pause/stop
Cycles - finish current cycles

Not implementing - Open platforms ():

Future improvements ideas:

  • per-user deadline for onboarding programs
  • out of the box programs
  • direct integration with platforms as KnowBe4/Huntress/CanIPhish
  • evidence import - possibility to simply add evidence instead of going through whole training

This will be amazing and a great addition to Eramba :raising_hands:

Testing in progress
Form-Content:


Portal Main page:

Questionaire:

Policy Attestation:

Video:

Disclaimer:
TBD

Awareness Program - Scenarios

Two modes:
Once (optional end date, evaluated on audience + completion count)
Cycles (recurrence, repeats every N day/week/month/year).

Scenario Mode Audience Notifications Evidence
1. Onboarding / continuous Once Dynamic (synced group), joiners added over time Invite on enrollment, after-start reminder Running completion rate over current audience
2. Event-driven / remedial Once Static group, assigned manually (e.g. failed phishing, post-incident) Same as Once Same as Once
3. Annual recertification Cycles Dynamic or static Invite, after-start, before-end Scoped per cycle, each cycle its own record, history retained
Role-based / contractor Once/Cycles Static group Same as above Same as above

Update - this shipped with release 3.31.0 (Enterprise).

The final implementation follows the design in this thread, with a few changes worth flagging:

What changed from the design above

  • The Before End Reminder and the Maximum Reminders cap did not make it. Notifications ended up as three types:
    • Invitation (sent when a user’s cycle starts, and automatically to anyone who joins the audience mid-cycle)
    • repeating Reminder (first one X days after the cycle starts, then every Y days until the user completes the training or the cycle ends)
    • Non-Completion notice (sent once, when a cycle closes with the training unfinished - requires an end date)
  • Questionnaires are imported from a CSV file - a template and a filled example are downloadable from the form. The question pool serves N random questions on every attempt.
  • “User Cycle Assignments” ended up as User Records - same object, better name.
  • The Schedule tab got two things the design did not have: a Start immediately option, and a “What will happen” box that lists the exact cycles and dates before you save.
  • Every program has a Demo Mode: you preview the whole training as a participant.

:warning: If you used the old awareness module: your existing programs are migrated as read-only historic evidence. Their cycles, user records and notification logs stay browsable for audits, and the uploaded content (video, questionnaire, disclaimer) can be retrieved with Download Content. To continue training, you create a new program from that material.

The mental model is exactly as described above - Programs → Cycles → User Records, with every email logged - and the four scenarios (onboarding, remedial, recertification, role-based) are the intended usage patterns. Both are covered in the documentation: [TBD].

Thanks to our beta testers!