
🔍 New access type: Auditor
Now you can give someone read-only access to the entire platform. A user with Auditor access sees everything —campaigns, courses, statistics, settings— and can't modify anything: creation buttons don't appear and actions are disabled with the notice "Your access is read-only, so you can't make this change.". It's assigned from Settings → Users, in the Access type dropdown, and the Access column in the table shows you who has it.
Access is read-only for the entire platform: it can't be limited by section. The only thing an Auditor can do is change their own password and set up their second factor. Exporting and downloading still work: taking the information with you is part of the role.
🧭 The Agent now starts with a plan overview
When you have an active plan, Awareness → Agent no longer takes you straight to the schedule: it opens with an overview showing overall plan progress, the objectives it covers, how much of each activity type you've completed, and what's coming up next. If there's no plan yet, the screen guides you through creating one.
This only appears for companies that already have an active Agent plan.
📙 New course: Secure Development, now also in Portuguese
The Portuguese version of Secure Development is now in the catalog, titled "Desenvolvimento Seguro". If you have teams that work in Portuguese, you can assign them this version instead of the Spanish or English one. You assign it like any other course, from Academy → Courses.
⚡ Course enrollments now open in large companies
In Academy → Courses → the course → Enrollments, the table now loads rows by page instead of downloading them all at once. In courses with a lot of enrolled people, that was the difference between the screen loading and not loading at all. What changes for you: the total at the bottom of the table is the actual course total and not the number of loaded rows; the search box and the Status, Department, Group, and Date range filters search across all enrollments in the course, so if you're looking for someone on page 8, you'll find them starting from page 1; sorting by Employee is preserved when you change pages; CSV and PDF exports download everything that matches the current filters; and if you turn on row selection and switch pages, what you've already checked stays checked.
The Date range filter now filters by the enrollment's start date. Before, it filtered by the due date, so the same range may give you a different result than before.
📨 The complete enrollment history now arrives by email
The Export complete history (XLSX) option no longer makes you wait with a frozen screen. Now you request it, the platform lets you know it's being prepared, and the file arrives by email with a download link that lasts 48 hours.
This is the complete history export, the one that includes all enrollments without a date filter. The CSV and PDF exports of what you're currently viewing on screen haven't changed: they still download instantly.
📅 Bulk due date extension is back
In Academy → Courses → the course → Enrollments you can once again extend the due date for several people at once. There's a Select rows icon in the upper right: clicking it shows a checkbox on each row, you check the ones you want, and on the bar that appears above the table you click Extend due date. You can build the batch across several pages: what you've checked isn't lost when you change pages, search, or filter.
Only Pending or Overdue enrollments can be selected; a Completed one has already met its goal, so its checkbox is disabled. Extending a batch updates existing enrollments: it doesn't create new enrollments or leave duplicates. The one-by-one action, from each row's three-dot menu, hasn't changed.
🔗 Links in a reported email are now analyzed clean
Links in a reported email arrived with the email add-on's markup stuck to the address, so the reputation service query was run against an address that wasn't the real one. Now they're cleaned before being queried and before being saved, and the verdict you see in Inbox → the email → Domain & URLs corresponds to the actual address. Links from which an address can't be recovered are still shown in the list.
This applies to reported emails from now on: reports that already existed keep the address as it was originally saved. And cleaning the address doesn't change the verdict itself — a domain registered yesterday can still come back as "Clean".
🏷️ "Delete when reporting" is now called "Junk when reporting"
The option said the email would be deleted, but what it actually does is move it to the junk mail folder. In Settings → Report Button the option has been renamed and now includes a note explaining exactly what it does.
This is a name change: the report button's behavior hasn't changed. Moving to junk mail works on Microsoft accounts (Outlook / Microsoft 365).
🗂️ Exporting a very long dashboard to PDF no longer fails
Exporting the dashboard for a company with many departments used to cut off the download. Now the file is generated properly.
🇧🇷 The roster template now accepts Portuguese
The template you download from Collaborators → Import → Load manually offered a language code that the import would later reject, so rows in Portuguese wouldn't go through. This has now been fixed in the template.
If you have a template downloaded from before, download it again: the old one still has the code that doesn't work.
🧩 The smart group preview no longer repeats people
The smart group preview used to show the same person multiple times, and the counter showed the sample size instead of how many people the group actually reaches. Both issues are fixed.
The group's membership was never wrong: what was failing was what the preview displayed.

🏭 Benchmark is now available for all companies
The Benchmark module leaves its trial stage: you'll find it in Insights → Benchmark, with no need to request access. There you compare your indicators against your industry average, you can choose which other industry to compare against, and export the dashboard as a report.
If your company still has little measured activity, some cards may show "No data" or percentages based on very few campaigns. This is not an error: Benchmark needs volume for its numbers to be meaningful. As you send campaigns and assign courses, the indicators fill in on their own.
🪄 The reports inbox now suggests an email's category on its own
When a reported email arrives, the platform automatically analyzes the security of its links and suggests a category in the Category column: Clean, Spam, or Threat, with a wand icon and a note indicating it's a suggestion. If the email has no links, it suggests nothing.
The suggestion is just a guide: the category you choose always wins and is not overwritten. This feature is being rolled out gradually, starting with a small group of accounts — if you don't see it in your inbox yet, it's because your company doesn't have it enabled yet.
📘 New course: Fundamentals and Best Practices of the ISO 9001 Standard
It's now available in the catalog, in Spanish. You assign it like any other course, from Academy → Courses.
📗 New course: Secure Development, now also in English
The English version of Secure Development is now in the catalog, under the title "Secure Development". If you have teams that work in English, you can assign them this version instead of the Spanish one.
📅 Extend the deadline or reassign a course from the same row
In Courses → the course → Enrollments, the menu for each row (⋮) now lets you resolve two things without leaving the list. Extend due date gives that person more time to finish the course, and is available for Pending or Overdue enrollments. Reassign assigns the course again to that person or to others, and is available for Completed or Overdue enrollments. If someone you selected already has an active enrollment for that course, you'll be notified and it won't be duplicated. When you finish — or if you cancel — you return to the list with the filters and search you had set.
🎓 Download the certificate from the person's row
The menu for each row in Enrollments now includes Certificate. It appears only when the enrollment is completed and the certificate has already been generated; it's the same diploma issued by the audit log.
🗑️ Delete the Agent's plan and build a new one
Until now, a generated awareness plan couldn't be undone. From the plan's timeline you can delete it, with a message confirming what will be removed: the schedule and its suggested activities. Your campaigns and courses are not affected. Once deleted, both ways of building a new plan become available again, either uploading a file or answering the questionnaire.
🔔 In-platform notice on update days
On Thursdays, from 12:00 to 15:30 (Argentina time), anyone who enters the dashboard sees a notice at the top announcing the weekly update. The update takes place between 14:30 and 15:00, and there may be brief intermittencies during those minutes. Your data, campaigns, and courses are not affected. The notice appears and disappears on its own, and can be dismissed for that day. It is visible to company administrators and Academy administrators; collaborators do not see it.
📗 Updated content: Secure Development in Spanish
The Secure Development course in Spanish has been updated. Anyone who already has it assigned will see the new content the next time they log in, without losing their progress. Those who had already completed it will see the status Updated - Redo in the enrollments list: this is a signal for you, it doesn't require them to redo it. If you want them to go through it again, assign it to them again.
📋 The course enrollments table has been redesigned
The email now appears below the name instead of taking up a separate column, the two date columns are merged into one showing the full period (since when they have it and when it expires), and the actions move to each row's menu instead of multiple selection. If a person has no groups, you'll see a dash. To extend the date for several enrollments at once, the Reschedule button is still at the top right.
📆 The courses and learning paths export now includes the date each person finished
The audit logs for Courses and Learning Paths now include the Completion date column. You enable it from "Show columns," and it's included in all three exports —CSV, XLSX, and PDF— even if it's hidden in the table. An enrollment that hasn't been completed yet shows a dash. This is useful for mandatory training reports where you need to show the exact day each person completed the training.
✨ Cards with images respond to mouse hover
Cards that have a cover image now show a slight darkening effect that fades when you hover over them, along with a subtle zoom of the image. Cards without images remain the same as before.
↕️ Audit logs can be sorted by any column again
In the audit logs for Courses and Learning Paths, you could only sort by Employee. All columns can now be sorted again.
🔓 Academy administrators can access their analytics again
An Academy administrator would get "action not authorized" when opening the Academy analytics. This no longer happens.

🏭 Compare your Benchmark against another industry
In Benchmark you can now choose which industry to compare your indicators against, and share that view by link. By default it keeps comparing against your profile's industry.
📄 Export the Benchmark as a report
The Benchmark dashboard can be exported as a report in PDF, PNG or JPEG from the Export button in its header. The report includes the brand cover page, the date and the user who generated it, the applied filters and each KPI with its value, the benchmark average and the difference. If your company doesn't have measured activity yet, the report is still generated and each indicator says "No data".
🗑️ Delete a custom course from the Courses list
The courses your company created can now be deleted from the Courses list: three-dot menu on the card → Delete, with a confirmation prompt. The option only appears on your company's custom courses; those from the Whalemate catalog cannot be deleted.
A course that has people taking it cannot be deleted: if there are incomplete enrollments with an active deadline, the platform blocks the deletion. To delete it, you must first remove those enrollments from Statistics → Enrollments.
↕️ Sort the course grid by five criteria
The Academy → Courses grid can be sorted by name, modification date, creation date, type or number of enrollments, and starts with the newest ones.
🏷️ Courses with recent changes are marked
A course that had a content change in the last 30 days carries the Updated badge on its card. After 30 days it disappears on its own, but the last available update date keeps showing.
📃 The employee list is paginated
The Statistics → Employees list now shows 20 people at a time instead of the whole roster at once, and can be set to 10, 50 or 100. The page, size and filters stay in the link: you can share the address and the back button restores the view with the filters applied.
📑 The Simulations export distinguishes what each person received from what they fell for
The people-by-status file from the Simulations Overview now has two campaign columns: Campaigns received and Campaigns fallen for, each with the launch date in parentheses. Before there was a single column listing the received ones, and next to the Status column, it read as the ones the person had failed.
Repeat offenders are counted per campaign, not per event
A person is a Repeat Offender when they fell for 2 or more different campaigns in the period. Before, events were counted, so two actions within the same campaign —opening the attachment and also entering the password— or an automatic click from the antivirus were enough to mark them.
Repeat offender numbers in the Overview may go down as a result of this adjustment.
Test campaigns no longer appear in the exported file
A simulation launched as a test doesn't show up in either of the two campaign columns nor does it affect people's status. Anyone who only received test campaigns in the period is marked as "Never Assigned".
The report button's storage toggle says what it does
In Settings → Report Button, the toggle is now called "Store reported emails on the platform". The notice to the incident reporting emails you set up is always sent and doesn't depend on this option; the toggle only controls whether the email is also stored on the platform for review.
When assigning a course or a path you see all your people
The assignment screen was hiding people who already had the content assigned, so the numbers didn't add up: out of a roster of 320, if 13 already had the path started, the screen showed 307 and there was no way to know where the other 13 were.
Now the list includes your entire roster. People who already have it show up with their status and can't be selected again, and the "Pending" filter no longer returns zero. When using "select all", the number selected will be less than the total: only those that can be assigned are selected.
Deleting a course no longer erases the history of those who took it
Before, deleting a course took with it the enrollments of everyone who had taken it: they disappeared from Enrollments and from reports. Now they remain, with the course name and its status, even though the course no longer exists.
The audit log PDF comes out with the columns you see
The audit log PDF for courses and learning paths only includes the columns visible in the table, in the same order: if you hide columns with "Show columns", the report is built without them. The CSV and XLSX still include all columns — they are spreadsheets for working with the data, not reports for reading.
Images can be inserted in a course's reading sections
In the custom course editor, the save and cancel buttons in the insert image dialog had invisible text, so it looked like they weren't working.
The audience selector adapts to the channel
In Email simulations, the audience selector no longer shows the "Valid phone number" filter, the Phone column, or the Reachable and Excluded counters: these only apply to the SMS channel. In Smishing they still appear unchanged.
Newsletters are no longer delivered repeatedly
The same newsletter could be sent multiple times to the same person when the list was large, because the sending process overlapped with itself. Now each recipient is reserved before receiving the email, so they get only one.
Smart Groups no longer include inactive collaborators
A Smart Group's audience automatically excludes inactive collaborators, without you having to specify it in the request. Groups you already have get corrected on their next sync, so their size may decrease: the new number is the actual people who will receive what you send them.

📋 Preview and confirmation when importing payroll
Payroll import now shows a preview with totals and row-by-row validation before applying changes, and requires explicit confirmation to continue. Upon completion, a summary of what was applied is displayed. If the file is empty or contains errors, confirmation is blocked along with the reason, so the administrator can correct it before continuing.
🧑💼 New Support role for reinforcement templates
The Support role is now available, restricted to the reinforcement templates screen: it can view, create, edit, and restore them, and cannot access any other section of the panel. Upon logging in, it lands directly on that screen. Designed so a third party can manage a client's templates without seeing the rest of the platform. This access is enabled upon request: write to us and we'll set it up.
🔁 Single attempt on quizzes
The attempts configuration for Academy quizzes changed from a numeric field to a three-mode selector: Per day (N retries within a 24 h window), Single (only one attempt per enrollment — once submitted, whether passed or failed, it cannot be retaken), and Unlimited. The quantity is requested only in "Per day" mode. It is configured once for the entire company's Academy. Companies that already had attempts configured will not see a change in behavior.
ℹ️ Clarification on the email report button
An informational notice was added to the report button configuration clarifying that the option to move the reported email to Junk Mail is only available for Microsoft accounts, not for Google. This avoids confusion when configuring this option, making its scope clear according to the email provider.
🌐 Report button messages in the company's language
The default messages for the report button are now preloaded in the company's configured language (Spanish, English, or Portuguese) instead of always in Spanish. Companies without a configured language will continue to see Spanish, and any message the client has already customized will not be modified.
📜 More manageable filter menus
Filter menus for tables with many options now have a maximum height with internal scrolling, instead of growing without limit and taking up the entire screen. Additionally, the selected item is highlighted within the menu, making it easier to quickly locate the active filter.
🏷️ We renamed "Teams" to "Groups"
The "Teams" section is now called "People & Groups," and throughout the platform the term "Teams" has changed to "Groups," for consistency with "Smart Groups." This is a name change and does not affect the functioning of the section or any related functionality.
🌍 Three courses now available in English Ransomware, Network Security, and Application Security can now be assigned in English, in addition to their Spanish and Portuguese versions. You can train multilingual teams with the same content, without relying on external translations.
🛠️ Cybersecurity Operations: updated content We updated the content of the Cybersecurity Operations course. The new version is released first in English; the Spanish and Portuguese versions will arrive later.
♻️ Bribery Prevention and Asset Laundering: updated content We updated the course content to keep it aligned with current compliance practices and requirements. Employees now have access to a clearer, more up-to-date version of the material. Available in Spanish.
✉️ Fix in the sender reauthorization notice
The text of the email sender reauthorization notice was corrected, as it incorrectly mentioned Campaigns as one of the affected areas. The message now correctly indicates that what may fail are Academy emails, gallery resources, and trivia, avoiding confusion about which functionalities are actually impacted.
🔗 Correct link in the Learning Path completion email
The "Certificate" button in the email sent upon completing a Learning Path was fixed: it now leads to Profile > Certificates instead of "My Learnings." This ensures the employee reaches their certificate directly when clicking on the email.
📋 Email and date columns restored in audit logs
The audit logs for learning path and course history now show the email address again (visible by default) along with start and due dates (can be enabled from "Show columns"). All three columns are included in CSV, XLSX, and PDF downloads, and the table's search feature now also finds results by email.
🔍 Filters and sorting fixed in trivia enrollments
Filters and sorting by Employee and by Email in trivia enrollments now work correctly; previously, any search would leave the list empty. Additionally, dates no longer show "Invalid date" when there is no data, and the grid now clearly distinguishes between "loading" and "no results."
🏷️ "Draft" label on QR campaigns
The display of QR campaign cards was fixed: those that are in draft status now show the "Draft" label, just as already occurs with smishing campaigns. Already published campaigns continue to be displayed without that label, with no changes.
📱 More stable Smishing campaign detail
You can now enter a Smishing campaign from the explorer and view its metrics and events without errors. Previously, an error screen with no data appeared, even in campaigns without scheduled dates, where "Invalid date" was also displayed.
🏷️ SMS events with correct name and color
SMS-specific events (delivered, tips viewed, file download) are now displayed with their translated name and color both in the campaign detail and in the employee's profile. Previously, they appeared with an internal identifier or blank, making them hard to read.
Have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap

🔗 Outbound webhooks in Integrations
You can now create, edit, and delete webhooks from Settings → Integrations to receive automatic notifications about your campaign events. Each webhook is protected with an HMAC secret that you can reveal only once and rotate whenever you need to. You can also test the endpoint before enabling it and disable it at any time.
📄 View documentation: https://roadmap.whalemate.com/docs/techincal-documentation/webhooks-de-salida
🧙♂️ New wizard for assigning courses
You can now assign courses to all employees or to a custom audience through a guided three-step wizard: course selection, audience definition, and date scheduling. Before confirming, a review screen shows a summary of the assignment, reducing errors and streamlining course management for the administrator.
📄 View documentation: https://roadmap.whalemate.com/docs/academy/academia-cursos-asignacion-masiva-de-cursos
📋 Redesign of the history table in Learning Paths
We redesigned the learning paths audit history table in Analytics, aligning it with the same design already used for Courses. It now features filters and configurable columns to customize the view, and the progress column shows the progress of each enrollment. You can also export the data to CSV and download certificates and history directly from the table.
🧹 Simplification of Academy Analytics
The previous analytics view and the button to access it were removed; now the new status, coverage, and audit log view is the only one available in Academy Analytics. Enrollment-level details can still be checked from the Courses and Learning Paths Audit Logs, keeping a simpler and more consistent experience.
📐 More accurate calculation in Training Completion
The Training Completion metric in Benchmark now also includes courses that are part of Learning Paths, not just individual courses, and it is calculated only once the deadline assigned to each assignment has passed. This prevents an assignment that is still active from being shown as "not completed" prematurely, giving a fairer reading of actual progress. Additionally, expanding the card shows a note explaining this calculation criterion.
📋 Enrollment source visible in the course report
The administrator's course report now shows the origin of each enrollment generated via deep link or self-enrollment, with an icon and a tooltip next to the employee's name, just as it already does for simulation-based enrollments. In addition, the CSV/XLSX export includes a Source column, making it easier to analyze data outside the platform.
✉️ Login button in Academy reminder emails
Course and learning path reminder emails now include a "Log In" button with the embedded link, instead of showing the URL as plain text. This makes accessing the platform from the email simpler and more direct.
🔑 Update your SSO credentials without relying on support
You can now rotate or update the Client ID, Domain, and Client Secret of your SSO configuration directly from the settings screen, without needing to contact Whalemate. The button automatically adapts based on the status ("Configure" or "Update credentials"), and if you leave the Client Secret field empty while editing, the current value is preserved. This gives you more autonomy and agility to keep your single sign-on integration always up to date.
📌 Sidebar menu easier to navigate
The logo and the user card now remain fixed at the top of the sidebar menu while scrolling, in addition to adjusting to the correct design size. This makes navigation easier and gives a cleaner and more consistent appearance throughout the platform.
🔧 Clearer error message when importing payroll from Google Workspace
We fixed an error that displayed an unclear technical message when trying to import payroll using a Google Workspace account without administrator permissions. A clear and actionable message is now shown, so you can identify and resolve the issue faster.
🔄 Automatic synchronization of smart groups
Smart groups now update automatically every time a directory sync runs (Google, Microsoft, or Okta), adding new members and removing departed ones without the need for manual intervention. In addition, a nightly process was added as a backup to ensure the information is always up to date. This guarantees that permissions and access always reflect the actual structure of the team.
⚠️ Clearer messages when importing payroll
We fixed an error that caused manual payroll imports to fail silently during certain high-load moments. The system now automatically retries and, if it still fails to complete the import, shows a clear on-screen message so the administrator knows what happened.
🎛️ Cleaner date filter menu
We fixed the size of the radio buttons and the spacing in the date range filter menu, both in Enrollment Statistics and in the filter drawers for Academy, Courses, Learning Paths, and Phishing. The elements now look consistent and with proper spacing throughout the platform.
Have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap

🔍 New filters in the course audit history
You can now filter the course audit history table by date, department, team, and course. CSV, PDF, and XLSX exports respect the applied filters, making it easier to analyze exactly the information you need.
📤 Unified export
The export of the course audit history has been simplified: now all options (CSV, PDF, XLSX, and full history) are available from a single "Export" button, streamlining and organizing the process.
🖨️ Your company's logo in the audit PDF
Your company's logo now automatically appears in the footer of every page of the audit PDF. This gives the report a more professional identity consistent with your brand, ideal for sharing with other teams or audits.
🔗 Direct access to the Audit Log from status cards
You can now click on the status cards in the Academy Statistics panel (At risk, Needs attention, Up to date, No training) to access directly the Audit Log table filtered by that status. The generated URL can be shared, and the cards are also keyboard accessible. This speeds up tracking training compliance without needing to apply filters manually
📄 More detail in the Audit Log download
The CSV download of the Academy Audit Log now includes the names of the trivias, courses, and learning paths completed by each collaborator. When a course is part of a learning path, the path it belongs to is also indicated. This makes it easier to analyze and track training progress without needing to cross-reference additional information.
✏️ Clear message when deleting completed enrollments
We fixed the message that appears when trying to delete an enrollment for a course that has already finished (expired or completed). The message is now unified and clearer: "An enrollment that has already finished cannot be deleted." This avoids confusion when managing enrollments.
🧩 Readability fix in quick course assignment
We fixed a readability issue in the quick action to assign courses and learning paths from Academy Analytics. The title is now readable correctly over any cover image, since the image is slightly desaturated and a dark overlay is added along with a text shadow.
🐛 Fixed PDF preview in the Campaign Explorer
We fixed an issue where the PDF preview in the Campaign Explorer appeared cropped or blank. It now renders complete and centered, regardless of the width of the template used, improving clarity when reviewing results.
🧩 Fix for QR campaigns in draft mode
We fixed the behavior of QR campaigns that remain in draft status (without a configured redirect URL). Now, from the actions menu, you can only Edit or Delete the campaign, avoiding options that didn't correspond to its status. Additionally, these campaigns no longer appear in the campaign explorer, avoiding confusion with active or finished campaigns.
🐛 Sender domain selection in phishing campaigns
We fixed a bug that allowed attempting to launch an email phishing campaign without having a valid sender domain. Now, if the template used doesn't have a domain assigned to your company, the system will ask you to choose one before you can send the campaign. This prevents sending failures and ensures emails arrive correctly identified.

🖼️ Customize your recommendation pages
You can now upload, preview, and replace your own recommendation page for each simulation type (Phishing, Smishing, and QRishing) from Settings. This way, when an employee falls for a simulation, they see the content you defined for your company, without depending on Whalemate for every change. If you don't configure your own page, your employees will continue to see the default Whalemate page.
📄 View documentation: https://roadmap.whalemate.com/docs/settings/gestion-de-landing-pages-de-recomendaciones-post-caida
✨ Security tips with comprehension verification
You can now create quick security tips that your employees open from a unique link, without needing prior assignment. Each tip includes an image and a verification question with immediate feedback upon answering, and it saves the answer to display if they log in again. The screen is responsive, with image zoom for greater clarity on mobile devices.
📄 View documentation: https://roadmap.whalemate.com/docs/academy/quick-check
✨ New employee training risk view
We added a table showing each employee's training status — At Risk, Needs Attention, Up to Date, or No Training — along with their completed trivia, courses, and learning paths. You can filter by status, department, country, or teams, search by name, sort by column, choose which columns to view, and export everything to CSV. This lets you identify at a glance who needs follow-up.
📄 View documentation: https://roadmap.whalemate.com/docs/insights/academia-analiticas-de-academia
📅 New default deadline when assigning content: 1 month
When assigning courses, learning paths, or trivia, the due date now comes pre-filled at 1 month (previously it was 6). You can still choose any date on the calendar, with no maximum limit: only the suggested value changes. This speeds up assignments and better reflects actual compliance deadlines.
✨ Renewed Course List
We redesigned the Course List with a grid card view, title search, alphabetical sorting, and filters by language, content, and custom courses, with chips to easily view and remove active filters. From each card you can access enrollments, assign the course, or edit it if it's custom. This renewal is the foundation on which we'll continue adding more features to this section in upcoming releases.
⏱️ Shorter deadlines for the reinforcement course
When assigning a reinforcement course to someone who falls for a simulation, you can now choose shorter deadlines to complete it (1 week or 2 weeks), in addition to the 30 and 45 day options. This gives you more flexibility to create urgency and quickly close the learning cycle after a simulated incident.
🔎 More traceability in the audit log
The audit log now includes Academy assignments (assigning or removing a course, learning path, or resource) and booster changes for a group or employee, showing the previous and new value. This way you can clearly answer who assigned what or who modified a group's risk level, with no blind spots.
✨ Redesigned course audit log
We renewed the per-employee course history table within Course analytics, with filters by department, country, team, course, and status, plus search and sorting by employee. You can now choose which columns to view, export the information to CSV, download certificates in bulk, and check the complete history of each enrollment. The result is a clearer, more flexible view for tracking training status.
🔁 More accurate recurrence calculation
We fixed the calculation of repeat offenders so it considers the most severe event according to the campaign type (for example, file download or password compromise, not just the click). The counter now correctly reflects recurrence cases, even when an employee falls for different campaign types. The data is now consistent between the campaign detail and the Campaign Impact module.
🔗 Deep link to course with Google SSO restored
We fixed an issue where, when opening the direct link to a course without an active session and logging in with Google, the flow didn't lead to the corresponding course. Now, when authenticating with Google, you arrive directly at the course with automatic enrollment if applicable, just like with other access methods. This issue only affected login with Google SAML.
📋 Completed course history for inactive employees
We fixed an issue where, when deactivating an employee in the payroll, their completed courses and learning paths stopped appearing in the enrollment history, altering the completion record. Now completed enrollments are always preserved in the history, even if the employee is no longer active; only incomplete enrollments stop being displayed. This keeps your team's training record whole and reliable over time.
🎯 Fixed audience selection by groups
We fixed an issue in audience selection when launching phishing campaigns. Now, when choosing a group, all its employees are included with no limits, no duplicates when someone belongs to more than one group, and errors no longer occur when working with large groups. Audience selection is now more accurate and reliable.

🔗 Direct deep link to courses
You can now copy the direct link of a course from its detail view in the admin panel and share it with your collaborators (for example, in internal newsletters). Upon clicking, the collaborator lands directly on the course: if they don't have an active session, they log in with their usual method and are automatically redirected; if they weren't enrolled, they are automatically enrolled upon arrival. Available for courses in this first version.
📄 View documentation
📚 New courses available in the Academy catalog
We added 11 new courses to the catalog, focused on regional regulatory compliance and technical security:
OWASP Top Ten: 2025 (ES, PT, EN) — A tour of the ten most critical security risks in web applications according to the latest OWASP edition.
Prevention of Money Laundering and Terrorist Financing (PLA/FT) – Bolivia (ES) — Key concepts and obligations to prevent money laundering and terrorist financing under Bolivian regulations.
Data Privacy – Bolivia (ES) — Principles of personal data protection and privacy best practices within Bolivia's regulatory framework.
Mobile Device and Application Security (EN) — Best practices to protect smartphones, tablets, and the applications we use daily.
Detecting Online Fraud and Scams (EN) — How to recognize and avoid the most common frauds and scams on the internet.
Introduction to LGPD (PT) — Fundamentals of the Brazilian personal data protection law and its impact on daily work life.
TISAX (ES) — Introduction to the automotive industry's information security standard and its requirements.
Corporate Governance for Banks (PT) — Corporate governance principles applied to the banking sector.
IT Governance for Banks (PT) — IT governance best practices in financial institutions.
IoT Security: Protecting the Connected World (PT) — Risks and protective measures for connected devices (IoT).
Fundamentals and Governance of Law 21.663 (ES) — Fundamentals of Chile's Cybersecurity Framework Law and its governance implications.
You can now assign them to your collaborators from the course catalog.
📥 Export of users by status in the Simulations Overview
You can now export a CSV with the details of the users behind each status in the simulations overview. The file includes campaigns received, Personal ID, name, email, department, groups, and status of each user, and is generated in your account's language. This makes manual follow-up, resends, and internal reports easier without leaving the platform.
🔗 Validation of external phishing reports
We improved the integration with email reporting add-ins (such as Outlook or Gmail) to validate that both the campaign and the collaborator belong to the same company before recording the event. This ensures that external reports are correctly reflected in analytics without incorrect records.
⚡ Faster and more reliable delivery for large campaigns
We optimized the sending of campaigns with many recipients: emails are now delivered in batches. Large campaigns are now delivered faster, without affecting or being affected by other operations.
🧪 Clear notice on test campaigns
Test campaigns are always sent immediately so you can quickly verify that emails arrive correctly. The interface now communicates this with a visible notice during creation, so there's no confusion if you set a send date.
🆔 Personal ID visible in Courses and Learning Paths
You can now see each collaborator's Personal ID directly in the progress table of Courses and Learning Paths, without needing to go to the Analytics section. This data is also included in the CSV files exported from both views, making it easier to look up and cross-reference information.
✨ Clearer Academy quick actions
We simplified the quick actions in the Academy Analytics overview, removing options that didn't belong to this module. We also updated the icons for the available actions to align them with the product's current design. The result is a clearer and more consistent experience when managing courses, learning paths, and assigned games.
🔄 Updated courses
We updated the content of three courses in the catalog: Asset Management and Access Control (ES, PT, EN), Cloud Security (ES, PT, EN), and Network Security (ES). The renewed versions are now available to assign to your collaborators.
📥 Incident export in the SIEM Inbox
You can now export the complete list from the SIEM Inbox as CSV directly from the new design. The export respects any filters and search terms you have applied, and includes category, status, sender, domain, subject, who reported it, and report date. This makes incident analysis and reporting outside the platform easier.
🎲 Random groups in Smart Groups
You can now request random groups when creating a Smart Group, for example "a random group of 20 high-risk collaborators." The generation is reliable and consistent, even when combining group size with other filters. Membership is randomly renewed with each sync, always maintaining the defined size.
🧠 Smart Groups better understands your requests
We improved the interpretation of requests when creating Smart Groups: terms such as "repeat offenders," "clickers," or "risky users" are now recognized, and area names are correctly identified even with accents or different capitalization. This reduces rejections in requests that previously failed inconsistently.
🌐 Language fix in exported courses
Fixed an issue where some text in courses exported in SCORM format was displayed in Spanish, even when the course was configured in another language. Now all content correctly respects the native language selected for the course.
🐛 Duplicate "Compromised" status in the campaign explorer
In the email events view of the Campaign Explorer, the "Compromised" status appeared twice in the table. We fixed the root cause so that each status is displayed only once, correctly reflecting the campaign data.