Reuse the same audience across several campaigns and assignments, without rebuilding it each time.
Segment by criteria that aren't in the payroll — who deals with clients, who handles payments, who joined this quarter.
Mark a sensitive area as riskier, and have that reflected in the risk score of each person in that area.
Bring in the groups that already exist in your Microsoft or Google directory, instead of rebuilding them by hand.
See at a glance how many people each group has and who they are.
Go to the screen
In the side menu, Settings → People & Groups, and there the Groups tab. The other tab, Employees, is your payroll.
Read the list
Each row is a group, with:
Name, with an avatar that tells you where it comes from: the group's initial if you created it, or the Microsoft or Google logo if it's synced from your directory.
Members, with photos of the first few and the total.
Booster, the group's risk level.
Groups generated with artificial intelligence carry the Smart label and have their own documentation.
You can filter by name, email, department, country, and position.
Create a group
The New group button opens a three-step form:
1. Choose a name for the group — you'll find it by this name later when building a campaign or assigning a course.
2. Assign a booster — the group's risk level, between Low, Normal, High, and Critical. If you don't touch it, it stays at Low.
3. Select the employees — from your payroll, with search and filters.
When you save, you'll see the message Group created.
The group's booster raises the risk for all its people. Each employee has their own risk level, and each group has its own. To calculate a person's risk score, the platform takes the higher of the two: their own and that of the riskiest group they belong to.
This has two practical consequences. If you create a group with Critical booster and put twenty people in it, all twenty are now calculated with critical risk, even if individually they're at Low. And it doesn't work the other way around: putting someone in a group with Low booster doesn't lower their risk, because the highest value always wins.
That's why it's best to use High and Critical only for areas that truly warrant it —finance, management, those who handle sensitive data— and leave operational groups at Low or Normal.
Or import a group from a file
The Import from file option lets you upload an .xlsx with a list of email addresses. Before uploading it, it shows you how many emails it detected and from which file.
The emails must already be in your payroll. The file doesn't add new people: emails that aren't in your employee list simply aren't registered, with no error. If your group ends up with fewer people than you expected, that's why.
A group imported this way ends up with Low booster. If you need a different level, edit it afterward.
Edit, view, or delete a group
The three-dot menu on each row gives you:
View — opens the detail view with the full list of members.
Edit — changes the name, the booster, or the members. When you save, you'll see Group updated.
Delete — asks for confirmation with "Are you sure you want to delete this group?" and confirms with Group deleted.
Deleting a group doesn't remove anyone from the payroll: it only undoes the grouping. And since each person's risk is recalculated based on the groups they belong to at that moment, deleting a group with a high booster causes its people to be recalculated with their own level again.
What is a group's "booster"?
It's the risk level you assign to the group, between Low, Normal, High, and Critical. It's not a decorative label: it's used to calculate the risk score of each member. The platform takes the higher of the person's own level and that of their groups.
I removed someone from a Critical risk group. Does their risk go down?
Yes. The calculation is based on the groups the person belongs to at that moment, so once they leave the group they stop carrying that level and their own level counts again.
Why do some groups have the Microsoft or Google logo?
Because you didn't create them in Whalemate: they come synced from your company's directory. If you see a notice on the screen about the Microsoft integration (Entra ID / Azure AD), it means the sync needs someone to review the configuration.
I imported a file and the group ended up with fewer people than I uploaded.
Emails that aren't in your payroll aren't registered. Check that the missing people are loaded as employees and upload the file again.
How are they different from Smart Groups?
You build a regular group yourself and its members are the ones you chose, until you change them. A Smart Group is generated by describing a criterion in natural language, and the platform figures out who belongs. Smart Groups have their own documentation and carry the Smart label in the list.