The admin digest

One recurring email that tells you how your organization's phishing defense is doing โ€” who clicked, who's protected, what your team reported, and what still needs your attention. You pick weekly or monthly. There's no off switch, on purpose.

Who gets it

The digest goes to every active Principal and IT Admin at your organization, and to any Enterprise Admin over it. Teachers, staff, students, and parents never receive it โ€” it's an admin tool.

  • Enterprise admins get a cross-school roll-up. If you administer a diocese or district, your digest aggregates every active school under you into one email โ€” click rates, reported senders, missing extensions, and to-dos across all of them โ€” instead of a separate message per school.
  • Membership is re-checked at send time. If someone stops being an admin between when the digest is queued and when it goes out, their copy is dropped โ€” no stale reports to people who've moved on.
  • It only needs an email on file. A brand-new admin who hasn't verified their address yet still gets the digest (it's treated as an operational email, not marketing).

Weekly or monthly โ€” your choice

Set your cadence under Settings โ†’ Notification preferences (/admin/settings/notifications), in the Admin digest cadence section:

  • Weekly โ€” Fridays at 1:00 PM your local time, covering the last 7 days. This is the default.
  • Monthly โ€” the 1st of the month at 1:00 PM your local time, covering the last 30 days.

The time is anchored to your own timezone (or your org's, falling back to US Eastern). Each admin sets their own cadence, so a principal can take the monthly summary while the IT admin watches weekly.

โœ๏ธ
Why there's no "off" switch
The digest is the one email that surfaces a problem you didn't go looking for โ€” a spike in clicks, a staffer who never installed the extension, a domain quietly failing verification. Letting it be silenced is how those things go unnoticed for months. So you can make it quieter (monthly) but not off. It only ever contains sections that actually have something to report, so a calm month is a short email.

What's in it

The digest is built from real data each period. A section only appears when there's something to show โ€” a week with no clicks has no "who clicked" table โ€” so the length of the email tracks how much is going on.

  • Headline stats (always shown) โ€” four tiles: signed-up count, click rate, report rate, and extension-installed rate; the three rates are color-coded green / amber / red.
  • Trend line โ€” a one-line "report rate up 2 points from last period" when there's a prior period to compare against (skipped on your very first digest, when there's no baseline yet).
  • Who clicked simulations โ€” up to 10 people who clicked a simulated phish this period, with their click count. They've already been shown the in-context training page, so no action is needed from you.
  • Staff missing the browser extension โ€” a count plus up to 8 names and how long it's been since they were invited, with a link to the mass-deployment guide.
  • Training completion โ€” how many staff finished a module this period, and your top performer.
  • Top senders your team reported โ€” up to 5 real (non-simulation) sender addresses your staff flagged, each with an "Alerted" badge if the platform has since confirmed it as a bad sender.
  • Community alerts your team raised โ€” up to 5 senders your org promoted to a community threat this period, with how many staff corroborated and whether it's pending or confirmed.
  • New staff โ€” who joined this period.
  • On your plate โ€” outstanding admin to-dos (e.g. a sending domain awaiting verification) and a short getting-started checklist while you're still setting up.
  • This period's spotlight (always shown) โ€” a rotating highlight: usually a security tip, occasionally a product or referral note.

Every digest ends with an Open Admin Dashboard button so you can jump straight to the live numbers.

Making the most of it

  • Don't chase the clickers. The digest deliberately frames clicks as training moments, not failures โ€” the people who clicked already saw the explainer. Use the trend, not individual names, to judge whether your culture is improving.
  • Act on "missing the extension." This is the single most useful section: a staffer without the extension has none of the real-time protection you're paying for. The force-install link takes you to the deployment options.
  • Watch "on your plate" early on. An unverified sending domain means your simulations may not land correctly โ€” clear those items first.

FAQ

Can I turn the digest off completely?+
No โ€” by design. You can switch from weekly to monthly to make it quieter, but there's no full off switch. It's the email that catches problems you weren't watching for, and a silenced safety email defeats its own purpose. On a quiet month it's only a few lines long.
Can I get it more often than weekly โ€” daily, say?+
Not currently. The two cadences are weekly (Fridays) and monthly (1st of the month). Daily would be noise for most schools; the live Admin Dashboard is there when you want up-to-the-minute numbers.
Does every admin have to get it?+
Every active Principal, IT Admin, and Enterprise Admin receives it, and each sets their own weekly/monthly cadence independently. There isn't a per-person off switch, but a monthly cadence keeps it light for admins who prefer a summary.
Is the spotlight personalized to my school?+
Not yet โ€” the spotlight rotates weekly through a small fixed set (mostly security tips, occasionally a product or referral note) and is the same for every organization that week. Per-org, data-driven spotlights are on the roadmap.
An admin left mid-week โ€” will they still get the digest?+
No. Recipients are re-checked the moment the digest sends, so anyone who's no longer an active admin at your org is dropped from that send.
โ† Previous
Activity log & undo
Next โ†’
Admin & feature-change alerts