Skip to content

Full Roster: Enterprise Employee Directory & Human Risk Profiles

Platform Feature: Full Roster
UI Location: Main Navigation > Human Attack Surface > Full Roster (/full-roster)
Core Capabilities: Employee Directory, Individual Human Risk Score (0–100), Susceptibility Timeline, Bulk CSV Import/Export, User Lifecycle Management
Associated Views: Target Groups (/target-groups), Escalation Managers (/employee-escalation-manager)


1. Executive Summary & Value Proposition

An effective security awareness and behavioral management program begins with accurate, real-time employee visibility. Enterprise organizations with thousands of employees across diverse business units, geographic offices, and shift rotations cannot rely on static spreadsheets or disconnected email lists.

Full Roster (/full-roster) serves as SimuPhish’s centralized human attack surface directory. It provides security teams with an exhaustive, real-time inventory of every employee in the organization, complete with their dynamic Individual Human Risk Score (HRS), risk tier categorization, comprehensive attack simulation interaction history, and mandatory training compliance records.


2. The Operational Problem Solved

  • Lack of Individual Risk Visibility: Standard security awareness tools provide aggregate click rates but fail to identify the specific individuals or job roles that consistently fall for phishing lures.
  • Tedious Employee Onboarding: Managing roster additions, departmental transfers, and terminations manually consumes hours of administrative overhead and leaves orphan accounts.
  • Unsubstantiated Remediation: When employees dispute a security failure, security leaders lack an indisputable, timestamped audit trail showing the exact moment links were clicked or credentials submitted.

3. How It Works (The User Journey)

graph TD
    DirectorySync["Automated SCIM / API Sync<br/>(Entra ID, Okta, Google)"] --> FullRoster["Full Roster Directory<br/>(/full-roster)"]
    CSVImport["Bulk CSV Upload & Manual Add"] --> FullRoster

    FullRoster --> Profile["Employee Risk Profile View"]
    Profile --> Score["Human Risk Score (0–100)"]
    Profile --> Tier["Risk Tier Badge<br/>(Critical, High, Medium, Low)"]
    Profile --> Timeline["Historical Attack Timeline<br/>(Simulations, Opens, Clicks, Reports)"]
    Profile --> TrainingStatus["Assigned Defense Curricula & Overdue Status"]

The Administrator Experience

  1. Directory Ingestion & Sync: Employees populate automatically via continuous directory synchronization (Microsoft Entra ID, Okta, Google Workspace, BambooHR) or via high-speed Bulk CSV Import with automatic column mapping.
  2. Search & Granular Filtering: Quickly filter thousands of records by Name, Email, Department/Division, Manager, Risk Tier (Critical, High, Medium, Low), or Account Status (Active, Suspended).
  3. Deep Employee Profile Inspection: Clicking an employee profile reveals:
  4. Calculated Human Risk Score (HRS): Mathematical score (0–100) based on simulation failure velocity, reporting frequency, course completion grades, and dark web exposure.
  5. Attack Susceptibility Timeline: Timestamped record of every drill received, including delivery date, time-to-open, time-to-click, credential entry, and threat reports.
  6. Assigned Training Missions: Track completed courses, active training, scores, and overdue certificates.
  7. Lifecycle & Access Actions: Add single users, edit profile metadata, assign escalation managers, manually assign remedial training modules, or deactivate/delete offboarded personnel with one click.

4. Key Business Benefits & Measurable ROI

  • Targeted Coaching for Repeat Clickers: Immediately isolate the 3–5% of repeat offenders who cause 80% of organizational human risk and enroll them in specialized remediation.
  • Audit-Proof Evidence Trails: Provide comprehensive, timestamped training and simulation records for every employee during annual compliance audits.
  • Automated Identity Lifecycle: Synchronizes seamlessly with corporate identity providers, ensuring zero lag when onboarding new hires or offboarding departing staff.

5. Competitive Edge: Why Full Roster Wins

Feature SimuPhish Full Roster Traditional SAT Directories
Individual Risk Scoring Dynamic 0–100 HRS: Multi-factor behavioral calculation. Basic pass/fail click percentage.
Interactive Attack Timeline Complete Forensic History: Opens, clicks, downloads, reports. Fragmented campaign-level lists.
Granular Roster Operations Inline Role, Manager & Division Assignment: 1-click updates. Clunky multi-step administrative workflows.

6. Target Stakeholders & Compliance Mapping

  • Primary Users: Security Awareness Program Manager, SOC Analyst, HR Operations, IT Directory Administrator.
  • Compliance Alignment:
  • SOC 2 Type II: Trust Services Criteria CC6.2 (User Access & Lifecycle Management).
  • ISO 27001:2022 Control 5.14: Individual awareness tracking and verifiable competence records.