Docs

Pre-launch authorization checklist

Check each of these before you launch a campaign.

  • The organization owner and the required security, legal, HR, and communications people have approved the campaign.
  • Where a works council or other employee-representative body has co-determination rights over monitoring tools in your jurisdiction (common in the EU), it has been consulted and has given any required approval. This is separate from, and usually stricter than, internal management sign-off.
  • Employees have had general prior notice, for example in an IT acceptable-use or security-awareness policy, that phishing simulations may happen as part of the security programme. The notice does not need to give timing or content, only that the programme exists.
  • The recipient groups, sender identity, domains, templates, and landing pages are in scope and match what was approved.
  • The target employees' email domain is added and verified under Settings → Domains & network → Verified domains. A campaign cannot reach an unverified-domain target.
  • The signed-in Company Admin has accepted the current Phishtime Terms of Service (the prompt shown on sign-in; the accepted version is recorded under Settings → Branding → Legal & policies).
  • You will not collect real passwords, MFA codes, recovery codes, payment data, or other sensitive real credentials. Phishtime's landing pages do not perform real authentication and do not store entered values, and your process should not try to work around that.
  • Results will be used for training and aggregate risk reporting, not to discipline or single out individuals. Punishing people for clicking measurably reduces future reporting, which is the metric you actually want to improve.
  • If your company has registered office, VPN, or data-centre IP ranges under Settings → Domains & network, note that campaign event data will show whether each click came from inside or outside your network. Factor that into what you disclose about the programme.
  • A support contact and escalation path is ready for employees with questions or concerns.
  • You will start with a small pilot group before expanding to the whole organization.