Docs

SOC mailbox and API

SOC reporting and scoped API access, where your plan includes them.

SOC reporting and scoped API access, where your plan includes them.

SOC mailbox

On the Pro and Enterprise plans. Once connected, an employee's "Report Phishing" click in Outlook is captured automatically, through a Microsoft Graph webhook, into Phishtime's SOC reports queue. Nothing needs to be forwarded by hand. On lower plans, the SOC reports page shows an upgrade prompt.

API keys

Create an API key only for a specific integration. Give each key a clear name and only the scopes it needs (campaigns:read, targets:read, events:read, reports:read). A key is shown once at creation and stored hashed. If you lose one, revoke it and create a new one.

See Handle reports and integrate safely for the exact steps.