Reference
Glossary
The words HumanRisk Shield uses on screen and in these guides, in plain English.
A to C
Acknowledgement. A person's signed confirmation that they have read a policy, with the version and date. See Policies and acknowledgement.
Activity points. Points people earn for lessons, passed knowledge checks and reporting practice phishing. They feed levels and the organization leaderboard. They are not a risk score.
Allowlisting. Telling your mail filters to let HRS practice phishing through and to leave its links alone. See Let practice phishing through your mail filters.
Automated click. A visit to a practice phishing link made by a link scanner or preview rather than a person. Never counted as a click.
Campaign. One practice phishing exercise: a message, what opens after a click, an audience and a send window.
Case. In HRS Triage, a reported email with its analysis, evidence and decision.
Certificate. Proof that a person completed a module. They can print it or save it as a PDF.
D to L
Delivery pace. How a campaign spreads its sending, from all at once to over 24 hours.
Delivery vector. How a practice phishing email tries to get a response: a link, a QR code, an attachment or an OAuth consent request.
Department. The attribute reports are grouped by. People without one land in an unassigned row.
Do-not-contact list. Addresses and domains that never receive practice phishing, whatever the campaign.
Experience. What a person sees after clicking a practice email: a short lesson, or a practice sign-in page followed by the lesson.
Exposure finding. Something HRS Exposure found about your domains or people from outside, such as a work account in an infostealer log.
Knowledge check. The short quiz at the end of a module, with a pass mark.
Learning path. A set of modules assigned together.
Lure. The practice phishing message itself.
M to R
Managed service provider (MSP). A company that runs HumanRisk Shield for several client organizations from the partner console.
Module. A unit of training made of lessons and usually a knowledge check.
Operate as. An MSP admin working inside a client organization. Everything they do is logged under the MSP's name.
Organization. One customer in HRS, with its own people, settings and data. MSP clients are separate organizations.
Personal risk. What employees see on their dashboard: their own ShieldScore. Lower is safer.
Practice phishing. A simulated phishing message your organization sends so people can practice spotting and reporting it. Also called a simulation.
Repeat clicker. Someone who has clicked more than one practice phishing campaign.
Report Phishing button. The button in Outlook people use to report suspicious email. See Report a suspicious email.
Reporting rate. The share of people who reported a practice email. Read it beside the click rate: it tells you whether people would catch the real thing.
S to Z
SCIM. A standard way for an identity provider to create, update and deactivate people in HRS automatically.
ShieldScore. A 0 to 100 risk score for each person, built from what they actually do. Higher means riskier. The organization's ShieldScore is the average of its active people. See ShieldScore.
Single sign-on (SSO). Signing in to HRS with your work account through Microsoft, Google or a SAML identity provider.
Smart Reinforcement. Training and nudges that HRS assigns automatically after a risky event, such as a practice click. Your organization turns it on.
Teachable moment. The short page a person lands on after clicking practice phishing. It shows the message, marks what gave it away and suggests one thing to do next time.
Tracking hostnames. The web addresses practice phishing links point to. They are how a click is recorded, and they must be excluded from link scanning.
Verdict. In HRS Triage, the decision about what a reported email is.