Concepts

How a simulation works

What happens between building a practice phishing campaign in HRS Learn and its results reaching people's ShieldScores.

PublicUpdated October 6, 2026

HRS Simulation sends practice phishing on your organization's behalf, records what people do with it, and teaches at the moment someone gets it wrong. You build and run every campaign inside HRS Learn. The simulation engine behind it does the sending and the tracking, and you never sign in to it separately.

Building a campaign

Admins create campaigns under Phishing in HRS Learn. The campaign wizard has four steps:

  1. Setup. Name the exercise and decide what you want people to practice.
  2. Email. Write or choose the message people receive, with a live preview.
  3. Experience. Choose what opens when someone clicks: a short lesson, or a practice form that looks like a sign-in page.
  4. Review & launch. Set the audience and the send window, check delivery, send yourself a test, then launch now or schedule it.

The step-by-step guide is Run a simulation.

Channels

Email is the standard channel. SMS and Microsoft Teams delivery need extra setup between HRS and your Microsoft or messaging admins before they can be used, so talk to support before you plan a campaign on either.

What gets recorded

For each person in the campaign, HRS records the furthest thing they did, plus whether they reported it:

Event What it means
Delivered The message was accepted by your mail system.
Opened The mail client loaded the message's images. Many clients block images, so treat opens as a lower bound.
Clicked The person followed a link, scanned a QR code or opened an attachment in the message.
Submitted The person filled in the practice form.
Reported The person reported the message as suspicious.

Nothing typed into a practice form is kept. The engine records that a submission happened and throws the content away. There is no code path that stores a password typed into a practice page.

Visits that look automated, such as link scanners and link previews, are logged by the engine but never counted as a click. See Clicks you didn't expect.

What the person sees

Someone who clicks lands on a teachable moment: a short page that shows the message, marks what gave it away, and suggests one thing to do next time. Someone who reports the message gets a confirmation that they did the right thing.

Employees can read about this from their side in Practice phishing at work.

Where results go

Results flow back into HRS Learn as they happen:

  • The campaign's results page shows the funnel and who did what.
  • Each event becomes a signal on the person's ShieldScore. Clicking and submitting count against them; reporting counts in their favor. Scores refresh overnight.
  • Repeat clickers are flagged so you can give them targeted training.

Before your first campaign

Your mail filters will treat practice phishing like the real thing unless you tell them otherwise. Do Let practice phishing through your mail filters first, then send yourself a test.

Still stuck?Contact support