Trainings
Trainings hold the awareness and security material your people have to work through. Use this section to add training content, assign it to members and roles, and track who has completed it.
Overview
Trainings are the content half of the "assign something to your people and prove they did it" workflow. A training points at material you already have (a YouTube or Vimeo video, a link to an external course, or a PDF you upload) and gives it an owner, a duration and a place in your compliance program.
On its own a training is inert. It becomes work for your people when you attach an assignment to it: an audience, a first due date, and an optional repeat cadence. From then on the training appears in each assigned person's portal, contributes to your deadline list, and produces reminder emails. Every completion is recorded per person and per due cycle, so "did everyone do the annual security awareness training this year?" is a question you can answer from the record rather than from memory.
Trainings and policies share the same assignment machinery. A policy is completed by acknowledging its published version; a training is completed by the person attesting they worked through it. Everything below about audiences, cycles and status applies identically to both.
Trainings
The Trainings list is the register of every training in your organization. Each row links to the training's detail page, which is split into tabs:
| Tab | What it holds |
|---|---|
| Detail | Source, owner role and duration. |
| Content | The embedded video, the outbound link or the PDF download. |
| Assignment | The audience, schedule and per-person completion status. |
| Evidence | Proof that the training actually ran (attendance exports, quiz results, screenshots). |
| Tasks | The work items attached to this training. |
| History | The audit trail of every change made to this training. |
| Field | Description |
|---|---|
| Title | A descriptive name for easy identification (required). |
| Description | What this training covers. |
| Training source | Where the content lives: YOUTUBE, VIMEO, LINK or PDF (required). |
| Source URL | Link to the training. Required for every source except PDF. |
| Owner role | The business role accountable for the training, not a person. |
| Duration (minutes) | Approximate time to complete, shown to the assignee before they start. |
The slug is generated from the title when the training is created and is what appears in links and URLs.
Owner role follows the same convention as the rest of the platform: ownership sits with a business role (Security Team, HR, CISO), never with an individual user. People come and go from roles; the accountability stays put.
Tick the checkbox on any row to select it. The selection survives paging, and Bulk Actions then offers Export selection (a CSV of exactly the selected trainings) and Delete selection. Deleting is permanent and takes the training's assignment and its completion history with it, so archive instead whenever the record still has to be produced for an audit.
Training content
The Training source decides how the material is delivered on the Content tab and in the portal:
YOUTUBE/VIMEO: the video is embedded and plays inline. If the URL isn't in a form that can be embedded, an "Open training" button opens it in a new tab instead.LINK: any external URL (an LMS course, a vendor's training portal, an intranet page). Always opens in a new tab.PDF: upload a document instead of linking out. The file uploads straight to storage, and readers get a time-limited download link rather than a public URL. Only PDFs are accepted.
Trainings are unversioned: editing a training changes it for everyone from that point on. Because of that, every completion snapshots the source it was completed against, so a past completion still says exactly what that person worked through even if the content is swapped later.
Assignment
The Assignment tab on the training detail page turns a training into an obligation. A training has at most one assignment.
| Field | Description |
|---|---|
| Members | Specific people who must complete it. |
| Roles | Business roles whose members must complete it. |
| First due date | When the first completion is due (required). |
| Frequency | One-off, MONTHLY, QUARTERLY, SEMI_ANNUAL or ANNUAL (required). |
The audience is the union of the named members and everyone in the selected roles, and it is resolved live rather than frozen at save time. Adding somebody to the Engineering role automatically enrols them in every assignment targeting that role, and removing them takes the obligation away. This is why assigning by role is usually the better choice: the audience maintains itself as people join, move and leave.
Archiving a role has the same effect as emptying it. Its members stop owing every training aimed at that role, stop counting towards its completion figures and stop being reminded about it. The confirmation on Settings → Roles states how many people and assignments that touches before you go ahead.
Save the card and the assignment takes effect immediately. Archive assignment at the bottom of the card ends it; the training itself stays in the register.
Cycles and due dates
A one-off assignment has a single due date: the first due date you set.
A recurring assignment generates a series of due dates from the first one: monthly, quarterly, every six months or yearly. Each due date in the series is a cycle, and completions are recorded against the cycle they satisfy. Nothing is generated in advance and nothing is stored per cycle, so changing the frequency reshapes the whole series rather than leaving orphaned dates behind.
Each assigned person therefore has a status at any moment:
| Status | Meaning |
|---|---|
| Completed | They have completed the current cycle. |
| Pending | The current cycle is still open and they haven't completed it yet. |
| Overdue | A one-off is past its due date, or a recurring assignment has gone a full period without a completion. |
The Assignment card shows the counts for all three at a glance, then lists every person in the audience with their status and the date they last completed.
Completing a training
Assigned people don't work in this section. Trainings show up in their portal, where they see the material, work through it, and confirm completion by ticking "I have completed this training" and pressing Mark as completed.
Training completion is self-attestation: the platform records that a person stated they completed the material on a given date, for a given cycle, against a given source. It does not verify that a video was watched to the end. For an auditor, the value is the documented, dated, per-person record and the reminder trail behind it.
Reminders
Assigned people are reminded automatically, and only when there is something to do. Reminders arrive by email, and for anyone who also works in the main app they appear in the notification inbox as well. Both channels are on by default and each person can tune them per category under Settings → Notifications. People who only ever use the portal have no inbox, so email is their whole reminder channel.
Four things prompt a reminder:
- Enrolment: sent when someone becomes newly responsible for a training, including when they land in the audience by joining a role. It goes out once per person per training and never repeats, not even when the training comes round again.
- Ahead of the due date: sent only while the current cycle is still open. How far ahead depends on how often the training repeats, per the table below.
- On the final day: a last nudge the day before the due date, or on the day itself.
- Overdue: sent once the due date has passed without a completion.
The first nudge scales with the cadence, because a week's notice is the only warning somebody gets all year on an annual training, and far too much on a monthly one:
| Frequency | First reminder |
|---|---|
ANNUAL | 30 days before the due date |
SEMI_ANNUAL | 14 days before |
QUARTERLY | 7 days before |
MONTHLY | 3 days before |
| One-off | 7 days before |
Reminders stop for anyone who has already completed the current cycle, and a message is never sent twice for the same cycle. When several items fall due together, they are collected into one email rather than one message per item. Unlike marketing email, these are obligations, so they are not affected by marketing preferences.
Evidence, tasks and history
The completion record proves that people attested; it does not hold the artefacts around the training itself. The Evidence tab is where those go. Attach an existing evidence from your Evidence Library, or drop a file straight onto the tab to mint one and link it in a single step: an attendance export from an external LMS, the slide deck the session was run from, a signed sign-off sheet. The same evidence can back several trainings and any number of controls at once, so an auditor following a control down to its proof lands on the same document you filed here. Removing a link never deletes the evidence.
The Tasks tab lists the work items attached to this training and lets you add one with the training already filled in: refresh the material before the next cycle, chase the people who are still overdue, re-record the video after a process change. A task belongs to at most one record, so a task filed here is unambiguously about this training.
The History tab is the audit trail: who changed what and when, including evidence links and unlinks.
Where trainings appear
- Dashboard: the registers card shows how many people are overdue on policies and trainings.
- Deadlines: every open assignment cycle appears as a dated item, tagged
TRAINING(orPOLICY), with a "x of y completed" progress line. - People: each person's Policies & Trainings tab lists everything assigned to them and their status on each.
- Search: trainings are searchable by title from the command palette.
Archiving
Archiving a training removes it from the active register while keeping it, its assignment and its completion history intact. Use it for material that has been superseded but whose record you still need to show an auditor. Archived trainings can be restored from the list's row menu.
How is this guide?
Policies
Your organization's policies define how work gets done and ensure everyone follows the same standards. Use this section to create, edit and update policies so they stay compliant with the frameworks you enabled.
Evidence
Evidence captures reusable proof that your controls are covered, with clear ownership, reviews on a set cadence, and each item labelled with where its proof comes from.