Workflow Template
Security Awareness Training Workflow
Security team assigns a security awareness training campaign to a staff member, tracks whether they pass, fail, or fail to complete by the due date, automatically reassigns failed attempts for retake, escalates overdue/non-completions to the staff member's manager, and reports final completion status to the campaign owner once the campaign closes.
Organisations subject to security compliance obligations must demonstrate that staff have completed mandated security awareness training within defined timeframes, with clear audit trails for regulators and internal risk committees. This workflow governs the full lifecycle of a training campaign—assignment, due date tracking, pass/fail recording, automated retake reassignment, and manager escalation for overdue or incomplete training—before reporting final outcomes to the campaign owner. Security, compliance, and people management teams share visibility across the process, ensuring accountability sits with the right stakeholder at each stage.
Business Outcomes
- Reduces manual chasing of overdue training through automated manager escalation
- Supports faster identification of non-compliant staff before campaign close
- Improves audit readiness with a consistent, timestamped record of every assignment outcome
- Streamlines retake handling by automatically reassigning failed attempts
- Helps campaign owners report completion status with less manual reconciliation
Workflow Steps
Steps
- 1Create Training Assignment Recordcreate record
Registers the staff training assignment for this campaign.
- 2Set Status: Assignedupdate record
Marks the assignment as Assigned.
- 3Set Completion Due Dateset due date
Applies a default SLA due date to the record for tracking (7 days from assignment).
- 4Notify Staff of Course Assignmentsend email
Emails the staff member their assigned course and due date.
- 5Record Training Resultcreate task
Security team records whether the staff member passed, failed, or did not complete the course by the due date.
- 6Persist Recorded Resultupdate record
Writes the recorded result onto the training record.
- 7Route on Training Result
Branches based on whether the staff member passed, failed, or did not complete the course.
result_outcome: "Passed"→Mark Status: Completedresult_outcome: "Failed"→Mark Status: Failed - Retakingresult_outcome: "Not Completed by Due Date"→Mark Status: Not CompletedDefault→End - 8Mark Status: Completedupdate record
Marks the staff member's training as Completed after passing.
- 9Notify Staff of Passsend email
Confirms to the staff member that they passed the course.
- 10Mark Status: Failed - Retakingupdate record
Marks the staff member's training as Failed and reassigns for retake.
- 11Notify Staff to Retake Coursesend email
Informs the staff member they failed and must retake the course.
- 12Restart for Retakerestart from step
Restarts the workflow from the result-recording step so the retake attempt can be tracked.
- 13Mark Status: Not Completedupdate record
Marks the staff member as not having completed the course by the due date.
- 14Refer to Manager: Status Updateupdate record
Marks the assignment as referred to the manager for follow-up.
- 15Notify Manager of Outstanding Trainingsend email
Emails the staff member's manager to follow up on the incomplete training.
- 16Report Completion to Campaign Ownersend email
Sends the final training outcome for this staff member to the campaign owner once resolved.
Fields
- Training Campaign Name*
- Target Audience*
- Assigned Course*
- Completion Due Date*
- Staff Member Name*
- Staff Member Email*
- +4 more fields
Forms
Assign Security Awareness Training
8 fields
Data Views
All Training Assignments
staff_name, campaign_name, assigned_course, completion_due_date +2 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Categories
FAQs
How is this audited within assess.one?
Every status change—assignment, result, retake, escalation, and closure—is recorded against the training assignment record with a timestamp, creating a traceable history for each staff member. This log supports internal compliance reviews and can be referenced when demonstrating training coverage to auditors or regulators.
Who has access to training assignment and result data?
Access is configured within assess.one by role, so the security team, campaign owners, and managers only see the records relevant to their responsibilities. Staff typically see their own assignment and result status, while managers are given visibility into their direct reports' outstanding training when escalations occur.
How does this integrate with notification tools like email or Slack?
Notifications to staff and managers—such as course assignment, retake requests, and overdue escalations—are configured directly inside assess.one using its built-in email and Slack integrations. No separate development work or external tooling is required to route these alerts to the right recipients.
Can the escalation logic to managers be customised?
Yes, the conditions that trigger a manager escalation, such as the number of days overdue or a failed retake, can be adjusted directly within the workflow's routing steps. Notification content and timing can also be tailored to match internal escalation policies.
What happens when a staff member fails the training?
A failed result automatically routes the record to a 'Failed - Retaking' status, triggers a retake notification to the staff member, and restarts the assignment for a new attempt. This removes the need for the security team to manually reissue training after each failure.
What happens if training is not completed by the due date?
Incomplete assignments past the due date are marked 'Not Completed' and automatically referred to the staff member's manager, who receives a notification of outstanding training. This ensures non-completion is surfaced to a responsible party rather than remaining unresolved in the system.
How long does it take to implement this workflow?
The template is ready to use and can be published in minutes, with no separate implementation project or software installation required. Once published, the security team can immediately begin assigning training campaigns and tracking results live.
Who needs access to this workflow to run it effectively?
The security or compliance team typically owns campaign creation and result recording, managers need access to respond to escalations, and staff need visibility into their own assignments and due dates. Campaign owners require access to the final reporting step to review overall completion outcomes.
How is the final completion status reported to the campaign owner?
Once the campaign closes, assess.one compiles the final status—completed, failed, or not completed—for each staff member and surfaces this in a report to the campaign owner. This step is built into the workflow so reporting does not require manual data pulling or reconciliation across spreadsheets.
Can approval or sign-off steps be added before closing a campaign?
Yes, additional approval logic can be configured within assess.one if a sign-off is required from the security lead or compliance officer before a campaign is marked closed. This can be inserted ahead of the final reporting step without altering the rest of the workflow structure.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
