assess.one – AI-powered business operations platform

Workflow Template

Security Awareness Training Workflow

Security team assigns a security awareness training campaign to a staff member, tracks whether they pass, fail, or fail to complete by the due date, automatically reassigns failed attempts for retake, escalates overdue/non-completions to the staff member's manager, and reports final completion status to the campaign owner once the campaign closes.

Organisations subject to security compliance obligations must demonstrate that staff have completed mandated security awareness training within defined timeframes, with clear audit trails for regulators and internal risk committees. This workflow governs the full lifecycle of a training campaign—assignment, due date tracking, pass/fail recording, automated retake reassignment, and manager escalation for overdue or incomplete training—before reporting final outcomes to the campaign owner. Security, compliance, and people management teams share visibility across the process, ensuring accountability sits with the right stakeholder at each stage.

Business Outcomes

  • Reduces manual chasing of overdue training through automated manager escalation
  • Supports faster identification of non-compliant staff before campaign close
  • Improves audit readiness with a consistent, timestamped record of every assignment outcome
  • Streamlines retake handling by automatically reassigning failed attempts
  • Helps campaign owners report completion status with less manual reconciliation

Workflow Steps

Steps

  1. 1
    Create Training Assignment Recordcreate record

    Registers the staff training assignment for this campaign.

  2. 2
    Set Status: Assignedupdate record

    Marks the assignment as Assigned.

  3. 3
    Set Completion Due Dateset due date

    Applies a default SLA due date to the record for tracking (7 days from assignment).

  4. 4
    Notify Staff of Course Assignmentsend email

    Emails the staff member their assigned course and due date.

  5. 5
    Record Training Resultcreate task

    Security team records whether the staff member passed, failed, or did not complete the course by the due date.

  6. 6
    Persist Recorded Resultupdate record

    Writes the recorded result onto the training record.

  7. 7
    Route on Training Result

    Branches based on whether the staff member passed, failed, or did not complete the course.

    result_outcome: "Passed"Mark Status: Completed
    result_outcome: "Failed"Mark Status: Failed - Retaking
    result_outcome: "Not Completed by Due Date"Mark Status: Not Completed
    DefaultEnd
  8. 8
    Mark Status: Completedupdate record

    Marks the staff member's training as Completed after passing.

  9. 9
    Notify Staff of Passsend email

    Confirms to the staff member that they passed the course.

  10. 10
    Mark Status: Failed - Retakingupdate record

    Marks the staff member's training as Failed and reassigns for retake.

  11. 11
    Notify Staff to Retake Coursesend email

    Informs the staff member they failed and must retake the course.

  12. 12
    Restart for Retakerestart from step

    Restarts the workflow from the result-recording step so the retake attempt can be tracked.

  13. 13
    Mark Status: Not Completedupdate record

    Marks the staff member as not having completed the course by the due date.

  14. 14
    Refer to Manager: Status Updateupdate record

    Marks the assignment as referred to the manager for follow-up.

  15. 15
    Notify Manager of Outstanding Trainingsend email

    Emails the staff member's manager to follow up on the incomplete training.

  16. 16
    Report Completion to Campaign Ownersend email

    Sends the final training outcome for this staff member to the campaign owner once resolved.

Fields

  • Training Campaign Name*
  • Target Audience*
  • Assigned Course*
  • Completion Due Date*
  • Staff Member Name*
  • Staff Member Email*
  • +4 more fields

Forms

Assign Security Awareness Training

8 fields

Data Views

All Training Assignments

staff_name, campaign_name, assigned_course, completion_due_date +2 more

Dashboard Widgets

Training Status BreakdownCampaign Progress

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
security awareness trainingcybersecurity trainingphishing trainingemployee security trainingcompliance training

Similar Workflows

Similar Categories

FAQs

How is this audited within assess.one?

Every status change—assignment, result, retake, escalation, and closure—is recorded against the training assignment record with a timestamp, creating a traceable history for each staff member. This log supports internal compliance reviews and can be referenced when demonstrating training coverage to auditors or regulators.

Who has access to training assignment and result data?

Access is configured within assess.one by role, so the security team, campaign owners, and managers only see the records relevant to their responsibilities. Staff typically see their own assignment and result status, while managers are given visibility into their direct reports' outstanding training when escalations occur.

How does this integrate with notification tools like email or Slack?

Notifications to staff and managers—such as course assignment, retake requests, and overdue escalations—are configured directly inside assess.one using its built-in email and Slack integrations. No separate development work or external tooling is required to route these alerts to the right recipients.

Can the escalation logic to managers be customised?

Yes, the conditions that trigger a manager escalation, such as the number of days overdue or a failed retake, can be adjusted directly within the workflow's routing steps. Notification content and timing can also be tailored to match internal escalation policies.

What happens when a staff member fails the training?

A failed result automatically routes the record to a 'Failed - Retaking' status, triggers a retake notification to the staff member, and restarts the assignment for a new attempt. This removes the need for the security team to manually reissue training after each failure.

What happens if training is not completed by the due date?

Incomplete assignments past the due date are marked 'Not Completed' and automatically referred to the staff member's manager, who receives a notification of outstanding training. This ensures non-completion is surfaced to a responsible party rather than remaining unresolved in the system.

How long does it take to implement this workflow?

The template is ready to use and can be published in minutes, with no separate implementation project or software installation required. Once published, the security team can immediately begin assigning training campaigns and tracking results live.

Who needs access to this workflow to run it effectively?

The security or compliance team typically owns campaign creation and result recording, managers need access to respond to escalations, and staff need visibility into their own assignments and due dates. Campaign owners require access to the final reporting step to review overall completion outcomes.

How is the final completion status reported to the campaign owner?

Once the campaign closes, assess.one compiles the final status—completed, failed, or not completed—for each staff member and surfaces this in a report to the campaign owner. This step is built into the workflow so reporting does not require manual data pulling or reconciliation across spreadsheets.

Can approval or sign-off steps be added before closing a campaign?

Yes, additional approval logic can be configured within assess.one if a sign-off is required from the security lead or compliance officer before a campaign is marked closed. This can be inserted ahead of the final reporting step without altering the rest of the workflow structure.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Security Awareness Training Tracking Workflow | assess.one