This article describes the Reports section of SMARTFENSE, where you can view user activity for each platform component. Training and simulation components have four reports grouped under In campaigns: User interactions over time, Percentage distribution of interactions, Consolidated analysis, and Benchmark. In addition, components that support proactive use (Interactive Modules, Videos, Video Games, and Newsletters) include a fifth report under Proactive activity: Proactive use.
You can access this section from the main menu: Reports.
Overview of the Reports section
The Reports section displays a summary view grouped by component. Each card corresponds to a platform component and provides access to the reports available for that component, organized into two groups:
- In campaigns: reports that analyze activity in the context of assigned campaigns.
- Proactive activity: reports on usage that users initiate on their own, outside of a campaign.
The components included in the view are:
- Training components: Interactive Modules, Videos, Video Games, Newsletters, Exams, Surveys.
- Simulation components: Phishing, Ransomware, Smishing, USB Drop.
- Specific blocks: Correlation and Gamification, which have their own reports documented in their respective articles.
- Key performance indicators: Awareness indicators in campaigns and Proactive use indicators, documented in their own articles.
- Adoption and activity: Proactive adoption by user and area, Proactive content coverage, and Assigned training status, documented in their own articles.
- Risk and behavior: User profile, Group comparison, Priority users for intervention, and Awareness references, documented in their own articles.
To access a report's detail view, click the eye icon within each component card.
Reports available for each component
All training and simulation components have the following four reports under In campaigns:
- User interactions over time
- Percentage distribution of interactions
- Consolidated analysis
- Benchmark
In addition, Interactive Modules, Videos, Video Games, and Newsletters include an additional report under Proactive activity:
- Proactive use
The Proactive use report is not available for Exams, Surveys, or simulation components (Phishing, Ransomware, Smishing, USB Drop), as those content types are only accessed within an assigned campaign.
The logic of each report is the same across all components where it is available. What changes between components are the indicators displayed (see the Indicators by component section).
User interactions over time
Shows the evolution of user interactions over time.
- Visualization: area evolution chart.
- X axis: months.
- Y axis: number of interactions.
- Series: one series per indicator for the component.
- Hover over the chart to see the detail for each data point.
Percentage distribution of interactions
Shows the proportion of each interaction relative to the total sends for the component.
- Visualization: funnel chart.
- Series: one band per indicator for the component, showing its absolute value and percentage relative to Sent.
Consolidated analysis
Brings together in a single view the behavior charts for users facing a given content type, aggregating all campaigns in the selected period. Unlike the detail of a single campaign — which shows one campaign at a time — it allows you to read trends and patterns at the component level to assess human risk and the effectiveness of the awareness program.
Scope and important notes:
- Includes campaigns of the selected content type within the period and applied filters, for the current organization. Sub-organization campaigns are not included automatically.
- Test campaigns are excluded.
- Times (for example, how long a user took to complete the content) are measured from the actual send to each user, so staggered campaigns are compared fairly.
How filters are applied:
- Groups, areas, and levels: filter by the user's current membership, not their membership at the time of the send. Values may therefore differ from those in the detail view of a specific campaign.
- Topic / scenario: limits the report to campaigns for the selected content.
- Period: the last 12 months are shown by default; you can narrow the range using the start and end month.
Definitions:
- Received: users to whom the content was sent. This is the base used to calculate percentages.
- Completed: when the user finishes the content according to its type.
Available charts:
The charts displayed in this report vary by component. The possible charts are:
- Percentage distribution of interactions: percentage of users who reached each interaction stage, over the total who received the content, summing all campaigns in the period.
- User interactions over time: month-by-month evolution of interactions, aggregating all campaigns of the component in the period.
- Time to complete: distribution of the time users took to complete the content from when they received it.
- Completion progress vs. expiration: cumulative percentage of users who completed the content throughout the available time period.
Benchmark
Compares the organization's awareness program results against the historical performance of all other SMARTFENSE client organizations.
- Visualization: horizontal bar chart.
- Indicators: the same ones shown in the other reports for the component (for example, Sent, Started, Completed for Interactive Modules).
The report offers two views selectable via tabs:
- Average by organization: calculates the typical performance of an average organization within the SMARTFENSE ecosystem, giving equal weight to each client regardless of their number of employees or license volume. This is the recommended criterion for evaluating the maturity of security culture against the corporate standard.
- Global user average: consolidates all historical interactions on the platform as if they belonged to a single global entity. The result is influenced by the total user volume; organizations with more employees have a greater impact on this percentage. Useful for analyzing user behavior at a global scale.
The Benchmark report does not expose date or group filters. This is because the benchmark is calculated over the full historical data of the platform and all client organizations. Applying filters only to your own data would produce an asymmetric comparison against an aggregate that includes all history and all segments.
Proactive use
Available only for Interactive Modules, Videos, Video Games, and Newsletters. Shows the activity users perform on their own initiative for that type of content, outside of an assigned campaign.
The report indicators are:
- Users who started: number of distinct users who started this type of content on their own initiative in the selected period.
- Users who completed: number of distinct users who completed this type of content on their own initiative in the period.
- Completion rate: percentage of users who completed out of those who started. Indicates how effective the content is at retaining users who begin it voluntarily.
- Content completed (this type): number of distinct pieces of content of this type that were proactively completed at least once in the period. Unlike the previous indicators, this counts distinct content pieces, not users.
In addition to the indicator summary, the report includes:
- Proactively active users per month: chart showing the monthly evolution of proactive use of that content type. Each month is counted independently, so the monthly total does not match the number of active users for the full period.
- Content ranking: list of content of that type ordered by the number of users who completed it, including users who started, users who completed, and the completion rate. Includes a CSV download button.
The report supports the same filters as User interactions over time and Percentage distribution of interactions (see the Available filters section). It also shows the date and time of the last data update at the bottom.
Available filters
The User interactions over time, Percentage distribution of interactions, Consolidated analysis, and Proactive use reports share the following filters:
- Filter by group
- Filter by functional area
- Filter by hierarchical level
- Filter by smart group
- Filter by topic (training components only) or Filter by scenario (simulation components only: Phishing, Ransomware, and Smishing)
- Start month
- End month
Export and print
Each report allows you to export or print the information. To access the options menu, click the three-dot icon (⋯) in the upper-right corner of the chart.
Available options:
- Export as image: PNG, JPG, or PDF.
- Export data: JSON, CSV, XLSX, PDF, or HTML.
- Print: sends the chart to the selected printer.
Exports respect the filters applied at the time the file is generated.
Indicators by component
The indicators shown in each report depend on the selected component.
Training components
Interactive Modules
- Sent: the campaign assignment to the user was recorded.
- Started: the user started the assigned Interactive Module.
- Completed: the user completed the assigned Interactive Module.
Videos
- Sent: the campaign assignment to the user was recorded.
- Started: the user started the assigned Video.
- Completed: the user completed the assigned Video.
- Answered correctly: the user answered the Video's validation question correctly.
- Answered incorrectly: the user answered the Video's validation question incorrectly.
Video Games
- Sent: the campaign assignment to the user was recorded.
- Started: the user started the assigned Video Game.
- Completed: the user completed the assigned Video Game.
Newsletters
- Sent: the Newsletter was sent to the user.
- Opened: the user opened the sent Newsletter.
- Answered correctly: the user answered the Newsletter's reading validation question correctly.
- Answered incorrectly: the user answered the Newsletter's reading validation question incorrectly.
Exams
- Sent: the campaign assignment to the user was recorded.
- Started: the user started the assigned exam.
- Passed: the user passed the assigned exam.
- Failed: the user failed the assigned exam.
Surveys
- Sent: the campaign assignment to the user was recorded.
- Started: the user started the assigned survey.
- Completed: the user completed the assigned survey.
Simulation components
Phishing
- Sent: the email was sent to the user.
- Opened: the user opened the email.
- Link clicks: the user clicked a link in the Phishing simulation email.
- Data entered: the user entered data in the form on the Phishing simulation landing page.
- Educational moments sent by email: the user performed an action that triggered the Educational Moment to be sent by email.
- Educational moments opened: the user viewed the Educational Moment in their email or instantly in their browser.
- Educational moments answered correctly: the user answered the Educational Moment's reading validation question correctly.
- Educational moments answered incorrectly: the user answered the Educational Moment's reading validation question incorrectly.
- Phishing campaigns reported: the user reported the phishing campaign using the report button.
Ransomware
- Sent: the email was sent to the user.
- Opened: the user opened the email.
- Ransomware downloaded: the Ransomware was downloaded via a link.
- Ransomware opened: the downloaded Ransomware was opened via a link.
- Ransomware attachments opened: the downloaded Ransomware was opened via an attached file.
- Possible encryption in user folder: an action was detected that would have allowed file encryption in the user's folder.
- Educational moments sent by email: the user performed an action that triggered the Educational Moment to be sent by email.
- Educational moments opened: the user viewed the Educational Moment in their email or instantly in their browser.
- Educational moments answered correctly: the user answered the Educational Moment's reading validation question correctly.
- Educational moments answered incorrectly: the user answered the Educational Moment's reading validation question incorrectly.
- Ransomware campaigns reported: the user reported the ransomware campaign using the report button.
Smishing
- Sent: the SMS was sent to the user.
- Delivered: the SMS was delivered to the user.
- Link click: the user clicked a link in the simulation SMS.
- Data entered: the user entered data in the form on the simulation landing page.
- Educational moments sent by email: the user performed an action that triggered the Educational Moment to be sent by email.
- Educational moments opened: the user viewed the Educational Moment in their email or instantly in their browser.
- Educational moments answered correctly: the user answered the Educational Moment's question correctly.
- Educational moments answered incorrectly: the user answered the Educational Moment's question incorrectly.
USB Drop
- File opened: the user opened a file contained in the simulation USB drive.
- Macros enabled: the user enabled macros in a file opened from the simulation USB drive.
💡 Best Practices
- Apply group, functional area, hierarchical level, or smart group filters to analyze specific subsets of the organization.
- Use Start month and End month to narrow the analysis period and compare trends across different timeframes.
- Use the Consolidated analysis report when you need an aggregated view of all campaigns for a component in the period: it reveals trends and patterns that the detail of an individual campaign cannot show.
- Review the Percentage distribution of interactions report first to identify conversion between stages, then use User interactions over time to understand how those stages evolved month by month.
- Use the Benchmark report as an indicative reference point, not as an absolute target. The most reliable measure of progress is the organization's own historical baseline.
- Combine the topic or scenario filter with organizational filters to evaluate the impact of a specific piece of content or simulation.
- Document the filter criteria applied when exporting or sharing results, to help other teams interpret the data correctly.
- Check the Proactive use report for each component to identify which formats generate the most voluntary interest and prioritize content creation in those types.