KnowBe4: phishing results and training progress per partner
KnowBe4 runs your partners' security awareness programme: the simulated phishing tests and the training campaigns behind them. This connector reads the results into Current per partner — the phish-prone rate from the most recent completed test, what that test's outcomes were, and how each training campaign is landing — so an account manager can answer "is their staff getting better at this" from the company record. Every other security feed in Current reports on machines. This one reports on people, which is the half of the security conversation the review could not tell before.
What Current syncs
| Data set | What Current stores | Where it lands |
|---|---|---|
| Accounts | Each KnowBe4 account by its primary domain and name, plus its subscription tier, seats purchased, renewal date and current risk score — the key Current maps to a company | The mapping panel on the KnowBe4 card |
| Phishing tests | Per test: its name, when it started, how long it ran, the template and difficulty used, the groups it targeted, and the vendor's own outcome counts — scheduled, delivered, opened, clicked, replied, attachment opened, macro enabled, data entered, QR scanned, reported and bounced — with the phish-prone rate for that test | The mapped company's People panel and its KnowBe4 card, plus the security chapter of a business review |
| Training campaigns | Per campaign: its name, status, start and end dates, the groups enrolled, its completion percentage, and how many people are enrolled, finished, in progress, not started, and past due | The company's People panel and the training figures in a business review |
Create the token in KnowBe4
Do this once per partner account, inside that partner's own KnowBe4 console.
- 11 · Open Account Settings ▸ Account Integrations ▸ APISign in to the KnowBe4 console as an administrator, click your email address at the top right, choose Account Settings, then open Account Integrations and its API tab.
- 22 · Tick Enable Reporting API AccessUnder Reporting API there is a tick box named Enable Reporting API Access. If it is not there, this account's KnowBe4 subscription does not include the Reporting API — it is sold on the Platinum, Diamond, SAT Foundation and SAT Advanced plans. That is a conversation with KnowBe4, and nothing in Current can work around it.
- 33 · Create the tokenIn the Reporting API subtab that opens, choose Create New API Token, fill in a name and status, and press Create Token.
- 44 · Copy it before you close the boxKnowBe4 shows the token once. Once you close that window it cannot be viewed again, and a lost token is re-created rather than recovered.
Connect it in Current
- 1Open the KnowBe4 cardIn Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find KnowBe4 in the Monitoring and security section.
- 2Add a row per partnerPress the Add button under the account list. It is named for whatever your workspace calls the businesses you serve, so it reads Add partner account here. Give the row a name you will recognise — it is your label, shown beside that row's test result and in the mapping list — then pick the region and paste that account's token.
- 3Pick the region that matches where they sign inKnowBe4 runs five separate regions and a token works against exactly one. Match the address that account signs in at: training.knowbe4.com (United States), eu.knowbe4.com, ca.knowbe4.com, uk.knowbe4.com, or de.knowbe4.com.
- 4Press Test connectionCurrent reads one account record per row to prove each token works, and reports the result for every row by the name you gave it. On success the set is stored server-side only — the browser never sees a token again.
How often it syncs, and what it costs your KnowBe4 account
KnowBe4 syncs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run reads the account summary, the phishing tests and the campaign list for every row you added.
KnowBe4 allows 2,000 API requests a day per account, and that allowance is your partner's — shared with their SIEM, any other tool wired into their console, and their own scripts. Current is built to stay a small share of it: roughly 20 to 40 requests a day per connected account for the regular reads. The training roll-up, which is the expensive one because it counts every person on every module, runs once a day rather than on all four passes, which is why the overdue figures update daily while the phishing numbers update every 6 hours.
The read-only guarantee
Every request Current makes to KnowBe4 passes through a read-only guard that permits four specific read endpoints and nothing else: the account summary, the phishing test list, the training campaign list, and the enrollment counts. The wider KnowBe4 platform can create and delete users, edit groups, and launch or delete phishing and training campaigns; none of those paths exists in the connector's code, so a code bug cannot reach them. The two employee-data endpoints described above are excluded on the same basis. KnowBe4 stays the source of truth; Current only reads.
Map accounts to your companies
Each KnowBe4 account is one of your partners, and Current identifies it by its primary domain. Current tries the domain against your companies' own websites first, which is the stronger signal, then falls back to a normalized name match — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and links only when exactly one company matches. Two companies that both fit stay unmapped for you to decide.
- 1Let the auto-matcher run firstEvery sync links each account to the one Current company its domain or name matches. Most map themselves.
- 2Open the mapping panelIntegrations → KnowBe4 → Manage → Customer mapping. It opens on the Unmapped tab, which lists every account the matcher could not place.
- 3Map an account to its companyOn an unmapped row press Map, type a few letters of the Current company, and pick it. That account's tests and campaigns attach to the company right away, rather than waiting for the next sync.
- 4Fix a wrong match laterThe Mapped tab lists every linked account, and Unmap corrects a bad auto-match. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.
Where the data shows up
- +The company's People panel: the phish-prone rate from the latest completed test with the date it ran, and how many people are past due on training.
- +The company's KnowBe4 card: the latest test with its delivered count beside the rate, the clicked and reported split, a chip when anyone entered credentials or enabled a macro, and each active campaign's completion and overdue count.
- +The security chapter of a Strategic Business Review, beside the machine-side signals.
- +Dashboard metrics — the phish-prone rate per company and across your book, training completion, and how many people are overdue.
- +The company alert band: an awareness entry that warns when the latest test's phish-prone rate reaches 15%, or when a quarter of the people enrolled in active training are past due, and turns critical at 30%.
When something looks wrong
| What you see | What it means |
|---|---|
| Test connection rejects a token you just copied | Check the region first — a correct token pointed at the wrong region fails the same way a wrong one does. If the region is right, check you created it on the Reporting API tab rather than the Product API or User Event tab, then create a fresh token. |
| Test connection says the subscription does not include it | The Reporting API is sold on some KnowBe4 plans and not others. If Account Settings ▸ Account Integrations ▸ API has no Enable Reporting API Access tick box for that account, this is the reason, and it is settled with KnowBe4. |
| Some rows connected and others did not | The ones that answered are syncing. The card names the rows that did not and what KnowBe4 said about each — fix those and press Test connection again. |
| Phish-prone shows a dash rather than a number | That account has no completed test that reported a rate yet. Current leaves it blank rather than showing 0%, which would read as a perfect result. |
| A training campaign says "still calculating" | KnowBe4 answers with a placeholder instead of a percentage for campaigns it considers too large to calculate. Current shows that as unknown rather than 0% complete, which would look like nobody had started. |
| The overdue counts are blank | The training roll-up did not finish on the last daily pass. Current leaves all four counts blank together rather than publishing part of the picture — three people overdue reads as a small problem when the real number is three hundred. |
| Connected, and the account shows no users | Some KnowBe4 consoles are set to anonymise user data, and those accounts return nothing through the API by design. The connection is working; that account's console is configured not to share it. |
