Skip to content
Current/ Help Center

KnowBe4: phishing results and training progress per partner

6 min read · Updated Sep 5, 2026

KnowBe4 runs your partners' security awareness programme: the simulated phishing tests and the training campaigns behind them. This connector reads the results into Current per partner — the phish-prone rate from the most recent completed test, what that test's outcomes were, and how each training campaign is landing — so an account manager can answer "is their staff getting better at this" from the company record. Every other security feed in Current reports on machines. This one reports on people, which is the half of the security conversation the review could not tell before.

Note
What this connector is for
It is a results feed, not a console. Current mirrors test outcomes, campaign progress and the account's own summary. Launching a phishing test, enrolling a person, creating or deleting a campaign, and editing a user or group are absent from the connector's code — so Current can never send a simulated phishing email to your partner's staff, even by mistake.
Heads up
One token reaches one KnowBe4 account
KnowBe4's Reporting API is built around a single console: a token created inside one partner's KnowBe4 account reads that account and nothing else. There is no partner-level key for it. So the card takes a list — one row per partner, each with its own name, region and token — and a partner with no row here sends no data. Add up to 25.

What Current syncs

Data setWhat Current storesWhere it lands
AccountsEach KnowBe4 account by its primary domain and name, plus its subscription tier, seats purchased, renewal date and current risk score — the key Current maps to a companyThe mapping panel on the KnowBe4 card
Phishing testsPer test: its name, when it started, how long it ran, the template and difficulty used, the groups it targeted, and the vendor's own outcome counts — scheduled, delivered, opened, clicked, replied, attachment opened, macro enabled, data entered, QR scanned, reported and bounced — with the phish-prone rate for that testThe mapped company's People panel and its KnowBe4 card, plus the security chapter of a business review
Training campaignsPer campaign: its name, status, start and end dates, the groups enrolled, its completion percentage, and how many people are enrolled, finished, in progress, not started, and past dueThe company's People panel and the training figures in a business review
Note
Phishing tests are kept as history
A test does not resolve the way an alert does, so its row stays even after KnowBe4 stops listing it. Current keeps 13 months, which is what makes a year-over-year comparison possible — "31% last spring, 12% now" is the sentence this feed exists to produce.
Heads up
No employee names are read, ever
KnowBe4's API can return a full employee directory — names, email addresses, job titles, phone numbers, and a per-person score for how often that individual clicks a simulated phish — and it can return the list of which named employees failed a given test. Neither is on the connector's allowlist, so neither is reachable. Every number above is a count. Nothing in Current names a person from your partner's staff, and adding that would be a separate decision with a privacy review attached, not a settings change.

Create the token in KnowBe4

Do this once per partner account, inside that partner's own KnowBe4 console.

  1. 1
    1 · Open Account Settings ▸ Account Integrations ▸ API
    Sign in to the KnowBe4 console as an administrator, click your email address at the top right, choose Account Settings, then open Account Integrations and its API tab.
  2. 2
    2 · Tick Enable Reporting API Access
    Under Reporting API there is a tick box named Enable Reporting API Access. If it is not there, this account's KnowBe4 subscription does not include the Reporting API — it is sold on the Platinum, Diamond, SAT Foundation and SAT Advanced plans. That is a conversation with KnowBe4, and nothing in Current can work around it.
  3. 3
    3 · Create the token
    In the Reporting API subtab that opens, choose Create New API Token, fill in a name and status, and press Create Token.
  4. 4
    4 · Copy it before you close the box
    KnowBe4 shows the token once. Once you close that window it cannot be viewed again, and a lost token is re-created rather than recovered.
Note
This is not the same key as the others
KnowBe4 issues several kinds of key. The Reporting API token is the one this connector uses. A User Event API token or a Product API token will be refused — and refused in a way that looks exactly like a wrong token, so it is worth checking which tab you created it on.

Connect it in Current

  1. 1
    Open the KnowBe4 card
    In Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find KnowBe4 in the Monitoring and security section.
  2. 2
    Add a row per partner
    Press the Add button under the account list. It is named for whatever your workspace calls the businesses you serve, so it reads Add partner account here. Give the row a name you will recognise — it is your label, shown beside that row's test result and in the mapping list — then pick the region and paste that account's token.
  3. 3
    Pick the region that matches where they sign in
    KnowBe4 runs five separate regions and a token works against exactly one. Match the address that account signs in at: training.knowbe4.com (United States), eu.knowbe4.com, ca.knowbe4.com, uk.knowbe4.com, or de.knowbe4.com.
  4. 4
    Press Test connection
    Current reads one account record per row to prove each token works, and reports the result for every row by the name you gave it. On success the set is stored server-side only — the browser never sees a token again.
Heads up
The wrong region looks exactly like a wrong token
Every KnowBe4 region answers a token it does not own with the same refusal a genuinely wrong token gets. There is no way to tell the two apart from the response, so if Test connection rejects a token you just copied, check the region against the address in your browser's bar before you create a new one. The US one is the trap: an admin signs in at training.knowbe4.com, which does not contain the word it needs.

How often it syncs, and what it costs your KnowBe4 account

KnowBe4 syncs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run reads the account summary, the phishing tests and the campaign list for every row you added.

KnowBe4 allows 2,000 API requests a day per account, and that allowance is your partner's — shared with their SIEM, any other tool wired into their console, and their own scripts. Current is built to stay a small share of it: roughly 20 to 40 requests a day per connected account for the regular reads. The training roll-up, which is the expensive one because it counts every person on every module, runs once a day rather than on all four passes, which is why the overdue figures update daily while the phishing numbers update every 6 hours.

Note
If the limit is reached
Current stops for the day and picks up on the next scheduled sync rather than retrying into the limit. The card says so, and it is not an error state — the connection is fine.

The read-only guarantee

Every request Current makes to KnowBe4 passes through a read-only guard that permits four specific read endpoints and nothing else: the account summary, the phishing test list, the training campaign list, and the enrollment counts. The wider KnowBe4 platform can create and delete users, edit groups, and launch or delete phishing and training campaigns; none of those paths exists in the connector's code, so a code bug cannot reach them. The two employee-data endpoints described above are excluded on the same basis. KnowBe4 stays the source of truth; Current only reads.

Map accounts to your companies

Each KnowBe4 account is one of your partners, and Current identifies it by its primary domain. Current tries the domain against your companies' own websites first, which is the stronger signal, then falls back to a normalized name match — lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped — and links only when exactly one company matches. Two companies that both fit stay unmapped for you to decide.

  1. 1
    Let the auto-matcher run first
    Every sync links each account to the one Current company its domain or name matches. Most map themselves.
  2. 2
    Open the mapping panel
    Integrations → KnowBe4 → Manage → Customer mapping. It opens on the Unmapped tab, which lists every account the matcher could not place.
  3. 3
    Map an account to its company
    On an unmapped row press Map, type a few letters of the Current company, and pick it. That account's tests and campaigns attach to the company right away, rather than waiting for the next sync.
  4. 4
    Fix a wrong match later
    The Mapped tab lists every linked account, and Unmap corrects a bad auto-match. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.
Note
An account can show a domain instead of a name
KnowBe4 falls the account name back to the domain when the organisation name is not set in its console, so an unmapped row may read northwind-traders.com rather than Northwind Traders. The name you gave the row on the card is shown beside it.

Where the data shows up

  • The company's People panel: the phish-prone rate from the latest completed test with the date it ran, and how many people are past due on training.
  • The company's KnowBe4 card: the latest test with its delivered count beside the rate, the clicked and reported split, a chip when anyone entered credentials or enabled a macro, and each active campaign's completion and overdue count.
  • The security chapter of a Strategic Business Review, beside the machine-side signals.
  • Dashboard metrics — the phish-prone rate per company and across your book, training completion, and how many people are overdue.
  • The company alert band: an awareness entry that warns when the latest test's phish-prone rate reaches 15%, or when a quarter of the people enrolled in active training are past due, and turns critical at 30%.

When something looks wrong

What you seeWhat it means
Test connection rejects a token you just copiedCheck the region first — a correct token pointed at the wrong region fails the same way a wrong one does. If the region is right, check you created it on the Reporting API tab rather than the Product API or User Event tab, then create a fresh token.
Test connection says the subscription does not include itThe Reporting API is sold on some KnowBe4 plans and not others. If Account Settings ▸ Account Integrations ▸ API has no Enable Reporting API Access tick box for that account, this is the reason, and it is settled with KnowBe4.
Some rows connected and others did notThe ones that answered are syncing. The card names the rows that did not and what KnowBe4 said about each — fix those and press Test connection again.
Phish-prone shows a dash rather than a numberThat account has no completed test that reported a rate yet. Current leaves it blank rather than showing 0%, which would read as a perfect result.
A training campaign says "still calculating"KnowBe4 answers with a placeholder instead of a percentage for campaigns it considers too large to calculate. Current shows that as unknown rather than 0% complete, which would look like nobody had started.
The overdue counts are blankThe training roll-up did not finish on the last daily pass. Current leaves all four counts blank together rather than publishing part of the picture — three people overdue reads as a small problem when the real number is three hundred.
Connected, and the account shows no usersSome KnowBe4 consoles are set to anonymise user data, and those accounts return nothing through the API by design. The connection is working; that account's console is configured not to share it.
Note
Who can do this, and disconnecting
Adding accounts, testing, mapping, and disconnecting are Tenant Admin actions; sales leadership can run a manual sync and read status. Disconnect stops the sync and skips your workspace on the schedule — the results already pulled stay put, and reconnecting resumes. Partner (read-only) viewers never see any of this data; it is blocked at the database, not just hidden.
Was this helpful?