Current + KnowBe4 integration
A read-only KnowBe4 feed that brings phish-prone rates, phishing test outcomes and training progress into business reviews — with no employee names.
KnowBe4 is where most MSPs run security awareness: the simulated phishing tests and the training that follows them. Current's KnowBe4 integration is a read-only feed into the company record and the SBR/QBR module. It reads what KnowBe4 already measured and never writes back.
What the integration does
You add one KnowBe4 Reporting API token per partner account — the API is built around a single console, so a token reads one account and nothing else — and Current reads each account every six hours. The phish-prone rate from the latest completed test, that test's outcome counts, and every training campaign's progress land on the matching company record, staged as evidence for AI-assisted Strategic Business Reviews. Instead of screenshotting a KnowBe4 dashboard the week of the review, the numbers are already on the account when you open it.
What data flows
- Accounts — each KnowBe4 account by its primary domain, with subscription tier, seats, renewal date and current risk score, matched to your Current companies.
- Phishing tests — per test, the vendor's own counts: scheduled, delivered, opened, clicked, replied, attachment opened, macro enabled, credentials entered, QR scanned, reported and bounced, with the phish-prone rate and the template difficulty used.
- Training campaigns — status, start and end dates, completion percentage, and how many people are enrolled, finished, in progress, not started and past due.
- Thirteen months of test history, so the year-over-year comparison is always available.
What it deliberately does not read
KnowBe4's API can return a full employee directory and the list of which named employees failed a given test. Neither endpoint is in the connector. Every figure above is a count, and no person from a partner's staff is stored in Current. That is a design decision rather than a configuration one: the endpoints are absent from the connector's permitted-reads list, so they are unreachable.
Read-only by construction
Four read endpoints are permitted and nothing else. KnowBe4's platform can create users, edit groups, and launch or delete phishing and training campaigns; none of those paths is in the connector's code, so Current can never send a simulated phishing email to a partner's staff. The connector also stays a small share of KnowBe4's request allowance, which belongs to the partner's account and is shared with anything else wired into it.
Where it shows up
Every security chapter in a business review has the same gap: the machine signals are easy to produce and the human ones are not. An MSP running KnowBe4 for a partner like Northwind Traders can open the account and see that the last simulated phish went to 84 people, 11 clicked it and 26 reported it, that the phish-prone rate has moved from 31% to 12% across the year, and that 9 people are past due on the current training campaign. The review becomes a conversation about what changed rather than about who is pulling the export.
The same figures drive a company's People panel, the awareness alert on the company record, and dashboard metrics across the book — so a sales manager can see which accounts have a phish-prone rate worth a conversation without opening any of them. They sit beside the multi-factor coverage Duo reports, which is the other half of the people story.
Sources
- 1.KnowBe4 security awareness training — KnowBe4