What this integration contributes
Cofense Triage can contribute normalized employee-reported email and investigation outcomes. Reviewed examples include:phishing.real.reported— reports real phishing emailsemail.suspicious.reported— reports suspicious emailsphishing.real.targeted— targeted by real phishing campaigns
What you need
Cofense Triage uses OAuth2 client credentials. Create an API application in your Triage tenant and copy its client ID and client secret. There is no browser consent step — you paste both values into Living Security and it requests the token itself.Setup
1
Create a dedicated Cofense credential
In Cofense Triage, create an API application that can read reports. Keep the credential limited to reporting access. Record the client ID and client secret — Triage shows the secret once.
2
Confirm the Triage hostname
Record your full tenant hostname, such as
acme.managedphishme.com or the hostname assigned to your Cofense environment. Omit https:// when entering it in Living Security.Verify and troubleshoot
Verify that the connection test can read the current user and reports before waiting for the first synchronization.403 Forbidden
403 Forbidden
The credential cannot read reports. Grant the minimum reporting permission required by your Cofense tenant, then reconnect.
The Triage hostname cannot be reached
The Triage hostname cannot be reached
If your Triage tenant restricts API access by source IP address, this integration needs two sets of addresses allowlisted. Living Security mints the access token itself and renews it continuously, so token requests and scheduled syncs leave from different networks — and on Triage they reach the same hostname.
Reports appear but reporters do not
Reports appear but reporters do not
Reporter enrichment is available only on connection variants that expose the reporter endpoint. Report-derived signals can still populate from supported report data.

