Skip to main content

What this integration contributes

NINJIO can contribute workforce, training, and phishing-simulation outcomes. Reviewed examples include:
  • training.assigned — has assigned security training
  • training.completed — completes security training
  • training.passed — passes security training assessments
  • phishing.simulation.clicked — clicked a simulation without reporting
  • phishing.simulation.reported — reports phishing simulations
These examples show the types of normalized activity Living Security can use. See how integration data becomes signals.

What Living Security needs

Scopes: NINJIO scopes each API key per access point, with separate read and write permissions. Living Security needs read on three: employees, training and phishing. Write access is not needed and should not be granted. Required role: An Administrator on your NINJIO account. Only administrators can reach the Integration area where keys are created.
NINJIO shows a new key once only, at the moment it is created. Copy it straight into the Living Security Platform, or into a password vault, before you navigate away. A key you did not copy cannot be retrieved — you have to generate a replacement.

What Living Security retrieves

Learner phone numbers are not stored. NINJIO returns a phone number on its employee record. Living Security discards it before storing anything, because no Living Security feature uses it.

Prerequisites

  • A NINJIO account with API access.
  • Administrator access to admin.goninjio.com.
  • Learner email addresses in NINJIO that match the addresses your other connected systems use. Email is how Living Security matches a NINJIO learner to a person.

Part A — In NINJIO

Your NINJIO administrator completes these steps.
1

Open the Integration area

  1. Sign in to admin.goninjio.com as an administrator.
  2. Select Integration at the top right of the screen.
2

Create the API key

  1. Select New API Key.
  2. Give the key a name you will recognise later — for example Living Security.
  3. Grant read access to the employee, training and phishing access points.
  4. Leave write access unselected. Living Security only reads from NINJIO.
  5. Select Generate Key.
Copy the key now. NINJIO displays it once and cannot show it again.

Part B — In the Living Security Platform

The program owner completes this step, or the system admin if using delegated setup.
You are now connected to NINJIO.

How often data is retrieved

On first connection, Living Security retrieves the past 12 months of training completions, then keeps up incrementally. Phishing simulations are read once each and re-checked for two weeks after they end, so late clicks and late reports are still captured.
A first connection on a large NINJIO account can take several scheduled runs to finish reading everything. Each run reads as much as it can and the next one continues from where it stopped, so counts climb over the first day or two rather than appearing all at once.

Troubleshooting

The API key is wrong or incomplete. The most common cause is a key that was partially copied — NINJIO shows it once, so a truncated paste is easy to do and impossible to spot afterwards. Generate a new key in NINJIO and reconnect with it.
This is not a credential problem. The key authenticated, but one of the access points it needs was not granted read permission.Re-pasting the same key will not help. In NINJIO, create a key with read access to all three access points — employee, training and phishing — and reconnect with that one.
Check in NINJIO that at least one training campaign is active and has a simulation attached. A campaign with no simulation stays inactive and delivers nothing, so there are no results to retrieve.If campaigns are active, confirm the learners in them have email addresses on their NINJIO records. A learner with no email address cannot be matched to a person and is skipped.
That is the expected display for training a learner has not finished. Living Security records the assignment when the NINJIO simulation starts, and records the completion separately when NINJIO reports a completion date.
Living Security matches a NINJIO learner to a person by email address. A learner whose NINJIO email differs from the address your directory holds — a personal address, an old domain, or a typo — will not match.Correct the address in NINJIO and it will match on the next scheduled retrieval.
Living Security re-checks a phishing simulation for two weeks after it ends, then stops. Results that NINJIO records after that window are not picked up. Contact support if you need an older simulation re-read.