Skip to main content
This glossary defines terms as they are used in the Living Security Platform. Product availability can depend on your organization’s entitlements and configuration. A · B · C · D · E · H · I · L · M · N · O · P · R · S · T · W

A

Achievement

A certificate or badge credential issued to a learner after the learner meets configured program criteria. Templates, issued credentials, engagement settings, and activity are managed under Outcomes → Recognition.

Action

One executable step in a playbook, such as assigning training, sending a nudge, creating a supported external-system task, or starting a simulation. Administrators compose and monitor actions through Playbooks.

Activity

An observed occurrence associated with a workforce entity, such as a training interaction, reported message, security event, or other source-system event. Activities are evidence; they are not the same as integration events or administrative audit history.

Agent

An AI agent represented in Workforce. Agents are non-human workforce entities with their own identity, activity, and risk context. Service accounts, API access keys, and certificates are credentials or identifiers and should not automatically be treated as AI agents.

Assignment

A request for a person to complete training or another supported learner task. An assignment records what was assigned and to whom; enrollment records participation in the learning experience when that distinction is exposed.

B

Behavior

Observed actions that affect human risk, such as reporting a suspicious message, interacting with a simulation, or completing assigned training. Behavior is one HRI component.

Benchmark

A comparison point used to interpret a metric. A benchmark may come from an approved peer, industry, or organizational baseline; availability depends on the report or metric.

C

Channel

A configured path for delivering supported communications to people, such as Email, Slack, Microsoft Teams, or Google Chat. Channels are configured under Settings → Communications → Channels.

Cohort

A saved group used for repeatable analysis, measurement, or playbook targeting. Cohorts can use static membership or supported dynamic criteria. Unlike a segment, a cohort persists in the platform.

Communication Log

The history of communication messages and delivery attempts. Use it to inspect channel, route, status, provider or SMTP response, attempts, and rejected recipients when those details are available.

Connection

An authenticated relationship between one Living Security organization and one external provider account or tenant. A connection can expose one or more streams and has its own health, pause, reauthorization, and removal lifecycle.

Content Studio

The Toolkit capability for creating and managing supported training and nudge content. Available creation tools can depend on entitlements and release status.

Course

A structured learning experience composed of one or more training modules.

D

Dashboard

A configurable Outcomes view that presents selected metrics and visualizations. “Dashboard” can also refer generally to the customer administrator application; use the surrounding context to distinguish them.

Delivery Policy

Organization-level communication rules that control supported timing, limits, quiet hours, or related delivery behavior. A delivery policy is not an access-control or endpoint-enforcement policy.

E

Enrollment

A learner’s participation record in an assigned course or learning experience, including supported progress and completion state.

Entity

A stable workforce subject managed by Living Security. Current workforce entity types are person and agent. Source-system identifiers attach to an entity but do not replace its stable identity.

H

HRI (Human Risk Index)

A composite score from 0–1000 measuring an individual or group’s security vigilance. Higher scores indicate greater vigilance and lower risk. HRI combines Behavior, Threat, and Identity components. See Human Risk Index.

Human Risk Management (HRM)

The practice of identifying, prioritizing, reducing, and measuring security risk associated with people and other workforce entities. HRM combines security and workforce data with targeted interventions and outcome measurement.

I

Identity

A source-associated representation of a person or agent, including identifiers and attributes such as email, employee number, provider object ID, role, department, or manager. Multiple identities can resolve to one stable entity. Identity is also one HRI component.

Insight

A surfaced observation about a potentially useful pattern, trend, anomaly, or risk in available organizational data. Insights appear in Intelligence and should be evaluated with their supporting data before action.

Integration

A supported capability for exchanging data or actions between Living Security and an external system. Inbound integrations contribute identities, activities, or signals; outbound capabilities deliver communications or supported events.

Intelligence

The program-loop area used to investigate signals, patterns, and prioritized findings from connected data.

L

Livvy

The AI assistant in the Living Security Platform. Livvy can explain supported concepts, investigate data available to the current user, and help prepare supported work. Its responses are constrained by permissions, connected data, and enabled capabilities.

M

Metric

A defined measurement used in Outcomes, dashboards, reports, or program analysis. A metric specifies what is measured and how results should be interpreted.

Module

An individual unit within a course, such as a video, quiz, document, or supported interactive block.

Monitored Source

A workforce identity source (built-in directory stream or connected integration) that can confer monitored status on people when they are active and match configured conditions. Configure sources under Settings → Monitored Sources.

N

Notification

A message sent through a configured channel. Notifications include operational and program communications; their availability and timing can be controlled by playbooks and delivery policies.

Nudge

A short, targeted communication intended to reinforce or change a security behavior. A nudge can be delivered through supported email or messaging channels.

O

Outcomes

The program-loop area for measuring program activity and change through metrics, dashboards, reports, scorecards, snapshots, and achievements.

P

Passwordless Engage Access

A supported magic-link path that allows a learner to open Engage without an SSO session. Administrators configure and monitor it under Settings → Passwordless Access when available.

Person / People

A human workforce entity. “Person” is singular and “people” is plural.

Playbook

A versioned orchestration of triggers, audience selection, actions, timing, and supported approvals used to run an intervention. Playbooks are created and monitored in the Playbooks area.

Playbook Run

One execution of a playbook for its selected audience and configuration. Run status and action results provide operational evidence separate from the playbook definition.

Program Maturity

An assessment of an organization’s current human risk management practices across defined dimensions. The Journey Map uses the assessment to surface potential Level Up work.

Program Owner

The customer administrator responsible for running the human risk program: coordinating integrations, investigating risk, preparing playbooks, and measuring outcomes. “Program owner” describes responsibility and does not by itself grant a particular platform role.

R

Recognition

The Outcomes section where program owners design certificates and badges, issue credentials, and optionally configure points, ranks, leaderboards, and earning rules. Navigate to Outcomes → Recognition. Engagement settings live on the Engagement tab.

Report

A structured presentation or export of program data for a defined audience or purpose. Reports may use metrics, tables, narrative, or scheduled delivery depending on the supported report type.

Report Button

A client-side control, such as an Outlook add-in, browser extension, or embedded email control, that lets a person report a suspicious message.

Resilience Ratio

A simulation effectiveness measure comparing people who reported a simulation with people who clicked or otherwise failed it. Use the definition shown by the relevant simulation report for its exact calculation.

Risk Category

An HRI score band. Current bands are High Vigilance (800–1000), Somewhat Vigilant (600–799), Neutral (400–599), Somewhat Risky (200–399), and High Risk (0–199).

Run

One execution of a sync, integration action, playbook, upload, or other operation. Always identify the owning object when discussing a run because statuses and retry behavior differ.

S

Scorecard

A learner-facing Engage view that presents an individual’s supported score, factors, recognition, and improvement opportunities.

Security Score

A customer-configured score used in supported scorecard experiences. It is distinct from HRI, which uses the platform’s 0–1000 vigilance scale.

Segment

An ad hoc, URL-backed workforce view filtered by a single supported organizational attribute, such as department, job title, division, cost center, organization, or locale. Segments are computed on demand and are not saved cohorts.

Signal

A defined indicator derived from activities or source data and used in supported analysis. Signals can represent risky, protective, or neutral evidence depending on their definition.

Simulation

A controlled exercise used to observe workforce response to a security scenario, such as a phishing simulation. Simulation definitions, runs, participants, and results are distinct records.

Snapshot

An immutable capture of a supported dashboard, metric set, or report state at a particular time, used for historical comparison or sharing where available.

Stream

A provider-specific data model or feed exposed through an integration connection. Streams can be enabled or paused independently and produce sync runs.

Sync

The configuration that ingests one stream from a connected provider. A sync has state and run history; the connection’s authentication state alone does not prove a sync is delivering data.

System Administrator

The person who administers a connected source system and can create or approve the credentials, consent, scopes, or allowlists required by that provider. This responsibility does not automatically grant access to Living Security.

T

Template

A reusable definition used to create supported content, communications, reports, achievements, or playbooks. A template is not a run or an issued instance.

Threat

External malicious activity targeting a person, such as phishing or other attack activity represented in connected data. Threat is one HRI component.

Training

Educational content assigned to people to build or reinforce security knowledge and behavior.

W

Workforce

The organization-scoped collection of people and AI agents managed and analyzed by Living Security.

Human Risk Index

Review the HRI scale, components, and vigilance bands.

Platform Overview

See how Workforce, Intelligence, Playbooks, and Outcomes connect.

Integrations Overview

Understand connections, streams, syncs, actions, and uploads.

Segments

Compare ad hoc segments with saved cohorts.