Skip to content

User Manual

FrikkieMalan edited this page Sep 3, 2026 · 6 revisions

User Guide

Overview

PhishShield is a phishing awareness and simulation platform. Employees receive realistic, simulated phishing emails in a safe environment, and then learn to recognise them, which earns them XP for reporting them correctly. This guide explains the processes of creating an account, logging in, navigating the website, and a description of what each page does. The hope is that this serves as a detailed manual for anyone using PhishShield for the first time and are unsure of how to use the website/application and its features.

image

Getting Started

Creating an Account (Registration)

Registration is a three-step process, shown as a numbered checklist on the left of the screen as you go.

Step 1: Account details. Enter your first name, last name, work email, and a password. A small checklist under the password field shows in real time whether it's long enough and contains an uppercase letter, a number, and a symbol.

image

Step 2: Organisation. Choose your department (IT and Security, Finance, Human Resources, Legal and Compliance, Operations, or Executive) and your role (User, Analyst, or Admin). Note that an administrator can always change your role later in the event that you incorrectly selected an option in this field.

image

Step 3: Check your email. After submitting Step 2, PhishShield sends a confirmation email to the address you registered with. You will see a "Check your email" message on screen. Click the link in that email to verify and activate your account, then come back and log in.

image

Note: Email delivery for account verification is still being stabilised by the development team. If you register and don't receive an email within a few minutes (check spam too), reach out using the Help Centre's "Contact Support" link rather than assuming something is wrong with your details. Or otherwise, contact your admin.

Logging In

Once your account is verified, go to the login page and enter your email and password.

The first time you log in after registering, you will be asked to enter a one-time verification code sent to your email, as an extra security step. After that first successful check, future logins only need your email and password.

image

Note: As noted above, the one-time verification is still being stabilised, and therefore it is possible to receive subesequent emails and requests for login attempts beyond the first initial login. Please bear with us during this time.

Forgot your password? Click "Forgot password?" on the login page, enter your email, and follow the reset link sent to you.

Screenshot: The "Forgot password" popup, both the email-entry state and the "check your email" confirmation state.

Finding Your Way Around

Once logged in, every page shares the same layout: a sidebar on the left for navigation, and a top bar across the top for account-level actions.

image

The Top Bar

From left to right: a button to collapse/expand the sidebar (useful on smaller screens), the current page's title, and then on the right:

  • Light/dark mode toggle (switches the whole app's colour theme).
  • Notifications bell (a red dot appears when there's something new).
  • Help Centre (?) (opens the in-app Help Centre; covered below).
  • Your avatar (click it to go to your profile page).
image

The Left Sidebar

The sidebar is organised into three sections, and what you see depends on your role. Note that some items are only visible to Analysts and Admins:

  • MAIN — Dashboard, Campaigns (Analyst/Admin only), Users (Analyst/Admin only), Training, Leaderboard
  • ANALYTICS — Analytics (Analyst/Admin only), Reports (Analyst/Admin only)
  • SYSTEM — Settings

Below the navigation links, a Security Score widget shows an overall score out of 100. A Sign out button sits at the very bottom.

image

Page-by-Page Guide

Dashboard

What you see here depends on your role.

  • Regular Users see their own XP total (with today's change highlighted), their organisation rank, reports filed, and current streak, plus a personal detection-accuracy graph and a list of assigned training.
  • Analysts and Admins instead see organisation-wide metrics (emails sent, click rate, reports filed, at-risk users), a detection-rate-over-time chart, a recent campaigns table, a "Top Defenders" leaderboard preview, and an alert banner flagging users who need extra training.
image

Leaderboard

Shows two views, switchable via tabs:

  • Users: Everyone's rank and XP, with your own row highlighted and marked "You". The top three are marked with medals. A search box filters by name or department.
  • Departments: Department-level totals, switchable between Total XP and Average XP, with a size filter to compare larger and smaller teams.

Your own XP updates live on this page the moment you earn more, without needing to refresh.

image

Training

Lists training modules assigned to you, each showing its status (Not Started / In Progress / Completed), estimated time, number of lessons, and due date if any. Starting a module marks it in progress; modules with a quiz let you take it once you're ready. Scoring 70% or higher completes the module and awards XP, and you can retake a quiz if you don't pass.

image

Campaigns (Analyst/Admin only)

Lists phishing simulation campaigns with their status (Draft, Scheduled, Active, Complete) and headline stats (sent/clicked/reported). Admins additionally see buttons to create a new phishing email, send an existing one, or schedule a campaign. Clicking a campaign opens a detail page with per-user outcomes (reported / clicked / no response) and response times.

image image

Users (Analyst/Admin only)

A searchable, filterable, sortable list of every registered user, showing name, email, role, department, XP, and join date. Clicking "Manage" on a user opens actions like editing their role, viewing their profile, resetting their password, suspending/reinstating, or removing them (admin-only actions are restricted further where relevant).

image image

Analytics (Analyst/Admin only)

Organisation-wide KPIs (detection rate, click rate, total simulations, at-risk users, training completion), a detection-rate-over-time chart, a per-department detection-rate breakdown, an at-risk-users list, and a campaign performance summary table.

image

Reports (Analyst/Admin only)

A list of generated reports (monthly summaries, campaign reports, department risk assessments, training completion reports) with a download option for each, and a button to generate a new one.

Note: This page is under construction and hence not yet available.

Settings

Five tabs: Profile (name, email, and your role — role changes need an administrator), Security (change password, sign out of all devices), Appearance (light/dark theme), Accessibility (text size, high-contrast mode, reduced motion, screen-reader optimisation), and Notifications (training reminders, leaderboard updates, weekly digest).

image

Help Centre

Covered in full in the separate Help Centre Guide wiki page. In short, it's a ?-icon-accessible page with Quick Links, step-by-step Tutorials, and Frequently Asked Questions, open to every role.

image

Your Profile

Reached by clicking your avatar in the top bar. Shows your account details (name, email, department, role) and a summary of your progress (current XP total, badges or achievements earned, and completed training modules). This is also where you can see your all-time reporting stats, separate from the Leaderboard's view.

image

Reporting Emails using the Outlook Add-in

PhishShield includes an Outlook add-in that lets you report a suspicious email directly from your inbox. Once installed, a "Report Phishing" button appears in the Outlook ribbon when you have an email open or selected. Clicking it submits the email directly to PhishShield for scoring, awards you XP if it was a simulated campaign email.

image

If the add-in feature is unavailable, the xml manifest file needs to be uploaded. This can be done by downloading the manifest file at https://capstone-five-guys.dns.net.za/addin/manifest.xml, and saving the manifest.xml file. In MS Outlook, in the top ribbon, click on the "Add-ins" group in the ribbon, followed by clicking on "Get add-ins". On the modal that pops up click "My add-ins" and then click "Add a custom add-in", followed by "from file" and then upload the manifest.xml that you previously saved.

image1 image2 image3 image4

Clone this wiki locally