1️⃣ What is a smart group?
A smart group automatically brings together the employees who meet one or more criteria. Unlike a manual group, you don't maintain its list of members: it updates by itself as synchronisations run and as your employees act.
That is what lets you target a specific population without spending time on it every month: a phishing campaign for employees who have already been caught, a course for those falling behind, an SMS simulation for those whose number you have.
👉 To create a smart group: Team > Groups > Create group. Some groups also exist by default on your workspace.
2️⃣ The available criteria
Criteria can be combined with each other. They fall into four families.
👉 Training
Employees who have - or have not - completed a given course.
Employees overdue on more or fewer than X courses, with the option to restrict this to a specific programme year.
👉 Behaviour when faced with attacks
Clicking a link and handing over a password are not the same mistake. The two behaviours are targeted separately.
Employees who clicked a link, or who submitted data during a simulation. For each, you specify how many times and over which period: the last X simulations, a date range, or since the beginning.
Employees who reported — or did not report — an email over the last X days. A report counts whether it was a real attack or a simulation.
👍 Good to know: these criteria work across all three attack types: email, SMS and phone. See Understanding Smishing and 'Callback attacks'.
Three common targets:
Repeat clickers: clicked at least twice across their last 4 simulations.
Those who hand over their credentials: submitted data at least twice across their last 4 simulations.
Those who click but never go further: clicked at least once, and never submitted data.
💡 Why the distinction matters: an employee who clicks out of curiosity but stops at the form does not have the same training need as one who types in their password. The first has a checking reflex, the second does not. Handling them separately lets you send a light reminder to one group and deeper support to the other.
👉 Employee profile
Language: the group gathers the employees whose language matches the one you pick. For an employee with no language set, the workspace's default language applies.
Valid phone number: useful for building the audience of a Smishing campaign without checking numbers by hand. A group with no country restriction automatically includes every supported country.
Cyber Posture: available on workspaces running Cyber Missions. You can target an exact level, or an "at most" / "at least" level — for example employees whose posture is critical, at most weak, or at least good.
👉 Devices
Device type, operating system and OS version, provided you have enabled device synchronisation. See Synchronize your device fleet.
3️⃣ Two targeting examples
👉 Catching up with your most exposed employees
Employees who were caught in the last 90 days + who have not completed the Phishing course. You end up with a population you can address with a targeted course rather than a general announcement.
👉 Launching an SMS campaign with no preparation
Employees with a valid phone number. The group maintains itself as your directory evolves.
4️⃣ Best practices
Two to three criteria maximum. Beyond that, the audience shrinks very quickly and the campaign loses its point.
Check the headcount before launching. The number of employees in the group is shown as you create it: that is the best indicator of whether your targeting is too narrow.
A group evolves. An employee who completes their course leaves the "overdue" group. That is the expected behaviour: your recurring campaigns stay relevant without any intervention.
Key takeaways
A smart group updates itself: you define a rule, not a list.
Criteria cover training, behaviour when faced with attacks, the employee profile and their devices.
Cyber Posture is only available on workspaces running Cyber Missions.
Stick to two or three criteria to keep a usable audience.


