Skip to main content

Smart Variables in your Simulation templates

Smart Variables are elements inserted into an attack template, the value of which is calculated at the time of sending, for each recipient.

Smart Variables are elements inserted into an attack template whose value is worked out at send time, for each recipient. The same template therefore produces a different message depending on the employee targeted — without you having to create one variant per population.

👍 Good to know: Smart Variables are available on every workspace, for phishing as well as smishing.

1️⃣ They already work without you doing anything

Every template in the catalogue comes with Smart Variables preset in a way that fits the message content. If you have neither the time nor the inclination to customise your templates, they are usable as they are.

If you want to go further, every variable can be changed.

2️⃣ The main families of variables

👉 Dynamic variables

Their value adapts to the recipient, their workspace and the moment of sending. They cover in particular:

  • the recipient themselves — first name, last name, email, photo, identifier;

  • a colleague, a manager, a direct report or a company leader;

  • the workspace — name, logo;

  • relative dates, such as "tomorrow" or "next week";

  • random values, or an IP address that looks foreign relative to the recipient's time zone;

  • the service being impersonated.

👉 Static variables

Fixed text that you can edit freely — an event name, for instance. Some also accept dynamic variables inside the text.

👉 Pre-computed values

Dynamic values that can't be edited, generally generated for the attack — the current year in a message footer, for example.

3️⃣ Changing a variable

👉 Step 1: Click the variable in the template editor. A menu opens with the available options.

👉 Step 2: Pick another value — for instance the recipient's manager's name rather than a colleague's.

👉 Step 3: Or type in a fixed value, if that makes more sense in your context.

The menu only offers alternatives that make sense for that variable and its context: you don't have to sift through a list of dozens of options.

In a template created from scratch or generated from a prompt, you can insert a variable by typing / in the text: a menu shows every available variable, with search by name. Variables also work in an attachment's file name.

4️⃣ Quality depends on your data

This is the most important point in this article. The variables tied to people — colleague, manager, direct report, company leader — are only as accurate as your directory (or your CSV import, depending on the method) is complete, particularly on teams and manager relationships.

Riot applies fallbacks when data is missing. For a manager, for example: the recipient's direct manager, failing that the company leader set in the CEO fraud course settings, failing that someone from HR, failing that the wording "Human Resources".

💡 The right reflex: if a variable's value doesn't look credible to you, replace it with a fixed value rather than giving up on the template. It takes a second, and the attack stays realistic.

👉 Where the manager used comes from

The manager selected is the employee's manager in Riot, across the whole workspace: they don't need to be part of the campaign audience or the targeted group, they only need to be an active employee of the workspace.

Several sources can set a manager. Where they conflict, a change made by hand by an administrator is not overwritten by your directory synchronisation. If you delete that manual value, Riot reverts to the directory's.

5️⃣ The preview doesn't show exactly what the employee will see

⚠️ Important: Smart Variables are computed at send time, from the recipient's data. The preview shown in the campaign editor, however, uses your administrator context. The two can therefore differ. The gap is particularly visible when you create a campaign from an organization workspace targeting child workspaces.

You can also send yourself a preview of the template from the editor, to see it arrive in a real inbox.

6️⃣ Translation

A template's language is determined for each recipient at send time, based on the language recorded for that employee. To change an employee's language, change it at the source, in your directory.

  • In catalogue templates, only the message text changes with the recipient's language. Static variables aren't translated; dynamic ones are where it makes sense — a date adapts, a photo doesn't.

  • In your custom templates, editable content is translated if you enable automatic translation.

Key takeaways

  • Variables come preset: catalogue templates work with no configuration.

  • Their accuracy depends on the quality of your directory, particularly manager relationships.

  • If you doubt a value, replace it with a fixed one.

  • The preview uses your administrator context, not the recipient's.

Did this answer your question?