All guides

Managers and administration

The manager console

What is on each page of the manager console, what the colours mean, and how to get the AI summary and the PDF report.

The manager console shows how your whole organisation is getting on with the training. It comes with Platform + manager console + audit and with Enterprise. Open it from the app's Profile page with Open the manager console. Only managers see it.

The figures come from your organisation's own completions, as recorded on the server. They are never compared with other organisations. The console starts out empty and fills in as your people complete lessons; there is nothing to set up.

The pages

PageWhat is there
OverviewThe key figures, activity, the share of wrong answers, module completion and a list of people who need attention.
ComplianceStatus by requirement, readiness, the evidence exports, the summary for management and the printable report.
PeopleEveryone with their figures, search and filters, reminders for inactive people, a CSV export and deleting a person.
DepartmentsThe department matrix and each department's people.
Management summaryWhere each member of your management body stands on the management path, and when they completed its lessons.
LessonsAll the content, and how each module has been taken up.
LeaderboardsThe people who have joined the leaderboard, with their points.
SettingsYour organisation's name, agreement and seats.

People and departments are managed on the Users and access page. See Inviting people, and seats.

What the colours mean

Every coloured figure also has an icon and a word next to it, so the status survives a black-and-white printout.

ColourWordWhen
GreenOn trackThe figure is at least 85% of its target.
AmberWatchThe figure is 60–84% of its target.
RedNeeds actionThe figure is under 60% of its target.
GreyNo dataThere is no figure yet.

A figure without a target of its own is measured against 100: 85 and over is green, 60–84 amber and under 60 red. Where lower is better, as with risk, the scale is turned round. Grey never means bad; it means the figure can't be worked out yet.

The key figures

  • Audit readiness: the share of your people who are up to date on the controls mapped to your requirements.
  • Retention-adjusted risk: lower is better. It weighs what people still remember, not just what they have completed.
  • Active this week: how many people did something in the last week.
  • Avg quiz score: the lesson quiz score over completed lessons.

Someone is up to date on a requirement once they have done at least 80% of the lessons mapped to it.

Readiness is worked out as completion 35%, quiz quality 25% and retention 40%. Retention weighs most because it tells you what stuck weeks after the lesson. If nobody has a figure for one part yet, that part is left out and the others carry its weight.

Departments and the department matrix

Once you have created departments on the Users and access page, or brought them in with the department column of the CSV import, the Departments page shows the department matrix. It has a row per department, and you choose Requirements or Competencies as its columns.

  • Requirements: each cell is the share of the department's people who are up to date on that requirement.
  • Competencies: each cell weights the completion of the competency's lessons at 60% and retention at 40%.

Open a department's row to see its people, their lessons and when they were last active.

On the People and Compliance pages you can narrow the figures to one department. The AI summary and the printed report always cover the whole organisation.

To move people between departments on the People page, select them, choose Move to and press Move.

The management summary

The Management summary page shows where each member of your management body stands on the management path. To use it, mark your management department on the Users and access page with Mark as management. One department can be marked, and it may consist of management only, such as the board and the CEO.

The page sets out what Article 20 of the NIS2 Directive (as your country's NIS2 law carries it; in Finland, section 10 of the Cybersecurity Act) and Article 4 of the AI Act ask of management. For each member it shows progress by requirement and their dated completions. Dated completions are evidence that supports showing management's familiarity with the subject. On their own they do not show that a requirement is met. There is more in Evidence for your auditor.

You can print the page or save it as a PDF with Print / save as PDF.

Reminding inactive people

Remind inactive on the People page sends a short email reminder to learners who haven't used Cyberact for 30 days. Before anything is sent you see how many people it will go to, and its subject and text.

  • The message is in Finnish and English, and it comes from support@cyberact.io.
  • Managers, disabled people and invited people don't get it.
  • Nobody gets a reminder more than once a day.
  • An organisation can send up to 200 reminders a day.

The AI summary

The Compliance page has a Summary for management card. It holds a short written summary of where your organisation stands, and the figures it was written from. The same summary shows on the Overview page when there is one.

  • The weekly summary is written every Monday at 5.30 (Finnish time) for the week before.
  • On demand: Generate summary writes a new one straight away, in the report's language. Next to the button you see how many more you can ask for today. If the figures haven't changed since the last summary, you get that one, and it doesn't count towards the day's limit.

The summary is written from your organisation's aggregated figures. They contain no names, email addresses or user identifiers, and groups of fewer than five people are merged. The summary says who wrote it: written by AI or compiled from the figures. The second is put together by fixed rules without AI, for example when AI is not in use for your organisation. AI can be switched off for your organisation with a change request to support@cyberact.io; see Privacy and your data.

The weekly summary is not emailed to you. It is always in the manager console.

The PDF report for management

Board summary on the Compliance page opens your browser's print dialog. It gives you a printable report: an executive summary, the key figures, six weeks of trends, status by requirement, competency by department, the cost and break-even (no forecast return) and what to do next. If you have created departments, it also has requirements by department and the members of your management body. To save it as a PDF, choose save as PDF as the printer.

The report carries the week's AI summary, and it ends by explaining how the figures were worked out.

The evidence exports

On the Compliance page you can download Training log (CSV), Evidence pack (CSV) and Server log (CSV), and on the People page Export CSV. What each one holds, and what it proves, is in Evidence for your auditor.